A Signed Certificate
Modulex509-1.7.7Haskell2010
Data.X509
Read/Write X509 Certificate, CRL and their signed equivalents.
Follows RFC5280 / RFC6818
- 35 types
- 1 class
- 23 values
- Packagex509-1.7.7
- Exports59
- LanguageHaskell2010
- LicenceBSD-3-Clause
- SourceX509.hs
Types
35 declarationsA Signed CRL
X.509 Certificate type.
This type doesn't include the signature, it's describe in the RFC as tbsCertificate.
Constructors
CertificatecertVersion :: IntVersion
certSerial :: IntegerSerial number
certSignatureAlg :: SignatureALGSignature algorithm
certIssuerDN :: DistinguishedNameIssuer DN
certValidity :: (DateTime, DateTime)Validity period (UTC)
certSubjectDN :: DistinguishedNameSubject DN
certPubKey :: PubKeyPublic key
certExtensions :: ExtensionsExtensions
Instances3Eq, Show, ASN1Object
Eq CertificateDefined in x509-1.7.7 · Data.X509.CertShow CertificateDefined in x509-1.7.7 · Data.X509.CertASN1Object CertificateDefined in x509-1.7.7 · Data.X509.Cert
Public key types known and used in X.509
Constructors
PubKeyRSA PublicKeyRSA public key
PubKeyDSA PublicKeyDSA public key
PubKeyDH (Integer, Integer, Integer, Maybe Integer, ([Word8], Integer))DH format with (p,g,q,j,(seed,pgenCounter))
PubKeyEC PubKeyECEC public key
PubKeyX25519 PublicKeyX25519 public key
PubKeyX448 PublicKeyX448 public key
PubKeyEd25519 PublicKeyEd25519 public key
PubKeyEd448 PublicKeyEd448 public key
PubKeyUnknown OID ByteStringunrecognized format
Elliptic Curve Public Key
TODO: missing support for binary curve.
Constructors
Serialized Elliptic Curve Point
Constructors
Instances2Eq, Show
Eq SerializedPointDefined in x509-1.7.7 · Data.X509.PublicKeyShow SerializedPointDefined in x509-1.7.7 · Data.X509.PublicKey
Private key types known and used in X.509
Constructors
PrivKeyRSA PrivateKeyRSA private key
PrivKeyDSA PrivateKeyDSA private key
PrivKeyEC PrivKeyECEC private key
PrivKeyX25519 SecretKeyX25519 private key
PrivKeyX448 SecretKeyX448 private key
PrivKeyEd25519 SecretKeyEd25519 private key
PrivKeyEd448 SecretKeyEd448 private key
Elliptic Curve Private Key
TODO: missing support for binary curve.
Constructors
Convert a Public key to the Public Key Algorithm type
Convert a Private key to the Public Key Algorithm type
Public Key Algorithm
Constructors
PubKeyALG_RSARSA Public Key algorithm
PubKeyALG_RSAPSSRSA PSS Key algorithm (RFC 3447)
PubKeyALG_DSADSA Public Key algorithm
PubKeyALG_ECECDSA & ECDH Public Key algorithm
PubKeyALG_X25519ECDH 25519 key agreement
PubKeyALG_X448ECDH 448 key agreement
PubKeyALG_Ed25519EdDSA 25519 signature algorithm
PubKeyALG_Ed448EdDSA 448 signature algorithm
PubKeyALG_DHDiffie Hellman Public Key algorithm
PubKeyALG_Unknown OIDUnknown Public Key algorithm
Signature Algorithm, often composed of a public key algorithm and a hash algorithm. For some signature algorithms the hash algorithm is intrinsic to the public key algorithm and is not needed in the data type.
Instances3Eq, Show, ASN1Object
Eq SignatureALGDefined in x509-1.7.7 · Data.X509.AlgorithmIdentifierShow SignatureALGDefined in x509-1.7.7 · Data.X509.AlgorithmIdentifierASN1Object SignatureALGDefined in x509-1.7.7 · Data.X509.AlgorithmIdentifier
Extension class.
each extension have a unique OID associated, and a way to encode and decode an ASN1 stream.
Errata: turns out, the content is not necessarily ASN1, it could be data that is only parsable by the extension e.g. raw ascii string. Add method to parse and encode with ByteString
Methods
extOID :: a -> OIDextHasNestedASN1 :: Proxy a -> BoolextEncode :: a -> [ASN1]extDecode :: [ASN1] -> Either String aextDecodeBs :: ByteString -> Either String aextEncodeBs :: a -> ByteString
Instances8Extension, …
Extension ExtAuthorityKeyIdDefined in x509-1.7.7 · Data.X509.ExtExtension ExtBasicConstraintsDefined in x509-1.7.7 · Data.X509.ExtExtension ExtCrlDistributionPointsDefined in x509-1.7.7 · Data.X509.ExtExtension ExtExtendedKeyUsageDefined in x509-1.7.7 · Data.X509.ExtExtension ExtKeyUsageDefined in x509-1.7.7 · Data.X509.ExtExtension ExtNetscapeCommentDefined in x509-1.7.7 · Data.X509.ExtExtension ExtSubjectAltNameDefined in x509-1.7.7 · Data.X509.ExtExtension ExtSubjectKeyIdDefined in x509-1.7.7 · Data.X509.Ext
Basic Constraints
Constructors
Instances3Eq, Show, Extension
Eq ExtBasicConstraintsDefined in x509-1.7.7 · Data.X509.ExtShow ExtBasicConstraintsDefined in x509-1.7.7 · Data.X509.ExtExtension ExtBasicConstraintsDefined in x509-1.7.7 · Data.X509.Ext
Describe key usage
Constructors
Instances3Eq, Show, Extension
Eq ExtKeyUsageDefined in x509-1.7.7 · Data.X509.ExtShow ExtKeyUsageDefined in x509-1.7.7 · Data.X509.ExtExtension ExtKeyUsageDefined in x509-1.7.7 · Data.X509.Ext
key usage flag that is found in the key usage extension field.
Instances4Enum, Eq, Ord, Show
Enum ExtKeyUsageFlagDefined in x509-1.7.7 · Data.X509.ExtEq ExtKeyUsageFlagDefined in x509-1.7.7 · Data.X509.ExtOrd ExtKeyUsageFlagDefined in x509-1.7.7 · Data.X509.ExtShow ExtKeyUsageFlagDefined in x509-1.7.7 · Data.X509.Ext
Extended key usage extension
Constructors
Instances3Eq, Show, Extension
Eq ExtExtendedKeyUsageDefined in x509-1.7.7 · Data.X509.ExtShow ExtExtendedKeyUsageDefined in x509-1.7.7 · Data.X509.ExtExtension ExtExtendedKeyUsageDefined in x509-1.7.7 · Data.X509.Ext
Key usage purposes for the ExtendedKeyUsage extension
Instances3Eq, Ord, Show
Eq ExtKeyUsagePurposeDefined in x509-1.7.7 · Data.X509.ExtOrd ExtKeyUsagePurposeDefined in x509-1.7.7 · Data.X509.ExtShow ExtKeyUsagePurposeDefined in x509-1.7.7 · Data.X509.Ext
Provide a way to identify a public key by a short hash.
Constructors
Instances3Eq, Show, Extension
Eq ExtSubjectKeyIdDefined in x509-1.7.7 · Data.X509.ExtShow ExtSubjectKeyIdDefined in x509-1.7.7 · Data.X509.ExtExtension ExtSubjectKeyIdDefined in x509-1.7.7 · Data.X509.Ext
Provide a way to supply alternate name that can be used for matching host name.
Constructors
Instances4Eq, Ord, Show, Extension
Eq ExtSubjectAltNameDefined in x509-1.7.7 · Data.X509.ExtOrd ExtSubjectAltNameDefined in x509-1.7.7 · Data.X509.ExtShow ExtSubjectAltNameDefined in x509-1.7.7 · Data.X509.ExtExtension ExtSubjectAltNameDefined in x509-1.7.7 · Data.X509.Ext
Provide a mean to identify the public key corresponding to the private key used to signed a certificate.
Constructors
Instances3Eq, Show, Extension
Eq ExtAuthorityKeyIdDefined in x509-1.7.7 · Data.X509.ExtShow ExtAuthorityKeyIdDefined in x509-1.7.7 · Data.X509.ExtExtension ExtAuthorityKeyIdDefined in x509-1.7.7 · Data.X509.Ext
Identify how CRL information is obtained
Constructors
Instances3Eq, Show, Extension
Eq ExtCrlDistributionPointsDefined in x509-1.7.7 · Data.X509.ExtShow ExtCrlDistributionPointsDefined in x509-1.7.7 · Data.X509.ExtExtension ExtCrlDistributionPointsDefined in x509-1.7.7 · Data.X509.Ext
Constructors
Instances3Eq, Show, Extension
Eq ExtNetscapeCommentDefined in x509-1.7.7 · Data.X509.ExtShow ExtNetscapeCommentDefined in x509-1.7.7 · Data.X509.ExtExtension ExtNetscapeCommentDefined in x509-1.7.7 · Data.X509.Ext
Different naming scheme use by the extension.
Not all name types are available, missing: otherName x400Address directoryName ediPartyName registeredID
Distribution point as either some GeneralNames or a DN
Instances2Eq, Show
Eq DistributionPointDefined in x509-1.7.7 · Data.X509.ExtShow DistributionPointDefined in x509-1.7.7 · Data.X509.Ext
Reason flag for the CRL
Instances4Enum, Eq, Ord, Show
Enum ReasonFlagDefined in x509-1.7.7 · Data.X509.ExtEq ReasonFlagDefined in x509-1.7.7 · Data.X509.ExtOrd ReasonFlagDefined in x509-1.7.7 · Data.X509.ExtShow ReasonFlagDefined in x509-1.7.7 · Data.X509.Ext
Get a specific extension from a lists of raw extensions
Get a specific extension from a lists of raw extensions
Try to decode an ExtensionRaw.
If this function return: * Nothing, the OID doesn't match * Just Left, the OID matched, but the extension couldn't be decoded * Just Right, the OID matched, and the extension has been succesfully decoded
Encode an Extension to extensionRaw
An undecoded extension
Constructors
ExtensionRawextRawOID :: OIDOID of this extension
extRawCritical :: Boolif this extension is critical
extRawContent :: ByteStringundecoded content
Instances3Eq, Show, ASN1Object
Eq ExtensionRawDefined in x509-1.7.7 · Data.X509.ExtensionRawShow ExtensionRawDefined in x509-1.7.7 · Data.X509.ExtensionRawASN1Object ExtensionRawDefined in x509-1.7.7 · Data.X509.ExtensionRaw
Deprecated. use tryExtRawASN1 instead
a Set of ExtensionRaw
Constructors
Instances3Eq, Show, ASN1Object
Eq ExtensionsDefined in x509-1.7.7 · Data.X509.ExtensionRawShow ExtensionsDefined in x509-1.7.7 · Data.X509.ExtensionRawASN1Object ExtensionsDefined in x509-1.7.7 · Data.X509.ExtensionRaw
Certificate Revocation List (CRL)
2 declarationsDescribe a Certificate revocation list
Describe a revoked certificate identifiable by serial number.
Constructors
Instances3Eq, Show, ASN1Object
Eq RevokedCertificateDefined in x509-1.7.7 · Data.X509.CRLShow RevokedCertificateDefined in x509-1.7.7 · Data.X509.CRLASN1Object RevokedCertificateDefined in x509-1.7.7 · Data.X509.CRL
Naming
4 declarationsA list of OID and strings.
Constructors
Instances6Eq, Ord, Show, Semigroup, Monoid, ASN1Object
Eq DistinguishedNameDefined in x509-1.7.7 · Data.X509.DistinguishedNameOrd DistinguishedNameDefined in x509-1.7.7 · Data.X509.DistinguishedNameShow DistinguishedNameDefined in x509-1.7.7 · Data.X509.DistinguishedNameSemigroup DistinguishedNameDefined in x509-1.7.7 · Data.X509.DistinguishedNameMonoid DistinguishedNameDefined in x509-1.7.7 · Data.X509.DistinguishedNameASN1Object DistinguishedNameDefined in x509-1.7.7 · Data.X509.DistinguishedName
Elements commonly available in a DistinguishedName structure
Constructors
DnCommonNameCN
DnCountryCountry
DnOrganizationO
DnOrganizationUnitOU
DnEmailAddressEmail Address (legacy)
ASN1 Character String with encoding
Instances4Eq, Ord, Show, IsString
Eq ASN1CharacterStringDefined in asn1-types-0.3.4 · Data.ASN1.Types.StringOrd ASN1CharacterStringDefined in asn1-types-0.3.4 · Data.ASN1.Types.StringShow ASN1CharacterStringDefined in asn1-types-0.3.4 · Data.ASN1.Types.StringIsString ASN1CharacterStringDefined in asn1-types-0.3.4 · Data.ASN1.Types.String
Try to get a specific element in a DistinguishedName structure
Certificate Chain
4 declarationsA chain of X.509 certificates in exact form.
Constructors
Instances2Eq, Show
Eq CertificateChainDefined in x509-1.7.7 · Data.X509.CertificateChainShow CertificateChainDefined in x509-1.7.7 · Data.X509.CertificateChain
Represent a chain of X.509 certificates in bytestring form.
Constructors
Instances2Eq, Show
Eq CertificateChainRawDefined in x509-1.7.7 · Data.X509.CertificateChainShow CertificateChainRawDefined in x509-1.7.7 · Data.X509.CertificateChain
Decode a CertificateChainRaw into a CertificateChain if every raw certificate are decoded correctly, otherwise return the index of the failed certificate and the error associated.
Convert a CertificateChain into a CertificateChainRaw
Signed types and marshalling
8 declarationsRepresent a signed object using a traditional X509 structure.
When dealing with external certificate, use the SignedExact structure not this one.
Constructors
SignedsignedObject :: aObject to sign
signedAlg :: SignatureALGSignature Algorithm used
signedSignature :: ByteStringSignature as bytes
Instances2Eq, Show
(Show a, ASN1Object a, Eq a) => Eq (Signed a)Defined in x509-1.7.7 · Data.X509.Signed(Eq a, ASN1Object a, Show a) => Show (Signed a)Defined in x509-1.7.7 · Data.X509.Signed
Represent the signed object plus the raw data that we need to keep around for non compliant case to be able to verify signature.
Instances2Eq, Show
(Show a, Eq a, ASN1Object a) => Eq (SignedExact a)Defined in x509-1.7.7 · Data.X509.Signed(Show a, Eq a, ASN1Object a) => Show (SignedExact a)Defined in x509-1.7.7 · Data.X509.Signed
get the decoded Signed data
Get the signed data for the signature
objectToSignedExact :: (Show a, Eq a, ASN1Object a)=> (ByteString -> (ByteString, SignatureALG, r))signature function
-> aobject to sign
-> (SignedExact a, r)
Transform an object into a SignedExact object
objectToSignedExactF :: (Functor f, Show a, Eq a, ASN1Object a)=> (ByteString -> f (ByteString, SignatureALG))signature function
-> aobject to sign
-> f (SignedExact a)
A generalization of objectToSignedExact where the signature function runs in an arbitrary functor. This allows for example to sign using an algorithm needing random values.
The raw representation of the whole signed structure
Try to parse a bytestring that use the typical X509 signed structure format
Parametrized Signed accessor
4 declarationsGet the Certificate associated to a SignedCertificate
Get the CRL associated to a SignedCRL
Try to decode a bytestring to a SignedCertificate
Try to decode a bytestring to a SignedCRL
Hash distinguished names related function
2 declarationsMake an OpenSSL style hash of distinguished name
OpenSSL algorithm is odd, and has been replicated here somewhat. only lower the case of ascii character.
Create an openssl style old hash of distinguished name