A Signed Certificate
Modulecrypton-x509-1.7.7Haskell2010
Data.X509
Read/Write X509 Certificate, CRL and their signed equivalents.
Follows RFC5280 / RFC6818
- 35 types
- 1 class
- 23 values
- Packagecrypton-x509-1.7.7
- Exports59
- LanguageHaskell2010
- LicenceBSD-3-Clause
- SourceX509.hs
Types
35 declarationsA Signed CRL
X.509 Certificate type.
This type doesn't include the signature, it's describe in the RFC as tbsCertificate.
Constructors
CertificatecertVersion :: IntVersion
certSerial :: IntegerSerial number
certSignatureAlg :: SignatureALGSignature algorithm
certIssuerDN :: DistinguishedNameIssuer DN
certValidity :: (DateTime, DateTime)Validity period (UTC)
certSubjectDN :: DistinguishedNameSubject DN
certPubKey :: PubKeyPublic key
certExtensions :: ExtensionsExtensions
Instances3Eq, Show, ASN1Object
Eq CertificateDefined in crypton-x509-1.7.7 · Data.X509.CertShow CertificateDefined in crypton-x509-1.7.7 · Data.X509.CertASN1Object CertificateDefined in crypton-x509-1.7.7 · Data.X509.Cert
Public key types known and used in X.509
Constructors
PubKeyRSA PublicKeyRSA public key
PubKeyDSA PublicKeyDSA public key
PubKeyDH (Integer, Integer, Integer, Maybe Integer, ([Word8], Integer))DH format with (p,g,q,j,(seed,pgenCounter))
PubKeyEC PubKeyECEC public key
PubKeyX25519 PublicKeyX25519 public key
PubKeyX448 PublicKeyX448 public key
PubKeyEd25519 PublicKeyEd25519 public key
PubKeyEd448 PublicKeyEd448 public key
PubKeyUnknown OID ByteStringunrecognized format
Elliptic Curve Public Key
TODO: missing support for binary curve.
Constructors
Serialized Elliptic Curve Point
Constructors
Instances2Eq, Show
Eq SerializedPointDefined in crypton-x509-1.7.7 · Data.X509.PublicKeyShow SerializedPointDefined in crypton-x509-1.7.7 · Data.X509.PublicKey
Private key types known and used in X.509
Constructors
PrivKeyRSA PrivateKeyRSA private key
PrivKeyDSA PrivateKeyDSA private key
PrivKeyEC PrivKeyECEC private key
PrivKeyX25519 SecretKeyX25519 private key
PrivKeyX448 SecretKeyX448 private key
PrivKeyEd25519 SecretKeyEd25519 private key
PrivKeyEd448 SecretKeyEd448 private key
Elliptic Curve Private Key
TODO: missing support for binary curve.
Constructors
Convert a Public key to the Public Key Algorithm type
Convert a Private key to the Public Key Algorithm type
Public Key Algorithm
Constructors
PubKeyALG_RSARSA Public Key algorithm
PubKeyALG_RSAPSSRSA PSS Key algorithm (RFC 3447)
PubKeyALG_DSADSA Public Key algorithm
PubKeyALG_ECECDSA & ECDH Public Key algorithm
PubKeyALG_X25519ECDH 25519 key agreement
PubKeyALG_X448ECDH 448 key agreement
PubKeyALG_Ed25519EdDSA 25519 signature algorithm
PubKeyALG_Ed448EdDSA 448 signature algorithm
PubKeyALG_DHDiffie Hellman Public Key algorithm
PubKeyALG_Unknown OIDUnknown Public Key algorithm
Signature Algorithm, often composed of a public key algorithm and a hash algorithm. For some signature algorithms the hash algorithm is intrinsic to the public key algorithm and is not needed in the data type.
Instances3Eq, Show, ASN1Object
Eq SignatureALGDefined in crypton-x509-1.7.7 · Data.X509.AlgorithmIdentifierShow SignatureALGDefined in crypton-x509-1.7.7 · Data.X509.AlgorithmIdentifierASN1Object SignatureALGDefined in crypton-x509-1.7.7 · Data.X509.AlgorithmIdentifier
Extension class.
each extension have a unique OID associated, and a way to encode and decode an ASN1 stream.
Errata: turns out, the content is not necessarily ASN1, it could be data that is only parsable by the extension e.g. raw ascii string. Add method to parse and encode with ByteString
Methods
extOID :: a -> OIDextHasNestedASN1 :: Proxy a -> BoolextEncode :: a -> [ASN1]extDecode :: [ASN1] -> Either String aextDecodeBs :: ByteString -> Either String aextEncodeBs :: a -> ByteString
Instances8Extension, …
Extension ExtAuthorityKeyIdDefined in crypton-x509-1.7.7 · Data.X509.ExtExtension ExtBasicConstraintsDefined in crypton-x509-1.7.7 · Data.X509.ExtExtension ExtCrlDistributionPointsDefined in crypton-x509-1.7.7 · Data.X509.ExtExtension ExtExtendedKeyUsageDefined in crypton-x509-1.7.7 · Data.X509.ExtExtension ExtKeyUsageDefined in crypton-x509-1.7.7 · Data.X509.ExtExtension ExtNetscapeCommentDefined in crypton-x509-1.7.7 · Data.X509.ExtExtension ExtSubjectAltNameDefined in crypton-x509-1.7.7 · Data.X509.ExtExtension ExtSubjectKeyIdDefined in crypton-x509-1.7.7 · Data.X509.Ext
Basic Constraints
Constructors
Instances3Eq, Show, Extension
Eq ExtBasicConstraintsDefined in crypton-x509-1.7.7 · Data.X509.ExtShow ExtBasicConstraintsDefined in crypton-x509-1.7.7 · Data.X509.ExtExtension ExtBasicConstraintsDefined in crypton-x509-1.7.7 · Data.X509.Ext
Describe key usage
Constructors
Instances3Eq, Show, Extension
Eq ExtKeyUsageDefined in crypton-x509-1.7.7 · Data.X509.ExtShow ExtKeyUsageDefined in crypton-x509-1.7.7 · Data.X509.ExtExtension ExtKeyUsageDefined in crypton-x509-1.7.7 · Data.X509.Ext
key usage flag that is found in the key usage extension field.
Instances4Enum, Eq, Ord, Show
Enum ExtKeyUsageFlagDefined in crypton-x509-1.7.7 · Data.X509.ExtEq ExtKeyUsageFlagDefined in crypton-x509-1.7.7 · Data.X509.ExtOrd ExtKeyUsageFlagDefined in crypton-x509-1.7.7 · Data.X509.ExtShow ExtKeyUsageFlagDefined in crypton-x509-1.7.7 · Data.X509.Ext
Extended key usage extension
Constructors
Instances3Eq, Show, Extension
Eq ExtExtendedKeyUsageDefined in crypton-x509-1.7.7 · Data.X509.ExtShow ExtExtendedKeyUsageDefined in crypton-x509-1.7.7 · Data.X509.ExtExtension ExtExtendedKeyUsageDefined in crypton-x509-1.7.7 · Data.X509.Ext
Key usage purposes for the ExtendedKeyUsage extension
Instances3Eq, Ord, Show
Eq ExtKeyUsagePurposeDefined in crypton-x509-1.7.7 · Data.X509.ExtOrd ExtKeyUsagePurposeDefined in crypton-x509-1.7.7 · Data.X509.ExtShow ExtKeyUsagePurposeDefined in crypton-x509-1.7.7 · Data.X509.Ext
Provide a way to identify a public key by a short hash.
Constructors
Instances3Eq, Show, Extension
Eq ExtSubjectKeyIdDefined in crypton-x509-1.7.7 · Data.X509.ExtShow ExtSubjectKeyIdDefined in crypton-x509-1.7.7 · Data.X509.ExtExtension ExtSubjectKeyIdDefined in crypton-x509-1.7.7 · Data.X509.Ext
Provide a way to supply alternate name that can be used for matching host name.
Constructors
Instances4Eq, Ord, Show, Extension
Eq ExtSubjectAltNameDefined in crypton-x509-1.7.7 · Data.X509.ExtOrd ExtSubjectAltNameDefined in crypton-x509-1.7.7 · Data.X509.ExtShow ExtSubjectAltNameDefined in crypton-x509-1.7.7 · Data.X509.ExtExtension ExtSubjectAltNameDefined in crypton-x509-1.7.7 · Data.X509.Ext
Provide a mean to identify the public key corresponding to the private key used to signed a certificate.
Constructors
Instances3Eq, Show, Extension
Eq ExtAuthorityKeyIdDefined in crypton-x509-1.7.7 · Data.X509.ExtShow ExtAuthorityKeyIdDefined in crypton-x509-1.7.7 · Data.X509.ExtExtension ExtAuthorityKeyIdDefined in crypton-x509-1.7.7 · Data.X509.Ext
Identify how CRL information is obtained
Constructors
Instances3Eq, Show, Extension
Eq ExtCrlDistributionPointsDefined in crypton-x509-1.7.7 · Data.X509.ExtShow ExtCrlDistributionPointsDefined in crypton-x509-1.7.7 · Data.X509.ExtExtension ExtCrlDistributionPointsDefined in crypton-x509-1.7.7 · Data.X509.Ext
Constructors
Instances3Eq, Show, Extension
Eq ExtNetscapeCommentDefined in crypton-x509-1.7.7 · Data.X509.ExtShow ExtNetscapeCommentDefined in crypton-x509-1.7.7 · Data.X509.ExtExtension ExtNetscapeCommentDefined in crypton-x509-1.7.7 · Data.X509.Ext
Different naming scheme use by the extension.
Not all name types are available, missing: otherName x400Address directoryName ediPartyName registeredID
Distribution point as either some GeneralNames or a DN
Instances2Eq, Show
Eq DistributionPointDefined in crypton-x509-1.7.7 · Data.X509.ExtShow DistributionPointDefined in crypton-x509-1.7.7 · Data.X509.Ext
Reason flag for the CRL
Instances4Enum, Eq, Ord, Show
Enum ReasonFlagDefined in crypton-x509-1.7.7 · Data.X509.ExtEq ReasonFlagDefined in crypton-x509-1.7.7 · Data.X509.ExtOrd ReasonFlagDefined in crypton-x509-1.7.7 · Data.X509.ExtShow ReasonFlagDefined in crypton-x509-1.7.7 · Data.X509.Ext
Get a specific extension from a lists of raw extensions
Get a specific extension from a lists of raw extensions
Try to decode an ExtensionRaw.
If this function return: * Nothing, the OID doesn't match * Just Left, the OID matched, but the extension couldn't be decoded * Just Right, the OID matched, and the extension has been succesfully decoded
Encode an Extension to extensionRaw
An undecoded extension
Constructors
ExtensionRawextRawOID :: OIDOID of this extension
extRawCritical :: Boolif this extension is critical
extRawContent :: ByteStringundecoded content
Instances3Eq, Show, ASN1Object
Eq ExtensionRawDefined in crypton-x509-1.7.7 · Data.X509.ExtensionRawShow ExtensionRawDefined in crypton-x509-1.7.7 · Data.X509.ExtensionRawASN1Object ExtensionRawDefined in crypton-x509-1.7.7 · Data.X509.ExtensionRaw
Deprecated. use tryExtRawASN1 instead
a Set of ExtensionRaw
Constructors
Instances3Eq, Show, ASN1Object
Eq ExtensionsDefined in crypton-x509-1.7.7 · Data.X509.ExtensionRawShow ExtensionsDefined in crypton-x509-1.7.7 · Data.X509.ExtensionRawASN1Object ExtensionsDefined in crypton-x509-1.7.7 · Data.X509.ExtensionRaw
Certificate Revocation List (CRL)
2 declarationsDescribe a Certificate revocation list
Describe a revoked certificate identifiable by serial number.
Constructors
Instances3Eq, Show, ASN1Object
Eq RevokedCertificateDefined in crypton-x509-1.7.7 · Data.X509.CRLShow RevokedCertificateDefined in crypton-x509-1.7.7 · Data.X509.CRLASN1Object RevokedCertificateDefined in crypton-x509-1.7.7 · Data.X509.CRL
Naming
4 declarationsA list of OID and strings.
Constructors
Instances6Eq, Ord, Show, Semigroup, Monoid, ASN1Object
Eq DistinguishedNameDefined in crypton-x509-1.7.7 · Data.X509.DistinguishedNameOrd DistinguishedNameDefined in crypton-x509-1.7.7 · Data.X509.DistinguishedNameShow DistinguishedNameDefined in crypton-x509-1.7.7 · Data.X509.DistinguishedNameSemigroup DistinguishedNameDefined in crypton-x509-1.7.7 · Data.X509.DistinguishedNameMonoid DistinguishedNameDefined in crypton-x509-1.7.7 · Data.X509.DistinguishedNameASN1Object DistinguishedNameDefined in crypton-x509-1.7.7 · Data.X509.DistinguishedName
Elements commonly available in a DistinguishedName structure
Constructors
DnCommonNameCN
DnCountryCountry
DnOrganizationO
DnOrganizationUnitOU
DnEmailAddressEmail Address (legacy)
ASN1 Character String with encoding
Instances4Eq, Ord, Show, IsString
Eq ASN1CharacterStringDefined in asn1-types-0.3.4 · Data.ASN1.Types.StringOrd ASN1CharacterStringDefined in asn1-types-0.3.4 · Data.ASN1.Types.StringShow ASN1CharacterStringDefined in asn1-types-0.3.4 · Data.ASN1.Types.StringIsString ASN1CharacterStringDefined in asn1-types-0.3.4 · Data.ASN1.Types.String
Try to get a specific element in a DistinguishedName structure
Certificate Chain
4 declarationsA chain of X.509 certificates in exact form.
Constructors
Instances2Eq, Show
Eq CertificateChainDefined in crypton-x509-1.7.7 · Data.X509.CertificateChainShow CertificateChainDefined in crypton-x509-1.7.7 · Data.X509.CertificateChain
Represent a chain of X.509 certificates in bytestring form.
Constructors
Instances2Eq, Show
Eq CertificateChainRawDefined in crypton-x509-1.7.7 · Data.X509.CertificateChainShow CertificateChainRawDefined in crypton-x509-1.7.7 · Data.X509.CertificateChain
Decode a CertificateChainRaw into a CertificateChain if every raw certificate are decoded correctly, otherwise return the index of the failed certificate and the error associated.
Convert a CertificateChain into a CertificateChainRaw
Signed types and marshalling
8 declarationsRepresent a signed object using a traditional X509 structure.
When dealing with external certificate, use the SignedExact structure not this one.
Constructors
SignedsignedObject :: aObject to sign
signedAlg :: SignatureALGSignature Algorithm used
signedSignature :: ByteStringSignature as bytes
Instances2Eq, Show
(Show a, ASN1Object a, Eq a) => Eq (Signed a)Defined in crypton-x509-1.7.7 · Data.X509.Signed(Eq a, ASN1Object a, Show a) => Show (Signed a)Defined in crypton-x509-1.7.7 · Data.X509.Signed
Represent the signed object plus the raw data that we need to keep around for non compliant case to be able to verify signature.
Instances2Eq, Show
(Show a, Eq a, ASN1Object a) => Eq (SignedExact a)Defined in crypton-x509-1.7.7 · Data.X509.Signed(Show a, Eq a, ASN1Object a) => Show (SignedExact a)Defined in crypton-x509-1.7.7 · Data.X509.Signed
get the decoded Signed data
Get the signed data for the signature
objectToSignedExact :: (Show a, Eq a, ASN1Object a)=> (ByteString -> (ByteString, SignatureALG, r))signature function
-> aobject to sign
-> (SignedExact a, r)
Transform an object into a SignedExact object
objectToSignedExactF :: (Functor f, Show a, Eq a, ASN1Object a)=> (ByteString -> f (ByteString, SignatureALG))signature function
-> aobject to sign
-> f (SignedExact a)
A generalization of objectToSignedExact where the signature function runs in an arbitrary functor. This allows for example to sign using an algorithm needing random values.
The raw representation of the whole signed structure
Try to parse a bytestring that use the typical X509 signed structure format
Parametrized Signed accessor
4 declarationsGet the Certificate associated to a SignedCertificate
Get the CRL associated to a SignedCRL
Try to decode a bytestring to a SignedCertificate
Try to decode a bytestring to a SignedCRL
Hash distinguished names related function
2 declarationsMake an OpenSSL style hash of distinguished name
OpenSSL algorithm is odd, and has been replicated here somewhat. only lower the case of ascii character.
Create an openssl style old hash of distinguished name