/* Licensed to the Apache Software Foundation (ASF) under one or more *contributorlicenseagreements.SeetheNOTICEfiledistributedwith *thisworkforadditionalinformationregardingcopyrightownership. *TheASFlicensesthisfiletoYouundertheApacheLicense,Version2.0 *(the"License");youmaynotusethisfileexceptincompliancewith *theLicense.YoumayobtainacopyoftheLicenseat * *http://www.apache.org/licenses/LICENSE-2.0 * *Unlessrequiredbyapplicablelaworagreedtoinwriting,software *distributedundertheLicenseisdistributedonan"ASIS"BASIS, *WITHOUTWARRANTIESORCONDITIONSOFANYKIND,eitherexpressorimplied. *SeetheLicenseforthespecificlanguagegoverningpermissionsand *limitationsundertheLicense.
*/
/* Minimum age for the HSTS header (RFC 6797), considered appropriate by Mozilla Security */ #define MD_HSTS_HEADER "Strict-Transport-Security" #define MD_HSTS_MAX_AGE_DEFAULT 15768000
typedefenum {
MD_S_UNKNOWN = 0, /* MD has not been analysed yet */
MD_S_INCOMPLETE = 1, /* MD is missing necessary information, cannot go live */
MD_S_COMPLETE = 2, /* MD has all necessary information, can go live */
MD_S_EXPIRED_DEPRECATED = 3, /* deprecated */
MD_S_ERROR = 4, /* MD data is flawed, unable to be processed as is */
MD_S_MISSING_INFORMATION = 5, /* User has not agreed to ToS */
} md_state_t;
typedefenum {
MD_RENEW_DEFAULT = -1, /* default value */
MD_RENEW_MANUAL, /* manually triggered renewal of certificate */
MD_RENEW_AUTO, /* automatic process performed by httpd */
MD_RENEW_ALWAYS, /* always renewed by httpd, even if not necessary */
} md_renew_mode_t;
typedefstruct md_t md_t; struct md_t { constchar *name; /* unique name of this MD */ struct apr_array_header_t *domains; /* all DNS names this MD includes */ struct apr_array_header_t *contacts; /* list of contact uris, e.g. mailto:xxx */
struct md_pkeys_spec_t *pks; /* specification for generating private keys */
md_timeslice_t *renew_window; /* time before expiration that starts renewal */
md_timeslice_t *warn_window; /* time before expiration that warnings are sent out */
constchar *ca_proto; /* protocol used vs CA (e.g. ACME) */ struct apr_array_header_t *ca_urls; /* urls of CAs */ constchar *ca_effective; /* url of CA used */ constchar *ca_account; /* account used at CA */ constchar *ca_agreement; /* accepted agreement uri between CA and user */ struct apr_array_header_t *ca_challenges; /* challenge types configured for this MD */ struct apr_array_header_t *cert_files; /* != NULL iff pubcerts explicitly configured */ struct apr_array_header_t *pkey_files; /* != NULL iff privkeys explicitly configured */ constchar *ca_eab_kid; /* optional KEYID for external account binding */ constchar *ca_eab_hmac; /* optional HMAC for external account binding */ constchar *profile; /* optional cert profile to order */ int profile_mandatory; /* if profile, when given, is mandatory */
constchar *state_descr; /* description of state of NULL */
struct apr_array_header_t *acme_tls_1_domains; /* domains supporting "acme-tls/1" protocol */ constchar *dns01_cmd; /* DNS challenge command, override global command */
conststruct md_srv_conf_t *sc; /* server config where it was defined or NULL */ constchar *defn_name; /* config file this MD was defined */ unsigned defn_line_number; /* line number of definition */ constchar *configured_name; /* name this MD was configured with, if different */
int renew_mode; /* mode of obtaining credentials */
md_require_t require_https; /* Iff https: is required for this MD */
md_state_t state; /* state of this MD */ int transitive; /* != 0 iff VirtualHost names/aliases are auto-added */ int must_staple; /* certificates should set the OCSP Must Staple extension */ int stapling; /* if OCSP stapling is enabled */ int watched; /* if certificate is supervised (renew or expiration warning) */
};
/* Check if a string member of a new MD (n) has *avalueandifitdiffersfromtheoldMDo
*/ #define MD_VAL_UPDATE(n,o,s) ((n)->s != (o)->s) #define MD_SVAL_UPDATE(n,o,s) ((n)->s && (!(o)->s || strcmp((n)->s, (o)->s)))
/** *DetermineiftheManagedDomaincontainsaspecificdomainname.
*/ int md_contains(const md_t *md, constchar *domain, int case_sensitive);
/** *Determineifthenamesofthetwomanageddomainsoverlap.
*/ int md_domains_overlap(const md_t *md1, const md_t *md2);
/** *Determineifthedomainnamesareequal.
*/ int md_equal_domains(const md_t *md1, const md_t *md2, int case_sensitive);
/** *Determineifthedomainsinmd1containalldomainsofmd2.
*/ int md_contains_domains(const md_t *md1, const md_t *md2);
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.