]>
Commit | Line | Data |
---|---|---|
b1ab9ed8 | 1 | /* |
d8f41ccd | 2 | * Copyright (c) 2002,2011,2014 Apple Inc. All Rights Reserved. |
b1ab9ed8 A |
3 | * |
4 | * The contents of this file constitute Original Code as defined in and are | |
5 | * subject to the Apple Public Source License Version 1.2 (the 'License'). | |
6 | * You may not use this file except in compliance with the License. Please obtain | |
7 | * a copy of the License at http://www.apple.com/publicsource and read it before | |
8 | * using this file. | |
9 | * | |
10 | * This Original Code and all software distributed under the License are | |
11 | * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS | |
12 | * OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, INCLUDING WITHOUT | |
13 | * LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR | |
14 | * PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. Please see the License for the | |
15 | * specific language governing rights and limitations under the License. | |
16 | */ | |
17 | ||
18 | ||
19 | /* | |
20 | * TPNetwork.h - LDAP (and eventually) other network tools | |
21 | * | |
b1ab9ed8 A |
22 | */ |
23 | ||
24 | #ifndef _TP_NETWORK_H_ | |
25 | #define _TP_NETWORK_H_ | |
26 | ||
27 | #include <Security/cssmtype.h> | |
28 | #include "TPCertInfo.h" | |
29 | #include "TPCrlInfo.h" | |
30 | ||
31 | extern "C" { | |
32 | ||
33 | /* | |
34 | * Fetch CRL(s) for specified cert if the cert has a cRlDistributionPoint | |
35 | * extension. If a non-NULL CRL is returned, it has passed verification | |
36 | * with specified TPVerifyContext. | |
37 | * The common, trivial failure of "no URI in a cRlDistributionPoint | |
38 | * extension" is indicated by CSSMERR_APPLETP_CRL_NOT_FOUND. | |
39 | */ | |
40 | extern CSSM_RETURN tpFetchCrlFromNet( | |
41 | TPCertInfo &cert, | |
42 | TPVerifyContext &verifyContext, | |
43 | TPCrlInfo *&crl); // RETURNED | |
44 | ||
45 | /* | |
46 | * Fetch issuer cert of specified cert if the cert has an issuerAltName | |
47 | * with a URI. If non-NULL cert is returned, it has passed subject/issuer | |
48 | * name comparison and signature verification with target cert. | |
49 | * The common, trivial failure of "no URI in an issuerAltName | |
50 | * extension" is indicated by CSSMERR_TP_CERTGROUP_INCOMPLETE. | |
51 | * A CSSMERR_CSP_APPLE_PUBLIC_KEY_INCOMPLETE return indicates that | |
52 | * subsequent signature verification is needed. | |
53 | */ | |
54 | extern CSSM_RETURN tpFetchIssuerFromNet( | |
55 | TPCertInfo &subject, | |
56 | CSSM_CL_HANDLE clHand, | |
57 | CSSM_CSP_HANDLE cspHand, | |
58 | const char *verifyTime, | |
59 | TPCertInfo *&issuer); // RETURNED | |
60 | ||
61 | } | |
62 | ||
63 | #endif /* TP_NETWORK_H_ */ |