mirror of
https://github.com/opnsense/src.git
synced 2026-06-07 15:52:40 -04:00
Summary: Release notes can be found at https://www.openssl.org/news/openssl-3.0-notes.html . Obtained from: https://www.openssl.org/source/openssl-3.0.8.tar.gz Differential Revision: https://reviews.freebsd.org/D38835 Test Plan: ``` $ git status On branch vendor/openssl-3.0 nothing to commit, working tree clean $ (cd ..; fetch http://www.openssl.org/source/openssl-${OSSLVER}.tar.gz http://www.openssl.org/source/openssl-${OSSLVER}.tar.gz.asc) openssl-3.0.8.tar.gz 14 MB 4507 kBps 04s openssl-3.0.8.tar.gz.asc 833 B 10 MBps 00s $ set | egrep '(XLIST|OSSLVER)=' OSSLVER=3.0.8 XLIST=FREEBSD-Xlist $ gpg --list-keys /home/ngie/.gnupg/pubring.kbx ----------------------------- pub rsa4096 2014-10-04 [SC] 7953AC1FBC3DC8B3B292393ED5E9E43F7DF9EE8C uid [ unknown] Richard Levitte <richard@levitte.org> uid [ unknown] Richard Levitte <levitte@lp.se> uid [ unknown] Richard Levitte <levitte@openssl.org> sub rsa4096 2014-10-04 [E] $ gpg --verify openssl-${OSSLVER}.tar.gz.asc openssl-${OSSLVER}.tar.gz gpg: Signature made Tue Feb 7 05:43:55 2023 PST gpg: using RSA key 7953AC1FBC3DC8B3B292393ED5E9E43F7DF9EE8C gpg: Good signature from "Richard Levitte <richard@levitte.org>" [unknown] gpg: aka "Richard Levitte <levitte@lp.se>" [unknown] gpg: aka "Richard Levitte <levitte@openssl.org>" [unknown] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 7953 AC1F BC3D C8B3 B292 393E D5E9 E43F 7DF9 EE8C $ (cd vendor.checkout/; git status; find . -type f -or -type l | cut -c 3- | sort > ../old) On branch vendor/openssl-3.0 nothing to commit, working tree clean $ tar -x -X $XLIST -f ../openssl-${OSSLVER}.tar.gz -C .. $ rsync --exclude FREEBSD.* --delete -avzz ../openssl-${OSSLVER}/* . $ cat .git gitdir: /home/ngie/git/freebsd-src/.git/worktrees/vendor.checkout $ diff -arq ../openssl-3.0.8 . Only in .: .git Only in .: FREEBSD-Xlist Only in .: FREEBSD-upgrade $ git status FREEBSD* On branch vendor/openssl-3.0 nothing to commit, working tree clean $ ``` Reviewers: emaste, jkim Subscribers: imp, andrew, dab Differential Revision: https://reviews.freebsd.org/D38835
80 lines
2.8 KiB
Text
80 lines
2.8 KiB
Text
=pod
|
|
|
|
=head1 NAME
|
|
|
|
CMS_EnvelopedData_create_ex, CMS_EnvelopedData_create,
|
|
CMS_AuthEnvelopedData_create, CMS_AuthEnvelopedData_create_ex
|
|
- Create CMS envelope
|
|
|
|
=head1 SYNOPSIS
|
|
|
|
#include <openssl/cms.h>
|
|
|
|
CMS_ContentInfo *
|
|
CMS_EnvelopedData_create_ex(const EVP_CIPHER *cipher, OSSL_LIB_CTX *libctx,
|
|
const char *propq);
|
|
CMS_ContentInfo *CMS_EnvelopedData_create(const EVP_CIPHER *cipher);
|
|
|
|
CMS_ContentInfo *
|
|
CMS_AuthEnvelopedData_create_ex(const EVP_CIPHER *cipher, OSSL_LIB_CTX *libctx,
|
|
const char *propq);
|
|
CMS_ContentInfo *CMS_AuthEnvelopedData_create(const EVP_CIPHER *cipher);
|
|
|
|
=head1 DESCRIPTION
|
|
|
|
CMS_EnvelopedData_create_ex() creates a B<CMS_ContentInfo> structure
|
|
with a type B<NID_pkcs7_enveloped>. I<cipher> is the symmetric cipher to use.
|
|
The library context I<libctx> and the property query I<propq> are used when
|
|
retrieving algorithms from providers.
|
|
|
|
CMS_AuthEnvelopedData_create_ex() creates a B<CMS_ContentInfo>
|
|
structure with a type B<NID_id_smime_ct_authEnvelopedData>. B<cipher> is the
|
|
symmetric AEAD cipher to use. Currently only AES variants with GCM mode are
|
|
supported. The library context I<libctx> and the property query I<propq> are
|
|
used when retrieving algorithms from providers.
|
|
|
|
The algorithm passed in the I<cipher> parameter must support ASN1 encoding of
|
|
its parameters.
|
|
|
|
The recipients can be added later using L<CMS_add1_recipient_cert(3)> or
|
|
L<CMS_add0_recipient_key(3)>.
|
|
|
|
The B<CMS_ContentInfo> structure needs to be finalized using L<CMS_final(3)>
|
|
and then freed using L<CMS_ContentInfo_free(3)>.
|
|
|
|
CMS_EnvelopedData_create() and CMS_AuthEnvelopedData_create are similar to
|
|
CMS_EnvelopedData_create_ex() and
|
|
CMS_AuthEnvelopedData_create_ex() but use default values of NULL for
|
|
the library context I<libctx> and the property query I<propq>.
|
|
|
|
=head1 NOTES
|
|
|
|
Although CMS_EnvelopedData_create() and CMS_AuthEnvelopedData_create() allocate
|
|
a new B<CMS_ContentInfo> structure, they are not usually used in applications.
|
|
The wrappers L<CMS_encrypt(3)> and L<CMS_decrypt(3)> are often used instead.
|
|
|
|
=head1 RETURN VALUES
|
|
|
|
If the allocation fails, CMS_EnvelopedData_create() and
|
|
CMS_AuthEnvelopedData_create() return NULL and set an error code that can be
|
|
obtained by L<ERR_get_error(3)>. Otherwise they return a pointer to the newly
|
|
allocated structure.
|
|
|
|
=head1 SEE ALSO
|
|
|
|
L<ERR_get_error(3)>, L<CMS_encrypt(3)>, L<CMS_decrypt(3)>, L<CMS_final(3)>
|
|
|
|
=head1 HISTORY
|
|
|
|
The CMS_EnvelopedData_create_ex() method was added in OpenSSL 3.0.
|
|
|
|
=head1 COPYRIGHT
|
|
|
|
Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.
|
|
|
|
Licensed under the Apache License 2.0 (the "License"). You may not use
|
|
this file except in compliance with the License. You can obtain a copy
|
|
in the file LICENSE in the source distribution or at
|
|
L<https://www.openssl.org/source/license.html>.
|
|
|
|
=cut
|