Pkcs7 represents an abstract PKCS#7 structure. The concrete
type of structure is hidden in the object: such polymorphism isn't
very haskellish but please get it out of your mind since OpenSSL is
written in C.
ModuleHsOpenSSL-0.11.7.10Haskell2010
OpenSSL.PKCS7
An interface to PKCS#7 structure and S/MIME message.
- 4 types
- 8 values
- PackageHsOpenSSL-0.11.7.10
- Exports12
- LanguageHaskell2010
- LicenceLicenseRef-PublicDomain
- SourcePKCS7.hsc
Types
6 declarationsPkcs7Flag is a set of flags that are used in many operations
related to PKCS#7.
Pkcs7VerifyStatus represents a result of PKCS#7
verification. See pkcs7Verify.
Constructors
Pkcs7VerifySuccess (Maybe String)Nothing if the PKCS#7 signature was a detached signature, and
Just contentif it wasn't.Pkcs7VerifyFailure
Instances2Eq, Show
Eq Pkcs7VerifyStatusDefined in HsOpenSSL-0.11.7.10 · OpenSSL.PKCS7Show Pkcs7VerifyStatusDefined in HsOpenSSL-0.11.7.10 · OpenSSL.PKCS7
Encryption and Signing
4 declarationspkcs7Sign :: KeyPair key=> X509certificate to sign with
-> keycorresponding private key
-> [X509]optional additional set of certificates to include in the PKCS#7 structure (for example any intermediate CAs in the chain)
-> Stringdata to be signed
-> [Pkcs7Flag]An optional set of flags:
- Pkcs7Text
Many S/MIME clients expect the signed content to include valid MIME headers. If the
flag is set MIME headers for type "text/plain" are prepended to the data.
- Pkcs7NoCerts
If
is set the signer's certificate will not be included in the PKCS#7 structure, the signer's certificate must still be supplied in the parameter though. This can reduce the size of the signature if the signer's certificate can be obtained by other means: for example a previously signed message.
- Pkcs7Detached
The data being signed is included in the PKCS#7 structure, unless
is set in which case it is ommited. This is used for PKCS#7 detached signatures which are used in S/MIME plaintext signed message for example.
- Pkcs7Binary
Normally the supplied content is translated into MIME canonical format (as required by the S/MIME specifications) but if
is set no translation occurs. This option should be uesd if the supplied data is in binary format otherwise the translation will corrupt it.
- Pkcs7NoAttr
- Pkcs7NoSmimeCap
The signedData structure includes several PKCS#7 authenticatedAttributes including the signing time, the PKCS#7 content type and the supported list of ciphers in an SMIMECapabilities attribute. If
is set then no authenticatedAttributes will be used. If Pkcs7NoSmimeCap is set then just the SMIMECapabilities are omitted.
-> IO Pkcs7
pkcs7Sign creates a PKCS#7 signedData structure.
pkcs7Verify :: Pkcs7A PKCS#7 structure to verify.
-> [X509]Set of certificates in which to search for the signer's certificate.
-> X509StoreTrusted certificate store (used for chain verification).
-> Maybe StringSigned data if the content is not present in the PKCS#7 structure (that is it is detached).
-> [Pkcs7Flag]An optional set of flags:
- Pkcs7NoIntern
If
is set the certificates in the message itself are not searched when locating the signer's certificate. This means that all the signers certificates must be in the second argument ([
]).
- Pkcs7Text
If the
flag is set MIME headers for type "text/plain" are deleted from the content. If the content is not of type "text/plain" then an error is returned.
- Pkcs7NoVerify
If
is set the signer's certificates are not chain verified.
- Pkcs7NoChain
If
is set then the certificates contained in the message are not used as untrusted CAs. This means that the whole verify chain (apart from the signer's certificate) must be contained in the trusted store.
- Pkcs7NoSigs
If
is set then the signatures on the data are not checked.
-> IO Pkcs7VerifyStatus
pkcs7Verify verifies a PKCS#7 signedData structure.
pkcs7Encrypt :: [X509]A list of recipient certificates.
-> StringThe content to be encrypted.
-> CipherThe symmetric cipher to use.
-> [Pkcs7Flag]An optional set of flags:
- Pkcs7Text
If the
flag is set MIME headers for type "text/plain" are prepended to the data.
- Pkcs7Binary
Normally the supplied content is translated into MIME canonical format (as required by the S/MIME specifications) if
is set no translation occurs. This option should be used if the supplied data is in binary format otherwise the translation will corrupt it. If
is set then
is ignored.
-> IO Pkcs7
pkcs7Encrypt creates a PKCS#7 envelopedData structure.
pkcs7Decrypt pkcs7Decrypt decrypts content from PKCS#7 envelopedData
structure.
S/MIME
2 declarationswriteSmime :: Pkcs7A PKCS#7 structure to be written.
-> Maybe StringIf cleartext signing (multipart/signed) is being used then the signed data must be supplied here.
-> [Pkcs7Flag]An optional set of flags:
- Pkcs7Detached
If
is set then cleartext signing will be used, this option only makes sense for signedData where
is also set when
is also called.
- Pkcs7Text
If the
flag is set MIME headers for type "text/plain" are added to the content, this only makes sense if
is also set.
-> IO StringThe result S/MIME message.
writeSmime writes PKCS#7 structure to S/MIME message.
readSmime readSmime parses S/MIME message.