6 SSL - OpenSSL SSL/TLS library
12 The OpenSSL B<ssl> library implements the Secure Sockets Layer (SSL v2/v3) and
13 Transport Layer Security (TLS v1) protocols. It provides a rich API which is
18 Currently the OpenSSL B<ssl> library provides the following C header files
19 containing the prototypes for the data structures and and functions:
25 That's the common header file for the SSL/TLS API. Include it into your
26 program to make the API of the B<ssl> library available. It internally
27 includes both more private SSL headers and headers from the B<crypto> library.
33 Currently the OpenSSL B<ssl> library functions deal with the following data
38 =item B<SSL_CTX> (SSL Context)
40 =item B<SSL> (SSL Connection)
42 That's the SSL/TLS structure which is created by
43 a server or client per established connection.
45 =item B<SSL_METHOD> (SSL Method)
47 =item B<SSL_CIPHER> (SSL Cipher)
49 =item B<SSL_SESSION> (SSL Session)
55 Currently the OpenSSL B<ssl> library exports 143 API functions.
56 They are documented in the following:
60 =item [MACRO] B<SSL_ADH>(SSL_kEDH|SSL_aNULL);
62 =item [MACRO] B<SSL_CB_ACCEPT_EXIT>(SSL_ST_ACCEPT|SSL_CB_EXIT);
64 =item [MACRO] B<SSL_CB_ACCEPT_LOOP>(SSL_ST_ACCEPT|SSL_CB_LOOP);
66 =item [MACRO] B<SSL_CB_CONNECT_EXIT>(SSL_ST_CONNECT|SSL_CB_EXIT);
68 =item [MACRO] B<SSL_CB_CONNECT_LOOP>(SSL_ST_CONNECT|SSL_CB_LOOP);
70 =item [MACRO] B<SSL_CB_READ_ALERT>(SSL_CB_ALERT|SSL_CB_READ);
72 =item [MACRO] B<SSL_CB_WRITE_ALERT>(SSL_CB_ALERT|SSL_CB_WRITE);
74 =item char *B<SSL_CIPHER_description>(SSL_CIPHER *cipher, char *buf, int len);
76 =item int B<SSL_CIPHER_get_bits>(SSL_CIPHER *c, int *alg_bits);
78 =item char *B<SSL_CIPHER_get_name>(SSL_CIPHER *c);
80 =item char *B<SSL_CIPHER_get_version>(SSL_CIPHER *c);
82 =item int B<SSL_CTX_add_client_CA>(SSL_CTX *ctx, X509 *x);
84 =item [MACRO] B<SSL_CTX_add_extra_chain_cert>(ctx,x509);
86 =item int B<SSL_CTX_add_session>(SSL_CTX *ctx, SSL_SESSION *c);
88 =item int B<SSL_CTX_check_private_key>(SSL_CTX *ctx);
90 =item long B<SSL_CTX_ctrl>(SSL_CTX *ctx, int cmd, long larg, char *parg);
92 =item void B<SSL_CTX_flush_sessions>(SSL_CTX *s, long t);
94 =item void B<SSL_CTX_free>(SSL_CTX *a);
96 =item [MACRO] B<SSL_CTX_get_app_data>(ctx);
98 =item [MACRO] B<SSL_CTX_get_cert_store>(ctx);
100 =item STACK *B<SSL_CTX_get_client_CA_list>(SSL_CTX *ctx);
102 =item [MACRO] B<SSL_CTX_get_client_cert_cb>(ctx);
104 =item char *B<SSL_CTX_get_ex_data>(SSL_CTX *s, int idx);
106 =item int B<SSL_CTX_get_ex_new_index>(long argl, char *argp, int (*new_func);(void), int (*dup_func)(void), void (*free_func)(void))
108 =item [MACRO] B<SSL_CTX_get_info_callback>(ctx);
110 =item int B<SSL_CTX_get_quiet_shutdown>(SSL_CTX *ctx);
112 =item [MACRO] B<SSL_CTX_get_session_cache_mode>(ctx);
114 =item [MACRO] B<SSL_CTX_get_timeout>(ctx);
116 =item int (*B<SSL_CTX_get_verify_callback>(SSL_CTX *ctx);)(void)
118 =item int B<SSL_CTX_get_verify_mode>(SSL_CTX *ctx);
120 =item int B<SSL_CTX_load_verify_locations>(SSL_CTX *ctx, char *CAfile, char *CApath);
122 =item [MACRO] B<SSL_CTX_need_tmp_RSA>(ctx);
124 =item SSL_CTX *B<SSL_CTX_new>(SSL_METHOD *meth);
126 =item int B<SSL_CTX_remove_session>(SSL_CTX *ctx, SSL_SESSION *c);
128 =item [MACRO] B<SSL_CTX_sess_accept>(ctx);
130 =item [MACRO] B<SSL_CTX_sess_accept_good>(ctx);
132 =item [MACRO] B<SSL_CTX_sess_accept_renegotiate>(ctx);
134 =item [MACRO] B<SSL_CTX_sess_cache_full>(ctx);
136 =item [MACRO] B<SSL_CTX_sess_cb_hits>(ctx);
138 =item [MACRO] B<SSL_CTX_sess_connect>(ctx);
140 =item [MACRO] B<SSL_CTX_sess_connect_good>(ctx);
142 =item [MACRO] B<SSL_CTX_sess_connect_renegotiate>(ctx);
144 =item [MACRO] B<SSL_CTX_sess_get_cache_size>(ctx);
146 =item [MACRO] B<SSL_CTX_sess_get_get_cb>(ctx);
148 =item [MACRO] B<SSL_CTX_sess_get_new_cb>(ctx);
150 =item [MACRO] B<SSL_CTX_sess_get_remove_cb>(ctx);
152 =item [MACRO] B<SSL_CTX_sess_hits>(ctx);
154 =item [MACRO] B<SSL_CTX_sess_misses>(ctx);
156 =item [MACRO] B<SSL_CTX_sess_number>(ctx);
158 =item [MACRO] B<SSL_CTX_sess_set_cache_size>(ctx,t);
160 =item [MACRO] B<SSL_CTX_sess_set_get_cb>(ctx,cb);
162 =item [MACRO] B<SSL_CTX_sess_set_new_cb>(ctx,cb);
164 =item [MACRO] B<SSL_CTX_sess_set_remove_cb>(ctx,cb);
166 =item [MACRO] B<SSL_CTX_sess_timeouts>(ctx);
168 =item [MACRO] B<SSL_CTX_sessions>(ctx);
170 =item [MACRO] B<SSL_CTX_set_app_data>(ctx,arg);
172 =item [MACRO] B<SSL_CTX_set_cert_store>(ctx,cs);
174 =item [MACRO] B<SSL_CTX_set_cert_verify_callback>(a,b,c);
176 =item void B<SSL_CTX_set_cert_verify_cb>(SSL_CTX *ctx, int (*cb);(void), char *arg)
178 =item int B<SSL_CTX_set_cipher_list>(SSL_CTX *ctx, char *str);
180 =item void B<SSL_CTX_set_client_CA_list>(SSL_CTX *ctx, STACK *list);
182 =item [MACRO] B<SSL_CTX_set_client_cert_cb>(ctx,cb);
184 =item void B<SSL_CTX_set_default_passwd_cb>(SSL_CTX *ctx, int (*cb);(void))
186 =item [MACRO] B<SSL_CTX_set_default_read_ahead>(ctx,m);
188 =item [MACRO] B<SSL_CTX_set_default_verify>(a,b,c);
190 =item int B<SSL_CTX_set_default_verify_paths>(SSL_CTX *ctx);
192 =item int B<SSL_CTX_set_ex_data>(SSL_CTX *s, int idx, char *arg);
194 =item [MACRO] B<SSL_CTX_set_info_callback>(ctx,cb);
196 =item [MACRO] B<SSL_CTX_set_options>(ctx,op);
198 =item void B<SSL_CTX_set_quiet_shutdown>(SSL_CTX *ctx, int mode);
200 =item [MACRO] B<SSL_CTX_set_session_cache_mode>(ctx,m);
202 =item int B<SSL_CTX_set_ssl_version>(SSL_CTX *ctx, SSL_METHOD *meth);
204 =item [MACRO] B<SSL_CTX_set_timeout>(ctx,t);
206 =item [MACRO] B<SSL_CTX_set_tmp_dh>(ctx,dh);
208 =item [MACRO] B<SSL_CTX_set_tmp_dh_callback>(ctx,dh);
210 =item [MACRO] B<SSL_CTX_set_tmp_rsa>(ctx,rsa);
212 =item [MACRO] B<SSL_CTX_set_tmp_rsa_callback>(ctx,cb);
214 =item void B<SSL_CTX_set_verify>(SSL_CTX *ctx, int mode, int (*cb);(void))
216 =item int B<SSL_CTX_use_PrivateKey>(SSL_CTX *ctx, EVP_PKEY *pkey);
218 =item int B<SSL_CTX_use_PrivateKey_ASN1>(int type, SSL_CTX *ctx, unsigned char *d, long len);
220 =item int B<SSL_CTX_use_PrivateKey_file>(SSL_CTX *ctx, char *file, int type);
222 =item int B<SSL_CTX_use_RSAPrivateKey>(SSL_CTX *ctx, RSA *rsa);
224 =item int B<SSL_CTX_use_RSAPrivateKey_ASN1>(SSL_CTX *ctx, unsigned char *d, long len);
226 =item int B<SSL_CTX_use_RSAPrivateKey_file>(SSL_CTX *ctx, char *file, int type);
228 =item int B<SSL_CTX_use_certificate>(SSL_CTX *ctx, X509 *x);
230 =item int B<SSL_CTX_use_certificate_ASN1>(SSL_CTX *ctx, int len, unsigned char *d);
232 =item int B<SSL_CTX_use_certificate_file>(SSL_CTX *ctx, char *file, int type);
234 =item [MACRO] B<SSL_DH>(SSL_kDHr|SSL_kDHd|SSL_kEDH);
236 =item [MACRO] B<SSL_EDH>(SSL_kEDH|(SSL_AUTH_MASK^SSL_aNULL);
238 =item [MACRO] B<SSL_FZA>(SSL_aFZA|SSL_kFZA|SSL_eFZA);
240 =item [MACRO] B<SSL_MIN_RSA_MODULUS_LENGTH_IN_BYTES>(512/8);
242 =item [MACRO] B<SSL_NULL>(SSL_eNULL);
244 =item [MACRO] B<SSL_RSA>(SSL_kRSA|SSL_aRSA);
246 =item [MACRO] B<SSL_SESSION_CACHE_MAX_SIZE_DEFAULT>(1024*20);
248 =item int B<SSL_SESSION_cmp>(SSL_SESSION *a, SSL_SESSION *b);
250 =item void B<SSL_SESSION_free>(SSL_SESSION *ss);
252 =item [MACRO] B<SSL_SESSION_get_app_data>(s);
254 =item char *B<SSL_SESSION_get_ex_data>(SSL_SESSION *s, int idx);
256 =item int B<SSL_SESSION_get_ex_new_index>(long argl, char *argp, int (*new_func);(void), int (*dup_func)(void), void (*free_func)(void))
258 =item long B<SSL_SESSION_get_time>(SSL_SESSION *s);
260 =item long B<SSL_SESSION_get_timeout>(SSL_SESSION *s);
262 =item unsigned long B<SSL_SESSION_hash>(SSL_SESSION *a);
264 =item SSL_SESSION *B<SSL_SESSION_new>(void);
266 =item int B<SSL_SESSION_print>(BIO *bp, SSL_SESSION *x);
268 =item int B<SSL_SESSION_print_fp>(FILE *fp, SSL_SESSION *x);
270 =item [MACRO] B<SSL_SESSION_set_app_data>(s,a);
272 =item int B<SSL_SESSION_set_ex_data>(SSL_SESSION *s, int idx, char *arg);
274 =item long B<SSL_SESSION_set_time>(SSL_SESSION *s, long t);
276 =item long B<SSL_SESSION_set_timeout>(SSL_SESSION *s, long t);
278 =item [MACRO] B<SSL_SESS_CACHE_BOTH>(SSL_SESS_CACHE_CLIENT|SSL_SESS_CACHE_SERVER);
280 =item [MACRO] B<SSL_SHA>(SSL_SHA1);
282 =item [MACRO] B<SSL_ST_INIT>(SSL_ST_CONNECT|SSL_ST_ACCEPT);
284 =item [MACRO] B<SSL_ST_RENEGOTIATE>(0x04|SSL_ST_INIT);
286 =item int B<SSL_accept>(SSL *s);
288 =item int B<SSL_add_client_CA>(SSL *ssl, X509 *x);
290 =item [MACRO] B<SSL_add_session>(a,b);
292 =item char *B<SSL_alert_desc_string>(int value);
294 =item char *B<SSL_alert_desc_string_long>(int value);
296 =item char *B<SSL_alert_type_string>(int value);
298 =item char *B<SSL_alert_type_string_long>(int value);
300 =item int B<SSL_check_private_key>(SSL *ssl);
302 =item void B<SSL_clear>(SSL *s);
304 =item [MACRO] B<SSL_clear_num_renegotiations>(ssl);
306 =item int B<SSL_connect>(SSL *s);
308 =item void B<SSL_copy_session_id>(SSL *t, SSL *f);
310 =item long B<SSL_ctrl>(SSL *s, int cmd, long larg, char *parg);
312 =item int B<SSL_do_handshake>(SSL *s);
314 =item SSL *B<SSL_dup>(SSL *s);
316 =item STACK *B<SSL_dup_CA_list>(STACK *sk);
318 =item [MACRO] B<SSL_flush_sessions>(a,b);
320 =item void B<SSL_free>(SSL *s);
322 =item SSL_CTX *B<SSL_get_SSL_CTX>(SSL *ssl);
324 =item [MACRO] B<SSL_get_app_data>(s);
326 =item X509 *B<SSL_get_certificate>(SSL *s);
328 =item [MACRO] B<SSL_get_cipher>(s);
330 =item [MACRO] B<SSL_get_cipher_bits>(s,np);
332 =item char *B<SSL_get_cipher_list>(SSL *s, int n);
334 =item [MACRO] B<SSL_get_cipher_name>(s);
336 =item [MACRO] B<SSL_get_cipher_version>(s);
338 =item STACK *B<SSL_get_ciphers>(SSL *s);
340 =item STACK *B<SSL_get_client_CA_list>(SSL *s);
342 =item SSL_CIPHER *B<SSL_get_current_cipher>(SSL *s);
344 =item long B<SSL_get_default_timeout>(SSL *s);
346 =item int B<SSL_get_error>(SSL *s, int i);
348 =item char *B<SSL_get_ex_data>(SSL *s, int idx);
350 =item int B<SSL_get_ex_data_X509_STORE_CTX_idx>(void);
352 =item int B<SSL_get_ex_new_index>(long argl, char *argp, int (*new_func);(void), int (*dup_func)(void), void (*free_func)(void))
354 =item int B<SSL_get_fd>(SSL *s);
356 =item void (*B<SSL_get_info_callback>(SSL *ssl);)(void)
358 =item STACK *B<SSL_get_peer_cert_chain>(SSL *s);
360 =item X509 *B<SSL_get_peer_certificate>(SSL *s);
362 =item EVP_PKEY *B<SSL_get_privatekey>(SSL *s);
364 =item int B<SSL_get_quiet_shutdown>(SSL *s);
366 =item BIO *B<SSL_get_rbio>(SSL *s);
368 =item int B<SSL_get_read_ahead>(SSL *s);
370 =item SSL_SESSION *B<SSL_get_session>(SSL *ssl);
372 =item char *B<SSL_get_shared_ciphers>(SSL *s, char *buf, int len);
374 =item int B<SSL_get_shutdown>(SSL *s);
376 =item SSL_METHOD *B<SSL_get_ssl_method>(SSL *s);
378 =item [MACRO] B<SSL_get_state>(a);
380 =item [MACRO] B<SSL_get_time>(a);
382 =item [MACRO] B<SSL_get_timeout>(a);
384 =item int (*B<SSL_get_verify_callback>(SSL *s);)(void)
386 =item int B<SSL_get_verify_mode>(SSL *s);
388 =item long B<SSL_get_verify_result>(SSL *ssl);
390 =item char *B<SSL_get_version>(SSL *s);
392 =item BIO *B<SSL_get_wbio>(SSL *s);
394 =item [MACRO] B<SSL_in_accept_init>(a);
396 =item [MACRO] B<SSL_in_before>(a);
398 =item [MACRO] B<SSL_in_connect_init>(a);
400 =item [MACRO] B<SSL_in_init>(a);
402 =item [MACRO] B<SSL_is_init_finished>(a);
404 =item STACK *B<SSL_load_client_CA_file>(char *file);
406 =item void B<SSL_load_error_strings>(void);
408 =item SSL *B<SSL_new>(SSL_CTX *ctx);
410 =item [MACRO] B<SSL_num_renegotiations>(ssl);
412 =item int B<SSL_peek>(SSL *s, char *buf, int num);
414 =item int B<SSL_pending>(SSL *s);
416 =item int B<SSL_read>(SSL *s, char *buf, int num);
418 =item [MACRO] B<SSL_remove_session>(a,b);
420 =item int B<SSL_renegotiate>(SSL *s);
422 =item char *B<SSL_rstate_string>(SSL *s);
424 =item char *B<SSL_rstate_string_long>(SSL *s);
426 =item [MACRO] B<SSL_session_reused>(ssl);
428 =item void B<SSL_set_accept_state>(SSL *s);
430 =item [MACRO] B<SSL_set_app_data>(s,arg);
432 =item void B<SSL_set_bio>(SSL *s, BIO *rbio, BIO *wbio);
434 =item int B<SSL_set_cipher_list>(SSL *s, char *str);
436 =item void B<SSL_set_client_CA_list>(SSL *s, STACK *list);
438 =item void B<SSL_set_connect_state>(SSL *s);
440 =item int B<SSL_set_ex_data>(SSL *s, int idx, char *arg);
442 =item int B<SSL_set_fd>(SSL *s, int fd);
444 =item void B<SSL_set_info_callback>(SSL *ssl, void (*cb);(void))
446 =item [MACRO] B<SSL_set_options>(ssl,op);
448 =item [MACRO] B<SSL_set_pref_cipher>(c,n);
450 =item void B<SSL_set_quiet_shutdown>(SSL *s, int mode);
452 =item void B<SSL_set_read_ahead>(SSL *s, int yes);
454 =item int B<SSL_set_rfd>(SSL *s, int fd);
456 =item int B<SSL_set_session>(SSL *s, SSL_SESSION *session);
458 =item void B<SSL_set_shutdown>(SSL *s, int mode);
460 =item int B<SSL_set_ssl_method>(SSL *s, SSL_METHOD *meth);
462 =item [MACRO] B<SSL_set_time>(a,b);
464 =item [MACRO] B<SSL_set_timeout>(a,b);
466 =item void B<SSL_set_verify>(SSL *s, int mode, int (*callback);(void))
468 =item void B<SSL_set_verify_result>(SSL *ssl, long arg);
470 =item int B<SSL_set_wfd>(SSL *s, int fd);
472 =item int B<SSL_shutdown>(SSL *s);
474 =item int B<SSL_state>(SSL *ssl);
476 =item char *B<SSL_state_string>(SSL *s);
478 =item char *B<SSL_state_string_long>(SSL *s);
480 =item [MACRO] B<SSL_total_renegotiations>(ssl);
482 =item int B<SSL_use_PrivateKey>(SSL *ssl, EVP_PKEY *pkey);
484 =item int B<SSL_use_PrivateKey_ASN1>(int type, SSL *ssl, unsigned char *d, long len);
486 =item int B<SSL_use_PrivateKey_file>(SSL *ssl, char *file, int type);
488 =item int B<SSL_use_RSAPrivateKey>(SSL *ssl, RSA *rsa);
490 =item int B<SSL_use_RSAPrivateKey_ASN1>(SSL *ssl, unsigned char *d, long len);
492 =item int B<SSL_use_RSAPrivateKey_file>(SSL *ssl, char *file, int type);
494 =item int B<SSL_use_certificate>(SSL *ssl, X509 *x);
496 =item int B<SSL_use_certificate_ASN1>(SSL *ssl, int len, unsigned char *d);
498 =item int B<SSL_use_certificate_file>(SSL *ssl, char *file, int type);
500 =item int B<SSL_version>(SSL *s);
502 =item [MACRO] B<SSL_want>(s);
504 =item [MACRO] B<SSL_want_nothing>(s);
506 =item [MACRO] B<SSL_want_read>(s);
508 =item [MACRO] B<SSL_want_write>(s);
510 =item [MACRO] B<SSL_want_x509_lookup>(s);
512 =item int B<SSL_write>(SSL *s, char *buf, int num);
514 =item SSL_METHOD *B<SSLv2_client_method>(void);
516 =item SSL_METHOD *B<SSLv2_method>(void);
518 =item SSL_METHOD *B<SSLv2_server_method>(void);
520 =item SSL_METHOD *B<SSLv3_client_method>(void);
522 =item SSL_METHOD *B<SSLv3_method>(void);
524 =item SSL_METHOD *B<SSLv3_server_method>(void);
526 =item SSL_METHOD *B<TLSv1_client_method>(void);
528 =item SSL_METHOD *B<TLSv1_method>(void);
530 =item SSL_METHOD *B<TLSv1_server_method>(void);
536 openssl(1), crypto(3)