X509Req is an opaque object that represents PKCS#10
certificate request.
ModuleHsOpenSSL-0.11.7.10Haskell2010
OpenSSL.X509.Request
An interface to PKCS#10 certificate request.
- 2 types
- 16 values
- PackageHsOpenSSL-0.11.7.10
- Exports18
- LanguageHaskell2010
- LicenceLicenseRef-PublicDomain
- SourceRequest.hs
Type
2 declarationsFunctions to manipulate request
8 declarationsnewX509Req creates an empty certificate request. You must set
the following properties to and sign it (see signX509Req) to
actually use the certificate request.
- Version
See
.
- Subject Name
See
.
- Public Key
See
.
signX509Req signX509Req signs a certificate request with a subject private
key.
verifyX509Req :: PublicKey key=> X509ReqThe request to be verified.
-> keyThe public key to verify with.
-> IO VerifyStatus
verifyX509Req verifies a signature of certificate request with
a subject public key.
printX509Req req translates a certificate request into
human-readable format.
writeX509ReqDER req writes a PKCS#10 certificate request to DER string.
makeX509FromReq req cert creates an empty X.509 certificate
and copies as much data from the request as possible. The resulting
certificate doesn't have the following data and it isn't signed so
you must fill them and sign it yourself.
Serial number
Validity (Not Before and Not After)
Example:
import Data.Time.Clock
genCert :: X509 -> EvpPKey -> Integer -> Int -> X509Req -> IO X509
genCert caCert caKey serial days req
= do cert <- makeX509FromReq req caCert
now <- getCurrentTime
setSerialNumber cert serial
setNotBefore cert $ addUTCTime (-1) now
setNotAfter cert $ addUTCTime (days * 24 * 60 * 60) now
signX509 cert caKey Nothing
return certAccessors
8 declarationsgetVersion req returns the version number of certificate
request.
setVersion req ver updates the version number of certificate
request.
getSubjectName req wantLongName returns the subject name of
certificate request. See getSubjectName of
OpenSSL.X509.
setSubjectName req name updates the subject name of
certificate request. See setSubjectName of
OpenSSL.X509.
getPublicKey req returns the public key of the subject of
certificate request.
setPublicKey req updates the public key of the subject of
certificate request.
addExtensions req [(nid, str)]E.g., nid 85 = subjectAltName http://osxr.org:8080/openssl/source/crypto/objects/objects.h#0476
(TODO: more docs; NID type)
Add Extensions to a certificate (when the Server accepting certs requires it) E.g.:
addExtensionToX509 cert1 87 "CA:FALSE"
addExtensionToX509 cert1 85 "critical,serverAuth, clientAuth" -- when this extension field is critical