ocsp_resp_validate.h
Go to the documentation of this file.
1 /**
2  * @file ocsp_resp_validate.h
3  * @brief OCSP response validation
4  *
5  * @section License
6  *
7  * SPDX-License-Identifier: GPL-2.0-or-later
8  *
9  * Copyright (C) 2010-2024 Oryx Embedded SARL. All rights reserved.
10  *
11  * This file is part of CycloneCRYPTO Open.
12  *
13  * This program is free software; you can redistribute it and/or
14  * modify it under the terms of the GNU General Public License
15  * as published by the Free Software Foundation; either version 2
16  * of the License, or (at your option) any later version.
17  *
18  * This program is distributed in the hope that it will be useful,
19  * but WITHOUT ANY WARRANTY; without even the implied warranty of
20  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21  * GNU General Public License for more details.
22  *
23  * You should have received a copy of the GNU General Public License
24  * along with this program; if not, write to the Free Software Foundation,
25  * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
26  *
27  * @author Oryx Embedded SARL (www.oryx-embedded.com)
28  * @version 2.4.0
29  **/
30 
31 #ifndef _OCSP_RESP_VALIDATE_H
32 #define _OCSP_RESP_VALIDATE_H
33 
34 //Dependencies
35 #include "ocsp/ocsp_common.h"
36 
37 //C++ guard
38 #ifdef __cplusplus
39 extern "C" {
40 #endif
41 
42 //OCSP related functions
44  const X509CertInfo *certInfo, const X509CertInfo *issuerCertInfo,
45  const uint8_t *nonce, size_t nonceLen);
46 
48  const X509CertInfo *issuerCertInfo);
49 
51  const X509CertInfo *responderCertInfo, const X509CertInfo *issuerCertInfo);
52 
54  const X509CertInfo *issuerCertInfo);
55 
56 error_t ocspCheckCertId(const OcspCertId *certId, const X509CertInfo *certInfo,
57  const X509CertInfo *issuerCertInfo);
58 
59 error_t ocspCheckValidity(const OcspSingleResponse *singleResponse);
60 
61 error_t ocspCheckNonce(const OcspExtensions *extensions, const uint8_t *nonce,
62  size_t nonceLen);
63 
64 //C++ guard
65 #ifdef __cplusplus
66 }
67 #endif
68 
69 #endif
error_t
Error codes.
Definition: error.h:43
OCSP common definitions.
error_t ocspValidateResponse(const OcspResponse *response, const X509CertInfo *certInfo, const X509CertInfo *issuerCertInfo, const uint8_t *nonce, size_t nonceLen)
OCSP response validation.
error_t ocspCheckResponderId(const OcspResponderId *responderId, const X509CertInfo *issuerCertInfo)
Check responder identifier.
error_t ocspCheckValidity(const OcspSingleResponse *singleResponse)
Check the validity interval of the OCSP response.
error_t ocspCheckNonce(const OcspExtensions *extensions, const uint8_t *nonce, size_t nonceLen)
Check nonce.
error_t ocspCheckCertId(const OcspCertId *certId, const X509CertInfo *certInfo, const X509CertInfo *issuerCertInfo)
Check certificate identifier.
error_t ocspCheckResponseSignature(const OcspBasicResponse *basicResponse, const X509CertInfo *issuerCertInfo)
Verify response signature.
error_t ocspCheckResponderCert(const OcspResponderId *responderId, const X509CertInfo *responderCertInfo, const X509CertInfo *issuerCertInfo)
Check responder's certificate.
BasicOCSPResponse structure.
Definition: ocsp_common.h:275
CertID structure.
Definition: ocsp_common.h:142
OCSP extensions.
Definition: ocsp_common.h:176
ResponderID structure.
Definition: ocsp_common.h:238
OCSPResponse structure.
Definition: ocsp_common.h:288
SingleResponse structure.
Definition: ocsp_common.h:223
X.509 certificate.
Definition: x509_common.h:1064
uint8_t extensions[]
Definition: tls13_misc.h:300