Skip to content

File syn_x509.c

FileList > crypto > syn_x509.c

Go to the source code of this file

Zero-Heap X.509 v3 Certificate & Chain Parser and Validator implementation.

  • #include "syntropic/crypto/syn_x509.h"
  • #include "syntropic/crypto/syn_ed25519.h"
  • #include "syntropic/crypto/syn_p256.h"
  • #include "syntropic/crypto/syn_sha256.h"
  • #include <string.h>

Public Functions

Type Name
bool syn_x509_parse (const uint8_t * der, size_t der_len, SYN_X509_Cert * cert_out)
Parse a raw DER-encoded X.509 certificate.
bool syn_x509_validate_chain (const SYN_X509_Cert * cert, const SYN_X509_Cert * root_ca, const char * expected_cn)
Validate a certificate chain back to a trusted Root CA certificate.
bool syn_x509_verify_signature (const SYN_X509_Cert * cert, const uint8_t * issuer_pubkey, size_t issuer_pubkey_len, SYN_X509_Algo algo)
Verify certificate signature against an issuer's public key.

Public Functions Documentation

function syn_x509_parse

Parse a raw DER-encoded X.509 certificate.

bool syn_x509_parse (
    const uint8_t * der,
    size_t der_len,
    SYN_X509_Cert * cert_out
) 

Parameters:

  • der Raw DER bytes of certificate.
  • der_len Length of DER bytes.
  • cert_out [out] Output parsed certificate struct.

Returns:

true if valid X.509 certificate parsed successfully.


function syn_x509_validate_chain

Validate a certificate chain back to a trusted Root CA certificate.

bool syn_x509_validate_chain (
    const SYN_X509_Cert * cert,
    const SYN_X509_Cert * root_ca,
    const char * expected_cn
) 

Parameters:

  • cert Leaf certificate.
  • root_ca Trusted Root CA certificate.
  • expected_cn Expected Server Name (SNI) to match against leaf CN/SAN.

Returns:

true if chain is valid and trusted.


function syn_x509_verify_signature

Verify certificate signature against an issuer's public key.

bool syn_x509_verify_signature (
    const SYN_X509_Cert * cert,
    const uint8_t * issuer_pubkey,
    size_t issuer_pubkey_len,
    SYN_X509_Algo algo
) 

Parameters:

  • cert Parsed child certificate to verify.
  • issuer_pubkey Issuer's public key.
  • issuer_pubkey_len Issuer's public key length.
  • algo Algorithm of issuer's public key.

Returns:

true if signature is valid.



The documentation for this class was generated from the following file src/syntropic/crypto/syn_x509.c