6 SSL - OpenSSL SSL/TLS library
12 The OpenSSL B<ssl> library implements the Secure Sockets Layer (SSL v2/v3) and
13 Transport Layer Security (TLS v1) protocols. It provides a rich API which is
18 Currently the OpenSSL B<ssl> library provides the following C header files
19 containing the prototypes for the data structures and and functions:
25 That's the common header file for the SSL/TLS API. Include it into your
26 program to make the API of the B<ssl> library available. It internally
27 includes both more private SSL headers and headers from the B<crypto> library.
33 Currently the OpenSSL B<ssl> library functions deal with the following data
38 =item B<SSL_CTX> (SSL Context)
40 =item B<SSL> (SSL Connection)
42 That's the SSL/TLS structure which is created by
43 a server or client per established connection.
45 =item B<SSL_METHOD> (SSL Method)
47 =item B<SSL_CIPHER> (SSL Cipher)
49 =item B<SSL_SESSION> (SSL Session)
55 Currently the OpenSSL B<ssl> library exports 214 API functions.
56 They are documented in the following:
60 =item char *B<SSL_CIPHER_description>(SSL_CIPHER *cipher, char *buf, int len);
62 =item int B<SSL_CIPHER_get_bits>(SSL_CIPHER *c, int *alg_bits);
64 =item char *B<SSL_CIPHER_get_name>(SSL_CIPHER *c);
66 =item char *B<SSL_CIPHER_get_version>(SSL_CIPHER *c);
68 =item int B<SSL_CTX_add_client_CA>(SSL_CTX *ctx, X509 *x);
70 =item long B<SSL_CTX_add_extra_chain_cert>(SSL_CTX *ctx, X509 *x509);
72 =item int B<SSL_CTX_add_session>(SSL_CTX *ctx, SSL_SESSION *c);
74 =item int B<SSL_CTX_check_private_key>(SSL_CTX *ctx);
76 =item long B<SSL_CTX_ctrl>(SSL_CTX *ctx, int cmd, long larg, char *parg);
78 =item void B<SSL_CTX_flush_sessions>(SSL_CTX *s, long t);
80 =item void B<SSL_CTX_free>(SSL_CTX *a);
82 =item char *B<SSL_CTX_get_app_data>(SSL_CTX *ctx);
84 =item X509_STORE *B<SSL_CTX_get_cert_store>(SSL_CTX *ctx);
86 =item STACK *B<SSL_CTX_get_client_CA_list>(SSL_CTX *ctx);
88 =item int (*B<SSL_CTX_get_client_cert_cb>(SSL_CTX *ctx))(SSL *ssl, X509 **x509, EVP_PKEY **pkey);
90 =item char *B<SSL_CTX_get_ex_data>(SSL_CTX *s, int idx);
92 =item int B<SSL_CTX_get_ex_new_index>(long argl, char *argp, int (*new_func);(void), int (*dup_func)(void), void (*free_func)(void))
94 =item void (*B<SSL_CTX_get_info_callback>(SSL_CTX *ctx))(SSL *ssl, int cb, int ret);
96 =item int B<SSL_CTX_get_quiet_shutdown>(SSL_CTX *ctx);
98 =item int B<SSL_CTX_get_session_cache_mode>(SSL_CTX *ctx);
100 =item long B<SSL_CTX_get_timeout>(SSL_CTX *ctx);
102 =item int (*B<SSL_CTX_get_verify_callback>(SSL_CTX *ctx))(int ok, X509_STORE_CTX *ctx);
104 =item int B<SSL_CTX_get_verify_mode>(SSL_CTX *ctx);
106 =item int B<SSL_CTX_load_verify_locations>(SSL_CTX *ctx, char *CAfile, char *CApath);
108 =item long B<SSL_CTX_need_tmp_RSA>(SSL_CTX *ctx);
110 =item SSL_CTX *B<SSL_CTX_new>(SSL_METHOD *meth);
112 =item int B<SSL_CTX_remove_session>(SSL_CTX *ctx, SSL_SESSION *c);
114 =item int B<SSL_CTX_sess_accept>(SSL_CTX *ctx);
116 =item int B<SSL_CTX_sess_accept_good>(SSL_CTX *ctx);
118 =item int B<SSL_CTX_sess_accept_renegotiate>(SSL_CTX *ctx);
120 =item int B<SSL_CTX_sess_cache_full>(SSL_CTX *ctx);
122 =item int B<SSL_CTX_sess_cb_hits>(SSL_CTX *ctx);
124 =item int B<SSL_CTX_sess_connect>(SSL_CTX *ctx);
126 =item int B<SSL_CTX_sess_connect_good>(SSL_CTX *ctx);
128 =item int B<SSL_CTX_sess_connect_renegotiate>(SSL_CTX *ctx);
130 =item int B<SSL_CTX_sess_get_cache_size>(SSL_CTX *ctx);
132 =item SSL_SESSION *(*B<SSL_CTX_sess_get_get_cb>(SSL_CTX *ctx))(SSL *ssl, unsigned char *data, int len, int *copy);
134 =item int (*B<SSL_CTX_sess_get_new_cb>(SSL_CTX *ctx)(SSL *ssl, SSL_SESSION *sess);
136 =item void (*B<SSL_CTX_sess_get_remove_cb>(SSL_CTX *ctx)(SSL_CTX *ctx, SSL_SESSION *sess);
138 =item int B<SSL_CTX_sess_hits>(SSL_CTX *ctx);
140 =item int B<SSL_CTX_sess_misses>(SSL_CTX *ctx);
142 =item int B<SSL_CTX_sess_number>(SSL_CTX *ctx);
144 =item void B<SSL_CTX_sess_set_cache_size>(SSL_CTX *ctx,t);
146 =item void B<SSL_CTX_sess_set_get_cb>(SSL_CTX *ctx, SSL_SESSION *(*cb)(SSL *ssl, unsigned char *data, int len, int *copy));
148 =item void B<SSL_CTX_sess_set_new_cb>(SSL_CTX *ctx, int (*cb)(SSL *ssl, SSL_SESSION *sess));
150 =item void B<SSL_CTX_sess_set_remove_cb>(SSL_CTX *ctx, void (*cb)(SSL_CTX *ctx, SSL_SESSION *sess));
152 =item int B<SSL_CTX_sess_timeouts>(SSL_CTX *ctx);
154 =item LHASH *B<SSL_CTX_sessions>(SSL_CTX *ctx);
156 =item void B<SSL_CTX_set_app_data>(SSL_CTX *ctx, void *arg);
158 =item void B<SSL_CTX_set_cert_store>(SSL_CTX *ctx, X509_STORE *cs);
160 =item void B<SSL_CTX_set_cert_verify_cb>(SSL_CTX *ctx, int (*cb)(SSL_CTX *), char *arg)
162 =item int B<SSL_CTX_set_cipher_list>(SSL_CTX *ctx, char *str);
164 =item void B<SSL_CTX_set_client_CA_list>(SSL_CTX *ctx, STACK *list);
166 =item void B<SSL_CTX_set_client_cert_cb>(SSL_CTX *ctx, int (*cb)(SSL *ssl, X509 **x509, EVP_PKEY **pkey));
168 =item void B<SSL_CTX_set_default_passwd_cb>(SSL_CTX *ctx, int (*cb);(void))
170 =item void B<SSL_CTX_set_default_read_ahead>(SSL_CTX *ctx, int m);
172 =item int B<SSL_CTX_set_default_verify_paths>(SSL_CTX *ctx);
174 =item int B<SSL_CTX_set_ex_data>(SSL_CTX *s, int idx, char *arg);
176 =item void B<SSL_CTX_set_info_callback>(SSL_CTX *ctx, void (*cb)(SSL *ssl, int cb, int ret));
178 =item void B<SSL_CTX_set_options>(SSL_CTX *ctx, unsigned long op);
180 =item void B<SSL_CTX_set_quiet_shutdown>(SSL_CTX *ctx, int mode);
182 =item void B<SSL_CTX_set_session_cache_mode>(SSL_CTX *ctx, int mode);
184 =item int B<SSL_CTX_set_ssl_version>(SSL_CTX *ctx, SSL_METHOD *meth);
186 =item void B<SSL_CTX_set_timeout>(SSL_CTX *ctx, long t);
188 =item long B<SSL_CTX_set_tmp_dh>(SSL_CTX* ctx, DH *dh);
190 =item long B<SSL_CTX_set_tmp_dh_callback>(SSL_CTX *ctx, DH *(*cb)(void));
192 =item long B<SSL_CTX_set_tmp_rsa>(SSL_CTX *ctx, RSA *rsa);
194 =item long B<SSL_CTX_set_tmp_rsa_callback>(SSL_CTX *ctx, RSA *(*cb)(void));
196 =item void B<SSL_CTX_set_verify>(SSL_CTX *ctx, int mode, int (*cb);(void))
198 =item int B<SSL_CTX_use_PrivateKey>(SSL_CTX *ctx, EVP_PKEY *pkey);
200 =item int B<SSL_CTX_use_PrivateKey_ASN1>(int type, SSL_CTX *ctx, unsigned char *d, long len);
202 =item int B<SSL_CTX_use_PrivateKey_file>(SSL_CTX *ctx, char *file, int type);
204 =item int B<SSL_CTX_use_RSAPrivateKey>(SSL_CTX *ctx, RSA *rsa);
206 =item int B<SSL_CTX_use_RSAPrivateKey_ASN1>(SSL_CTX *ctx, unsigned char *d, long len);
208 =item int B<SSL_CTX_use_RSAPrivateKey_file>(SSL_CTX *ctx, char *file, int type);
210 =item int B<SSL_CTX_use_certificate>(SSL_CTX *ctx, X509 *x);
212 =item int B<SSL_CTX_use_certificate_ASN1>(SSL_CTX *ctx, int len, unsigned char *d);
214 =item int B<SSL_CTX_use_certificate_file>(SSL_CTX *ctx, char *file, int type);
216 =item int B<SSL_SESSION_cmp>(SSL_SESSION *a, SSL_SESSION *b);
218 =item void B<SSL_SESSION_free>(SSL_SESSION *ss);
220 =item char *B<SSL_SESSION_get_app_data>(SSL_SESSION *s);
222 =item char *B<SSL_SESSION_get_ex_data>(SSL_SESSION *s, int idx);
224 =item int B<SSL_SESSION_get_ex_new_index>(long argl, char *argp, int (*new_func);(void), int (*dup_func)(void), void (*free_func)(void))
226 =item long B<SSL_SESSION_get_time>(SSL_SESSION *s);
228 =item long B<SSL_SESSION_get_timeout>(SSL_SESSION *s);
230 =item unsigned long B<SSL_SESSION_hash>(SSL_SESSION *a);
232 =item SSL_SESSION *B<SSL_SESSION_new>(void);
234 =item int B<SSL_SESSION_print>(BIO *bp, SSL_SESSION *x);
236 =item int B<SSL_SESSION_print_fp>(FILE *fp, SSL_SESSION *x);
238 =item void B<SSL_SESSION_set_app_data>(SSL_SESSION *s, char *a);
240 =item int B<SSL_SESSION_set_ex_data>(SSL_SESSION *s, int idx, char *arg);
242 =item long B<SSL_SESSION_set_time>(SSL_SESSION *s, long t);
244 =item long B<SSL_SESSION_set_timeout>(SSL_SESSION *s, long t);
246 =item int B<SSL_accept>(SSL *ssl);
248 =item int B<SSL_add_client_CA>(SSL *ssl, X509 *x);
250 =item char *B<SSL_alert_desc_string>(int value);
252 =item char *B<SSL_alert_desc_string_long>(int value);
254 =item char *B<SSL_alert_type_string>(int value);
256 =item char *B<SSL_alert_type_string_long>(int value);
258 =item int B<SSL_check_private_key>(SSL *ssl);
260 =item void B<SSL_clear>(SSL *ssl);
262 =item long B<SSL_clear_num_renegotiations>(SSL *ssl);
264 =item int B<SSL_connect>(SSL *ssl);
266 =item void B<SSL_copy_session_id>(SSL *t, SSL *f);
268 =item long B<SSL_ctrl>(SSL *ssl, int cmd, long larg, char *parg);
270 =item int B<SSL_do_handshake>(SSL *ssl);
272 =item SSL *B<SSL_dup>(SSL *ssl);
274 =item STACK *B<SSL_dup_CA_list>(STACK *sk);
276 =item void B<SSL_free>(SSL *ssl);
278 =item SSL_CTX *B<SSL_get_SSL_CTX>(SSL *ssl);
280 =item char *B<SSL_get_app_data>(SSL *ssl);
282 =item X509 *B<SSL_get_certificate>(SSL *ssl);
284 =item SSL_CIPHER *B<SSL_get_cipher>(SSL *ssl);
286 =item int B<SSL_get_cipher_bits>(SSL *ssl, int *alg_bits);
288 =item char *B<SSL_get_cipher_list>(SSL *ssl, int n);
290 =item char *B<SSL_get_cipher_name>(SSL *ssl);
292 =item char *B<SSL_get_cipher_version>(SSL *ssl);
294 =item STACK *B<SSL_get_ciphers>(SSL *ssl);
296 =item STACK *B<SSL_get_client_CA_list>(SSL *ssl);
298 =item SSL_CIPHER *B<SSL_get_current_cipher>(SSL *ssl);
300 =item long B<SSL_get_default_timeout>(SSL *ssl);
302 =item int B<SSL_get_error>(SSL *ssl, int i);
304 =item char *B<SSL_get_ex_data>(SSL *ssl, int idx);
306 =item int B<SSL_get_ex_data_X509_STORE_CTX_idx>(void);
308 =item int B<SSL_get_ex_new_index>(long argl, char *argp, int (*new_func);(void), int (*dup_func)(void), void (*free_func)(void))
310 =item int B<SSL_get_fd>(SSL *ssl);
312 =item void (*B<SSL_get_info_callback>(SSL *ssl);)(void)
314 =item STACK *B<SSL_get_peer_cert_chain>(SSL *ssl);
316 =item X509 *B<SSL_get_peer_certificate>(SSL *ssl);
318 =item EVP_PKEY *B<SSL_get_privatekey>(SSL *ssl);
320 =item int B<SSL_get_quiet_shutdown>(SSL *ssl);
322 =item BIO *B<SSL_get_rbio>(SSL *ssl);
324 =item int B<SSL_get_read_ahead>(SSL *ssl);
326 =item SSL_SESSION *B<SSL_get_session>(SSL *ssl);
328 =item char *B<SSL_get_shared_ciphers>(SSL *ssl, char *buf, int len);
330 =item int B<SSL_get_shutdown>(SSL *ssl);
332 =item SSL_METHOD *B<SSL_get_ssl_method>(SSL *ssl);
334 =item int B<SSL_get_state>(SSL *ssl);
336 =item long B<SSL_get_time>(SSL *ssl);
338 =item long B<SSL_get_timeout>(SSL *ssl);
340 =item int (*B<SSL_get_verify_callback>(SSL *ssl);)(void)
342 =item int B<SSL_get_verify_mode>(SSL *ssl);
344 =item long B<SSL_get_verify_result>(SSL *ssl);
346 =item char *B<SSL_get_version>(SSL *ssl);
348 =item BIO *B<SSL_get_wbio>(SSL *ssl);
350 =item int B<SSL_in_accept_init>(SSL *ssl);
352 =item int B<SSL_in_before>(SSL *ssl);
354 =item int B<SSL_in_connect_init>(SSL *ssl);
356 =item int B<SSL_in_init>(SSL *ssl);
358 =item int B<SSL_is_init_finished>(SSL *ssl);
360 =item STACK *B<SSL_load_client_CA_file>(char *file);
362 =item void B<SSL_load_error_strings>(void);
364 =item SSL *B<SSL_new>(SSL_CTX *ctx);
366 =item long B<SSL_num_renegotiations>(SSL *ssl);
368 =item int B<SSL_peek>(SSL *ssl, char *buf, int num);
370 =item int B<SSL_pending>(SSL *ssl);
372 =item int B<SSL_read>(SSL *ssl, char *buf, int num);
374 =item int B<SSL_renegotiate>(SSL *ssl);
376 =item char *B<SSL_rstate_string>(SSL *ssl);
378 =item char *B<SSL_rstate_string_long>(SSL *ssl);
380 =item long B<SSL_session_reused>(SSL *ssl);
382 =item void B<SSL_set_accept_state>(SSL *ssl);
384 =item void B<SSL_set_app_data>(SSL *ssl, char *arg);
386 =item void B<SSL_set_bio>(SSL *ssl, BIO *rbio, BIO *wbio);
388 =item int B<SSL_set_cipher_list>(SSL *ssl, char *str);
390 =item void B<SSL_set_client_CA_list>(SSL *ssl, STACK *list);
392 =item void B<SSL_set_connect_state>(SSL *ssl);
394 =item int B<SSL_set_ex_data>(SSL *ssl, int idx, char *arg);
396 =item int B<SSL_set_fd>(SSL *ssl, int fd);
398 =item void B<SSL_set_info_callback>(SSL *ssl, void (*cb);(void))
400 =item void B<SSL_set_options>(SSL *ssl, unsigned long op);
402 =item void B<SSL_set_quiet_shutdown>(SSL *ssl, int mode);
404 =item void B<SSL_set_read_ahead>(SSL *ssl, int yes);
406 =item int B<SSL_set_rfd>(SSL *ssl, int fd);
408 =item int B<SSL_set_session>(SSL *ssl, SSL_SESSION *session);
410 =item void B<SSL_set_shutdown>(SSL *ssl, int mode);
412 =item int B<SSL_set_ssl_method>(SSL *ssl, SSL_METHOD *meth);
414 =item void B<SSL_set_time>(SSL *ssl, long t);
416 =item void B<SSL_set_timeout>(SSL *ssl, long t);
418 =item void B<SSL_set_verify>(SSL *ssl, int mode, int (*callback);(void))
420 =item void B<SSL_set_verify_result>(SSL *ssl, long arg);
422 =item int B<SSL_set_wfd>(SSL *ssl, int fd);
424 =item int B<SSL_shutdown>(SSL *ssl);
426 =item int B<SSL_state>(SSL *ssl);
428 =item char *B<SSL_state_string>(SSL *ssl);
430 =item char *B<SSL_state_string_long>(SSL *ssl);
432 =item long B<SSL_total_renegotiations>(SSL *ssl);
434 =item int B<SSL_use_PrivateKey>(SSL *ssl, EVP_PKEY *pkey);
436 =item int B<SSL_use_PrivateKey_ASN1>(int type, SSL *ssl, unsigned char *d, long len);
438 =item int B<SSL_use_PrivateKey_file>(SSL *ssl, char *file, int type);
440 =item int B<SSL_use_RSAPrivateKey>(SSL *ssl, RSA *rsa);
442 =item int B<SSL_use_RSAPrivateKey_ASN1>(SSL *ssl, unsigned char *d, long len);
444 =item int B<SSL_use_RSAPrivateKey_file>(SSL *ssl, char *file, int type);
446 =item int B<SSL_use_certificate>(SSL *ssl, X509 *x);
448 =item int B<SSL_use_certificate_ASN1>(SSL *ssl, int len, unsigned char *d);
450 =item int B<SSL_use_certificate_file>(SSL *ssl, char *file, int type);
452 =item int B<SSL_version>(SSL *ssl);
454 =item int B<SSL_want>(SSL *ssl);
456 =item int B<SSL_want_nothing>(SSL *ssl);
458 =item int B<SSL_want_read>(SSL *ssl);
460 =item int B<SSL_want_write>(SSL *ssl);
462 =item int B<SSL_want_x509_lookup>(s);
464 =item int B<SSL_write>(SSL *ssl, char *buf, int num);
466 =item SSL_METHOD *B<SSLv2_client_method>(void);
468 =item SSL_METHOD *B<SSLv2_method>(void);
470 =item SSL_METHOD *B<SSLv2_server_method>(void);
472 =item SSL_METHOD *B<SSLv3_client_method>(void);
474 =item SSL_METHOD *B<SSLv3_method>(void);
476 =item SSL_METHOD *B<SSLv3_server_method>(void);
478 =item SSL_METHOD *B<TLSv1_client_method>(void);
480 =item SSL_METHOD *B<TLSv1_method>(void);
482 =item SSL_METHOD *B<TLSv1_server_method>(void);
488 openssl(1), crypto(3)
492 The ssl(3) document appeared in OpenSSL 0.9.2