3
* (C) 1999-2007 Jack Lloyd
5
* Botan is released under the Simplified BSD License (see license.txt)
8
#ifndef BOTAN_X509_OBJECT_H_
9
#define BOTAN_X509_OBJECT_H_
11
#include <botan/asn1_obj.h>
12
#include <botan/alg_id.h>
13
#include <botan/cert_status.h>
19
class RandomNumberGenerator;
22
* This class represents abstract X.509 signed objects as in the X.500
25
class BOTAN_PUBLIC_API(2,0) X509_Object : public ASN1_Object
29
* The underlying data that is to be or was signed
30
* @return data that is or was signed
32
std::vector<uint8_t> tbs_data() const;
35
* @return signature on tbs_data()
37
const std::vector<uint8_t>& signature() const { return m_sig; }
42
const std::vector<uint8_t>& signed_body() const { return m_tbs_bits; }
45
* @return signature algorithm that was used to generate signature
47
const AlgorithmIdentifier& signature_algorithm() const { return m_sig_algo; }
50
* @return hash algorithm that was used to generate signature
52
std::string hash_used_for_signature() const;
55
* Create a signed X509 object.
56
* @param signer the signer used to sign the object
57
* @param rng the random number generator to use
58
* @param alg_id the algorithm identifier of the signature scheme
59
* @param tbs the tbs bits to be signed
60
* @return signed X509 object
62
static std::vector<uint8_t> make_signed(class PK_Signer* signer,
63
RandomNumberGenerator& rng,
64
const AlgorithmIdentifier& alg_id,
65
const secure_vector<uint8_t>& tbs);
68
* Check the signature on this data
69
* @param key the public key purportedly used to sign this data
70
* @return status of the signature - OK if verified or otherwise an indicator of
71
* the problem preventing verification.
73
Certificate_Status_Code verify_signature(const Public_Key& key) const;
76
* Check the signature on this data
77
* @param key the public key purportedly used to sign this data
78
* @return true if the signature is valid, otherwise false
80
bool check_signature(const Public_Key& key) const;
83
* Check the signature on this data
84
* @param key the public key purportedly used to sign this data
85
* the object will be deleted after use (this should have
86
* been a std::unique_ptr<Public_Key>)
87
* @return true if the signature is valid, otherwise false
89
bool check_signature(const Public_Key* key) const;
92
* DER encode an X509_Object
93
* See @ref ASN1_Object::encode_into()
95
void encode_into(class DER_Encoder& to) const override;
98
* Decode a BER encoded X509_Object
99
* See @ref ASN1_Object::decode_from()
101
void decode_from(class BER_Decoder& from) override;
104
* @return BER encoding of this
106
std::vector<uint8_t> BER_encode() const;
109
* @return PEM encoding of this
111
std::string PEM_encode() const;
113
X509_Object(const X509_Object&) = default;
114
X509_Object& operator=(const X509_Object&) = default;
116
virtual std::string PEM_label() const = 0;
118
virtual std::vector<std::string> alternate_PEM_labels() const
119
{ return std::vector<std::string>(); }
121
virtual ~X509_Object() = default;
124
X509_Object() = default;
127
* Decodes from src as either DER or PEM data, then calls force_decode()
129
void load_data(DataSource& src);
132
virtual void force_decode() = 0;
134
AlgorithmIdentifier m_sig_algo;
135
std::vector<uint8_t> m_tbs_bits;
136
std::vector<uint8_t> m_sig;