1=pod
2
3=head1 NAME
4
5ossl_cmp_calc_protection,
6ossl_cmp_msg_protect,
7ossl_cmp_msg_add_extraCerts
8- functions for producing CMP message protection
9
10=head1 SYNOPSIS
11
12 #include "cmp_local.h"
13
14 ASN1_BIT_STRING *ossl_cmp_calc_protection(const OSSL_CMP_CTX *ctx,
15                                           const OSSL_CMP_MSG *msg);
16 int ossl_cmp_msg_protect(OSSL_CMP_CTX *ctx, OSSL_CMP_MSG *msg);
17 int ossl_cmp_msg_add_extraCerts(OSSL_CMP_CTX *ctx, OSSL_CMP_MSG *msg);
18
19=head1 DESCRIPTION
20
21ossl_cmp_calc_protection() calculates the protection for the given I<msg>
22according to the algorithm and parameters in the message header's protectionAlg
23using the credentials, library context, and property criteria in the I<ctx>.
24Unless I<msg->header->protectionAlg> is B<PasswordBasedMAC>,
25its value is completed according to I<ctx->pkey> and I<ctx->digest>,
26where the latter irrelevant in the case of Edwards curves.
27
28ossl_cmp_msg_protect() (re-)protects the given message I<msg> using an algorithm
29depending on the available context information given in the I<ctx>.
30If there is a secretValue it selects PBMAC, else if there is a protection cert
31it selects Signature and uses ossl_cmp_msg_add_extraCerts (see below).
32It also sets the protectionAlg field in the message header accordingly.
33
34ossl_cmp_msg_add_extraCerts() adds elements to the extraCerts field in I<msg>.
35If signature-based message protection is used it adds first the CMP signer cert
36ctx->cert and then its chain ctx->chain. If this chain is not present in I<ctx>
37tries to build it using ctx->untrusted and caches the result in ctx->chain.
38In any case all the certificates explicitly specified to be sent out (i.e.,
39I<ctx->extraCertsOut>) are added. Note that it will NOT add the root certificate
40of the chain, i.e, the trust anchor (unless it is part of extraCertsOut).
41
42=head1 NOTES
43
44CMP is defined in RFC 4210 (and CRMF in RFC 4211).
45
46The I<ctx> parameter of ossl_cmp_msg_add_extraCerts()
47and thus also of ossl_cmp_msg_protect() cannot be made I<const>
48because I<ctx->chain> may get adapted to cache the chain of the CMP signer cert.
49
50=head1 RETURN VALUES
51
52ossl_cmp_calc_protection() returns the protection on success, else NULL.
53
54All other functions return 1 on success, 0 on error.
55
56=head1 HISTORY
57
58The OpenSSL CMP support was added in OpenSSL 3.0.
59
60=head1 COPYRIGHT
61
62Copyright 2007-2023 The OpenSSL Project Authors. All Rights Reserved.
63
64Licensed under the Apache License 2.0 (the "License").  You may not use
65this file except in compliance with the License.  You can obtain a copy
66in the file LICENSE in the source distribution or at
67L<https://www.openssl.org/source/license.html>.
68
69=cut
70