Class: OpenSSL::X509::StoreContext
| Relationships & Source Files | |
| Inherits: | Object | 
| Defined in: | ext/openssl/ossl_x509store.c, ext/openssl/lib/openssl/x509.rb | 
Overview
A StoreContext is used while validating a single certificate and holds the status involved.
Class Method Summary
- .new(store, cert = nil, chain = nil) constructor
Instance Attribute Summary
- #error ⇒ Integer rw
- #error=(error_code) rw
- 
    
      #flags=(flags)  
    
    writeonly
    Sets the verification flags to the context. 
- 
    
      #purpose=(purpose)  
    
    writeonly
    Sets the purpose of the context. 
- 
    
      #time=(time)  
    
    writeonly
    Sets the time used in the verification. 
- #trust=(trust) writeonly
Instance Method Summary
- #chain ⇒ Array of X509::Certificate
- #cleanup
- #current_cert ⇒ X509::Certificate
- #current_crl ⇒ X509::CRL
- #error_depth ⇒ Integer
- 
    
      #error_string  ⇒ String 
    
    Returns the error string corresponding to the error code retrieved by #error. 
- #verify ⇒ Boolean
Constructor Details
.new(store, cert = nil, chain = nil)
# File 'ext/openssl/ossl_x509store.c', line 524
static VALUE
ossl_x509stctx_initialize(int argc, VALUE *argv, VALUE self)
{
    VALUE store, cert, chain, t;
    X509_STORE_CTX *ctx;
    X509_STORE *x509st;
    X509 *x509 = NULL;
    STACK_OF(X509) *x509s = NULL;
    rb_scan_args(argc, argv, "12", &store, &cert, &chain);
    GetX509StCtx(self, ctx);
    GetX509Store(store, x509st);
    if(!NIL_P(cert)) x509 = DupX509CertPtr(cert); /* NEED TO DUP */
    if(!NIL_P(chain)) x509s = ossl_x509_ary2sk(chain);
    if(X509_STORE_CTX_init(ctx, x509st, x509, x509s) != 1){
        sk_X509_pop_free(x509s, X509_free);
        ossl_raise(eX509StoreError, NULL);
    }
    if (!NIL_P(t = rb_iv_get(store, "@time")))
	ossl_x509stctx_set_time(self, t);
    rb_iv_set(self, "@verify_callback", rb_iv_get(store, "@verify_callback"));
    rb_iv_set(self, "@cert", cert);
    return self;
}
  Instance Attribute Details
#error ⇒ Integer (rw)
[ GitHub ]# File 'ext/openssl/ossl_x509store.c', line 608
static VALUE
ossl_x509stctx_get_err(VALUE self)
{
    X509_STORE_CTX *ctx;
    GetX509StCtx(self, ctx);
    return INT2NUM(X509_STORE_CTX_get_error(ctx));
}
  #error=(error_code) (rw)
# File 'ext/openssl/ossl_x509store.c', line 622
static VALUE
ossl_x509stctx_set_error(VALUE self, VALUE err)
{
    X509_STORE_CTX *ctx;
    GetX509StCtx(self, ctx);
    X509_STORE_CTX_set_error(ctx, NUM2INT(err));
    return err;
}
  #flags=(flags) (writeonly)
Sets the verification flags to the context. See Store#flags=.
# File 'ext/openssl/ossl_x509store.c', line 703
static VALUE
ossl_x509stctx_set_flags(VALUE self, VALUE flags)
{
    X509_STORE_CTX *store;
    long f = NUM2LONG(flags);
    GetX509StCtx(self, store);
    X509_STORE_CTX_set_flags(store, f);
    return flags;
}
  #purpose=(purpose) (writeonly)
Sets the purpose of the context. See Store#purpose=.
# File 'ext/openssl/ossl_x509store.c', line 721
static VALUE
ossl_x509stctx_set_purpose(VALUE self, VALUE purpose)
{
    X509_STORE_CTX *store;
    int p = NUM2INT(purpose);
    GetX509StCtx(self, store);
    X509_STORE_CTX_set_purpose(store, p);
    return purpose;
}
  #time=(time) (writeonly)
Sets the time used in the verification. If not set, the current time is used.
# File 'ext/openssl/ossl_x509store.c', line 755
static VALUE
ossl_x509stctx_set_time(VALUE self, VALUE time)
{
    X509_STORE_CTX *store;
    long t;
    t = NUM2LONG(rb_Integer(time));
    GetX509StCtx(self, store);
    X509_STORE_CTX_set_time(store, 0, t);
    return time;
}
  #trust=(trust) (writeonly)
# File 'ext/openssl/ossl_x509store.c', line 737
static VALUE
ossl_x509stctx_set_trust(VALUE self, VALUE trust)
{
    X509_STORE_CTX *store;
    int t = NUM2INT(trust);
    GetX509StCtx(self, store);
    X509_STORE_CTX_set_trust(store, t);
    return trust;
}
  Instance Method Details
    #chain  ⇒ Array of X509::Certificate   
# File 'ext/openssl/ossl_x509store.c', line 578
static VALUE
ossl_x509stctx_get_chain(VALUE self)
{
    X509_STORE_CTX *ctx;
    STACK_OF(X509) *chain;
    X509 *x509;
    int i, num;
    VALUE ary;
    GetX509StCtx(self, ctx);
    if((chain = X509_STORE_CTX_get0_chain(ctx)) == NULL){
        return Qnil;
    }
    if((num = sk_X509_num(chain)) < 0){
	OSSL_Debug("certs in chain < 0???");
	return rb_ary_new();
    }
    ary = rb_ary_new2(num);
    for(i = 0; i < num; i++) {
	x509 = sk_X509_value(chain, i);
	rb_ary_push(ary, ossl_x509_new(x509));
    }
    return ary;
}
  #cleanup
[ GitHub ]# File 'ext/openssl/lib/openssl/x509.rb', line 176
def cleanup warn "(#{caller.first}) OpenSSL::X509::StoreContext#cleanup is deprecated with no replacement" if $VERBOSE end
#current_cert ⇒ X509::Certificate
# File 'ext/openssl/ossl_x509store.c', line 669
static VALUE
ossl_x509stctx_get_curr_cert(VALUE self)
{
    X509_STORE_CTX *ctx;
    GetX509StCtx(self, ctx);
    return ossl_x509_new(X509_STORE_CTX_get_current_cert(ctx));
}
  #current_crl ⇒ X509::CRL
# File 'ext/openssl/ossl_x509store.c', line 683
static VALUE
ossl_x509stctx_get_curr_crl(VALUE self)
{
    X509_STORE_CTX *ctx;
    X509_CRL *crl;
    GetX509StCtx(self, ctx);
    crl = X509_STORE_CTX_get0_current_crl(ctx);
    if (!crl)
	return Qnil;
    return ossl_x509crl_new(crl);
}
  #error_depth ⇒ Integer
# File 'ext/openssl/ossl_x509store.c', line 655
static VALUE
ossl_x509stctx_get_err_depth(VALUE self)
{
    X509_STORE_CTX *ctx;
    GetX509StCtx(self, ctx);
    return INT2NUM(X509_STORE_CTX_get_error_depth(ctx));
}
  
    #error_string  ⇒ String   
Returns the error string corresponding to the error code retrieved by #error.
# File 'ext/openssl/ossl_x509store.c', line 639
static VALUE
ossl_x509stctx_get_err_string(VALUE self)
{
    X509_STORE_CTX *ctx;
    long err;
    GetX509StCtx(self, ctx);
    err = X509_STORE_CTX_get_error(ctx);
    return rb_str_new2(X509_verify_cert_error_string(err));
}
  
    #verify  ⇒ Boolean   
# File 'ext/openssl/ossl_x509store.c', line 554
static VALUE
ossl_x509stctx_verify(VALUE self)
{
    X509_STORE_CTX *ctx;
    GetX509StCtx(self, ctx);
    X509_STORE_CTX_set_ex_data(ctx, stctx_ex_verify_cb_idx,
			       (void *)rb_iv_get(self, "@verify_callback"));
    switch (X509_verify_cert(ctx)) {
      case 1:
	return Qtrue;
      case 0:
	ossl_clear_error();
	return Qfalse;
      default:
	ossl_raise(eX509CertError, NULL);
    }
}