HORIZON HASKELLDocslts/ghc-9.10.x248f8f02026-10-05Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · 248f8f0 · 2026-10-05

ModuleHsOpenSSL-0.11.7.10Haskell2010

OpenSSL.X509.Request

An interface to PKCS#10 certificate request.

  • 2 types
  • 16 values
  • PackageHsOpenSSL-0.11.7.10
  • Exports18
  • LanguageHaskell2010
  • LicenceLicenseRef-PublicDomain
  • SourceRequest.hs

Type

2 declarations
newtypenewtype X509Req
#

X509Req is an opaque object that represents PKCS#10 certificate request.

Functions to manipulate request

8 declarations
valuesignX509Req
  1. :: KeyPair key
  2. => X509Req

    The request to be signed.

  3. -> key

    The private key to sign with.

  4. -> Maybe Digest

    A hashing algorithm to use. If Nothing the most suitable algorithm for the key is automatically used.

  5. -> IO ()
#

signX509Req signs a certificate request with a subject private key.

valuemakeX509FromReq :: X509Req -> X509 -> IO X509
#

makeX509FromReq req cert creates an empty X.509 certificate and copies as much data from the request as possible. The resulting certificate doesn't have the following data and it isn't signed so you must fill them and sign it yourself.

  • Serial number

  • Validity (Not Before and Not After)

Example:

import Data.Time.Clock

genCert :: X509 -> EvpPKey -> Integer -> Int -> X509Req -> IO X509
genCert caCert caKey serial days req
    = do cert <- makeX509FromReq req caCert
         now  <- getCurrentTime
         setSerialNumber cert serial
         setNotBefore cert $ addUTCTime (-1) now
         setNotAfter  cert $ addUTCTime (days * 24 * 60 * 60) now
         signX509 cert caKey Nothing
         return cert

Accessors

8 declarations
valueaddExtensionToX509 :: X509 -> Int -> String -> IO Bool
#

Add Extensions to a certificate (when the Server accepting certs requires it) E.g.:

addExtensionToX509 cert1 87 "CA:FALSE"
addExtensionToX509 cert1 85 "critical,serverAuth, clientAuth" -- when this extension field is critical