Skip to main content

ERUCES::TEAdminCertificate

#include <teadmin_certificate.h>

The TEAdminCertificate class represents certificate administrative tasks and is derived from the TEAdmin class.

The TEAdminCertificate class

© Pi Soft, 2018-2026 · Tricryption Engine 8.1

Inheritance​

Public Member Functions​

MemberDescription
TEAdminCertificate()The TEAdminCertificate constructor is the default class constructor.
~TEAdminCertificate()The TEAdminCertificate destructor is the class destructor.
TECertObjectInfo issueCertificate(const _TESTD string &strCSR)The issueCertificate method issues a certificate.
void addCAToTrustedCAList(const TEObjectContainer &certs)The addCAToTrustedCAList method adds a certificate authority (CA) to the list of trusted certificate authorities.
void removeCAFromTrustedCAList(const TEObjectContainer &certs)The removeCAFromTrustedCAList method removes a certificate authority (CA) from a list of trusted certificate authorities.
void getTrustedCAList(TEObjectContainer &certs)The getTrustedCAList method gets a list of trusted certificate authorities.
unsigned char * generateCertificate(_TESTD string &strDN, uint32_t type, uint32_t kl_curve, _TESTD string &certName, size_t *certSize)The generateCertificate method generates certificate requests based on particular algorithm and key length or curve.
_TESTD string generateCertificate(_TESTD string &strDN, uint32_t type, uint32_t kl_curve, _TESTD string &certName)The generateCertificate method generates certificate requests based on particular algorithm and key length or curve.
uint16_t getServerCertificates(_TESTD string &key, TEObjectContainer &certs)The getServerCertificates method gets server certificates.
uint16_t getRootCertificates(_TESTD string &key, TEObjectContainer &certs)The getRootCertificates method gets the root certificates.
uint32_t getPrincipalCertificates(uint32_t sid, te_oid pid, TEObjectContainer &certs)The getPrincipalCertificates gets the Transport Principal certificates.
void importCRL(const _TESTD vector< _TESTD string > &crls, _TESTD vector< TERevocationEvidence > &accepted)The importCRL method imports one or more DER-encoded CRLs (IMPORT_CRL; TE81-447, ADR 0114).
uint32_t getRevocationEvidence(_TESTD vector< TERevocationEvidence > &rows)The getRevocationEvidence method reads every stored CRL evidence row (GET_REVOCATION_EVIDENCE).
TERevocationLookup lookupRevocation(const _TESTD string &certificateDer)The lookupRevocation method asks the key server whether one certificate is revoked (LOOKUP_REVOCATION): the revocation facts stored for its issuer, keyed by issuer name and serial, and the revocation policy in force for that issuer. Reads the store; changes nothing.

Member Function Documentation​

TEAdminCertificate()​

The TEAdminCertificate constructor is the default class constructor.

~TEAdminCertificate()​

The TEAdminCertificate destructor is the class destructor.

TECertObjectInfo issueCertificate(const _TESTD string &strCSR)​

The issueCertificate method issues a certificate.

Parameters

ParameterDescription
strCSRA string representing a certificate request.

Returns: Returns a TECertObjectInfo object.

void addCAToTrustedCAList(const TEObjectContainer &certs)​

The addCAToTrustedCAList method adds a certificate authority (CA) to the list of trusted certificate authorities.

Parameters

ParameterDescription
certsOne or more certificate authorities to be added; must be TECertObjectInfo objects.

void removeCAFromTrustedCAList(const TEObjectContainer &certs)​

The removeCAFromTrustedCAList method removes a certificate authority (CA) from a list of trusted certificate authorities.

Parameters

ParameterDescription
certsOne or more certificate authorities to be removed; must be TECertObjectInfo objects.

void getTrustedCAList(TEObjectContainer &certs)​

The getTrustedCAList method gets a list of trusted certificate authorities.

Parameters

ParameterDescription
certsA container to hold the returned CA certificates; must be TECertObjectInfo objects.

unsigned char * generateCertificate(_TESTD string &strDN, uint32_t type, uint32_t kl_curve, _TESTD string &certName, size_t *certSize)​

The generateCertificate method generates certificate requests based on particular algorithm and key length or curve.

Parameters

ParameterDescription
strDNstring of certificate request
typeType of algorithm. 0: ECC, 1: RSA
kl_curveKey length or curve id. RSA: default=2048
certNamecertificate name
certSizeSize of certificate buffer returned

Exceptions

ExceptionDescription
TEAdminExceptionif the Key Service cannot execute the signing request – for example the connection is not open, or the server rejects the algorithm, key length or curve. The originating engine error code and message are carried in the exception. An empty strDN is not an error: the call returns NULL and sets certSize to zero.

Returns: Binary buffer of certificate chain

_TESTD string generateCertificate(_TESTD string &strDN, uint32_t type, uint32_t kl_curve, _TESTD string &certName)​

The generateCertificate method generates certificate requests based on particular algorithm and key length or curve.

Parameters

ParameterDescription
strDNstring of certificate request
typeType of algorithm. 0: ECC, 1: RSA
kl_curveKey length or curve id. RSA: default=2048
certNamecertificate name

Exceptions

ExceptionDescription
TEAdminExceptionif the Key Service cannot execute the signing request – for example the connection is not open, or the server rejects the algorithm, key length or curve. The originating engine error code and message are carried in the exception.

Returns: Binary buffer of certificate chain

uint16_t getServerCertificates(_TESTD string &key, TEObjectContainer &certs)​

The getServerCertificates method gets server certificates.

Parameters

ParameterDescription
keystring of key attribute of certificate store
certsserver certificates returned

Exceptions

ExceptionDescription
TEAdminExceptionif the server certificate store cannot be read under key, or the command fails. The originating engine error code and message are carried in the exception.

Returns: An integer representing the number of server certificates returned

uint16_t getRootCertificates(_TESTD string &key, TEObjectContainer &certs)​

The getRootCertificates method gets the root certificates.

Parameters

ParameterDescription
keystring of key attribute of root certificate store
certsroot certificates returned

Exceptions

ExceptionDescription
TEAdminExceptionif the root certificate store cannot be read under key, or the command fails. The originating engine error code and message are carried in the exception.

Returns: An integer representing the number of root certificates returned

uint32_t getPrincipalCertificates(uint32_t sid, te_oid pid, TEObjectContainer &certs)​

The getPrincipalCertificates gets the Transport Principal certificates.

Parameters

ParameterDescription
sidAn integer presenting the system ID.
pidAn object representing the principal ID.
certsA TEObjectContainer object representing the certificates.

Exceptions

ExceptionDescription
TEAdminExceptionif the certificates for the given system and principal id cannot be retrieved. The originating engine error code and message are carried in the exception.

Returns: An integer representing the number of certificates the principal ID is on.

void importCRL(const _TESTD vector< _TESTD string > &crls, _TESTD vector< TERevocationEvidence > &accepted)​

The importCRL method imports one or more DER-encoded CRLs (IMPORT_CRL; TE81-447, ADR 0114).

Each CRL is validated by the key server – its issuer must be a trusted anchor at that moment, its signature must verify under that anchor, it must be a complete (non-delta, non-indirect, non-partitioned) CRL, and it must be current – and its revocation facts are stored inside one transaction: an import that refuses one CRL persists nothing. A newer CRL from an issuer replaces the stored evidence for that issuer; an older one is refused.

Parameters

ParameterDescription
crlsThe DER bytes of each CRL.
acceptedReceives one TERevocationEvidence per accepted CRL, in order.

Exceptions

ExceptionDescription
TEAdminExceptioncarrying the key server's refusal (ERR_INVALID_ARGUMENT and the validation path's own text), or the command failure.

uint32_t getRevocationEvidence(_TESTD vector< TERevocationEvidence > &rows)​

The getRevocationEvidence method reads every stored CRL evidence row (GET_REVOCATION_EVIDENCE).

Parameters

ParameterDescription
rowsReceives the rows, oldest first.

Returns: The number of rows.

TERevocationLookup lookupRevocation(const _TESTD string &certificateDer)​

The lookupRevocation method asks the key server whether one certificate is revoked (LOOKUP_REVOCATION): the revocation facts stored for its issuer, keyed by issuer name and serial, and the revocation policy in force for that issuer. Reads the store; changes nothing.

Parameters

ParameterDescription
certificateDerThe DER bytes of the certificate.

Exceptions

ExceptionDescription
TEAdminExceptionwhen the certificate does not decode or the policy in force does not parse (the key server names the parameter and the defect), or the command fails.

Returns: The answer.