openssl-prebuild/linux_amd64/ssl/share/doc/openssl/html/man3/X509_verify_cert.html

96 lines
3.2 KiB
HTML
Executable File

<?xml version="1.0" ?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>X509_verify_cert</title>
<meta http-equiv="content-type" content="text/html; charset=utf-8" />
<link rev="made" href="mailto:root@localhost" />
</head>
<body style="background-color: white">
<!-- INDEX BEGIN -->
<div name="index">
<p><a name="__index__"></a></p>
<ul>
<li><a href="#name">NAME</a></li>
<li><a href="#synopsis">SYNOPSIS</a></li>
<li><a href="#description">DESCRIPTION</a></li>
<li><a href="#return_values">RETURN VALUES</a></li>
<li><a href="#bugs">BUGS</a></li>
<li><a href="#see_also">SEE ALSO</a></li>
<li><a href="#copyright">COPYRIGHT</a></li>
</ul>
<hr name="index" />
</div>
<!-- INDEX END -->
<p>
</p>
<hr />
<h1><a name="name">NAME</a></h1>
<p>X509_verify_cert - discover and verify X509 certificate chain</p>
<p>
</p>
<hr />
<h1><a name="synopsis">SYNOPSIS</a></h1>
<pre>
#include &lt;openssl/x509.h&gt;</pre>
<pre>
int X509_verify_cert(X509_STORE_CTX *ctx);</pre>
<p>
</p>
<hr />
<h1><a name="description">DESCRIPTION</a></h1>
<p>The X509_verify_cert() function attempts to discover and validate a
certificate chain based on parameters in <strong>ctx</strong>. A complete description of
the process is contained in the <em>openssl-verify(1)</em> manual page.</p>
<p>Applications rarely call this function directly but it is used by
OpenSSL internally for certificate validation, in both the S/MIME and
SSL/TLS code.</p>
<p>A negative return value from X509_verify_cert() can occur if it is invoked
incorrectly, such as with no certificate set in <strong>ctx</strong>, or when it is called
twice in succession without reinitialising <strong>ctx</strong> for the second call.
A negative return value can also happen due to internal resource problems or if
a retry operation is requested during internal lookups (which never happens
with standard lookup methods).
Applications must check for &lt;= 0 return value on error.</p>
<p>
</p>
<hr />
<h1><a name="return_values">RETURN VALUES</a></h1>
<p>If a complete chain can be built and validated this function returns 1,
otherwise it return zero, in exceptional circumstances it can also
return a negative code.</p>
<p>If the function fails additional error information can be obtained by
examining <strong>ctx</strong> using, for example X509_STORE_CTX_get_error().</p>
<p>
</p>
<hr />
<h1><a name="bugs">BUGS</a></h1>
<p>This function uses the header <em class="file">&lt;x509.h</em> &gt;&gt;
as opposed to most chain verification
functions which use <em class="file">&lt;x509_vfy.h</em> &gt;&gt;.</p>
<p>
</p>
<hr />
<h1><a name="see_also">SEE ALSO</a></h1>
<p><em>X509_STORE_CTX_get_error(3)</em></p>
<p>
</p>
<hr />
<h1><a name="copyright">COPYRIGHT</a></h1>
<p>Copyright 2009-2016 The OpenSSL Project Authors. All Rights Reserved.</p>
<p>Licensed under the Apache License 2.0 (the &quot;License&quot;). You may not use
this file except in compliance with the License. You can obtain a copy
in the file LICENSE in the source distribution or at
<a href="https://www.openssl.org/source/license.html">https://www.openssl.org/source/license.html</a>.</p>
</body>
</html>