xref: /openssl/doc/man3/X509_dup.pod (revision 044b9583)
1=pod
2
3=head1 NAME
4
5DECLARE_ASN1_FUNCTIONS,
6IMPLEMENT_ASN1_FUNCTIONS,
7ASN1_ITEM,
8ACCESS_DESCRIPTION_free,
9ACCESS_DESCRIPTION_new,
10ADMISSIONS_free,
11ADMISSIONS_new,
12ADMISSION_SYNTAX_free,
13ADMISSION_SYNTAX_new,
14ASIdOrRange_free,
15ASIdOrRange_new,
16ASIdentifierChoice_free,
17ASIdentifierChoice_new,
18ASIdentifiers_free,
19ASIdentifiers_new,
20ASRange_free,
21ASRange_new,
22AUTHORITY_INFO_ACCESS_free,
23AUTHORITY_INFO_ACCESS_new,
24AUTHORITY_KEYID_free,
25AUTHORITY_KEYID_new,
26BASIC_CONSTRAINTS_free,
27BASIC_CONSTRAINTS_new,
28CERTIFICATEPOLICIES_free,
29CERTIFICATEPOLICIES_new,
30CMS_ContentInfo_free,
31CMS_ContentInfo_new,
32CMS_ContentInfo_new_ex,
33CMS_ContentInfo_print_ctx,
34CMS_EnvelopedData_it,
35CMS_ReceiptRequest_free,
36CMS_ReceiptRequest_new,
37CMS_SignedData_free,
38CMS_SignedData_new,
39CRL_DIST_POINTS_free,
40CRL_DIST_POINTS_new,
41DIRECTORYSTRING_free,
42DIRECTORYSTRING_new,
43DISPLAYTEXT_free,
44DISPLAYTEXT_new,
45DIST_POINT_NAME_free,
46DIST_POINT_NAME_new,
47DIST_POINT_NAME_dup,
48DIST_POINT_free,
49DIST_POINT_new,
50DSAparams_dup,
51ECPARAMETERS_free,
52ECPARAMETERS_new,
53ECPKPARAMETERS_free,
54ECPKPARAMETERS_new,
55EDIPARTYNAME_free,
56EDIPARTYNAME_new,
57ESS_CERT_ID_dup,
58ESS_CERT_ID_free,
59ESS_CERT_ID_new,
60ESS_CERT_ID_V2_dup,
61ESS_CERT_ID_V2_free,
62ESS_CERT_ID_V2_new,
63ESS_ISSUER_SERIAL_dup,
64ESS_ISSUER_SERIAL_free,
65ESS_ISSUER_SERIAL_new,
66ESS_SIGNING_CERT_dup,
67ESS_SIGNING_CERT_free,
68ESS_SIGNING_CERT_it,
69ESS_SIGNING_CERT_new,
70ESS_SIGNING_CERT_V2_dup,
71ESS_SIGNING_CERT_V2_free,
72ESS_SIGNING_CERT_V2_it,
73ESS_SIGNING_CERT_V2_new,
74EXTENDED_KEY_USAGE_free,
75EXTENDED_KEY_USAGE_new,
76GENERAL_NAMES_free,
77GENERAL_NAMES_new,
78GENERAL_NAME_dup,
79GENERAL_NAME_free,
80GENERAL_NAME_new,
81GENERAL_SUBTREE_free,
82GENERAL_SUBTREE_new,
83OSSL_IETF_ATTR_SYNTAX_free,
84OSSL_IETF_ATTR_SYNTAX_it,
85OSSL_IETF_ATTR_SYNTAX_new,
86IPAddressChoice_free,
87IPAddressChoice_new,
88IPAddressFamily_free,
89IPAddressFamily_new,
90IPAddressOrRange_free,
91IPAddressOrRange_new,
92IPAddressRange_free,
93IPAddressRange_new,
94ISSUER_SIGN_TOOL_free,
95ISSUER_SIGN_TOOL_it,
96ISSUER_SIGN_TOOL_new,
97ISSUING_DIST_POINT_free,
98ISSUING_DIST_POINT_it,
99ISSUING_DIST_POINT_new,
100NAME_CONSTRAINTS_free,
101NAME_CONSTRAINTS_new,
102NAMING_AUTHORITY_free,
103NAMING_AUTHORITY_new,
104NETSCAPE_CERT_SEQUENCE_free,
105NETSCAPE_CERT_SEQUENCE_new,
106NETSCAPE_SPKAC_free,
107NETSCAPE_SPKAC_new,
108NETSCAPE_SPKI_free,
109NETSCAPE_SPKI_new,
110NOTICEREF_free,
111NOTICEREF_new,
112OCSP_BASICRESP_free,
113OCSP_BASICRESP_new,
114OCSP_CERTID_dup,
115OCSP_CERTID_new,
116OCSP_CERTSTATUS_free,
117OCSP_CERTSTATUS_new,
118OCSP_CRLID_free,
119OCSP_CRLID_new,
120OCSP_ONEREQ_free,
121OCSP_ONEREQ_new,
122OCSP_REQINFO_free,
123OCSP_REQINFO_new,
124OCSP_RESPBYTES_free,
125OCSP_RESPBYTES_new,
126OCSP_RESPDATA_free,
127OCSP_RESPDATA_new,
128OCSP_RESPID_free,
129OCSP_RESPID_new,
130OCSP_RESPONSE_new,
131OCSP_REVOKEDINFO_free,
132OCSP_REVOKEDINFO_new,
133OCSP_SERVICELOC_free,
134OCSP_SERVICELOC_new,
135OCSP_SIGNATURE_free,
136OCSP_SIGNATURE_new,
137OCSP_SINGLERESP_free,
138OCSP_SINGLERESP_new,
139OSSL_ATTRIBUTE_DESCRIPTOR_free,
140OSSL_ATTRIBUTE_DESCRIPTOR_new,
141OSSL_ATTRIBUTE_DESCRIPTOR_it,
142OSSL_ATTRIBUTES_SYNTAX_free,
143OSSL_ATTRIBUTES_SYNTAX_it,
144OSSL_ATTRIBUTES_SYNTAX_new,
145OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX_free,
146OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX_it,
147OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX_new,
148OSSL_BASIC_ATTR_CONSTRAINTS_free,
149OSSL_BASIC_ATTR_CONSTRAINTS_it,
150OSSL_BASIC_ATTR_CONSTRAINTS_new,
151OSSL_CMP_ATAVS_new,
152OSSL_CMP_ATAVS_free,
153OSSL_CMP_ATAVS_it,
154OSSL_CMP_CRLSTATUS_free,
155OSSL_CMP_ITAV_dup,
156OSSL_CMP_ITAV_free,
157OSSL_CMP_MSG_dup,
158OSSL_CMP_MSG_it,
159OSSL_CMP_MSG_free,
160OSSL_CMP_PKIHEADER_free,
161OSSL_CMP_PKIHEADER_it,
162OSSL_CMP_PKIHEADER_new,
163OSSL_CMP_PKISI_dup,
164OSSL_CMP_PKISI_free,
165OSSL_CMP_PKISI_it,
166OSSL_CMP_PKISI_new,
167OSSL_CMP_PKISTATUS_it,
168OSSL_CRMF_CERTID_dup,
169OSSL_CRMF_CERTID_free,
170OSSL_CRMF_CERTID_it,
171OSSL_CRMF_CERTID_new,
172OSSL_CRMF_CERTTEMPLATE_free,
173OSSL_CRMF_CERTTEMPLATE_it,
174OSSL_CRMF_CERTTEMPLATE_new,
175OSSL_CRMF_CERTTEMPLATE_dup,
176OSSL_CRMF_ATTRIBUTETYPEANDVALUE_dup,
177OSSL_CRMF_ATTRIBUTETYPEANDVALUE_free,
178OSSL_CRMF_ENCRYPTEDVALUE_free,
179OSSL_CRMF_ENCRYPTEDVALUE_it,
180OSSL_CRMF_ENCRYPTEDVALUE_new,
181OSSL_CRMF_MSGS_free,
182OSSL_CRMF_MSGS_it,
183OSSL_CRMF_MSGS_new,
184OSSL_CRMF_MSG_dup,
185OSSL_CRMF_MSG_free,
186OSSL_CRMF_MSG_it,
187OSSL_CRMF_MSG_new,
188OSSL_CRMF_PBMPARAMETER_free,
189OSSL_CRMF_PBMPARAMETER_it,
190OSSL_CRMF_PBMPARAMETER_new,
191OSSL_CRMF_PKIPUBLICATIONINFO_free,
192OSSL_CRMF_PKIPUBLICATIONINFO_it,
193OSSL_CRMF_PKIPUBLICATIONINFO_new,
194OSSL_CRMF_SINGLEPUBINFO_free,
195OSSL_CRMF_SINGLEPUBINFO_it,
196OSSL_CRMF_SINGLEPUBINFO_new,
197OSSL_HASH_free,
198OSSL_HASH_it,
199OSSL_HASH_new,
200OSSL_INFO_SYNTAX_free,
201OSSL_INFO_SYNTAX_it,
202OSSL_INFO_SYNTAX_new,
203OSSL_INFO_SYNTAX_POINTER_free,
204OSSL_INFO_SYNTAX_POINTER_it,
205OSSL_INFO_SYNTAX_POINTER_new,
206OSSL_PRIVILEGE_POLICY_ID_free,
207OSSL_PRIVILEGE_POLICY_ID_it,
208OSSL_PRIVILEGE_POLICY_ID_new,
209OSSL_TARGET_CERT_free,
210OSSL_TARGET_CERT_it,
211OSSL_TARGET_CERT_new,
212OSSL_TARGET_free,
213OSSL_TARGET_it,
214OSSL_TARGET_new,
215OSSL_TARGETING_INFORMATION_free,
216OSSL_TARGETING_INFORMATION_it,
217OSSL_TARGETING_INFORMATION_new,
218OSSL_TARGETS_free,
219OSSL_TARGETS_it,
220OSSL_TARGETS_new,
221OSSL_IETF_ATTR_SYNTAX_VALUE_free,
222OSSL_IETF_ATTR_SYNTAX_VALUE_it,
223OSSL_IETF_ATTR_SYNTAX_VALUE_new,
224OSSL_ISSUER_SERIAL_free,
225OSSL_ISSUER_SERIAL_new,
226OSSL_OBJECT_DIGEST_INFO_free,
227OSSL_OBJECT_DIGEST_INFO_new,
228OSSL_ROLE_SPEC_CERT_ID_free,
229OSSL_ROLE_SPEC_CERT_ID_new,
230OSSL_ROLE_SPEC_CERT_ID_it,
231OSSL_ROLE_SPEC_CERT_ID_SYNTAX_free,
232OSSL_ROLE_SPEC_CERT_ID_SYNTAX_new,
233OSSL_ROLE_SPEC_CERT_ID_SYNTAX_it,
234OSSL_USER_NOTICE_SYNTAX_free,
235OSSL_USER_NOTICE_SYNTAX_new,
236OSSL_USER_NOTICE_SYNTAX_it,
237OTHERNAME_free,
238OTHERNAME_new,
239PBE2PARAM_free,
240PBE2PARAM_new,
241PBEPARAM_free,
242PBEPARAM_new,
243PBKDF2PARAM_free,
244PBKDF2PARAM_new,
245PBMAC1PARAM_free,
246PBMAC1PARAM_it,
247PBMAC1PARAM_new,
248PKCS12_BAGS_free,
249PKCS12_BAGS_new,
250PKCS12_MAC_DATA_free,
251PKCS12_MAC_DATA_new,
252PKCS12_SAFEBAG_free,
253PKCS12_SAFEBAG_new,
254PKCS12_free,
255PKCS12_new,
256PKCS7_DIGEST_free,
257PKCS7_DIGEST_new,
258PKCS7_ENCRYPT_free,
259PKCS7_ENCRYPT_new,
260PKCS7_ENC_CONTENT_free,
261PKCS7_ENC_CONTENT_new,
262PKCS7_ENVELOPE_free,
263PKCS7_ENVELOPE_new,
264PKCS7_ISSUER_AND_SERIAL_free,
265PKCS7_ISSUER_AND_SERIAL_new,
266PKCS7_RECIP_INFO_free,
267PKCS7_RECIP_INFO_new,
268PKCS7_SIGNED_free,
269PKCS7_SIGNED_new,
270PKCS7_SIGNER_INFO_free,
271PKCS7_SIGNER_INFO_new,
272PKCS7_SIGN_ENVELOPE_free,
273PKCS7_SIGN_ENVELOPE_new,
274PKCS7_dup,
275PKCS7_free,
276PKCS7_new_ex,
277PKCS7_new,
278PKCS7_print_ctx,
279PKCS8_PRIV_KEY_INFO_free,
280PKCS8_PRIV_KEY_INFO_new,
281PKEY_USAGE_PERIOD_free,
282PKEY_USAGE_PERIOD_new,
283POLICYINFO_free,
284POLICYINFO_new,
285POLICYQUALINFO_free,
286POLICYQUALINFO_new,
287POLICY_CONSTRAINTS_free,
288POLICY_CONSTRAINTS_new,
289POLICY_MAPPING_free,
290POLICY_MAPPING_new,
291PROFESSION_INFOS_free,
292PROFESSION_INFOS_new,
293PROFESSION_INFO_free,
294PROFESSION_INFO_new,
295PROXY_CERT_INFO_EXTENSION_free,
296PROXY_CERT_INFO_EXTENSION_new,
297PROXY_POLICY_free,
298PROXY_POLICY_new,
299RSAPrivateKey_dup,
300RSAPublicKey_dup,
301RSA_OAEP_PARAMS_free,
302RSA_OAEP_PARAMS_new,
303RSA_PSS_PARAMS_free,
304RSA_PSS_PARAMS_new,
305RSA_PSS_PARAMS_dup,
306SCRYPT_PARAMS_free,
307SCRYPT_PARAMS_new,
308SXNETID_free,
309SXNETID_new,
310SXNET_free,
311SXNET_new,
312TLS_FEATURE_free,
313TLS_FEATURE_new,
314TS_ACCURACY_dup,
315TS_ACCURACY_free,
316TS_ACCURACY_new,
317TS_MSG_IMPRINT_dup,
318TS_MSG_IMPRINT_free,
319TS_MSG_IMPRINT_new,
320TS_REQ_dup,
321TS_REQ_free,
322TS_REQ_new,
323TS_RESP_dup,
324TS_RESP_free,
325TS_RESP_new,
326TS_STATUS_INFO_dup,
327TS_STATUS_INFO_free,
328TS_STATUS_INFO_new,
329TS_TST_INFO_dup,
330TS_TST_INFO_free,
331TS_TST_INFO_new,
332USERNOTICE_free,
333USERNOTICE_new,
334X509_ACERT_dup,
335X509_ACERT_free,
336X509_ACERT_it,
337X509_ACERT_new,
338X509_ACERT_INFO_free,
339X509_ACERT_INFO_it,
340X509_ACERT_INFO_new,
341X509_ACERT_ISSUER_V2FORM_free,
342X509_ACERT_ISSUER_V2FORM_new,
343X509_ALGOR_free,
344X509_ALGOR_it,
345X509_ALGOR_new,
346X509_ATTRIBUTE_dup,
347X509_ATTRIBUTE_free,
348X509_ATTRIBUTE_new,
349X509_CERT_AUX_free,
350X509_CERT_AUX_new,
351X509_CINF_free,
352X509_CINF_new,
353X509_CRL_INFO_free,
354X509_CRL_INFO_new,
355X509_CRL_dup,
356X509_CRL_free,
357X509_CRL_new_ex,
358X509_CRL_new,
359X509_EXTENSION_dup,
360X509_EXTENSION_free,
361X509_EXTENSION_new,
362X509_NAME_ENTRY_dup,
363X509_NAME_ENTRY_free,
364X509_NAME_ENTRY_new,
365X509_NAME_dup,
366X509_NAME_free,
367X509_NAME_new,
368X509_REQ_INFO_free,
369X509_REQ_INFO_new,
370X509_REQ_dup,
371X509_REQ_free,
372X509_REQ_new,
373X509_REQ_new_ex,
374X509_REVOKED_dup,
375X509_REVOKED_free,
376X509_REVOKED_new,
377X509_SIG_free,
378X509_SIG_new,
379X509_VAL_free,
380X509_VAL_new,
381X509_dup,
382- ASN1 object utilities
383
384=head1 SYNOPSIS
385
386=for openssl generic
387
388 #include <openssl/asn1t.h>
389
390 DECLARE_ASN1_FUNCTIONS(type)
391 IMPLEMENT_ASN1_FUNCTIONS(stname)
392
393 typedef struct ASN1_ITEM_st ASN1_ITEM;
394
395 extern const ASN1_ITEM TYPE_it;
396 TYPE *TYPE_new(void);
397 TYPE *TYPE_dup(const TYPE *a);
398 void TYPE_free(TYPE *a);
399 int TYPE_print_ctx(BIO *out, TYPE *a, int indent, const ASN1_PCTX *pctx);
400
401The following functions have been deprecated since OpenSSL 3.0, and can be
402hidden entirely by defining B<OPENSSL_API_COMPAT> with a suitable version value,
403see L<openssl_user_macros(7)>:
404
405 DSA *DSAparams_dup(const DSA *dsa);
406 RSA *RSAPrivateKey_dup(const RSA *rsa);
407 RSA *RSAPublicKey_dup(const RSA *rsa);
408
409=head1 DESCRIPTION
410
411In the description below, B<I<TYPE>> is used
412as a placeholder for any of the OpenSSL datatypes, such as B<X509>.
413
414The OpenSSL ASN1 parsing library templates are like a data-driven bytecode
415interpreter.
416Every ASN1 object as a global variable, TYPE_it, that describes the item
417such as its fields.  (On systems which cannot export variables from shared
418libraries, the global is instead a function which returns a pointer to a
419static variable.
420
421The macro DECLARE_ASN1_FUNCTIONS() is typically used in header files
422to generate the function declarations.
423
424The macro IMPLEMENT_ASN1_FUNCTIONS() is used once in a source file
425to generate the function bodies.
426
427
428B<I<TYPE>_new>() allocates an empty object of the indicated type.
429The object returned must be released by calling B<I<TYPE>_free>().
430
431B<I<TYPE>_new_ex>() is similar to B<I<TYPE>_new>() but also passes the
432library context I<libctx> and the property query I<propq> to use when retrieving
433algorithms from providers. This created object can then be used when loading
434binary data using B<d2i_I<TYPE>>().
435
436B<I<TYPE>_dup>() copies an existing object, leaving it untouched.
437Note, however, that the internal representation of the object
438may contain (besides the ASN.1 structure) further data, which is not copied.
439For instance, an B<X509> object usually is augmented by cached information
440on X.509v3 extensions, etc., and losing it can lead to wrong validation results.
441To avoid such situations, better use B<I<TYPE>_up_ref>() if available.
442For the case of B<X509> objects, an alternative to using L<X509_up_ref(3)>
443may be to still call B<I<TYPE>_dup>(), e.g., I<copied_cert = X509_dup(cert)>,
444followed by I<X509_check_purpose(copied_cert, -1, 0)>,
445which re-builds the cached data.
446
447B<I<TYPE>_free>() releases the object and all pointers and sub-objects
448within it. If the argument is NULL, nothing is done.
449
450B<I<TYPE>_print_ctx>() prints the object I<a> on the specified BIO I<out>.
451Each line will be prefixed with I<indent> spaces.
452The I<pctx> specifies the printing context and is for internal
453use; use NULL to get the default behavior.  If a print function is
454user-defined, then pass in any I<pctx> down to any nested calls.
455
456=head1 RETURN VALUES
457
458B<I<TYPE>_new>(), B<I<TYPE>_new_ex>() and B<I<TYPE>_dup>() return a pointer to
459the object or NULL on failure.
460
461B<I<TYPE>_print_ctx>() returns 1 on success or zero on failure.
462
463=head1 SEE ALSO
464
465L<X509_up_ref(3)>
466
467=head1 HISTORY
468
469The functions X509_REQ_new_ex(), X509_CRL_new_ex(), PKCS7_new_ex() and
470CMS_ContentInfo_new_ex() were added in OpenSSL 3.0.
471
472The functions DSAparams_dup(), RSAPrivateKey_dup() and RSAPublicKey_dup() were
473deprecated in 3.0.
474
475=head1 COPYRIGHT
476
477Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.
478
479Licensed under the Apache License 2.0 (the "License").  You may not use
480this file except in compliance with the License.  You can obtain a copy
481in the file LICENSE in the source distribution or at
482L<https://www.openssl.org/source/license.html>.
483
484=cut
485