CTLOG_STORE_new.3ossl 7.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220
  1. .\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42)
  2. .\"
  3. .\" Standard preamble:
  4. .\" ========================================================================
  5. .de Sp \" Vertical space (when we can't use .PP)
  6. .if t .sp .5v
  7. .if n .sp
  8. ..
  9. .de Vb \" Begin verbatim text
  10. .ft CW
  11. .nf
  12. .ne \\$1
  13. ..
  14. .de Ve \" End verbatim text
  15. .ft R
  16. .fi
  17. ..
  18. .\" Set up some character translations and predefined strings. \*(-- will
  19. .\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left
  20. .\" double quote, and \*(R" will give a right double quote. \*(C+ will
  21. .\" give a nicer C++. Capital omega is used to do unbreakable dashes and
  22. .\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff,
  23. .\" nothing in troff, for use with C<>.
  24. .tr \(*W-
  25. .ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p'
  26. .ie n \{\
  27. . ds -- \(*W-
  28. . ds PI pi
  29. . if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch
  30. . if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch
  31. . ds L" ""
  32. . ds R" ""
  33. . ds C` ""
  34. . ds C' ""
  35. 'br\}
  36. .el\{\
  37. . ds -- \|\(em\|
  38. . ds PI \(*p
  39. . ds L" ``
  40. . ds R" ''
  41. . ds C`
  42. . ds C'
  43. 'br\}
  44. .\"
  45. .\" Escape single quotes in literal strings from groff's Unicode transform.
  46. .ie \n(.g .ds Aq \(aq
  47. .el .ds Aq '
  48. .\"
  49. .\" If the F register is >0, we'll generate index entries on stderr for
  50. .\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index
  51. .\" entries marked with X<> in POD. Of course, you'll have to process the
  52. .\" output yourself in some meaningful fashion.
  53. .\"
  54. .\" Avoid warning from groff about undefined register 'F'.
  55. .de IX
  56. ..
  57. .nr rF 0
  58. .if \n(.g .if rF .nr rF 1
  59. .if (\n(rF:(\n(.g==0)) \{\
  60. . if \nF \{\
  61. . de IX
  62. . tm Index:\\$1\t\\n%\t"\\$2"
  63. ..
  64. . if !\nF==2 \{\
  65. . nr % 0
  66. . nr F 2
  67. . \}
  68. . \}
  69. .\}
  70. .rr rF
  71. .\"
  72. .\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2).
  73. .\" Fear. Run. Save yourself. No user-serviceable parts.
  74. . \" fudge factors for nroff and troff
  75. .if n \{\
  76. . ds #H 0
  77. . ds #V .8m
  78. . ds #F .3m
  79. . ds #[ \f1
  80. . ds #] \fP
  81. .\}
  82. .if t \{\
  83. . ds #H ((1u-(\\\\n(.fu%2u))*.13m)
  84. . ds #V .6m
  85. . ds #F 0
  86. . ds #[ \&
  87. . ds #] \&
  88. .\}
  89. . \" simple accents for nroff and troff
  90. .if n \{\
  91. . ds ' \&
  92. . ds ` \&
  93. . ds ^ \&
  94. . ds , \&
  95. . ds ~ ~
  96. . ds /
  97. .\}
  98. .if t \{\
  99. . ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u"
  100. . ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u'
  101. . ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u'
  102. . ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u'
  103. . ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u'
  104. . ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u'
  105. .\}
  106. . \" troff and (daisy-wheel) nroff accents
  107. .ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V'
  108. .ds 8 \h'\*(#H'\(*b\h'-\*(#H'
  109. .ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#]
  110. .ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H'
  111. .ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u'
  112. .ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#]
  113. .ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#]
  114. .ds ae a\h'-(\w'a'u*4/10)'e
  115. .ds Ae A\h'-(\w'A'u*4/10)'E
  116. . \" corrections for vroff
  117. .if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u'
  118. .if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u'
  119. . \" for low resolution devices (crt and lpr)
  120. .if \n(.H>23 .if \n(.V>19 \
  121. \{\
  122. . ds : e
  123. . ds 8 ss
  124. . ds o a
  125. . ds d- d\h'-1'\(ga
  126. . ds D- D\h'-1'\(hy
  127. . ds th \o'bp'
  128. . ds Th \o'LP'
  129. . ds ae ae
  130. . ds Ae AE
  131. .\}
  132. .rm #[ #] #H #V #F C
  133. .\" ========================================================================
  134. .\"
  135. .IX Title "CTLOG_STORE_NEW 3ossl"
  136. .TH CTLOG_STORE_NEW 3ossl "2024-09-03" "3.3.2" "OpenSSL"
  137. .\" For nroff, turn off justification. Always turn off hyphenation; it makes
  138. .\" way too many mistakes in technical documents.
  139. .if n .ad l
  140. .nh
  141. .SH "NAME"
  142. CTLOG_STORE_new_ex,
  143. CTLOG_STORE_new, CTLOG_STORE_free,
  144. CTLOG_STORE_load_default_file, CTLOG_STORE_load_file \-
  145. Create and populate a Certificate Transparency log list
  146. .SH "SYNOPSIS"
  147. .IX Header "SYNOPSIS"
  148. .Vb 1
  149. \& #include <openssl/ct.h>
  150. \&
  151. \& CTLOG_STORE *CTLOG_STORE_new_ex(OSSL_LIB_CTX *libctx, const char *propq);
  152. \& CTLOG_STORE *CTLOG_STORE_new(void);
  153. \& void CTLOG_STORE_free(CTLOG_STORE *store);
  154. \&
  155. \& int CTLOG_STORE_load_default_file(CTLOG_STORE *store);
  156. \& int CTLOG_STORE_load_file(CTLOG_STORE *store, const char *file);
  157. .Ve
  158. .SH "DESCRIPTION"
  159. .IX Header "DESCRIPTION"
  160. A \s-1CTLOG_STORE\s0 is a container for a list of CTLOGs (Certificate Transparency
  161. logs). The list can be loaded from one or more files and then searched by LogID
  162. (see \s-1RFC 6962,\s0 Section 3.2, for the definition of a LogID).
  163. .PP
  164. \&\fBCTLOG_STORE_new_ex()\fR creates an empty list of \s-1CT\s0 logs associated with
  165. the library context \fIlibctx\fR and the property query string \fIpropq\fR.
  166. .PP
  167. \&\fBCTLOG_STORE_new()\fR does the same thing as \fBCTLOG_STORE_new_ex()\fR but with
  168. the default library context and property query string.
  169. .PP
  170. The \s-1CTLOG_STORE\s0 is then populated by \fBCTLOG_STORE_load_default_file()\fR or
  171. \&\fBCTLOG_STORE_load_file()\fR. \fBCTLOG_STORE_load_default_file()\fR loads from the default
  172. file, which is named \fIct_log_list.cnf\fR in \s-1OPENSSLDIR\s0 (see the output of
  173. \&\fBopenssl\-version\fR\|(1)). This can be overridden using an environment variable
  174. named \fB\s-1CTLOG_FILE\s0\fR. \fBCTLOG_STORE_load_file()\fR loads from a caller-specified file
  175. path instead. Both of these functions append any loaded \s-1CT\s0 logs to the
  176. \&\s-1CTLOG_STORE.\s0
  177. .PP
  178. The expected format of the file is:
  179. .PP
  180. .Vb 1
  181. \& enabled_logs=foo,bar
  182. \&
  183. \& [foo]
  184. \& description = Log 1
  185. \& key = <base64\-encoded DER SubjectPublicKeyInfo here>
  186. \&
  187. \& [bar]
  188. \& description = Log 2
  189. \& key = <base64\-encoded DER SubjectPublicKeyInfo here>
  190. .Ve
  191. .PP
  192. Once a \s-1CTLOG_STORE\s0 is no longer required, it should be passed to
  193. \&\fBCTLOG_STORE_free()\fR. This will delete all of the CTLOGs stored within, along
  194. with the \s-1CTLOG_STORE\s0 itself. If the argument is \s-1NULL,\s0 nothing is done.
  195. .SH "NOTES"
  196. .IX Header "NOTES"
  197. If there are any invalid \s-1CT\s0 logs in a file, they are skipped and the remaining
  198. valid logs will still be added to the \s-1CTLOG_STORE. A CT\s0 log will be considered
  199. invalid if it is missing a \*(L"key\*(R" or \*(L"description\*(R" field.
  200. .SH "RETURN VALUES"
  201. .IX Header "RETURN VALUES"
  202. Both \fBCTLOG_STORE_load_default_file\fR and \fBCTLOG_STORE_load_file\fR return 1 if
  203. all \s-1CT\s0 logs in the file are successfully parsed and loaded, 0 otherwise.
  204. .SH "SEE ALSO"
  205. .IX Header "SEE ALSO"
  206. \&\fBct\fR\|(7),
  207. \&\fBCTLOG_STORE_get0_log_by_id\fR\|(3),
  208. \&\fBSSL_CTX_set_ctlog_list_file\fR\|(3)
  209. .SH "HISTORY"
  210. .IX Header "HISTORY"
  211. CTLOG_STORE_new_ex was added in OpenSSL 3.0. All other functions were
  212. added in OpenSSL 1.1.0.
  213. .SH "COPYRIGHT"
  214. .IX Header "COPYRIGHT"
  215. Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved.
  216. .PP
  217. Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use
  218. this file except in compliance with the License. You can obtain a copy
  219. in the file \s-1LICENSE\s0 in the source distribution or at
  220. <https://www.openssl.org/source/license.html>.