Skip to content

File syn_x509.h

FileList > crypto > syn_x509.h

Go to the source code of this file

Zero-Heap X.509 v3 Certificate & Chain Parser and Validator.

  • #include "syntropic/crypto/syn_asn1.h"
  • #include <stdbool.h>
  • #include <stddef.h>
  • #include <stdint.h>

Classes

Type Name
struct SYN_X509_Cert

Public Types

Type Name
enum SYN_X509_Algo

Public Functions

Type Name
bool syn_x509_parse (const uint8_t * der, size_t der_len, SYN_X509_Cert * cert_out)
Parse a raw DER-encoded X.509 certificate.
bool syn_x509_validate_chain (const SYN_X509_Cert * cert, const SYN_X509_Cert * root_ca, const char * expected_cn)
Validate a certificate chain back to a trusted Root CA certificate.
bool syn_x509_verify_signature (const SYN_X509_Cert * cert, const uint8_t * issuer_pubkey, size_t issuer_pubkey_len, SYN_X509_Algo algo)
Verify certificate signature against an issuer's public key.

Macros

Type Name
define SYN_X509_MAX_NAME_LEN 128U
Maximum CommonName string length (128).
define SYN_X509_PUBKEY_MAX_LEN 128U
Maximum public key buffer length (128).
define SYN_X509_SIG_MAX_LEN 256U
Maximum signature buffer length (256).

Public Types Documentation

enum SYN_X509_Algo

enum SYN_X509_Algo {
    SYN_X509_ALGO_UNKNOWN = 0,
    SYN_X509_ALGO_ED25519,
    SYN_X509_ALGO_ECDSA_P256,
    SYN_X509_ALGO_RSA_PSS
};

Public Key Algorithm Types in X.509 SubjectPublicKeyInfo


Public Functions Documentation

function syn_x509_parse

Parse a raw DER-encoded X.509 certificate.

bool syn_x509_parse (
    const uint8_t * der,
    size_t der_len,
    SYN_X509_Cert * cert_out
) 

Parameters:

  • der Raw DER bytes of certificate.
  • der_len Length of DER bytes.
  • cert_out [out] Output parsed certificate struct.

Returns:

true if valid X.509 certificate parsed successfully.


function syn_x509_validate_chain

Validate a certificate chain back to a trusted Root CA certificate.

bool syn_x509_validate_chain (
    const SYN_X509_Cert * cert,
    const SYN_X509_Cert * root_ca,
    const char * expected_cn
) 

Parameters:

  • cert Leaf certificate.
  • root_ca Trusted Root CA certificate.
  • expected_cn Expected Server Name (SNI) to match against leaf CN/SAN.

Returns:

true if chain is valid and trusted.


function syn_x509_verify_signature

Verify certificate signature against an issuer's public key.

bool syn_x509_verify_signature (
    const SYN_X509_Cert * cert,
    const uint8_t * issuer_pubkey,
    size_t issuer_pubkey_len,
    SYN_X509_Algo algo
) 

Parameters:

  • cert Parsed child certificate to verify.
  • issuer_pubkey Issuer's public key.
  • issuer_pubkey_len Issuer's public key length.
  • algo Algorithm of issuer's public key.

Returns:

true if signature is valid.


Macro Definition Documentation

define SYN_X509_MAX_NAME_LEN

Maximum CommonName string length (128).

#define SYN_X509_MAX_NAME_LEN `128U`


define SYN_X509_PUBKEY_MAX_LEN

Maximum public key buffer length (128).

#define SYN_X509_PUBKEY_MAX_LEN `128U`


define SYN_X509_SIG_MAX_LEN

Maximum signature buffer length (256).

#define SYN_X509_SIG_MAX_LEN `256U`



The documentation for this class was generated from the following file src/syntropic/crypto/syn_x509.h