2 Copyright (C) 2012-2021 Carl Hetherington <cth@carlh.net>
4 This file is part of libdcp.
6 libdcp is free software; you can redistribute it and/or modify
7 it under the terms of the GNU General Public License as published by
8 the Free Software Foundation; either version 2 of the License, or
9 (at your option) any later version.
11 libdcp is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 GNU General Public License for more details.
16 You should have received a copy of the GNU General Public License
17 along with libdcp. If not, see <http://www.gnu.org/licenses/>.
19 In addition, as a special exception, the copyright holders give
20 permission to link the code of portions of this program with the
21 OpenSSL library under certain conditions as described in each
22 individual source file, and distribute linked combinations
25 You must obey the GNU General Public License in all respects
26 for all of the code used other than OpenSSL. If you modify
27 file(s) with this exception, you may extend this exception to your
28 version of the file(s), but you are not obligated to do so. If you
29 do not wish to do so, delete this exception statement from your
30 version. If you delete this exception statement from all source
31 files in the program, then also delete it here.
35 /** @file src/certificate.h
36 * @brief Certificate class
40 #ifndef LIBDCP_CERTIFICATE_H
41 #define LIBDCP_CERTIFICATE_H
44 #include "local_time.h"
46 #include <openssl/x509.h>
47 #include <boost/filesystem.hpp>
60 /** @class Certificate
61 * @brief A wrapper for an X509 certificate
63 * This class can take a Certificate from a string or an OpenSSL X509 object
70 /** Load an X509 certificate from a string
71 * @param cert String to read from
73 explicit Certificate (std::string);
75 /** @param c X509 certificate, which this object will take ownership of */
76 explicit Certificate (X509 *);
78 Certificate (Certificate const &);
81 Certificate& operator= (Certificate const &);
83 /** Read a certificate from a string.
84 * @param cert String to read.
85 * @return remaining part of the input string after the certificate which was read.
87 std::string read_string (std::string);
89 /** Return the certificate as a string
90 * @param with_begin_end true to include the -----BEGIN CERTIFICATE--- / -----END CERTIFICATE----- markers
91 * @return Certificate string
93 std::string certificate (bool with_begin_end = false) const;
95 std::string serial () const;
97 /** @return Certificate's issuer, in the form
98 * dnqualifier=<dnQualififer>,CN=<commonName>,OU=<organizationalUnitName>,O=<organizationName>
99 * and with + signs escaped to \+
101 std::string issuer () const;
102 std::string issuer_common_name() const;
103 std::string issuer_organization_name() const;
104 std::string issuer_organizational_unit_name() const;
106 std::string subject () const;
107 std::string subject_common_name () const;
108 std::string subject_organization_name () const;
109 std::string subject_organizational_unit_name () const;
110 std::string subject_dn_qualifier() const;
112 LocalTime not_before () const;
113 LocalTime not_after () const;
115 X509* x509 () const {
119 /** @return RSA public key from this Certificate. Caller must not free the returned value. */
120 RSA* public_key () const;
121 std::string public_key_digest() const;
123 /** @return thumbprint of the to-be-signed portion of this certificate */
124 std::string thumbprint () const;
126 bool has_utf8_strings () const;
130 static std::string name_for_xml (X509_NAME *);
131 static std::string asn_to_utf8 (ASN1_STRING *);
132 static std::string get_name_part (X509_NAME *, int);
134 X509* _certificate = nullptr;
135 mutable RSA* _public_key = nullptr;
139 bool operator== (Certificate const & a, Certificate const & b);
140 bool operator< (Certificate const & a, Certificate const & b);
141 std::ostream& operator<< (std::ostream&s, Certificate const & c);