/*
- Copyright (C) 2012 Carl Hetherington <cth@carlh.net>
+ Copyright (C) 2012-2014 Carl Hetherington <cth@carlh.net>
This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
*/
+/** @file src/certificates.h
+ * @brief Certificate and CertificateChain classes.
+ */
+
#ifndef LIBDCP_CERTIFICATES_H
#define LIBDCP_CERTIFICATES_H
-#include <string>
-#include <list>
-#include <boost/noncopyable.hpp>
-#include <boost/shared_ptr.hpp>
-#include <boost/filesystem.hpp>
#undef X509_NAME
#include <openssl/x509.h>
+#include <boost/filesystem.hpp>
+#include <string>
+#include <list>
class certificates;
class Element;
}
-namespace libdcp {
+namespace dcp {
+/** @class Certificate
+ * @brief A wrapper for an X509 certificate.
+ *
+ * This class can take a Certificate from a string or an OpenSSL X509 object.
+ */
class Certificate
{
public:
Certificate ()
: _certificate (0)
+ , _public_key (0)
{}
- Certificate (boost::filesystem::path);
Certificate (std::string);
Certificate (X509 *);
Certificate (Certificate const &);
Certificate& operator= (Certificate const &);
- /** @param with_begin_end true to include BEGIN CERTIFICATE / END CERTIFICATE markers
- * @return the whole certificate as a string.
- */
std::string certificate (bool with_begin_end = false) const;
std::string issuer () const;
std::string serial () const;
std::string subject () const;
std::string common_name () const;
- /** @return RSA public key from this Certificate. Caller must not free the returned value. */
+ X509* x509 () const {
+ return _certificate;
+ }
+
RSA* public_key () const;
std::string thumbprint () const;
mutable RSA* _public_key;
};
+bool operator== (Certificate const & a, Certificate const & b);
+bool operator< (Certificate const & a, Certificate const & b);
+std::ostream& operator<< (std::ostream&s, Certificate const & c);
+
+/** @class CertificateChain
+ * @brief A chain of any number of certificates, from root to leaf.
+ */
class CertificateChain
{
public:
CertificateChain () {}
- void add (boost::shared_ptr<Certificate>);
+ void add (Certificate c);
+ void remove (Certificate c);
+ void remove (int);
- boost::shared_ptr<Certificate> root () const;
- boost::shared_ptr<Certificate> leaf () const;
+ Certificate root () const;
+ Certificate leaf () const;
- std::list<boost::shared_ptr<Certificate> > leaf_to_root () const;
+ typedef std::list<Certificate> List;
+
+ List leaf_to_root () const;
+ List root_to_leaf () const;
+
+ bool valid () const;
+ bool attempt_reorder ();
private:
friend class ::certificates;
- std::list<boost::shared_ptr<Certificate> > _certificates;
+
+ List _certificates;
};
}