1*0a302681Sschwarze.\" $OpenBSD: d2i_PKCS8PrivateKey_bio.3,v 1.11 2019/06/07 19:28:52 schwarze Exp $ 20c3e06d9Sschwarze.\" full merge up to: OpenSSL 61f805c1 Jan 16 01:01:46 2018 +0800 38974101aSjmc.\" 4a4110d59Sschwarze.\" This file was written by Dr. Stephen Henson <steve@openssl.org>. 50c3e06d9Sschwarze.\" Copyright (c) 2002, 2016, 2017 The OpenSSL Project. All rights reserved. 6a4110d59Sschwarze.\" 7a4110d59Sschwarze.\" Redistribution and use in source and binary forms, with or without 8a4110d59Sschwarze.\" modification, are permitted provided that the following conditions 9a4110d59Sschwarze.\" are met: 10a4110d59Sschwarze.\" 11a4110d59Sschwarze.\" 1. Redistributions of source code must retain the above copyright 12a4110d59Sschwarze.\" notice, this list of conditions and the following disclaimer. 13a4110d59Sschwarze.\" 14a4110d59Sschwarze.\" 2. Redistributions in binary form must reproduce the above copyright 15a4110d59Sschwarze.\" notice, this list of conditions and the following disclaimer in 16a4110d59Sschwarze.\" the documentation and/or other materials provided with the 17a4110d59Sschwarze.\" distribution. 18a4110d59Sschwarze.\" 19a4110d59Sschwarze.\" 3. All advertising materials mentioning features or use of this 20a4110d59Sschwarze.\" software must display the following acknowledgment: 21a4110d59Sschwarze.\" "This product includes software developed by the OpenSSL Project 22a4110d59Sschwarze.\" for use in the OpenSSL Toolkit. (http://www.openssl.org/)" 23a4110d59Sschwarze.\" 24a4110d59Sschwarze.\" 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to 25a4110d59Sschwarze.\" endorse or promote products derived from this software without 26a4110d59Sschwarze.\" prior written permission. For written permission, please contact 27a4110d59Sschwarze.\" openssl-core@openssl.org. 28a4110d59Sschwarze.\" 29a4110d59Sschwarze.\" 5. Products derived from this software may not be called "OpenSSL" 30a4110d59Sschwarze.\" nor may "OpenSSL" appear in their names without prior written 31a4110d59Sschwarze.\" permission of the OpenSSL Project. 32a4110d59Sschwarze.\" 33a4110d59Sschwarze.\" 6. Redistributions of any form whatsoever must retain the following 34a4110d59Sschwarze.\" acknowledgment: 35a4110d59Sschwarze.\" "This product includes software developed by the OpenSSL Project 36a4110d59Sschwarze.\" for use in the OpenSSL Toolkit (http://www.openssl.org/)" 37a4110d59Sschwarze.\" 38a4110d59Sschwarze.\" THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY 39a4110d59Sschwarze.\" EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 40a4110d59Sschwarze.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 41a4110d59Sschwarze.\" PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR 42a4110d59Sschwarze.\" ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, 43a4110d59Sschwarze.\" SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 44a4110d59Sschwarze.\" NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; 45a4110d59Sschwarze.\" LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 46a4110d59Sschwarze.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, 47a4110d59Sschwarze.\" STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 48a4110d59Sschwarze.\" ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED 49a4110d59Sschwarze.\" OF THE POSSIBILITY OF SUCH DAMAGE. 50a4110d59Sschwarze.\" 51*0a302681Sschwarze.Dd $Mdocdate: June 7 2019 $ 5226265810Sschwarze.Dt D2I_PKCS8PRIVATEKEY_BIO 3 5326265810Sschwarze.Os 5426265810Sschwarze.Sh NAME 5526265810Sschwarze.Nm d2i_PKCS8PrivateKey_bio , 5626265810Sschwarze.Nm d2i_PKCS8PrivateKey_fp , 5726265810Sschwarze.Nm i2d_PKCS8PrivateKey_bio , 5826265810Sschwarze.Nm i2d_PKCS8PrivateKey_fp , 5926265810Sschwarze.Nm i2d_PKCS8PrivateKey_nid_bio , 6026265810Sschwarze.Nm i2d_PKCS8PrivateKey_nid_fp 6126265810Sschwarze.Nd PKCS#8 format private key functions 6226265810Sschwarze.Sh SYNOPSIS 6326265810Sschwarze.In openssl/evp.h 6426265810Sschwarze.Ft EVP_PKEY * 6526265810Sschwarze.Fo d2i_PKCS8PrivateKey_bio 6626265810Sschwarze.Fa "BIO *bp" 6726265810Sschwarze.Fa "EVP_PKEY **x" 6826265810Sschwarze.Fa "pem_password_cb *cb" 6926265810Sschwarze.Fa "void *u" 7026265810Sschwarze.Fc 7126265810Sschwarze.Ft EVP_PKEY * 7226265810Sschwarze.Fo d2i_PKCS8PrivateKey_fp 7326265810Sschwarze.Fa "FILE *fp" 7426265810Sschwarze.Fa "EVP_PKEY **x" 7526265810Sschwarze.Fa "pem_password_cb *cb" 7626265810Sschwarze.Fa "void *u" 7726265810Sschwarze.Fc 7826265810Sschwarze.Ft int 7926265810Sschwarze.Fo i2d_PKCS8PrivateKey_bio 8026265810Sschwarze.Fa "BIO *bp" 8126265810Sschwarze.Fa "EVP_PKEY *x" 8226265810Sschwarze.Fa "const EVP_CIPHER *enc" 8326265810Sschwarze.Fa "char *kstr" 8426265810Sschwarze.Fa "int klen" 8526265810Sschwarze.Fa "pem_password_cb *cb" 8626265810Sschwarze.Fa "void *u" 8726265810Sschwarze.Fc 8826265810Sschwarze.Ft int 8926265810Sschwarze.Fo i2d_PKCS8PrivateKey_fp 9026265810Sschwarze.Fa "FILE *fp" 9126265810Sschwarze.Fa "EVP_PKEY *x" 9226265810Sschwarze.Fa "const EVP_CIPHER *enc" 9326265810Sschwarze.Fa "char *kstr" 9426265810Sschwarze.Fa "int klen" 9526265810Sschwarze.Fa "pem_password_cb *cb" 9626265810Sschwarze.Fa "void *u" 9726265810Sschwarze.Fc 9826265810Sschwarze.Ft int 9926265810Sschwarze.Fo i2d_PKCS8PrivateKey_nid_bio 10026265810Sschwarze.Fa "BIO *bp" 10126265810Sschwarze.Fa "EVP_PKEY *x" 10226265810Sschwarze.Fa "int nid" 10326265810Sschwarze.Fa "char *kstr" 10426265810Sschwarze.Fa "int klen" 10526265810Sschwarze.Fa "pem_password_cb *cb" 10626265810Sschwarze.Fa "void *u" 10726265810Sschwarze.Fc 10826265810Sschwarze.Ft int 10926265810Sschwarze.Fo i2d_PKCS8PrivateKey_nid_fp 11026265810Sschwarze.Fa "FILE *fp" 11126265810Sschwarze.Fa "EVP_PKEY *x" 11226265810Sschwarze.Fa "int nid" 11326265810Sschwarze.Fa "char *kstr" 11426265810Sschwarze.Fa "int klen" 11526265810Sschwarze.Fa "pem_password_cb *cb" 11626265810Sschwarze.Fa "void *u" 11726265810Sschwarze.Fc 11826265810Sschwarze.Sh DESCRIPTION 11926265810SschwarzeThe PKCS#8 functions encode and decode private keys in PKCS#8 format 12026265810Sschwarzeusing both PKCS#5 v1.5 and PKCS#5 v2.0 password based encryption 12126265810Sschwarzealgorithms. 12226265810Sschwarze.Pp 12326265810SschwarzeOther than the use of DER as opposed to PEM these functions are 124a4110d59Sschwarzeidentical to the corresponding functions described in 125a4110d59Sschwarze.Xr PEM_read_PrivateKey 3 . 126a4110d59Sschwarze.Pp 12726265810SschwarzeThese functions are currently the only way to store encrypted private 12826265810Sschwarzekeys using DER format. 12926265810Sschwarze.Pp 13026265810SschwarzeCurrently all the functions use 13126265810Sschwarze.Vt BIO 13226265810Sschwarzeor 13326265810Sschwarze.Vt FILE 134403e03d2Sjmcpointers. 135403e03d2SjmcThere are no functions which work directly on memory, 136403e03d2Sjmcthough this can be readily worked around 137403e03d2Sjmcby converting the buffers to memory BIOs; 138403e03d2Sjmcsee 13926265810Sschwarze.Xr BIO_s_mem 3 14026265810Sschwarzefor details. 1410c3e06d9Sschwarze.Sh RETURN VALUES 1420c3e06d9Sschwarze.Fn d2i_PKCS8PrivateKey_bio 1430c3e06d9Sschwarzeand 1440c3e06d9Sschwarze.Fn d2i_PKCS8PrivateKey_fp 1450c3e06d9Sschwarzereturn a 1460c3e06d9Sschwarze.Vt EVP_PKEY 1470c3e06d9Sschwarzeobject or 1480c3e06d9Sschwarze.Dv NULL 1490c3e06d9Sschwarzeif an error occurs. 1500c3e06d9Sschwarze.Pp 1510c3e06d9Sschwarze.Fn i2d_PKCS8PrivateKey_bio , 1520c3e06d9Sschwarze.Fn i2d_PKCS8PrivateKey_fp , 1530c3e06d9Sschwarze.Fn i2d_PKCS8PrivateKey_nid_bio , 1540c3e06d9Sschwarzeand 1550c3e06d9Sschwarze.Fn i2d_PKCS8PrivateKey_nid_fp 1560c3e06d9Sschwarzereturn 1 on success or 0 on error. 15726265810Sschwarze.Sh SEE ALSO 15812e340e8Sschwarze.Xr d2i_X509_SIG 3 , 15943653837Sschwarze.Xr PEM_write_PKCS8PrivateKey 3 , 1602fd71f8dSschwarze.Xr PKCS8_PRIV_KEY_INFO_new 3 161958c08b5Sschwarze.Sh HISTORY 162958c08b5SschwarzeThese functions first appeared in OpenSSL 0.9.5 163958c08b5Sschwarzeand have been available since 164958c08b5Sschwarze.Ox 2.7 . 16512e340e8Sschwarze.Sh CAVEATS 16612e340e8SschwarzeDo not confuse these functions with 16712e340e8Sschwarze.Xr i2d_PKCS8PrivateKeyInfo_bio 3 16812e340e8Sschwarzeand 16912e340e8Sschwarze.Xr i2d_PKCS8PrivateKeyInfo_fp 3 , 17012e340e8Sschwarzewhich write out private keys in 17112e340e8Sschwarze.Sy unencrypted 17212e340e8SschwarzeDER format. 173