HORIZON HASKELLDocslts/ghc-9.10.x248f8f02026-10-05Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · 248f8f0 · 2026-10-05

Modulex509-1.7.7Haskell2010

Data.X509

Read/Write X509 Certificate, CRL and their signed equivalents.

Follows RFC5280 / RFC6818

  • 35 types
  • 1 class
  • 23 values
  • Packagex509-1.7.7
  • Exports59
  • LanguageHaskell2010
  • LicenceBSD-3-Clause
  • SourceX509.hs

Types

35 declarations
datadata Certificate
#

X.509 Certificate type.

This type doesn't include the signature, it's describe in the RFC as tbsCertificate.

Constructors

Instances3Eq, Show, ASN1Object
datadata PubKey
#

Public key types known and used in X.509

Constructors

Instances3Eq, Show, ASN1Object
datadata PubKeyEC
#
Instances2Eq, Show
  • Eq PubKeyECDefined in x509-1.7.7 · Data.X509.PublicKey
  • Show PubKeyECDefined in x509-1.7.7 · Data.X509.PublicKey
datadata PrivKey
#

Private key types known and used in X.509

Constructors

Instances3Eq, Show, ASN1Object
datadata PrivKeyEC
#
Instances2Eq, Show
datadata PubKeyALG
#

Public Key Algorithm

Constructors

Instances3Eq, Show, OIDable
  • Eq PubKeyALGDefined in x509-1.7.7 · Data.X509.AlgorithmIdentifier
  • Show PubKeyALGDefined in x509-1.7.7 · Data.X509.AlgorithmIdentifier
  • OIDable PubKeyALGDefined in x509-1.7.7 · Data.X509.AlgorithmIdentifier
datadata SignatureALG
#

Signature Algorithm, often composed of a public key algorithm and a hash algorithm. For some signature algorithms the hash algorithm is intrinsic to the public key algorithm and is not needed in the data type.

Instances3Eq, Show, ASN1Object
classclass Extension a where
#

Extension class.

each extension have a unique OID associated, and a way to encode and decode an ASN1 stream.

Errata: turns out, the content is not necessarily ASN1, it could be data that is only parsable by the extension e.g. raw ascii string. Add method to parse and encode with ByteString

Instances8Extension, …
datadata ExtKeyUsageFlag
#
Instances4Enum, Eq, Ord, Show

Try to decode an ExtensionRaw.

If this function return: * Nothing, the OID doesn't match * Just Left, the OID matched, but the extension couldn't be decoded * Just Right, the OID matched, and the extension has been succesfully decoded

Certificate Revocation List (CRL)

2 declarations

Naming

4 declarations
newtypenewtype DistinguishedName
#

A list of OID and strings.

Instances6Eq, Ord, Show, Semigroup, Monoid, ASN1Object
datadata ASN1CharacterString
#
Instances4Eq, Ord, Show, IsString

Certificate Chain

4 declarations

Signed types and marshalling

8 declarations
datadata (Show a, Eq a, ASN1Object a) => Signed a
#

Represent a signed object using a traditional X509 structure.

When dealing with external certificate, use the SignedExact structure not this one.

Constructors

Instances2Eq, Show

Parametrized Signed accessor

4 declarations

Hash distinguished names related function

2 declarations

Make an OpenSSL style hash of distinguished name

OpenSSL algorithm is odd, and has been replicated here somewhat. only lower the case of ascii character.