2 * Copyright 2017 Facebook, Inc.
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
8 * http://www.apache.org/licenses/LICENSE-2.0
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
21 #include <folly/Optional.h>
22 #include <folly/io/IOBuf.h>
23 #include <folly/portability/OpenSSL.h>
24 #include <folly/ssl/OpenSSLPtrTypes.h>
29 class OpenSSLCertUtils {
31 // Note: non-const until OpenSSL 1.1.0
32 static Optional<std::string> getCommonName(X509& x509);
34 static std::vector<std::string> getSubjectAltNames(X509& x509);
37 * Return the subject name, if any, from the cert
38 * @param x509 Reference to an X509
39 * @return a folly::Optional<std::string>, or folly::none
41 static Optional<std::string> getSubject(X509& x509);
44 * Return the issuer name, if any, from the cert
45 * @param x509 Reference to an X509
46 * @return a folly::Optional<std::string>, or folly::none
48 static Optional<std::string> getIssuer(X509& x509);
51 * Get a string representation of the not-before time on the certificate
53 static std::string getNotBeforeTime(X509& x509);
56 * Get a string representation of the not-after (expiration) time
58 static std::string getNotAfterTime(X509& x509);
61 * Summarize the CN, Subject, Issuer, Validity, and extensions as a string
63 static folly::Optional<std::string> toString(X509& x509);
66 * Decodes the DER representation of an X509 certificate.
68 * Throws on error (if a valid certificate can't be decoded).
70 static X509UniquePtr derDecode(ByteRange);
73 * DER encodes an X509 certificate.
77 static std::unique_ptr<IOBuf> derEncode(X509&);
80 * Reads certificates from memory and returns them as a vector of X509
83 static std::vector<X509UniquePtr> readCertsFromBuffer(ByteRange);
86 * Return the output of the X509_digest for chosen message-digest algo
87 * NOTE: The returned digest will be in binary, and may need to be
90 static std::array<uint8_t, SHA_DIGEST_LENGTH> getDigestSha1(X509& x509);
91 static std::array<uint8_t, SHA256_DIGEST_LENGTH> getDigestSha256(X509& x509);
94 static std::string getDateTimeStr(const ASN1_TIME* time);