41#define SEC_NULL_KEY SecStringWithDefaultValue("<NULL>","Certificate", 0,"<NULL>","Value of a field if its length is 0")
42#define SEC_OID_TOO_LONG_KEY SecStringWithDefaultValue("OID too long","Certificate", 0,"OID too long","value of an OID field if its length is more than what we allow for OIDs")
43#define SEC_UNPARSED_KEY SecStringWithDefaultValue("Unparsed %@","Certificate", 0,"Unparsed %@","Label of a value is printed into this string if the data can not been parsed according to its type")
44#define SEC_INVALID_KEY SecStringWithDefaultValue("Invalid %@","Certificate", 0,"Invalid %@","Label of a value is printed into this string if the data is not valid")
45#define SEC_ALGORITHM_KEY SecStringWithDefaultValue("Algorithm","Certificate", 0,"Algorithm","Label of the algorithm sub-field of an AlgorithmIdentifier")
46#define SEC_PARAMETERS_KEY SecStringWithDefaultValue("Parameters","Certificate", 0,"Parameters","Label of the parameters sub-field of an AlgorithmIdentifier")
47#define SEC_NONE_KEY SecStringWithDefaultValue("none","Certificate", 0,"none","field value of parameters field when no parameters are present")
48#define SEC_BLOB_KEY SecStringWithDefaultValue("%@;%d%@; data = %@","Certificate", 0,"%@;%d%@; data = %@","Format string for encoded field data (e.g. Sequence; 128 bytes; data = 00 00 ...)")
49#define SEC_BYTE_STRING_KEY SecStringWithDefaultValue("Byte string","Certificate", 0,"Byte string","First argument to SEC_BLOB_KEY format string for a Byte string")
50#define SEC_BYTES_KEY SecStringWithDefaultValue("bytes","Certificate", 0,"bytes","Third argument to SEC_BLOB_KEY format string for a byte string")
51#define SEC_BIT_STRING_KEY SecStringWithDefaultValue("Bit string","Certificate", 0,"Bit string","First argument to SEC_BLOB_KEY format string for a bit string")
53#define SEC_SEQUENCE_KEY SecStringWithDefaultValue("Sequence","Certificate", 0,"Sequence","First argument to SEC_BLOB_KEY format string for a Sequence")
54#define SEC_SET_KEY SecStringWithDefaultValue("Set","Certificate", 0,"Set","First argument to SEC_BLOB_KEY format string for a Set")
55#define SEC_NOT_DISPLAYED_KEY SecStringWithDefaultValue("not displayed (tag =%ld; length%ld)","Certificate", 0,"not displayed (tag =%ld; length%ld)","format string for undisplayed field data with a given DER tag and length")
56#define SEC_RDN_KEY SecStringWithDefaultValue("RDN","Certificate", 0,"RDN","Label of a RDN")
57#define SEC_X501_NAME_KEY SecStringWithDefaultValue("X.501 Name","Certificate", 0,"X.501 Name","Label of a X.501 Name")
58#define SEC_YES_KEY SecStringWithDefaultValue("Yes","Certificate", 0,"Yes","Value for a boolean property when it's value is true (example critical: yes)")
59#define SEC_NO_KEY SecStringWithDefaultValue("No","Certificate", 0,"No","Value for a boolean property when it's value is false (example critical: no)")
60#define SEC_STRING_LIST_KEY SecStringWithDefaultValue("%@, %@","Certificate", 0,"%@, %@","Format string used to build a list of values, first argument is list second argument is to be appended element")
70#define SEC_USAGE_KEY SecStringWithDefaultValue("Usage","Certificate", 0,"Usage","Label for Key Usage bit-field values")
71#define SEC_NOT_VALID_BEFORE_KEY SecStringWithDefaultValue("Not Valid Before","Certificate", 0,"Not Valid Before","label indicating the soonest date at which something is valid")
72#define SEC_NOT_VALID_AFTER_KEY SecStringWithDefaultValue("Not Valid After","Certificate", 0,"Not Valid After","label indicating the date after which something is no longer valid")
74#define SEC_PRIVATE_KU_PERIOD_KEY SecStringWithDefaultValue("Private Key Usage Period","Certificate", 0,"Private Key Usage Period","Label for an invalid private key usage period value")
75#define SEC_OTHER_NAME_KEY SecStringWithDefaultValue("Other Name","Certificate", 0,"Other Name","Label used for Other Name RDN when value is invalid")
76#define SEC_EMAIL_ADDRESS_KEY SecStringWithDefaultValue("Email Address","Certificate", 0,"Email Address","label for general name field value")
77#define SEC_DNS_NAME_KEY SecStringWithDefaultValue("DNS Name","Certificate", 0,"DNS Name","label for general name field value")
78#define SEC_X400_ADDRESS_KEY SecStringWithDefaultValue("X.400 Address","Certificate", 0,"X.400 Address","label for general name field value")
79#define SEC_DIRECTORY_NAME_KEY SecStringWithDefaultValue("Directory Name","Certificate", 0,"Directory Name","label for general name field value")
80#define SEC_EDI_PARTY_NAME_KEY SecStringWithDefaultValue("EDI Party Name","Certificate", 0,"EDI Party Name","label for general name field value")
81#define SEC_URI_KEY SecStringWithDefaultValue("URI","Certificate", 0,"URI","label for general name field value")
82#define SEC_IP_ADDRESS_KEY SecStringWithDefaultValue("IP Address","Certificate", 0,"IP Address","label for general name field value")
83#define SEC_REGISTERED_ID_KEY SecStringWithDefaultValue("Registered ID","Certificate", 0,"Registered ID","label for general name field value")
84#define SEC_GENERAL_NAME_KEY SecStringWithDefaultValue("General Name","Certificate", 0,"General Name","Label used for General Name entry when value is invalid")
85#define SEC_GENERAL_NAMES_KEY SecStringWithDefaultValue("General Names","Certificate", 0,"General Names","Label used for General Names when value is invalid")
86#define SEC_CERT_AUTHORITY_KEY SecStringWithDefaultValue("Certificate Authority","Certificate", 0,"Certificate Authority","Label for boolean is_ca property of a basic constraints extension")
87#define SEC_PATH_LEN_CONSTRAINT_KEY SecStringWithDefaultValue("Path Length Constraint","Certificate", 0,"Path Length Constraint","Label for path length constraint property of a basic constraints extension")
88#define SEC_BASIC_CONSTRAINTS_KEY SecStringWithDefaultValue("Basic Constraints","Certificate", 0,"Basic Constraints","Label used for Basic Constraints when value is invalid")
91#define SEC_NAME_CONSTRAINTS_KEY SecStringWithDefaultValue("Name Constraints","Certificate", 0,"Name Constraints","Label used for Name Constraints when value is invalid")
92#define SEC_PERMITTED_MINIMUM_KEY SecStringWithDefaultValue("Permitted Subtree Minimum","Certificate", 0,"Permitted Subtree Minimum","Label for minimum base distance property of a permitted subtree in name constraints extension.")
93#define SEC_PERMITTED_MAXIMUM_KEY SecStringWithDefaultValue("Permitted Subtree Maximum","Certificate", 0,"Permitted Subtree Maximum","Label for maximum base distance property of a permitted subtree in name constraints extension.")
94#define SEC_PERMITTED_NAME_KEY SecStringWithDefaultValue("Permitted Subtree General Name","Certificate", 0,"Permitted Subtree General Name","Label for general name of a permitted subtree in name constraints extension.")
95#define SEC_EXCLUDED_MINIMUM_KEY SecStringWithDefaultValue("Excluded Subtree Minimum","Certificate", 0,"Excluded Subtree Minimum","Label for minimum base distance property of an excluded subtree in name constraints extension.")
96#define SEC_EXCLUDED_MAXIMUM_KEY SecStringWithDefaultValue("Excluded Subtree Maximum","Certificate", 0,"Excluded Subtree Maximum","Label for maximum base distance property of an excluded subtree in name constraints extension.")
97#define SEC_EXCLUDED_NAME_KEY SecStringWithDefaultValue("Excluded Subtree General Name","Certificate", 0,"Excluded Subtree General Name","Label for general name of an excluded subtree in name constraints extension.")
100#define SEC_NAME_REL_CRL_ISSUER_KEY SecStringWithDefaultValue("Name Relative To CRL Issuer","Certificate", 0,"Name Relative To CRL Issuer","Subsection label in CRL Distribution Points extension.")
101#define SEC_UNUSED_KEY SecStringWithDefaultValue("Unused","Certificate", 0,"Unused","CRL Distribution Points extension supported reason name")
105#define SEC_SUPERSEDED_KEY SecStringWithDefaultValue("Superseded","Certificate", 0,"Superseded","CRL Distribution Points extension supported reason name")
106#define SEC_CESSATION_OF_OPER_KEY SecStringWithDefaultValue("Cessation Of Operation","Certificate", 0,"Cessation Of Operation","CRL Distribution Points extension supported reason name")
111#define SEC_CRL_ISSUER_KEY SecStringWithDefaultValue("CRL Issuer","Certificate", 0,"CRL Issuer","Label for CRL issuer field of CRL Distribution Points extension")
112#define SEC_CRL_DISTR_POINTS_KEY SecStringWithDefaultValue("CRL Distribution Points","Certificate", 0,"CRL Distribution Points","CRL Distribution Points extension label")
115#define SEC_POLICY_IDENTIFIER_KEY SecStringWithDefaultValue("Policy Identifier #%d","Certificate", 0,"Policy Identifier #%d","Format string for label of field in Certificate Policies extension,%dis a monotonic increasing counter starting at 1")
116#define SEC_POLICY_QUALIFIER_KEY SecStringWithDefaultValue("Policy Qualifier #%d","Certificate", 0,"Policy Qualifier #%d","Format string for label of field in Certificate Policies extension,%dis a monotonic increasing counter starting at 1")
117#define SEC_CPS_URI_KEY SecStringWithDefaultValue("CPS URI","Certificate", 0,"CPS URI","Label of field in Certificate Policies extension")
118#define SEC_ORGANIZATION_KEY SecStringWithDefaultValue("Organization","Certificate", 0,"Organization","Label of field in Certificate Policies extension")
119#define SEC_NOTICE_NUMBERS_KEY SecStringWithDefaultValue("Notice Numbers","Certificate", 0,"Notice Numbers","Label of field in Certificate Policies extension")
120#define SEC_EXPLICIT_TEXT_KEY SecStringWithDefaultValue("Explicit Text","Certificate", 0,"Explicit Text","Label of field in Certificate Policies extension")
121#define SEC_QUALIFIER_KEY SecStringWithDefaultValue("Qualifier","Certificate", 0,"Qualifier","Label of field in Certificate Policies extension")
124/* Subject and Authority Key Identifier extensions */
125#define SEC_KEY_IDENTIFIER_KEY SecStringWithDefaultValue("Key Identifier","Certificate", 0,"Key Identifier","Label of field in Subject or Authority Key Identifier extension")
127#define SEC_AUTH_CERT_SERIAL_KEY SecStringWithDefaultValue("Authority Certificate Serial Number","Certificate", 0,"Authority Certificate Serial Number","Label of field in Authority Key Identifier extension")
131#define SEC_REQUIRE_EXPL_POLICY_KEY SecStringWithDefaultValue("Require Explicit Policy","Certificate", 0,"Require Explicit Policy","Label of field in policy constraints extension")
132#define SEC_INHIBIT_POLICY_MAP_KEY SecStringWithDefaultValue("Inhibit Policy Mapping","Certificate", 0,"Inhibit Policy Mapping","Label of field in policy constraints extension")
140#define SEC_ACCESS_METHOD_KEY SecStringWithDefaultValue("Access Method","Certificate", 0,"Access Method","Label of field in authority info access extension")
141//#define SEC_ACCESS_LOCATION_KEY SecStringWithDefaultValue("Access Location", "Certificate", 0, "Access Location", "Label of field in authority info access extension")
142#define SEC_AUTH_INFO_ACCESS_KEY SecStringWithDefaultValue("Authority Information Access","Certificate", 0,"Authority Information Access","Authority info access extension label")
155#define SEC_CRITICAL_KEY SecStringWithDefaultValue("Critical","Certificate", 0,"Critical","Label of field in extension that indicates whether this extension is critical")
156#define SEC_DATA_KEY SecStringWithDefaultValue("Data","Certificate", 0,"Data","Label for raw data of extension (used for unknown extensions)")
158#define SEC_COMMON_NAME_DESC_KEY SecStringWithDefaultValue("%@ (%@)","Certificate", 0,"%@ (%@)","If a X.500 name has a description and a common name we display Common Name (Description) using this format string")
165#define SEC_CERT_NOT_YET_VALID_KEY SecStringWithDefaultValue("This certificate is not yet valid","Certificate", 0,"This certificate is not yet valid","")
166#define SEC_ISSUER_EXPIRED_KEY SecStringWithDefaultValue("This certificate has an issuer that has expired","Certificate", 0,"This certificate has an issuer that has expired","")
167#define SEC_ISSR_NOT_YET_VALID_KEY SecStringWithDefaultValue("This certificate has an issuer that is not yet valid","Certificate", 0,"This certificate has an issuer that is not yet valid","")
168#define SEC_EXPIRES_KEY SecStringWithDefaultValue("Expires","Certificate", 0,"Expires","Label of expiration date value when certificate is temporally valid")
169#define SEC_CERT_VALID_KEY SecStringWithDefaultValue("This certificate is valid","Certificate", 0,"This certificate is valid","The certificate is temporally valid")
194#define SEC_CK_PASSWORD_INCORRECT SecStringWithDefaultValue("Incorrect Password For “%@”","CloudKeychain", 0,"Incorrect Password For “%@”","Title for alert when password has been entered incorrectly")
195#define SEC_CK_TRY_AGAIN SecStringWithDefaultValue("Try Again","CloudKeychain", 0,"Try Again","Button for try again after incorrect password")
209#define SEC_CK_PWD_REQUIRED_TITLE SecStringWithDefaultValue("Apple ID Password Required","CloudKeychain", 0,"Apple ID Password Required","Title for alert when iCloud keychain was disabled or reset")
210#define SEC_CK_PWD_REQUIRED_BODY_OSX SecStringWithDefaultValue("Enter your password in Apple ID Preferences.","CloudKeychain", 0,"Enter your password in Apple ID Preferences.","macOS alert text when iCloud keychain was disabled or reset")
211#define SEC_CK_PWD_REQUIRED_BODY_IOS SecStringWithDefaultValue("Enter your password in iCloud Settings.","CloudKeychain", 0,"Enter your password in iCloud Settings.","iOS alert text when iCloud keychain was disabled or reset")
216#define SEC_CK_APPROVAL_TITLE SecStringWithDefaultValue("Approve “%@”?","CloudKeychain", 0,"Approve “%@”?","Title for alert when approving another device")
217#define SEC_CK_APPROVAL_BODY_OSX_IPAD SecStringWithDefaultValue("This iPad wants to use your iCloud account.","CloudKeychain", 0,"This iPad wants to use your iCloud account.","Body text when approving an iPad on Mac")
218#define SEC_CK_APPROVAL_BODY_OSX_IPHONE SecStringWithDefaultValue("This iPhone wants to use your iCloud account.","CloudKeychain", 0,"This iPhone wants to use your iCloud account.","Body text when approving an iPhone on Mac")
219#define SEC_CK_APPROVAL_BODY_OSX_IPOD SecStringWithDefaultValue("This iPod wants to use your iCloud account.","CloudKeychain", 0,"This iPod wants to use your iCloud account.","Body text when approving an iPod on Mac")
220#define SEC_CK_APPROVAL_BODY_OSX_MAC SecStringWithDefaultValue("This Mac wants to use your iCloud account.","CloudKeychain", 0,"This Mac wants to use your iCloud account.","Body text when approving a Mac on Mac")
221#define SEC_CK_APPROVAL_BODY_OSX_GENERIC SecStringWithDefaultValue("This device wants to use your iCloud account.","CloudKeychain", 0,"This device wants to use your iCloud account.","Body text when approving a device on Mac")
222#define SEC_CK_APPROVE SecStringWithDefaultValue("Approve","CloudKeychain", 0,"Approve","Button text to approve iCloud sign in request")
223#define SEC_CK_DECLINE SecStringWithDefaultValue("Decline","CloudKeychain", 0,"Decline","Button text to decline iCloud sign in request")
225#define SEC_CK_APPROVAL_BODY_IOS_IPAD SecStringWithDefaultValue("Enter the password for the Apple ID “%@” to allow this new iPad to use your iCloud account.","CloudKeychain", 0,"Enter the password for the Apple ID “%@” to allow this new iPad to use your iCloud account.","Body text when approving an iPad")
226#define SEC_CK_APPROVAL_BODY_IOS_IPHONE SecStringWithDefaultValue("Enter the password for the Apple ID “%@” to allow this new iPhone to use your iCloud account.","CloudKeychain", 0,"Enter the password for the Apple ID “%@” to allow this new iPhone to use your iCloud account.","Body text when approving an iPhone")
227#define SEC_CK_APPROVAL_BODY_IOS_IPOD SecStringWithDefaultValue("Enter the password for the Apple ID “%@” to allow this new iPod to use your iCloud account.","CloudKeychain", 0,"Enter the password for the Apple ID “%@” to allow this new iPod to use your iCloud account.","Body text when approving an iPod")
228#define SEC_CK_APPROVAL_BODY_IOS_MAC SecStringWithDefaultValue("Enter the password for the Apple ID “%@” to allow this new Mac to use your iCloud account.","CloudKeychain", 0,"Enter the password for the Apple ID “%@” to allow this new Mac to use your iCloud account.","Body text when approving another Mac")
229#define SEC_CK_APPROVAL_BODY_IOS_GENERIC SecStringWithDefaultValue("Enter the password for the Apple ID “%@” to allow this new device to use your iCloud account.","CloudKeychain", 0,"Enter the password for the Apple ID “%@” to allow this new device to use your iCloud account.","Body text when approving another (generic) device")
231#define SEC_CK_REMINDER_TITLE_OSX SecStringWithDefaultValue("iCloud Approval Required","CloudKeychain", 0,"iCloud Approval Required","Title for reminder that iCloud Keychain Application (from this device) is still pending")
232#define SEC_CK_REMINDER_BODY_OSX SecStringWithDefaultValue("This Mac is still waiting for approval by another device.","CloudKeychain", 0,"This Mac is still waiting for approval by another device.","Body text for reminder that iCloud Keychain Application (from this device) is still pending")
233#define SEC_CK_REMINDER_TITLE_IOS SecStringWithDefaultValue("Approval Request Sent","CloudKeychain", 0,"Approval Request Sent","Title for reminder that iCloud Keychain Application (from this device) is still pending")
234#define SEC_CK_REMINDER_BODY_IOS_IPAD SecStringWithDefaultValue("To continue using iCloud on this iPad, approve it from one of your other devices using iCloud or enter your iCloud Security Code.","CloudKeychain", 0,"To continue using iCloud on this iPad, approve it from one of your other devices using iCloud or enter your iCloud Security Code.","Body of reminder text that the iCloud keychain application for this iPad is still pending")
235#define SEC_CK_REMINDER_BODY_IOS_IPHONE SecStringWithDefaultValue("To continue using iCloud on this iPhone, approve it from one of your other devices using iCloud or enter your iCloud Security Code.","CloudKeychain", 0,"To continue using iCloud on this iPhone, approve it from one of your other devices using iCloud or enter your iCloud Security Code.","Body of reminder text that the iCloud keychain application for this iPhone is still pending")
236#define SEC_CK_REMINDER_BODY_IOS_IPOD SecStringWithDefaultValue("To continue using iCloud on this iPod, approve it from one of your other devices using iCloud or enter your iCloud Security Code.","CloudKeychain", 0,"To continue using iCloud on this iPod, approve it from one of your other devices using iCloud or enter your iCloud Security Code.","Body of reminder text that the iCloud keychain application for this iPod is still pending")
237#define SEC_CK_REMINDER_BODY_IOS_GENERIC SecStringWithDefaultValue("To continue using iCloud on this device, approve it from one of your other devices using iCloud or enter your iCloud Security Code.","CloudKeychain", 0,"To continue using iCloud on this device, approve it from one of your other devices using iCloud or enter your iCloud Security Code.","Body of reminder text that the iCloud keychain application for this device is still pending")
238#define SEC_CK_REMINDER_BUTTON_ICSC SecStringWithDefaultValue("Use Security Code","CloudKeychain", 0,"Use Security Code","Button label to approve via iCSC")
239#define SEC_CK_REMINDER_BUTTON_OK SecStringWithDefaultValue("OK","CloudKeychain", 0,"OK","Button label to acknowledge/dismiss reminder alert without further action")
243#define SEC_BAD_CRIT_EXTN_KEY SecStringWithDefaultValue("One or more unsupported critical extensions found.","Certificate", 0,"One or more unsupported critical extensions found.","")
244#define SEC_ROOT_UNTRUSTED_KEY SecStringWithDefaultValue("Root certificate is not trusted.","Certificate", 0,"Root certificate is not trusted.","")
246#define SEC_POLICY__REQ_NOT_MET_KEY SecStringWithDefaultValue("Policy requirements not met.","Certificate", 0,"Policy requirements not met.","")
247#define SEC_CHAIN_VALIDITY_ERR_KEY SecStringWithDefaultValue("One or more certificates have expired or are not valid yet.","Certificate", 0,"One or more certificates have expired or are not valid yet.","")
248#define SEC_WEAK_KEY_ERR_KEY SecStringWithDefaultValue("One or more certificates is using a weak key size.","Certificate", 0,"One or more certificates is using a weak key size.","")
249#define SEC_MISSING_INTERMEDIATE_KEY SecStringWithDefaultValue("Unable to build chain to root certificate.","Certificate", 0,"Unable to build chain to root certificate.","")
251#define SEC_TRUST_CERTIFICATE_ERROR SecStringWithDefaultValue("Certificate%ld “%@” has errors: ","Trust", 0,"Certificate%ld “%@” has errors: ","Preface for per-certificate errors")
253#define SEC_TRUST_ERROR_SUBTYPE_BLOCKED SecStringWithDefaultValue("“%@” certificate is blocked","Trust", 0,"“%@” certificate is blocked","Error for blocked certificates")
254#define SEC_TRUST_ERROR_SUBTYPE_REVOKED SecStringWithDefaultValue("“%@” certificate is revoked","Trust", 0,"“%@” certificate is revoked","Error for revoked certificates")
255#define SEC_TRUST_ERROR_SUBTYPE_KEYSIZE SecStringWithDefaultValue("“%@” certificate is using a broken key size","Trust", 0,"“%@” certificate is using a broken key size","Error for certificates with weak key sizes")
256#define SEC_TRUST_ERROR_SUBTYPE_WEAKHASH SecStringWithDefaultValue("“%@” certificate is using a broken signature algorithm","Trust", 0,"“%@” certificate is using a broken signature algorithm","Error for certificates with weak signature algorithms")
257#define SEC_TRUST_ERROR_SUBTYPE_DENIED SecStringWithDefaultValue("User or administrator set “%@” certificate as distrusted","Trust", 0,"User or administrator set “%@” certificate as distrusted","Error for certificates with deny trust settings")
258#define SEC_TRUST_ERROR_SUBTYPE_COMPLIANCE SecStringWithDefaultValue("“%@” certificate is not standards compliant","Trust", 0,"“%@” certificate is not standards compliant","Error for certificates that violate standards")
259#define SEC_TRUST_ERROR_SUBTYPE_EXPIRED SecStringWithDefaultValue("“%@” certificate is expired","Trust", 0,"“%@” certificate is expired","Error for certificates that are expired")
260#define SEC_TRUST_ERROR_SUBTYPE_TRUST SecStringWithDefaultValue("“%@” certificate is not trusted","Trust", 0,"“%@” certificate is not trusted","Error for certificates that are not trusted")
261#define SEC_TRUST_ERROR_SUBTYPE_NAME SecStringWithDefaultValue("“%@” certificate name does not match input","Trust", 0,"“%@” certificate name does not match input","Error for certificates whose names do not match the policy")
262#define SEC_TRUST_ERROR_SUBTYPE_USAGE SecStringWithDefaultValue("“%@” certificate is not permitted for this usage","Trust", 0,"“%@” certificate is not permitted for this usage","Error for certificates whose usages do not match the policy")
263#define SEC_TRUST_ERROR_SUBTYPE_PINNING SecStringWithDefaultValue("%@ certificates do not meet pinning requirements","Trust", 0,"%@ certificates do not meet pinning requirements","Error for certificates that do not meet pinning requirements")
264#define SEC_TRUST_ERROR_SUBTYPE_ISSUER SecStringWithDefaultValue("“%@” certificate does not meet issuer constraints","Trust", 0,"“%@” certificate does not meet issuer constraints","Error for certificates which violate constraints set on their issuer")
265#define SEC_TRUST_ERROR_SUBTYPE_INVALID SecStringWithDefaultValue("Unknown trust error for “%@” certificate","Trust", 0,"Unknown trust error for “%@” certificate","Error for unknown error")
267//Note the the following errors do not follow the casing conventions of the above so that they can be used with POLICYCHECKMACRO
268#define SEC_TRUST_ERROR_SSLHostname SecStringWithDefaultValue("SSL hostname does not match name(s) in certificate","Trust", 0,"SSL hostname does not match name(s) in certificate","Error for SSL hostname mismatch")
269#define SEC_TRUST_ERROR_Email SecStringWithDefaultValue("Email address does not match name(s) in certificate","Trust", 0,"Email address does not match name(s) in certificate","Error for email mismatch")
270#define SEC_TRUST_ERROR_TemporalValidity SecStringWithDefaultValue("Certificate is not temporally valid","Trust", 0,"Certificate is not temporally valid","Error for temporal validity")
271#define SEC_TRUST_ERROR_WeakKeySize SecStringWithDefaultValue("Certificate is using a broken key size","Trust", 0,"Certificate is using a broken key size","Error for weak keys")
272#define SEC_TRUST_ERROR_WeakSignature SecStringWithDefaultValue("Certificate is using a broken signature algorithm","Trust", 0,"Certificate is using a broken signature algorithm","Error for weak signatures")
273#define SEC_TRUST_ERROR_KeyUsage SecStringWithDefaultValue("Key usage does not match certificate usage","Trust", 0,"Key usage does not match certificate usage","Error for key usage mismatch")
274#define SEC_TRUST_ERROR_ExtendedKeyUsage SecStringWithDefaultValue("Extended key usage does not match certificate usage","Trust", 0,"Extended key usage does not match certificate usage","Error for extended key usage mismatch")
275#define SEC_TRUST_ERROR_SubjectCommonName SecStringWithDefaultValue("Common Name does not match expected name","Trust", 0,"Common Name does not match expected name","Error for subject common name mismatch")
276#define SEC_TRUST_ERROR_SubjectCommonNamePrefix SecStringWithDefaultValue("Common Name does not match expected name","Trust", 0,"Common Name does not match expected name","Error for subject common name prefix mismatch")
277#define SEC_TRUST_ERROR_SubjectCommonNameTEST SecStringWithDefaultValue("Common Name does not match expected name","Trust", 0,"Common Name does not match expected name","Error for subject common name mismatch, allowing test")
278#define SEC_TRUST_ERROR_SubjectOrganization SecStringWithDefaultValue("Organization does not match expected name","Trust", 0,"Organization does not match expected name","Error for subject organization mismatch")
279#define SEC_TRUST_ERROR_SubjectOrganizationalUnit SecStringWithDefaultValue("Organizational Unit does not match expected name","Trust", 0,"Certificate Organizational Unit does not match expected name","Error for subject organizational unit mismatch")
280#define SEC_TRUST_ERROR_NotValidBefore SecStringWithDefaultValue("Certificate issued before allowed time","Trust", 0,"Certificate issued before allowed time","Error for not before date")
281#define SEC_TRUST_ERROR_EAPTrustedServerNames SecStringWithDefaultValue("Trusted EAP hostname does not match name(s) in certificate","Trust", 0,"Trusted EAP hostname does not match name(s) in certificate","Error for EAP hostname mismatch")
283#define SEC_TRUST_ERROR_LeafMarkerOidWithoutValueCheck SecStringWithDefaultValue("Missing project-specific extension OID","Trust", 0,"Missing project-specific extension OID","Error for leaf marker OID without value check")
284#define SEC_TRUST_ERROR_LeafMarkersProdAndQA SecStringWithDefaultValue("Missing project-specific extension OID","Trust", 0,"Missing project-specific extension OID","Error for leaf marker OID allowing prod or QA")
285#define SEC_TRUST_ERROR_BlackListedLeaf SecStringWithDefaultValue("Certificate is blocked","Trust", 0,"Certificate is blocked","Error for blocklisted certificates")
286#define SEC_TRUST_ERROR_GrayListedLeaf SecStringWithDefaultValue("Certificate is listed as untrusted","Trust", 0,"Certificate is listed as untrusted","Error for graylisted certificates")
287#define SEC_TRUST_ERROR_IssuerCommonName SecStringWithDefaultValue("Common Name does not match expected name","Trust", 0,"Common Name does not match expected name","Error for issuer common name mismatch")
288#define SEC_TRUST_ERROR_BasicConstraints SecStringWithDefaultValue("Basic constraints are required but missing","Trust", 0,"Basic constraints are required but missing","Error for missing basic constraints")
289#define SEC_TRUST_ERROR_BasicConstraintsCA SecStringWithDefaultValue("Non-CA certificate used as a CA","Trust", 0,"Non-CA certificate used as a CA","Error for CA basic constraints")
291#define SEC_TRUST_ERROR_IntermediateSPKISHA256 SecStringWithDefaultValue("Public key does not match pinned value","Trust", 0,"Public key does not match pinned value","Error for intermediate public key pin")
292#define SEC_TRUST_ERROR_IntermediateEKU SecStringWithDefaultValue("Extended key usage does not match pinned value","Trust", 0,"Extended key usage does not match pinned value","Error for intermediate extended key usage pin")
295#define SEC_TRUST_ERROR_IntermediateOrganization SecStringWithDefaultValue("Organization does not match expected name","Trust", 0,"Organization does not match expected name","Error for issuer organization mismatch")
296#define SEC_TRUST_ERROR_IntermediateCountry SecStringWithDefaultValue("Country or Region does not match expected name","Trust", 0,"Country or Region does not match expected name","Error for issuer country mismatch")
297#define SEC_TRUST_ERROR_AnchorSHA1 SecStringWithDefaultValue("Anchor does not match pinned fingerprint","Trust", 0,"Anchor does not match pinned fingerprint","Error for anchor SHA-1 fingerprint pin")
298#define SEC_TRUST_ERROR_AnchorSHA256 SecStringWithDefaultValue("Anchor does not match pinned fingerprint","Trust", 0,"Anchor does not match pinned fingerprint","Error for anchor SHA-256 fingerprint pin")
299#define SEC_TRUST_ERROR_AnchorTrusted SecStringWithDefaultValue("Root is not trusted","Trust", 0,"Root is not trusted","Error for untrusted root")
300#define SEC_TRUST_ERROR_MissingIntermediate SecStringWithDefaultValue("Unable to build chain to root (possible missing intermediate)","Trust", 0,"Unable to build chain to root (possible missing intermediate)","Error for missing intermediates")
301#define SEC_TRUST_ERROR_AnchorApple SecStringWithDefaultValue("Anchor is not an Apple root","Trust", 0,"Anchor is not an Apple root","Error for Apple anchor pin")
302#define SEC_TRUST_ERROR_NonEmptySubject SecStringWithDefaultValue("Certificate missing a name","Trust", 0,"Certificate missing a name","Error for empty subject name")
303#define SEC_TRUST_ERROR_IdLinkage SecStringWithDefaultValue("SubjectKeyID/AuthorityKeyID mismatch in chain","Trust", 0,"SubjectKeyID/AuthorityKeyID mismatch in chain","Error for bad key ID linkage")
304#define SEC_TRUST_ERROR_KeySize SecStringWithDefaultValue("Key size is not permitted for this use","Trust", 0,"Key size is not permitted for this use","Error for pinned key size")
305#define SEC_TRUST_ERROR_SignatureHashAlgorithms SecStringWithDefaultValue("Signature hash algorithm is not permitted for this use","Trust", 0,"Signature hash algorithm is not permitted for this use","Error for pinned hash algorithm")
307#define SEC_TRUST_ERROR_ValidRoot SecStringWithDefaultValue("Root is not temporally valid","Trust", 0,"Root is not temporally valid","Error for root temporal validity")
309#define SEC_TRUST_ERROR_ChainLength SecStringWithDefaultValue("Chain does not match expected path length","Trust", 0,"Chain does not match expected path length","Error for pinned chain length")
310#define SEC_TRUST_ERROR_BasicCertificateProcessing SecStringWithDefaultValue("Certificate is not standards compliant","Trust", 0,"Certificate is not standards compliant","Error for certificates that violate standards")
311#define SEC_TRUST_ERROR_NameConstraints SecStringWithDefaultValue("Name constraints violated","Trust", 0,"Name constraints violated","Error for name constraints")
313#define SEC_TRUST_ERROR_GrayListedKey SecStringWithDefaultValue("Key is listed as untrusted","Trust", 0,"Key is listed as untrusted","Error for graylisted keys")
314#define SEC_TRUST_ERROR_BlackListedKey SecStringWithDefaultValue("Key is blocked","Trust", 0,"Key is blocked","Error for blocklisted keys")
315#define SEC_TRUST_ERROR_UsageConstraints SecStringWithDefaultValue("User or administrator set certificate as distrusted","Trust", 0,"User or administrator set certificate as distrusted","Error for certificates with deny trust settings")
316#define SEC_TRUST_ERROR_SystemTrustedWeakHash SecStringWithDefaultValue("Signature hash algorithm is not permitted for this use","Trust", 0,"Signature hash algorithm is not permitted for this use","Error for system-trust hash algorithm")
317#define SEC_TRUST_ERROR_SystemTrustedWeakKey SecStringWithDefaultValue("Key size is not permitted for this use","Trust", 0,"Key size is not permitted for this use","Error for system-trust key size")
318#define SEC_TRUST_ERROR_SystemTrustedCTRequired SecStringWithDefaultValue("Certificate Transparency validation required for this use","Trust", 0,"Certificate Transparency validation required for this use","Error for system-trust CT requirement")
319#define SEC_TRUST_ERROR_PinningRequired SecStringWithDefaultValue("Pinning required but not used","Trust", 0,"Pinning required but not used","Error for required pinning")
320#define SEC_TRUST_ERROR_Revocation SecStringWithDefaultValue("Certificate is revoked","Trust", 0,"Certificate is revoked","Error for revocation")
321#define SEC_TRUST_ERROR_RevocationResponseRequired SecStringWithDefaultValue("Failed to check revocation","Trust", 0,"Failed to check revocation","Error for revocation required")
322#define SEC_TRUST_ERROR_CTRequired SecStringWithDefaultValue("Certificate Transparency validation required but missing","Trust", 0,"Certificate Transparency validation required but missing","Error for missing Certificate Transparency validation")
327#define SEC_TRUST_ERROR_IssuerPolicyConstraints SecStringWithDefaultValue("Certificate violates issuer policy constraints","Trust", 0,"Certificate violates issuer policy constraints","Error for certificates which violate policy constraints set on their issuer")
328#define SEC_TRUST_ERROR_IssuerNameConstraints SecStringWithDefaultValue("Certificate violates issuer name constraints","Trust", 0,"Certificate violates issuer name constraints","Error for certificates which violate name constraints set on their issuer")
329#define SEC_TRUST_ERROR_ValidityPeriodMaximums SecStringWithDefaultValue("Certificate exceeds maximum temporal validity period","Trust", 0,"Certificate exceeds maximum temporal validity period","Error for certificates that exceed the system's maximum temporal validity")
330#define SEC_TRUST_ERROR_ServerAuthEKU SecStringWithDefaultValue("Extended key usage does not match certificate usage","Trust", 0,"Extended key usage does not match certificate usage","Error for extended key usage mismatch")
331#define SEC_TRUST_ERROR_UnparseableExtension SecStringWithDefaultValue("Unable to parse known extension","Trust", 0,"Unable to parse known extension","Error for unparseable known extensions")