summaryrefslogtreecommitdiffstats
path: root/doc/man3/X509_get_subject_name.pod
blob: 2f392ad7a2e6cc55b438fa1499aca060a6a211cd (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
=pod

=head1 NAME

X509_NAME_hash_ex, X509_NAME_hash,
X509_get_subject_name, X509_set_subject_name, X509_subject_name_hash,
X509_get_issuer_name, X509_set_issuer_name, X509_issuer_name_hash,
X509_REQ_get_subject_name, X509_REQ_set_subject_name,
X509_ACERT_get0_issuerName, X509_ACERT_set1_issuerName,
X509_CRL_get_issuer, X509_CRL_set_issuer_name -
get X509_NAME hashes or get and set issuer or subject names

=head1 SYNOPSIS

 #include <openssl/x509.h>

 unsigned long X509_NAME_hash_ex(const X509_NAME *x, OSSL_LIB_CTX *libctx,
                                 const char *propq, int *ok);

 X509_NAME *X509_get_subject_name(const X509 *x);
 int X509_set_subject_name(X509 *x, const X509_NAME *name);
 unsigned long X509_subject_name_hash(X509 *x);

 X509_NAME *X509_get_issuer_name(const X509 *x);
 int X509_set_issuer_name(X509 *x, const X509_NAME *name);
 unsigned long X509_issuer_name_hash(X509 *x);

 X509_NAME *X509_REQ_get_subject_name(const X509_REQ *req);
 int X509_REQ_set_subject_name(X509_REQ *req, const X509_NAME *name);

 X509_NAME *X509_CRL_get_issuer(const X509_CRL *crl);
 int X509_CRL_set_issuer_name(X509_CRL *x, const X509_NAME *name);

 #include <openssl/x509_acert.h>

 X509_NAME *X509_ACERT_get0_issuerName(const X509_ACERT *x);
 int X509_ACERT_set1_issuerName(X509_ACERT *x, const X509_NAME *name);

The following macro has been deprecated since OpenSSL 3.0, and can be
hidden entirely by defining B<OPENSSL_API_COMPAT> with a suitable version value,
see L<openssl_user_macros(7)>:

 #define X509_NAME_hash(x) X509_NAME_hash_ex(x, NULL, NULL, NULL)

=head1 DESCRIPTION

X509_NAME_hash_ex() returns a hash value of name I<x> or 0 on failure,
using any given library context I<libctx> and property query I<propq>.
The I<ok> result argument may be NULL
or else is used to return 1 for success and 0 for failure.
Failure may happen on malloc error or if no SHA1 implementation is available.

X509_NAME_hash() returns a hash value of name I<x> or 0 on failure,
using the default library context and default property query.

X509_get_subject_name() returns the subject name of certificate I<x>. The
returned value is an internal pointer which B<MUST NOT> be freed.

X509_set_subject_name() sets the issuer name of certificate I<x> to
I<name>. The I<name> parameter is copied internally and should be freed
up when it is no longer needed.

X509_subject_name_hash() returns a hash value of the subject name of
certificate I<x>.

X509_get_issuer_name(), X509_set_issuer_name(), and X509_issuer_name_hash()
are identical to
X509_get_subject_name(), X509_set_subject_name(), and X509_subject_name_hash()
except they relate to the issuer name of I<x>.

Similarly X509_REQ_get_subject_name(), X509_REQ_set_subject_name(),
X509_ACERT_get0_issuerName(), X509_ACERT_set1_issuerName(),
X509_CRL_get_issuer() and X509_CRL_set_issuer_name() get or set the subject
or issuer names of certificate requests of CRLs respectively.

Since attribute certificates do not have a subject name, only the issuer name
can be set.  For details on setting X509_ACERT holder identities, see
L<X509_ACERT_set0_holder_entityName(3)>.

=head1 RETURN VALUES

X509_get_subject_name(), X509_get_issuer_name(), X509_REQ_get_subject_name()
X509_ACERT_get0_issuerName() and X509_CRL_get_issuer() return
an B<X509_NAME> pointer.

X509_NAME_hash_ex(), X509_NAME_hash(),
X509_subject_name_hash() and X509_issuer_name_hash()
return the first four bytes of the SHA1 hash value,
converted to B<unsigned long> in little endian order,
or 0 on failure.

X509_set_subject_name(), X509_set_issuer_name(), X509_REQ_set_subject_name(),
X509_ACERT_get0_issuerName() and X509_CRL_set_issuer_name() return 1 for
success and 0 for failure.

=head1 BUGS

In case X509_NAME_hash(), X509_subject_name_hash(), or X509_issuer_name_hash()
returns 0 it remains unclear if this is the real hash value or due to failure.
Better use X509_NAME_hash_ex() instead.

=head1 SEE ALSO

L<d2i_X509(3)>,
L<ERR_get_error(3)>, L<d2i_X509(3)>
L<X509_CRL_get0_by_serial(3)>,
L<X509_get0_signature(3)>,
L<X509_get_ext_d2i(3)>,
L<X509_get_extension_flags(3)>,
L<X509_get_pubkey(3)>,
L<X509_NAME_add_entry_by_txt(3)>,
L<X509_NAME_ENTRY_get_object(3)>,
L<X509_NAME_get_index_by_NID(3)>,
L<X509_NAME_print_ex(3)>,
L<X509_new(3)>,
L<X509_sign(3)>,
L<X509V3_get_d2i(3)>,
L<X509_verify_cert(3)>

=head1 HISTORY

X509_REQ_get_subject_name() is a function in OpenSSL 1.1.0 and a macro in
earlier versions.

X509_CRL_get_issuer() is a function in OpenSSL 1.1.0. It was previously
added in OpenSSL 1.0.0 as a macro.

X509_NAME_hash() was turned into a macro and deprecated in OpenSSL 3.0.

=head1 COPYRIGHT

Copyright 2015-2021 The OpenSSL Project Authors. All Rights Reserved.

Licensed under the Apache License 2.0 (the "License").  You may not use
this file except in compliance with the License.  You can obtain a copy
in the file LICENSE in the source distribution or at
L<https://www.openssl.org/source/license.html>.

=cut