ERUCES::TEAdminCertificate
#include <teadmin_certificate.h>
The TEAdminCertificate class represents certificate administrative tasks and is derived from the TEAdmin class.
The TEAdminCertificate class
© Pi Soft, 2018-2026 · Tricryption Engine 8.1
Inheritance
- Inherits ERUCES::TEAdmin
Public Member Functions
| Member | Description |
|---|---|
TEAdminCertificate() | The TEAdminCertificate constructor is the default class constructor. |
~TEAdminCertificate() | The TEAdminCertificate destructor is the class destructor. |
TECertObjectInfo issueCertificate(const _TESTD string &strCSR) | The issueCertificate method issues a certificate. |
void addCAToTrustedCAList(const TEObjectContainer &certs) | The addCAToTrustedCAList method adds a certificate authority (CA) to the list of trusted certificate authorities. |
void removeCAFromTrustedCAList(const TEObjectContainer &certs) | The removeCAFromTrustedCAList method removes a certificate authority (CA) from a list of trusted certificate authorities. |
void getTrustedCAList(TEObjectContainer &certs) | The getTrustedCAList method gets a list of trusted certificate authorities. |
unsigned char * generateCertificate(_TESTD string &strDN, uint32_t type, uint32_t kl_curve, _TESTD string &certName, size_t *certSize) | The generateCertificate method generates certificate requests based on particular algorithm and key length or curve. |
_TESTD string generateCertificate(_TESTD string &strDN, uint32_t type, uint32_t kl_curve, _TESTD string &certName) | The generateCertificate method generates certificate requests based on particular algorithm and key length or curve. |
uint16_t getServerCertificates(_TESTD string &key, TEObjectContainer &certs) | The getServerCertificates method gets server certificates. |
uint16_t getRootCertificates(_TESTD string &key, TEObjectContainer &certs) | The getRootCertificates method gets the root certificates. |
uint32_t getPrincipalCertificates(uint32_t sid, te_oid pid, TEObjectContainer &certs) | The getPrincipalCertificates gets the Transport Principal certificates. |
void importCRL(const _TESTD vector< _TESTD string > &crls, _TESTD vector< TERevocationEvidence > &accepted) | The importCRL method imports one or more DER-encoded CRLs (IMPORT_CRL; TE81-447, ADR 0114). |
uint32_t getRevocationEvidence(_TESTD vector< TERevocationEvidence > &rows) | The getRevocationEvidence method reads every stored CRL evidence row (GET_REVOCATION_EVIDENCE). |
TERevocationLookup lookupRevocation(const _TESTD string &certificateDer) | The lookupRevocation method asks the key server whether one certificate is revoked (LOOKUP_REVOCATION): the revocation facts stored for its issuer, keyed by issuer name and serial, and the revocation policy in force for that issuer. Reads the store; changes nothing. |
Member Function Documentation
TEAdminCertificate()
The TEAdminCertificate constructor is the default class constructor.
~TEAdminCertificate()
The TEAdminCertificate destructor is the class destructor.
TECertObjectInfo issueCertificate(const _TESTD string &strCSR)
The issueCertificate method issues a certificate.
Parameters
| Parameter | Description |
|---|---|
strCSR | A string representing a certificate request. |
Returns: Returns a TECertObjectInfo object.
void addCAToTrustedCAList(const TEObjectContainer &certs)
The addCAToTrustedCAList method adds a certificate authority (CA) to the list of trusted certificate authorities.
Parameters
| Parameter | Description |
|---|---|
certs | One or more certificate authorities to be added; must be TECertObjectInfo objects. |
void removeCAFromTrustedCAList(const TEObjectContainer &certs)
The removeCAFromTrustedCAList method removes a certificate authority (CA) from a list of trusted certificate authorities.
Parameters
| Parameter | Description |
|---|---|
certs | One or more certificate authorities to be removed; must be TECertObjectInfo objects. |
void getTrustedCAList(TEObjectContainer &certs)
The getTrustedCAList method gets a list of trusted certificate authorities.
Parameters
| Parameter | Description |
|---|---|
certs | A container to hold the returned CA certificates; must be TECertObjectInfo objects. |
unsigned char * generateCertificate(_TESTD string &strDN, uint32_t type, uint32_t kl_curve, _TESTD string &certName, size_t *certSize)
The generateCertificate method generates certificate requests based on particular algorithm and key length or curve.
Parameters
| Parameter | Description |
|---|---|
strDN | string of certificate request |
type | Type of algorithm. 0: ECC, 1: RSA |
kl_curve | Key length or curve id. RSA: default=2048 |
certName | certificate name |
certSize | Size of certificate buffer returned |
Exceptions
| Exception | Description |
|---|---|
TEAdminException | if the Key Service cannot execute the signing request – for example the connection is not open, or the server rejects the algorithm, key length or curve. The originating engine error code and message are carried in the exception. An empty strDN is not an error: the call returns NULL and sets certSize to zero. |
Returns: Binary buffer of certificate chain
_TESTD string generateCertificate(_TESTD string &strDN, uint32_t type, uint32_t kl_curve, _TESTD string &certName)
The generateCertificate method generates certificate requests based on particular algorithm and key length or curve.
Parameters
| Parameter | Description |
|---|---|
strDN | string of certificate request |
type | Type of algorithm. 0: ECC, 1: RSA |
kl_curve | Key length or curve id. RSA: default=2048 |
certName | certificate name |
Exceptions
| Exception | Description |
|---|---|
TEAdminException | if the Key Service cannot execute the signing request – for example the connection is not open, or the server rejects the algorithm, key length or curve. The originating engine error code and message are carried in the exception. |
Returns: Binary buffer of certificate chain
uint16_t getServerCertificates(_TESTD string &key, TEObjectContainer &certs)
The getServerCertificates method gets server certificates.
Parameters
| Parameter | Description |
|---|---|
key | string of key attribute of certificate store |
certs | server certificates returned |
Exceptions
| Exception | Description |
|---|---|
TEAdminException | if the server certificate store cannot be read under key, or the command fails. The originating engine error code and message are carried in the exception. |
Returns: An integer representing the number of server certificates returned
uint16_t getRootCertificates(_TESTD string &key, TEObjectContainer &certs)
The getRootCertificates method gets the root certificates.
Parameters
| Parameter | Description |
|---|---|
key | string of key attribute of root certificate store |
certs | root certificates returned |
Exceptions
| Exception | Description |
|---|---|
TEAdminException | if the root certificate store cannot be read under key, or the command fails. The originating engine error code and message are carried in the exception. |
Returns: An integer representing the number of root certificates returned
uint32_t getPrincipalCertificates(uint32_t sid, te_oid pid, TEObjectContainer &certs)
The getPrincipalCertificates gets the Transport Principal certificates.
Parameters
| Parameter | Description |
|---|---|
sid | An integer presenting the system ID. |
pid | An object representing the principal ID. |
certs | A TEObjectContainer object representing the certificates. |
Exceptions
| Exception | Description |
|---|---|
TEAdminException | if the certificates for the given system and principal id cannot be retrieved. The originating engine error code and message are carried in the exception. |
Returns: An integer representing the number of certificates the principal ID is on.
void importCRL(const _TESTD vector< _TESTD string > &crls, _TESTD vector< TERevocationEvidence > &accepted)
The importCRL method imports one or more DER-encoded CRLs (IMPORT_CRL; TE81-447, ADR 0114).
Each CRL is validated by the key server – its issuer must be a trusted anchor at that moment, its signature must verify under that anchor, it must be a complete (non-delta, non-indirect, non-partitioned) CRL, and it must be current – and its revocation facts are stored inside one transaction: an import that refuses one CRL persists nothing. A newer CRL from an issuer replaces the stored evidence for that issuer; an older one is refused.
Parameters
| Parameter | Description |
|---|---|
crls | The DER bytes of each CRL. |
accepted | Receives one TERevocationEvidence per accepted CRL, in order. |
Exceptions
| Exception | Description |
|---|---|
TEAdminException | carrying the key server's refusal (ERR_INVALID_ARGUMENT and the validation path's own text), or the command failure. |
uint32_t getRevocationEvidence(_TESTD vector< TERevocationEvidence > &rows)
The getRevocationEvidence method reads every stored CRL evidence row (GET_REVOCATION_EVIDENCE).
Parameters
| Parameter | Description |
|---|---|
rows | Receives the rows, oldest first. |
Returns: The number of rows.
TERevocationLookup lookupRevocation(const _TESTD string &certificateDer)
The lookupRevocation method asks the key server whether one certificate is revoked (LOOKUP_REVOCATION): the revocation facts stored for its issuer, keyed by issuer name and serial, and the revocation policy in force for that issuer. Reads the store; changes nothing.
Parameters
| Parameter | Description |
|---|---|
certificateDer | The DER bytes of the certificate. |
Exceptions
| Exception | Description |
|---|---|
TEAdminException | when the certificate does not decode or the policy in force does not parse (the key server names the parameter and the defect), or the command fails. |
Returns: The answer.