| /freebsd/crypto/openssl/test/ssl-tests/ |
| H A D | 32-compressed-certificate.cnf | 5 test-0 = 0-no-compressed-certificates 6 test-1 = 1-server-compressed-certificates 7 test-2 = 2-client-compressed-certificates 8 test-3 = 3-both-compressed-certificates 9 test-4 = 4-no-compressed-certificates-mtls 10 test-5 = 5-server-compressed-certificates-mtls 11 test-6 = 6-client-compressed-certificates-mtls 12 test-7 = 7-both-compressed-certificates-mtls 15 [0-no-compressed-certificates] 16 ssl_conf = 0-no-compressed-certificates-ssl [all …]
|
| H A D | 32-compressed-certificate.cnf.in | 20 name => "no-compressed-certificates", 34 name => "server-compressed-certificates", 48 name => "client-compressed-certificates", 62 name => "both-compressed-certificates", 76 name => "no-compressed-certificates-mtls", 94 name => "server-compressed-certificates-mtls", 112 name => "client-compressed-certificates-mtls", 130 name => "both-compressed-certificates-mtls",
|
| /freebsd/crypto/openssl/demos/certs/ |
| H A D | README.txt | 1 There is often a need to generate test certificates automatically using 3 CA certificates, obsolete V1 certificates or duplicate serial numbers. 6 The mkcerts.sh script is an example of how to generate certificates 8 signed by the root and several certificates signed by the intermediate CA. 11 certificates and generates a CRL. Then one certificate is revoked and a 15 client certificates. 17 The script ocspquery.sh queries the status of the certificates using the
|
| /freebsd/crypto/openssl/doc/man3/ |
| H A D | SSL_CTX_load_verify_locations.pod | 9 - set default locations for trusted CA certificates 32 locations for B<ctx>, at which CA certificates for verification purposes 33 are located. The certificates available via B<CAfile>, B<CApath> and 40 which CA certificates are loaded should be used. There is one default directory, 42 The default CA certificates directory is called F<certs> in the default OpenSSL 46 The default CA certificates file is called F<cert.pem> in the default 66 If B<CAfile> is not NULL, it points to a file of CA certificates in PEM 67 format. The file can contain several CA certificates identified by 73 sequences. Before, between, and after the certificates text is allowed 74 which can be used e.g. for descriptions of the certificates. [all …]
|
| H A D | SSL_CTX_add_extra_chain_cert.pod | 9 - add, get or clear extra chain certificates 23 certificates associated with B<ctx>. Several certificates can be added one 26 SSL_CTX_get_extra_chain_certs() retrieves the extra chain certificates 31 SSL_CTX_get_extra_chain_certs_only() retrieves the extra chain certificates 35 SSL_CTX_clear_extra_chain_certs() clears all extra chain certificates 42 When sending a certificate chain, extra chain certificates are sent in order 46 available CA certificates in the trusted CA storage, see 55 Only one set of extra chain certificates can be specified per SSL_CTX 56 structure. Different chains for different certificates (for example if both 57 RSA and DSA certificates are specified by the same server) or different SSL
|
| H A D | PKCS7_verify.pod | 20 The optional I<certs> parameter refers to a set of certificates 21 in which to search for signer's certificates. 23 as a source of untrusted intermediate CA certificates for chain building. 24 I<p7> may contain extra untrusted CA certificates that may be used for 33 PKCS7_get0_signers() retrieves the signer's certificates from I<p7>, it does 50 An attempt is made to locate all the signer's certificates, first looking in 52 certificates contained in the I<p7> structure unless B<PKCS7_NOINTERN> is set. 53 If any signer's certificates cannot be located the operation fails. 57 Any internal certificates in the message, which may have been added using 74 If B<PKCS7_NOINTERN> is set the certificates in the message itself are not [all …]
|
| H A D | SSL_load_client_CA_file.pod | 29 SSL_load_client_CA_file_ex() reads certificates from I<file> and returns 36 SSL_add_file_cert_subjects_to_stack() reads certificates from I<file>, 39 SSL_add_dir_cert_subjects_to_stack() reads certificates from every 43 SSL_add_store_cert_subjects_to_stack() loads certificates from the 49 SSL_load_client_CA_file() reads a file of PEM formatted certificates and 50 extracts the X509_NAMES of the certificates found. While the name suggests 53 it is not limited to CA certificates. 68 Pointer to the subject names of the successfully read certificates.
|
| H A D | CMS_verify.pod | 27 The optional I<certs> parameter refers to a set of certificates 28 in which to search for signing certificates. 30 as a source of untrusted intermediate CA certificates for chain building. 31 I<cms> may contain extra untrusted CA certificates that may be used for 45 certificates that may be helpful for chain building in certificate validation. 46 This list of certificates must not contain duplicates. 65 certificates contained in the I<cms> structure unless B<CMS_NOINTERN> is set. 70 Any internal certificates in the message, which may have been added using 85 If B<CMS_NOINTERN> is set the certificates in the message itself are not 87 This means that all the signing certificates must be in the I<certs> parameter. [all …]
|
| H A D | X509_STORE_add_cert.pod | 50 holding information about X.509 certificates and CRLs, and constructing 51 and validating chains of certificates terminating in trusted roots. 53 with large numbers of certificates, and a great deal of flexibility in 61 no information about trusted certificates or where such certificates 63 certificates will be added to the B<X509_STORE> to prepare it for use, 71 certificate to be verified and an additional set of untrusted certificates 73 certificates included in the B<X509_STORE> are certificates that represent 75 OpenSSL represents these trusted certificates internally as B<X509> objects 78 The public interfaces that operate on such trusted certificates still 107 The certificates in the directory must be in hashed form, as [all …]
|
| H A D | X509_get_default_cert_file.pod | 7 retrieve default locations for trusted CA certificates 22 to a file containing trusted CA certificates. OpenSSL will use this as 23 the default path when it is asked to load trusted CA certificates 24 from a file and no other path is specified. If the file exists, CA certificates 28 list of paths to a directories containing trusted CA certificates named in the 30 asked to load trusted CA certificates from a directory and no other path is 32 CA certificates in this directory by calculating a filename based on a hash of 56 for certificates in the directory B<"file"> (relative to the current working
|
| H A D | X509_LOOKUP_hash_dir.pod | 38 Internally loading of certificates and CRLs is implemented via functions 42 B<FILETYPE_DEFAULT>. They load certificates and/or CRLs from specified 69 The B<X509_LOOKUP_file> method loads all the certificates or CRLs 73 File format is ASCII text which contains concatenated PEM certificates 82 certificates and CRLs on demand, and caches them in memory once 91 applied to the subject name for certificates or issuer name for CRLs. 103 certificates with same subject name hash value. 104 For example, it is possible to have in the store several certificates with same 109 loaded, hash_dir lookup method checks only for certificates with 122 certificates and CRLs through any loader supported by [all …]
|
| H A D | X509_add_cert.pod | 33 the reference counts of those certificates added successfully are increased. 35 If B<X509_ADD_FLAG_PREPEND> is set then the certificates are prepended to I<sk>. 37 In both cases the original order of the added certificates is preserved. 39 If B<X509_ADD_FLAG_NO_DUP> is set then certificates already contained in I<sk>, 42 If B<X509_ADD_FLAG_NO_SS> is set then certificates that are marked self-signed, 54 the ownership is transferred to the list of certificates I<sk>.
|
| H A D | SSL_CTX_set1_cert_comp_preference.pod | 67 the configured certificates on an SSL_CTX/SSL object with algorithm B<alg>. If 68 B<alg> is 0, then the certificates are compressed with the algorithms specified 70 will result in an error, as only server certificates may be pre-compressed. 75 error, as only server certificates may be pre-compressed. The B<data> and 93 Only server certificates may be pre-compressed. Calling any of these functions 95 on a client SSL_CTX/SSL object will return an error. Client certificates are 115 =item * If no certificates have been configured. 123 Sending compressed certificates may be disabled on a connection via the 124 SSL_OP_NO_TX_CERTIFICATE_COMPRESSION option. Receiving compressed certificates
|
| H A D | X509_STORE_CTX_new.pod | 96 This may be NULL because there are no trusted certificates or because 99 and a list of additional certificates may be provided in I<untrusted>, 108 list of untrusted certificates as its verification target, 119 X509_STORE_CTX_set0_trusted_stack() sets the set of trusted certificates of 120 I<ctx> to I<sk>. This is an alternative way of specifying trusted certificates 122 or to make sure that only the given set I<sk> of certificates are trusted. 158 stack of untrusted certificates associated with I<ctx>. 161 of untrusted certificates associated with I<ctx> to I<sk>. 165 X509_STORE_CTX_get_num_untrusted() returns the number of untrusted certificates 202 X509 certificates may contain information about what purposes keys contained [all …]
|
| /freebsd/crypto/openssl/doc/man1/ |
| H A D | openssl-verification-options.pod | 16 There are many situations where X.509 certificates are verified 24 In a nutshell, a valid chain of certificates needs to be built up and verified 43 and thus is acceptable as the root of a chain of certificates. 45 In practice, trust anchors are given in the form of certificates, 48 OpenSSL checks the validity period of such certificates 54 all self-signed "root" CA certificates that are placed in the I<trust store>, 55 which is a collection of certificates that are trusted for certain uses. 68 (EKUs) that may be given in X.509 extensions of end-entity certificates. 111 is taken, otherwise the one that expired most recently of all such certificates. 113 any further candidate issuer certificates that would match equally are ignored. [all …]
|
| H A D | openssl-crl2pkcs7.pod.in | 6 openssl-crl2pkcs7 - Create a PKCS#7 structure from a CRL and certificates 23 certificates and converts them into a PKCS#7 degenerate "certificates 56 Specifies a filename containing one or more certificates in B<PEM> format. 57 All certificates in the file will be added to the PKCS#7 structure. This 58 option can be used more than once to read certificates from multiple 77 different certificates: 85 just certificates and an optional CRL. 87 This command can be used to send certificates and CAs to Netscape as part of 92 install user certificates and CAs in MSIE using the Xenroll control.
|
| H A D | openssl-nseq.pod.in | 20 sequence and prints out the certificates contained in it or takes a 21 file of certificates and converts it into a Netscape certificate 26 format when several certificates are sent to the browser, for example during 49 is the certificates contained in it. With the B<-toseq> option the 51 a file of certificates. 59 Output the certificates in a Netscape certificate sequence
|
| H A D | openssl-pkcs12.pod.in | 139 No certificates will be output. 158 and the default encryption algorithm for both certificates and private keys is 183 The filename to write certificates and private keys to, standard output by 197 Only output client certificates (not CA certificates). 201 Only output CA certificates (not client certificates). 255 With the B<-export> option this is a file with certificates and a key, 259 certificates are present they will also be included in the PKCS#12 output file. 272 An input file with extra certificates t [all...] |
| H A D | openssl-verify.pod.in | 47 Attempt to download CRL information for certificates via their CDP entries. 61 A file or URI of (more or less) trusted certificates. 64 This option can be specified more than once to load certificates from multiple 69 A file or URI of untrusted certificates to use for chain building. 70 This option can be specified more than once to load certificates from multiple 82 To load certificates or CRLs that require engine support, specify the 101 One or more target certificates to verify, one per file. If no certificates are 108 of options and starts the list of certificates. If you place any options 110 but as certificates.
|
| /freebsd/crypto/heimdal/doc/ |
| H A D | hx509.texi | 192 @c * Issuing certificates:: 194 * Issuing certificates:: 236 A system or collection of distributed systems that stores certificates and CRLs 237 and serves as a means of distributing these certificates and CRLs to end entities 270 @section Type of certificates 278 Trust anchors are strictly not certificates, but commonly stored in a 280 the keys that an end entity would trust to validate other certificates. 284 @item End Entity (EE) certificates 286 End entity certificates are the most common types of certificates. End 287 entity certificates cannot issue (sign) certificate themselves and are generally [all …]
|
| /freebsd/secure/caroot/ |
| H A D | README | 7 certificates included by Mozilla. 10 1) Remove the old trusted certificates (cleancerts) 15 1) Any no-longer-trusted certificates should be moved to the 17 2) any newly added certificates will need to be added (git add) 23 Delete the old certificates, run as a dependency of updatecerts.
|
| /freebsd/crypto/openssl/doc/internal/man3/ |
| H A D | ossl_cmp_X509_STORE_add1_certs.pod | 7 - functions manipulating stores of certificates 19 ossl_cmp_X509_STORE_add1_certs() adds all or only self-signed certificates from 22 ossl_cmp_X509_STORE_get1_certs() retrieves a copy of all certificates in the 29 ossl_cmp_X509_STORE_get1_certs() returns a list of certificates, NULL on error.
|
| /freebsd/crypto/heimdal/lib/hx509/ |
| H A D | hxtool-commands.in | 43 help = "certificate stores to pull certificates from" 62 help = "certificate store to pull certificates from" 136 help = "certificate store to pull certificates from" 216 help = "certificates used to receive the data" 262 help = "allow proxy certificates" 305 help = "print the content of the certificates" 319 help = "Print certificates" 332 help = "Validate content of certificates" 350 argument="in-certificates-1 ... out-certificate" 351 help = "Copy in certificates stores into out certificate store" [all …]
|
| /freebsd/crypto/openssl/doc/man7/ |
| H A D | proxy-certificates.pod | 7 proxy-certificates - Proxy certificates in OpenSSL 11 Proxy certificates are defined in RFC 3820. They are used to 43 OpenSSL expects applications that want to use proxy certificates to be 55 =head2 Creating proxy certificates 57 Creating proxy certificates can be done using the L<openssl-x509(1)> 135 rights by checking the rights against the chain of proxy certificates, 136 user certificate and CA certificates. 214 * ok is 1, the certificates are checked from top to 218 * certificates. 324 certificates checked properly, using the code above: [all …]
|
| /freebsd/packages/caroot/ |
| H A D | common.ucl | 19 comment = "Mozilla Root Store trusted TLS certificates" 22 This package contains trusted TLS certificates from the Mozilla Root Store. 23 These certificates allow applications to make secure TLS connections to remote 28 of the provided certificates. For more information on the Mozilla Root Store,
|