mirror of
https://github.com/sigmasternchen/php-doc-en
synced 2025-03-26 13:58:55 +00:00
159 lines
4.5 KiB
XML
159 lines
4.5 KiB
XML
<?xml version="1.0" encoding="utf-8"?>
|
|
<!-- $Revision$ -->
|
|
<refentry xml:id="function.openssl-x509-verify" xmlns="http://docbook.org/ns/docbook">
|
|
<refnamediv>
|
|
<refname>openssl_x509_verify</refname>
|
|
<refpurpose>Verifies digital signature of x509 certificate against a public key</refpurpose>
|
|
</refnamediv>
|
|
|
|
<refsect1 role="description">
|
|
&reftitle.description;
|
|
<methodsynopsis>
|
|
<type>int</type><methodname>openssl_x509_verify</methodname>
|
|
<methodparam><type class="union"><type>OpenSSLCertificate</type><type>string</type></type><parameter>certificate</parameter></methodparam>
|
|
<methodparam><type class="union"><type>OpenSSLAsymmetricKey</type><type>OpenSSLCertificate</type><type>array</type><type>string</type></type><parameter>public_key</parameter></methodparam>
|
|
</methodsynopsis>
|
|
<para>
|
|
<function>openssl_x509_verify</function> verifies that the
|
|
<parameter>certificate</parameter> certificate was signed by the private
|
|
key corresponding to public key <parameter>public_key</parameter>.
|
|
</para>
|
|
</refsect1>
|
|
|
|
<refsect1 role="parameters">
|
|
&reftitle.parameters;
|
|
<para>
|
|
<variablelist>
|
|
&openssl.param.x509;
|
|
<varlistentry>
|
|
<term><parameter>public_key</parameter></term>
|
|
<listitem>
|
|
<para>
|
|
<classname>OpenSSLAsymmetricKey</classname> - a key, returned by <function>openssl_get_publickey</function>
|
|
</para>
|
|
<para>
|
|
<type>string</type> - a PEM formatted key, example, "-----BEGIN PUBLIC KEY-----
|
|
MIIBCgK..."
|
|
</para>
|
|
</listitem>
|
|
</varlistentry>
|
|
</variablelist>
|
|
</para>
|
|
</refsect1>
|
|
|
|
<refsect1 role="returnvalues">
|
|
&reftitle.returnvalues;
|
|
<para>
|
|
Returns 1 if the signature is correct, 0 if it is incorrect, and
|
|
-1 on error.
|
|
</para>
|
|
</refsect1>
|
|
|
|
<refsect1 role="changelog">
|
|
&reftitle.changelog;
|
|
<informaltable>
|
|
<tgroup cols="2">
|
|
<thead>
|
|
<row>
|
|
<entry>&Version;</entry>
|
|
<entry>&Description;</entry>
|
|
</row>
|
|
</thead>
|
|
<tbody>
|
|
<row>
|
|
<entry>8.0.0</entry>
|
|
<entry>
|
|
<parameter>certificate</parameter> accepts an <classname>OpenSSLCertificate</classname> instance now;
|
|
previously, a &resource; of type <literal>OpenSSL X.509</literal> was accepted.
|
|
</entry>
|
|
</row>
|
|
<row>
|
|
<entry>8.0.0</entry>
|
|
<entry>
|
|
<parameter>public_key</parameter> accepts an <classname>OpenSSLAsymmetricKey</classname>
|
|
or <classname>OpenSSLCertificate</classname> instance now;
|
|
previously, a &resource; of type <literal>OpenSSL key</literal> or <literal>OpenSSL X.509</literal>
|
|
was accepted.
|
|
</entry>
|
|
</row>
|
|
</tbody>
|
|
</tgroup>
|
|
</informaltable>
|
|
</refsect1>
|
|
|
|
<refsect1 role="examples">
|
|
&reftitle.examples;
|
|
<para>
|
|
<example>
|
|
<title><function>openssl_x509_verify</function> example</title>
|
|
<programlisting role="php">
|
|
<![CDATA[
|
|
<?php
|
|
$hostname = "news.php.net";
|
|
$ssloptions = array(
|
|
"capture_peer_cert" => true,
|
|
"capture_peer_cert_chain" => true,
|
|
"allow_self_signed"=> false,
|
|
"CN_match" => $hostname,
|
|
"verify_peer" => true,
|
|
"SNI_enabled" => true,
|
|
"SNI_server_name" => $hostname,
|
|
);
|
|
|
|
$ctx = stream_context_create( array("ssl" => $ssloptions) );
|
|
$result = stream_socket_client("ssl://$hostname:443", $errno, $errstr, 30, STREAM_CLIENT_CONNECT, $ctx);
|
|
$cont = stream_context_get_params($result);
|
|
$x509 = $cont["options"]["ssl"]["peer_certificate"];
|
|
$certparsed = openssl_x509_parse($x509);
|
|
|
|
foreach($cont["options"]["ssl"]["peer_certificate_chain"] as $chaincert)
|
|
{
|
|
$chainparsed = openssl_x509_parse($chaincert);
|
|
$chain_public_key = openssl_get_publickey($chaincert);
|
|
$r = openssl_x509_verify($x509, $chain_public_key);
|
|
if ($r==1)
|
|
{
|
|
echo $certparsed['subject']['CN'];
|
|
echo " was digitally signed by ";
|
|
echo $chainparsed['subject']['CN']."\n";
|
|
}
|
|
}
|
|
?>
|
|
]]>
|
|
</programlisting>
|
|
</example>
|
|
|
|
</para>
|
|
</refsect1>
|
|
|
|
<refsect1 role="seealso">
|
|
&reftitle.seealso;
|
|
<para>
|
|
<simplelist>
|
|
<member><function>openssl_verify</function></member>
|
|
<member><function>openssl_get_publickey</function></member>
|
|
</simplelist>
|
|
</para>
|
|
</refsect1>
|
|
|
|
</refentry>
|
|
<!-- Keep this comment at the end of the file
|
|
Local variables:
|
|
mode: sgml
|
|
sgml-omittag:t
|
|
sgml-shorttag:t
|
|
sgml-minimize-attributes:nil
|
|
sgml-always-quote-attributes:t
|
|
sgml-indent-step:1
|
|
sgml-indent-data:t
|
|
indent-tabs-mode:nil
|
|
sgml-parent-document:nil
|
|
sgml-default-dtd-file:"~/.phpdoc/manual.ced"
|
|
sgml-exposed-tags:nil
|
|
sgml-local-catalogs:nil
|
|
sgml-local-ecat-files:nil
|
|
End:
|
|
vim600: syn=xml fen fdm=syntax fdl=2 si
|
|
vim: et tw=78 syn=sgml
|
|
vi: ts=1 sw=1
|
|
-->
|