Class: OpenSSL::X509::Name
- Inherits:
-
Object
- Object
- OpenSSL::X509::Name
- Includes:
- Comparable, Marshal
- Defined in:
- ossl_x509name.c,
lib/openssl/x509.rb,
ossl_x509name.c
Overview
An X.509 name represents a hostname, email address or other entity associated with a public key.
You can create a Name by parsing a distinguished name String or by supplying the distinguished name as an Array.
name = OpenSSL::X509::Name.parse '/CN=nobody/DC=example'
name = OpenSSL::X509::Name.new [['CN', 'nobody'], ['DC', 'example']]
Defined Under Namespace
Modules: RFC2253DN
Constant Summary collapse
- DEFAULT_OBJECT_TYPE =
The default object type for name entries.
utf8str
- OBJECT_TYPE_TEMPLATE =
The default object type template for name entries.
hash
- COMPAT =
A flag for #to_s.
Breaks the name returned into multiple lines if longer than 80 characters.
ULONG2NUM(XN_FLAG_COMPAT)
- RFC2253 =
A flag for #to_s.
Returns an RFC2253 format name.
ULONG2NUM(XN_FLAG_RFC2253)
- ONELINE =
A flag for #to_s.
Returns a more readable format than RFC2253.
ULONG2NUM(XN_FLAG_ONELINE)
- MULTILINE =
A flag for #to_s.
Returns a multiline format.
ULONG2NUM(XN_FLAG_MULTILINE)
Class Method Summary collapse
- .parse_openssl(str, template = OBJECT_TYPE_TEMPLATE) ⇒ Object (also: parse)
- .parse_rfc2253(str, template = OBJECT_TYPE_TEMPLATE) ⇒ Object
Instance Method Summary collapse
-
#add_entry(oid, value[, type], loc: -1, set: 0) ⇒ self
Adds a new entry with the given oid and value to this name.
-
#cmp(other) ⇒ Object
(also: #<=>)
Compares this Name with other and returns
0
if they are the same and-1
or+1
if they are greater or less than each other respectively. -
#eql?(other) ⇒ Boolean
Returns true if name and other refer to the same hash key.
-
#hash ⇒ Integer
The hash value returned is suitable for use as a certificate’s filename in a CA path.
-
#hash_old ⇒ Integer
Returns an MD5 based hash used in OpenSSL 0.9.X.
-
#initialize(*args) ⇒ Object
constructor
Creates a new Name.
- #initialize_copy(other) ⇒ Object
-
#inspect ⇒ Object
:nodoc:.
- #pretty_print(q) ⇒ Object
-
#to_a ⇒ Array
Returns an Array representation of the distinguished name suitable for passing to ::new.
-
#to_der ⇒ String
Converts the name to DER encoding.
-
#to_s(*args) ⇒ Object
Returns a String representation of the Distinguished Name.
-
#to_utf8 ⇒ String
Returns an UTF-8 representation of the distinguished name, as specified in RFC 2253.
Methods included from Marshal
Constructor Details
#X509::Name.new ⇒ Object #X509::Name.new(der) ⇒ Object #X509::Name.new(distinguished_name) ⇒ Object #X509::Name.new(distinguished_name, template) ⇒ Object
Creates a new Name.
A name may be created from a DER encoded string der, an Array representing a distinguished_name or a distinguished_name along with a template.
name = OpenSSL::X509::Name.new [['CN', 'nobody'], ['DC', 'example']]
name = OpenSSL::X509::Name.new name.to_der
See add_entry for a description of the distinguished_name Array’s contents
145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 |
# File 'ossl_x509name.c', line 145
static VALUE
ossl_x509name_initialize(int argc, VALUE *argv, VALUE self)
{
X509_NAME *name;
VALUE arg, template;
GetX509Name(self, name);
if (rb_scan_args(argc, argv, "02", &arg, &template) == 0) {
return self;
}
else {
VALUE tmp = rb_check_array_type(arg);
if (!NIL_P(tmp)) {
VALUE args;
if(NIL_P(template)) template = OBJECT_TYPE_TEMPLATE;
args = rb_ary_new3(2, self, template);
rb_block_call(tmp, rb_intern("each"), 0, 0, ossl_x509name_init_i, args);
}
else{
const unsigned char *p;
VALUE str = ossl_to_der_if_possible(arg);
X509_NAME *x;
StringValue(str);
p = (unsigned char *)RSTRING_PTR(str);
x = d2i_X509_NAME(&name, &p, RSTRING_LEN(str));
DATA_PTR(self) = name;
if(!x){
ossl_raise(eX509NameError, NULL);
}
}
}
return self;
}
|
Class Method Details
.parse_openssl(str, template = OBJECT_TYPE_TEMPLATE) ⇒ Object Also known as: parse
287 288 289 290 291 292 293 294 295 296 |
# File 'lib/openssl/x509.rb', line 287 def parse_openssl(str, template=OBJECT_TYPE_TEMPLATE) if str.start_with?("/") # /A=B/C=D format ary = str[1..-1].split("/").map { |i| i.split("=", 2) } else # Comma-separated ary = str.split(",").map { |i| i.strip.split("=", 2) } end self.new(ary, template) end |
Instance Method Details
#add_entry(oid, value[, type], loc: -1, set: 0) ⇒ self
Adds a new entry with the given oid and value to this name. The oid is an object identifier defined in ASN.1. Some common OIDs are:
- C
-
Country Name
- CN
-
Common Name
- DC
-
Domain Component
- O
-
Organization Name
- OU
-
Organizational Unit Name
- ST
-
State or Province Name
The optional keyword parameters loc and set specify where to insert the new attribute. Refer to the manpage of X509_NAME_add_entry(3) for details. loc defaults to -1 and set defaults to 0. This appends a single-valued RDN to the end.
218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 |
# File 'ossl_x509name.c', line 218
static
VALUE ossl_x509name_add_entry(int argc, VALUE *argv, VALUE self)
{
X509_NAME *name;
VALUE oid, value, type, opts, kwargs[2];
static ID kwargs_ids[2];
const char *oid_name;
int loc = -1, set = 0;
if (!kwargs_ids[0]) {
kwargs_ids[0] = rb_intern_const("loc");
kwargs_ids[1] = rb_intern_const("set");
}
rb_scan_args(argc, argv, "21:", &oid, &value, &type, &opts);
rb_get_kwargs(opts, kwargs_ids, 0, 2, kwargs);
oid_name = StringValueCStr(oid);
StringValue(value);
if(NIL_P(type)) type = rb_aref(OBJECT_TYPE_TEMPLATE, oid);
if (kwargs[0] != Qundef)
loc = NUM2INT(kwargs[0]);
if (kwargs[1] != Qundef)
set = NUM2INT(kwargs[1]);
GetX509Name(self, name);
if (!X509_NAME_add_entry_by_txt(name, oid_name, NUM2INT(type),
(unsigned char *)RSTRING_PTR(value),
RSTRING_LENINT(value), loc, set))
ossl_raise(eX509NameError, "X509_NAME_add_entry_by_txt");
return self;
}
|
#cmp(other) ⇒ -1 | 0 | 1 | nil #<=>(other) ⇒ -1 | 0 | 1 | nil Also known as: <=>
Compares this Name with other and returns 0
if they are the same and -1
or +1
if they are greater or less than each other respectively. Returns nil
if they are not comparable (i.e. different types).
397 398 399 400 401 402 403 404 405 406 407 408 409 410 |
# File 'ossl_x509name.c', line 397
static VALUE
ossl_x509name_cmp(VALUE self, VALUE other)
{
int result;
if (!rb_obj_is_kind_of(other, cX509Name))
return Qnil;
result = ossl_x509name_cmp0(self, other);
if (result < 0) return INT2FIX(-1);
if (result > 0) return INT2FIX(1);
return INT2FIX(0);
}
|
#eql?(other) ⇒ Boolean
Returns true if name and other refer to the same hash key.
418 419 420 421 422 423 424 425 |
# File 'ossl_x509name.c', line 418
static VALUE
ossl_x509name_eql(VALUE self, VALUE other)
{
if (!rb_obj_is_kind_of(other, cX509Name))
return Qfalse;
return ossl_x509name_cmp0(self, other) == 0 ? Qtrue : Qfalse;
}
|
#hash ⇒ Integer
The hash value returned is suitable for use as a certificate’s filename in a CA path.
434 435 436 437 438 439 440 441 442 443 444 445 |
# File 'ossl_x509name.c', line 434
static VALUE
ossl_x509name_hash(VALUE self)
{
X509_NAME *name;
unsigned long hash;
GetX509Name(self, name);
hash = X509_NAME_hash(name);
return ULONG2NUM(hash);
}
|
#hash_old ⇒ Integer
Returns an MD5 based hash used in OpenSSL 0.9.X.
453 454 455 456 457 458 459 460 461 462 463 464 |
# File 'ossl_x509name.c', line 453
static VALUE
ossl_x509name_hash_old(VALUE self)
{
X509_NAME *name;
unsigned long hash;
GetX509Name(self, name);
hash = X509_NAME_hash_old(name);
return ULONG2NUM(hash);
}
|
#initialize_copy(other) ⇒ Object
180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 |
# File 'ossl_x509name.c', line 180
static VALUE
ossl_x509name_initialize_copy(VALUE self, VALUE other)
{
X509_NAME *name, *name_other, *name_new;
rb_check_frozen(self);
GetX509Name(self, name);
GetX509Name(other, name_other);
name_new = X509_NAME_dup(name_other);
if (!name_new)
ossl_raise(eX509NameError, "X509_NAME_dup");
SetX509Name(self, name_new);
X509_NAME_free(name);
return self;
}
|
#inspect ⇒ Object
:nodoc:
323 324 325 326 327 328 |
# File 'ossl_x509name.c', line 323
static VALUE
ossl_x509name_inspect(VALUE self)
{
return rb_enc_sprintf(rb_utf8_encoding(), "#<%"PRIsVALUE" %"PRIsVALUE">",
rb_obj_class(self), ossl_x509name_to_utf8(self));
}
|
#pretty_print(q) ⇒ Object
301 302 303 304 305 306 |
# File 'lib/openssl/x509.rb', line 301 def pretty_print(q) q.object_group(self) { q.text ' ' q.text to_s(OpenSSL::X509::Name::RFC2253) } end |
#to_a ⇒ Array
Returns an Array representation of the distinguished name suitable for passing to ::new
337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 |
# File 'ossl_x509name.c', line 337
static VALUE
ossl_x509name_to_a(VALUE self)
{
X509_NAME *name;
X509_NAME_ENTRY *entry;
int i,entries,nid;
char long_name[512];
const char *short_name;
VALUE ary, vname, ret;
ASN1_STRING *value;
GetX509Name(self, name);
entries = X509_NAME_entry_count(name);
if (entries < 0) {
OSSL_Debug("name entries < 0!");
return rb_ary_new();
}
ret = rb_ary_new2(entries);
for (i=0; i<entries; i++) {
if (!(entry = X509_NAME_get_entry(name, i))) {
ossl_raise(eX509NameError, NULL);
}
if (!i2t_ASN1_OBJECT(long_name, sizeof(long_name),
X509_NAME_ENTRY_get_object(entry))) {
ossl_raise(eX509NameError, NULL);
}
nid = OBJ_ln2nid(long_name);
if (nid == NID_undef) {
vname = rb_str_new2((const char *) &long_name);
} else {
short_name = OBJ_nid2sn(nid);
vname = rb_str_new2(short_name); /*do not free*/
}
value = X509_NAME_ENTRY_get_data(entry);
ary = rb_ary_new3(3, vname, asn1str_to_str(value), INT2NUM(value->type));
rb_ary_push(ret, ary);
}
return ret;
}
|
#to_der ⇒ String
Converts the name to DER encoding
472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 |
# File 'ossl_x509name.c', line 472
static VALUE
ossl_x509name_to_der(VALUE self)
{
X509_NAME *name;
VALUE str;
long len;
unsigned char *p;
GetX509Name(self, name);
if((len = i2d_X509_NAME(name, NULL)) <= 0)
ossl_raise(eX509NameError, NULL);
str = rb_str_new(0, len);
p = (unsigned char *)RSTRING_PTR(str);
if(i2d_X509_NAME(name, &p) <= 0)
ossl_raise(eX509NameError, NULL);
ossl_str_adjust(str, p);
return str;
}
|
#to_s ⇒ String #to_s(format) ⇒ String
Returns a String representation of the Distinguished Name. format is one of:
-
OpenSSL::X509::Name::COMPAT
-
OpenSSL::X509::Name::RFC2253
-
OpenSSL::X509::Name::ONELINE
-
OpenSSL::X509::Name::MULTILINE
If format is omitted, the largely broken and traditional OpenSSL format is used.
296 297 298 299 300 301 302 303 304 305 |
# File 'ossl_x509name.c', line 296
static VALUE
ossl_x509name_to_s(int argc, VALUE *argv, VALUE self)
{
rb_check_arity(argc, 0, 1);
/* name.to_s(nil) was allowed */
if (!argc || NIL_P(argv[0]))
return ossl_x509name_to_s_old(self);
else
return x509name_print(self, NUM2ULONG(argv[0]));
}
|
#to_utf8 ⇒ String
Returns an UTF-8 representation of the distinguished name, as specified in RFC 2253.
314 315 316 317 318 319 320 |
# File 'ossl_x509name.c', line 314
static VALUE
ossl_x509name_to_utf8(VALUE self)
{
VALUE str = x509name_print(self, XN_FLAG_RFC2253 & ~ASN1_STRFLGS_ESC_MSB);
rb_enc_associate_index(str, rb_utf8_encindex());
return str;
}
|