OpenSSL 结构体

1、X509_STORE

头文件:x509_vfy.h

定义

typedef struct x509_store_st X509_STORE;
struct x509_store_st
{
    /* The following is a cache of trusted certs */
    int cache;     /* if true, stash any hits */
    STACK_OF(X509_OBJECT) *objs;    /* Cache of all objects */

    /* These are external lookup methods */
    STACK_OF(X509_LOOKUP) *get_cert_methods;

    X509_VERIFY_PARAM *param;

    /* Callbacks for various operations */
    int (*verify)(X509_STORE_CTX *ctx);    /* called to verify a certificate */
    int (*verify_cb)(int ok,X509_STORE_CTX *ctx);    /* error callback */
    int (*get_issuer)(X509 **issuer, X509_STORE_CTX *ctx, X509 *x);    /* get issuers cert from ctx */
    int (*check_issued)(X509_STORE_CTX *ctx, X509 *x, X509 *issuer); /* check issued */
    int (*check_revocation)(X509_STORE_CTX *ctx); /* Check revocation status of chain */
    int (*get_crl)(X509_STORE_CTX *ctx, X509_CRL **crl, X509 *x); /* retrieve CRL */
    int (*check_crl)(X509_STORE_CTX *ctx, X509_CRL *crl); /* Check CRL validity */
    int (*cert_crl)(X509_STORE_CTX *ctx, X509_CRL *crl, X509 *x); /* Check certificate against CRL */
    STACK_OF(X509) * (*lookup_certs)(X509_STORE_CTX *ctx, X509_NAME *nm);
    STACK_OF(X509_CRL) * (*lookup_crls)(X509_STORE_CTX *ctx, X509_NAME *nm);
    int (*cleanup)(X509_STORE_CTX *ctx);

    CRYPTO_EX_DATA ex_data;
    int references;
} /* X509_STORE */;

2、SSL_METHOD

头文件:ssl.h

定义

typedef struct ssl_method_st SSL_METHOD;
struct ssl_method_st
{
    int version;
    int (*ssl_new)(SSL *s);
    void (*ssl_clear)(SSL *s);
    void (*ssl_free)(SSL *s);
    int (*ssl_accept)(SSL *s);
    int (*ssl_connect)(SSL *s);
    int (*ssl_read)(SSL *s,void *buf,int len);
    int (*ssl_peek)(SSL *s,void *buf,int len);
    int (*ssl_write)(SSL *s,const void *buf,int len);
    int (*ssl_shutdown)(SSL *s);
    int (*ssl_renegotiate)(SSL *s);
    int (*ssl_renegotiate_check)(SSL *s);
    long (*ssl_get_message)(SSL *s, int st1, int stn, int mt, long
                            max, int *ok);
    int (*ssl_read_bytes)(SSL *s, int type, unsigned char *buf, int len,
                          int peek);
    int (*ssl_write_bytes)(SSL *s, int type, const void *buf_, int len);
    int (*ssl_dispatch_alert)(SSL *s);
    long (*ssl_ctrl)(SSL *s,int cmd,long larg,void *parg);
    long (*ssl_ctx_ctrl)(SSL_CTX *ctx,int cmd,long larg,void *parg);
    const SSL_CIPHER *(*get_cipher_by_char)(const unsigned char *ptr);
    int (*put_cipher_by_char)(const SSL_CIPHER *cipher,unsigned char *ptr);
    int (*ssl_pending)(const SSL *s);
    int (*num_ciphers)(void);
    const SSL_CIPHER *(*get_cipher)(unsigned ncipher);
    const struct ssl_method_st *(*get_ssl_method)(int version);
    long (*get_timeout)(void);
    struct ssl3_enc_method *ssl3_enc; /* Extra SSLv3/TLS stuff */
    int (*ssl_version)(void);
    long (*ssl_callback_ctrl)(SSL *s, int cb_id, void (*fp)(void));
    long (*ssl_ctx_callback_ctrl)(SSL_CTX *s, int cb_id, void (*fp)(void));
};

3、SSL_METHOD

头文件:ssl.h

定义

typedef struct ssl_method_st SSL_METHOD;
struct ssl_method_st
{
    int version;
    int (*ssl_new)(SSL *s);
    void (*ssl_clear)(SSL *s);
    void (*ssl_free)(SSL *s);
    int (*ssl_accept)(SSL *s);
    int (*ssl_connect)(SSL *s);
    int (*ssl_read)(SSL *s,void *buf,int len);
    int (*ssl_peek)(SSL *s,void *buf,int len);
    int (*ssl_write)(SSL *s,const void *buf,int len);
    int (*ssl_shutdown)(SSL *s);
    int (*ssl_renegotiate)(SSL *s);
    int (*ssl_renegotiate_check)(SSL *s);
    long (*ssl_get_message)(SSL *s, int st1, int stn, int mt, long
                            max, int *ok);
    int (*ssl_read_bytes)(SSL *s, int type, unsigned char *buf, int len,
                          int peek);
    int (*ssl_write_bytes)(SSL *s, int type, const void *buf_, int len);
    int (*ssl_dispatch_alert)(SSL *s);
    long (*ssl_ctrl)(SSL *s,int cmd,long larg,void *parg);
    long (*ssl_ctx_ctrl)(SSL_CTX *ctx,int cmd,long larg,void *parg);
    const SSL_CIPHER *(*get_cipher_by_char)(const unsigned char *ptr);
    int (*put_cipher_by_char)(const SSL_CIPHER *cipher,unsigned char *ptr);
    int (*ssl_pending)(const SSL *s);
    int (*num_ciphers)(void);
    const SSL_CIPHER *(*get_cipher)(unsigned ncipher);
    const struct ssl_method_st *(*get_ssl_method)(int version);
    long (*get_timeout)(void);
    struct ssl3_enc_method *ssl3_enc; /* Extra SSLv3/TLS stuff */
    int (*ssl_version)(void);
    long (*ssl_callback_ctrl)(SSL *s, int cb_id, void (*fp)(void));
    long (*ssl_ctx_callback_ctrl)(SSL_CTX *s, int cb_id, void (*fp)(void));
};

4、SSL_CTX

头文件:ssl.h

定义

typedef struct ssl_ctx_st SSL_CTX;
struct ssl_ctx_st
{
    const SSL_METHOD *method;

    STACK_OF(SSL_CIPHER) *cipher_list;
    /* same as above but sorted for lookup */
    STACK_OF(SSL_CIPHER) *cipher_list_by_id;

    struct x509_store_st /* X509_STORE */ *cert_store;
    LHASH_OF(SSL_SESSION) *sessions;
    /* Most session-ids that will be cached, default is
     * SSL_SESSION_CACHE_MAX_SIZE_DEFAULT. 0 is unlimited. */
    unsigned long session_cache_size;
    struct ssl_session_st *session_cache_head;
    struct ssl_session_st *session_cache_tail;

    /* This can have one of 2 values, ored together,
     * SSL_SESS_CACHE_CLIENT,
     * SSL_SESS_CACHE_SERVER,
     * Default is SSL_SESSION_CACHE_SERVER, which means only
     * SSL_accept which cache SSL_SESSIONS. */
    int session_cache_mode;

    /* If timeout is not 0, it is the default timeout value set
     * when SSL_new() is called.  This has been put in to make
     * life easier to set things up */
    long session_timeout;

    /* If this callback is not null, it will be called each
     * time a session id is added to the cache.  If this function
     * returns 1, it means that the callback will do a
     * SSL_SESSION_free() when it has finished using it.  Otherwise,
     * on 0, it means the callback has finished with it.
     * If remove_session_cb is not null, it will be called when
     * a session-id is removed from the cache.  After the call,
     * OpenSSL will SSL_SESSION_free() it. */
    int (*new_session_cb)(struct ssl_st *ssl,SSL_SESSION *sess);
    void (*remove_session_cb)(struct ssl_ctx_st *ctx,SSL_SESSION *sess);
    SSL_SESSION *(*get_session_cb)(struct ssl_st *ssl,
                                   unsigned char *data,int len,int *copy);

    struct
    {
        int sess_connect;    /* SSL new conn - started */
        int sess_connect_renegotiate;/* SSL reneg - requested */
        int sess_connect_good;    /* SSL new conne/reneg - finished */
        int sess_accept;    /* SSL new accept - started */
        int sess_accept_renegotiate;/* SSL reneg - requested */
        int sess_accept_good;    /* SSL accept/reneg - finished */
        int sess_miss;        /* session lookup misses  */
        int sess_timeout;    /* reuse attempt on timeouted session */
        int sess_cache_full;    /* session removed due to full cache */
        int sess_hit;        /* session reuse actually done */
        int sess_cb_hit;    /* session-id that was not
                     * in the cache was
                     * passed back via the callback.  This
                     * indicates that the application is
                     * supplying session-id‘s from other
                     * processes - spooky :-) */
    } stats;

    int references;

    /* if defined, these override the X509_verify_cert() calls */
    int (*app_verify_callback)(X509_STORE_CTX *, void *);
    void *app_verify_arg;
    /* before OpenSSL 0.9.7, ‘app_verify_arg‘ was ignored
     * (‘app_verify_callback‘ was called with just one argument) */

    /* Default password callback. */
    pem_password_cb *default_passwd_callback;

    /* Default password callback user data. */
    void *default_passwd_callback_userdata;

    /* get client cert callback */
    int (*client_cert_cb)(SSL *ssl, X509 **x509, EVP_PKEY **pkey);

    /* cookie generate callback */
    int (*app_gen_cookie_cb)(SSL *ssl, unsigned char *cookie,
                             unsigned int *cookie_len);

    /* verify cookie callback */
    int (*app_verify_cookie_cb)(SSL *ssl, unsigned char *cookie,
                                unsigned int cookie_len);

    CRYPTO_EX_DATA ex_data;

    const EVP_MD *rsa_md5;/* For SSLv2 - name is ‘ssl2-md5‘ */
    const EVP_MD *md5;    /* For SSLv3/TLSv1 ‘ssl3-md5‘ */
    const EVP_MD *sha1;   /* For SSLv3/TLSv1 ‘ssl3->sha1‘ */

    STACK_OF(X509) *extra_certs;
    STACK_OF(SSL_COMP) *comp_methods; /* stack of SSL_COMP, SSLv3/TLSv1 */

    /* Default values used when no per-SSL value is defined follow */

    void (*info_callback)(const SSL *ssl,int type,int val); /* used if SSL‘s info_callback is NULL */

    /* what we put in client cert requests */
    STACK_OF(X509_NAME) *client_CA;

    /* Default values to use in SSL structures follow (these are copied by SSL_new) */

    unsigned long options;
    unsigned long mode;
    long max_cert_list;

    struct cert_st /* CERT */ *cert;
    int read_ahead;

    /* callback that allows applications to peek at protocol messages */
    void (*msg_callback)(int write_p, int version, int content_type, const void *buf, size_t len, SSL *ssl, void *arg);
    void *msg_callback_arg;

    int verify_mode;
    unsigned int sid_ctx_length;
    unsigned char sid_ctx[SSL_MAX_SID_CTX_LENGTH];
    int (*default_verify_callback)(int ok,X509_STORE_CTX *ctx); /* called ‘verify_callback‘ in the SSL */

    /* Default generate session ID callback. */
    GEN_SESSION_CB generate_session_id;

    X509_VERIFY_PARAM *param;

#if 0
    int purpose;        /* Purpose setting */
    int trust;        /* Trust setting */
#endif

    int quiet_shutdown;

    /* Maximum amount of data to send in one fragment.
     * actual record size can be more than this due to
     * padding and MAC overheads.
     */
    unsigned int max_send_fragment;

#ifndef OPENSSL_ENGINE
    /* Engine to pass requests for client certs to
     */
    ENGINE *client_cert_engine;
#endif

#ifndef OPENSSL_NO_TLSEXT
    /* TLS extensions servername callback */
    int (*tlsext_servername_callback)(SSL*, int *, void *);
    void *tlsext_servername_arg;
    /* RFC 4507 session ticket keys */
    unsigned char tlsext_tick_key_name[16];
    unsigned char tlsext_tick_hmac_key[16];
    unsigned char tlsext_tick_aes_key[16];
    /* Callback to support customisation of ticket key setting */
    int (*tlsext_ticket_key_cb)(SSL *ssl,
                                unsigned char *name, unsigned char *iv,
                                EVP_CIPHER_CTX *ectx,
                                HMAC_CTX *hctx, int enc);

    /* certificate status request info */
    /* Callback for status request */
    int (*tlsext_status_cb)(SSL *ssl, void *arg);
    void *tlsext_status_arg;

    /* draft-rescorla-tls-opaque-prf-input-00.txt information */
    int (*tlsext_opaque_prf_input_callback)(SSL *, void *peerinput, size_t len, void *arg);
    void *tlsext_opaque_prf_input_callback_arg;
#endif

#ifndef OPENSSL_NO_PSK
    char *psk_identity_hint;
    unsigned int (*psk_client_callback)(SSL *ssl, const char *hint, char *identity,
                                        unsigned int max_identity_len, unsigned char *psk,
                                        unsigned int max_psk_len);
    unsigned int (*psk_server_callback)(SSL *ssl, const char *identity,
                                        unsigned char *psk, unsigned int max_psk_len);
#endif

#ifndef OPENSSL_NO_BUF_FREELISTS
#define SSL_MAX_BUF_FREELIST_LEN_DEFAULT 32
    unsigned int freelist_max_len;
    struct ssl3_buf_freelist_st *wbuf_freelist;
    struct ssl3_buf_freelist_st *rbuf_freelist;
#endif

#ifndef OPENSSL_NO_TLSEXT

# ifndef OPENSSL_NO_NEXTPROTONEG
    /* Next protocol negotiation information */
    /* (for experimental NPN extension). */

    /* For a server, this contains a callback function by which the set of
     * advertised protocols can be provided. */
    int (*next_protos_advertised_cb)(SSL *s, const unsigned char **buf,
                                     unsigned int *len, void *arg);
    void *next_protos_advertised_cb_arg;
    /* For a client, this contains a callback function that selects the
     * next protocol from the list provided by the server. */
    int (*next_proto_select_cb)(SSL *s, unsigned char **out,
                                unsigned char *outlen,
                                const unsigned char *in,
                                unsigned int inlen,
                                void *arg);
    void *next_proto_select_cb_arg;
# endif
    /* SRTP profiles we are willing to do from RFC 5764 */
    STACK_OF(SRTP_PROTECTION_PROFILE) *srtp_profiles;
#endif
};

X509_VERIFY_PARAM

头文件:x509_vfy.h

定义

/* This structure hold all parameters associated with a verify operation
 * by including an X509_VERIFY_PARAM structure in related structures the
 * parameters used can be customized
 */

typedef struct X509_VERIFY_PARAM_st
{
    char *name;
    time_t check_time;    /* Time to use */
    unsigned long inh_flags; /* Inheritance flags */
    unsigned long flags;    /* Various verify flags */
    int purpose;        /* purpose to check untrusted certificates */
    int trust;        /* trust setting to check */
    int depth;        /* Verify depth */
    STACK_OF(ASN1_OBJECT) *policies;    /* Permissible policies */
} X509_VERIFY_PARAM;

_STACK

头文件:stack.h

定义

typedef struct stack_st
{
    int num;
    char **data;
    int sorted;

    int num_alloc;
    int (*comp)(const void *, const void *);
} _STACK;  /* Use STACK_OF(...) instead */

X509_LOOKUP

头文件:x509_vfy.h

定义

typedef struct x509_lookup_st X509_LOOKUP;

/* This is the functions plus an instance of the local variables. */
struct x509_lookup_st
{
    int init;            /* have we been started */
    int skip;            /* don‘t use us. */
    X509_LOOKUP_METHOD *method;    /* the functions */
    char *method_data;        /* method data */

    X509_STORE *store_ctx;    /* who owns us */
} /* X509_LOOKUP */;

X509_LOOKUP_METHOD

头文件:x509_vfy.h

定义

/* This is a static that defines the function interface */
typedef struct x509_lookup_method_st
{
    const char *name;
    int (*new_item)(X509_LOOKUP *ctx);
    void (*free)(X509_LOOKUP *ctx);
    int (*init)(X509_LOOKUP *ctx);
    int (*shutdown)(X509_LOOKUP *ctx);
    int (*ctrl)(X509_LOOKUP *ctx,int cmd,const char *argc,long argl,char **ret);
    int (*get_by_subject)(X509_LOOKUP *ctx,int type,X509_NAME *name,X509_OBJECT *ret);
    int (*get_by_issuer_serial)(X509_LOOKUP *ctx,int type,X509_NAME *name,ASN1_INTEGER *serial,X509_OBJECT *ret);
    int (*get_by_fingerprint)(X509_LOOKUP *ctx,int type,unsigned char *bytes,int len,X509_OBJECT *ret);
    int (*get_by_alias)(X509_LOOKUP *ctx,int type,char *str,int len,X509_OBJECT *ret);
} X509_LOOKUP_METHOD;
时间: 2024-08-25 12:57:28

OpenSSL 结构体的相关文章

关于结构体

1.结构体(struct)是由一系列具有相同类型或不同类型的数据构成的数据集合,叫做结构. typedef struct People { int a; char b; double c; }P: 其中:struct是关键词, People是标签, a b c是成员, P是此结构体声明的变量. 于是在声明变量的时候就可:P p1; 这里的P实际上就是struct People的别名.P==struct People 另外这里也可以不写People(于是也不能struct People p1;了,

Linux C中结构体初始化

    在阅读GNU/Linux内核代码时,我们会遇到一种特殊的结构初始化方式.该方式是某些C教材(如谭二版.K&R二版)中没有介绍过的.这种方式称为指定初始化(designated initializer).下面我们看一个例子,Linux-2.6.x/drivers/usb/storage/usb.c中有这样一个结构体初始化项目: static struct usb_driver usb_storage_driver = { .owner = THIS_MODULE, .name = "

在Swift结构体中如何实现写时复制?

结构体(Struct)在Swift语言中占有重要地位,在Swift标准库中,大约有90%的公开类型都是结构体,包括我们常用的Array.String.Dictionary.结构体相比类,一个最重要的特性就是它是值类型,而类似引用类型.值类型是通过复制值来赋值的,而不是引用同一个内存地址,这样就不存在数据共享的问题,能防止意外的数据改变,并且它是线程安全的. 举一个很简单的例子,在objc中,数组是类,是引用类型,在Swift中,数组是结构体,是值类型.因此下面的代码中: let array1 =

结构体的大小

系统在存储结构体变量时存在地址对齐问题,编译器在编译程序时会遵循两条原则: 一.结构体变量中成员的偏移量必须是成员大小的整数倍: 二.结构体大小必须是所有成员大小的整数倍. 1 #include<stdio.h> 2 3 struct a{ 4 int i; 5 float f; 6 char c; 7 double d; 8 long l; 9 }b; 10 11 int main(){ 12 printf("%d\n",sizeof(b.i));// 4 13 prin

关于OC中直接打印结构体,点(CGRect,CGSize,CGPoint,UIOffset)等数据类型

关于OC直接打印结构体,点(CGRect,CGSize,CGPoint,UIOffset)等数据类型,我们完全可以把其转换为OC对象来进项打印调试,而不必对结构体中的成员变量进行打印.就好比我们可以使用NSStringFromCGRect(CGRect rect)来直接打印一个结构体,其他打印可以参考以下内容 UIKIT_EXTERN NSString *NSStringFromCGPoint(CGPoint point); UIKIT_EXTERN NSString *NSStringFrom

38-oc常用结构体

常用结构体 在开发中苹果推荐我们使用CG开头的结构体, 也就是说NS开头的结构体一般不用 OC中定义一个点,用什么结构体 NSPoint; CGPoint point = NSMakePoint(10, 20); OC中保存物体尺寸的,用什么结构体 NSSize; CGSize size = NSMakeSize(100, 50); OC中保存某个物体的位置和尺寸,用什么结构体 NSRect; CGRect rect = NSMakeRect(10, 20, 100, 50); NSNumber

结构体在固件库中的应用

上次介绍了一般结构体的定义以及引用方法,那么接下来将对结构体在官方固件库是如何具体使用的做出简单说明. 结构体指针成员变量引用方法是通过“→”符号来实现,比如要访问student1结构体指针指向的结构体的成员变量name,那么方法是: stuednt1—>name; 如在STM32官方固件库中对端口使用模式结构体定义如下: typedef enum { GPIO_Mode_AIN = 0x0, //模拟输入模式 GPIO_Mode_IN_FLOATING = 0x04, //浮空输入模式 GPI

C# 定义一个学生的结构体,输入学生信息,学号,姓名,身高,按身高排序输出

class Program { //定义一个结构体 struct student//student就是我们自己造的新数据类型 { public int code;//public修饰符 public string name;//结构体的成员 public decimal height; } static void Main(string[] args) { ArrayList arr = new ArrayList(); for (int i = 0; i < 3; i++) { student

类和结构体

//类  class A {     var a = 0 } let classA = A() classA.a = 12     //虽然classA定义为常量,但是仍然可以修改A类中的变量值;结构体则不可以 //类属于引用类型,结构体属于值类型