summaryrefslogtreecommitdiff
path: root/static/freebsd/man7/OSSL_STORE-winstore.7
diff options
context:
space:
mode:
Diffstat (limited to 'static/freebsd/man7/OSSL_STORE-winstore.7')
-rw-r--r--static/freebsd/man7/OSSL_STORE-winstore.7126
1 files changed, 126 insertions, 0 deletions
diff --git a/static/freebsd/man7/OSSL_STORE-winstore.7 b/static/freebsd/man7/OSSL_STORE-winstore.7
new file mode 100644
index 00000000..d6c82aa5
--- /dev/null
+++ b/static/freebsd/man7/OSSL_STORE-winstore.7
@@ -0,0 +1,126 @@
+.\" -*- mode: troff; coding: utf-8 -*-
+.\" Automatically generated by Pod::Man v6.0.2 (Pod::Simple 3.45)
+.\"
+.\" Standard preamble:
+.\" ========================================================================
+.de Sp \" Vertical space (when we can't use .PP)
+.if t .sp .5v
+.if n .sp
+..
+.de Vb \" Begin verbatim text
+.ft CW
+.nf
+.ne \\$1
+..
+.de Ve \" End verbatim text
+.ft R
+.fi
+..
+.\" \*(C` and \*(C' are quotes in nroff, nothing in troff, for use with C<>.
+.ie n \{\
+. ds C` ""
+. ds C' ""
+'br\}
+.el\{\
+. ds C`
+. ds C'
+'br\}
+.\"
+.\" Escape single quotes in literal strings from groff's Unicode transform.
+.ie \n(.g .ds Aq \(aq
+.el .ds Aq '
+.\"
+.\" If the F register is >0, we'll generate index entries on stderr for
+.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index
+.\" entries marked with X<> in POD. Of course, you'll have to process the
+.\" output yourself in some meaningful fashion.
+.\"
+.\" Avoid warning from groff about undefined register 'F'.
+.de IX
+..
+.nr rF 0
+.if \n(.g .if rF .nr rF 1
+.if (\n(rF:(\n(.g==0)) \{\
+. if \nF \{\
+. de IX
+. tm Index:\\$1\t\\n%\t"\\$2"
+..
+. if !\nF==2 \{\
+. nr % 0
+. nr F 2
+. \}
+. \}
+.\}
+.rr rF
+.\"
+.\" Required to disable full justification in groff 1.23.0.
+.if n .ds AD l
+.\" ========================================================================
+.\"
+.IX Title "OSSL_STORE-WINSTORE 7ossl"
+.TH OSSL_STORE-WINSTORE 7ossl 2026-04-07 3.5.6 OpenSSL
+.\" For nroff, turn off justification. Always turn off hyphenation; it makes
+.\" way too many mistakes in technical documents.
+.if n .ad l
+.nh
+.SH NAME
+OSSL_STORE\-winstore \- OpenSSL built in OSSL_STORE for Windows
+.SH DESCRIPTION
+.IX Header "DESCRIPTION"
+The OSSL_STORE implementation for Windows provides access to Windows\*(Aq system
+\&\f(CW\*(C`ROOT\*(C'\fR certificate store through URIs, using the URI scheme
+\&\f(CW\*(C`org.openssl.winstore\*(C'\fR.
+.SS "Supported URIs"
+.IX Subsection "Supported URIs"
+There is only one supported URI:
+.PP
+.Vb 1
+\& org.openssl.winstore:
+.Ve
+.PP
+No authority (host, etc), no path, no query, no fragment.
+.SS "Supported OSSL_STORE_SEARCH operations"
+.IX Subsection "Supported OSSL_STORE_SEARCH operations"
+.IP \fBOSSL_STORE_SEARCH_by_name\fR\|(3) 4
+.IX Item "OSSL_STORE_SEARCH_by_name"
+As a matter of fact, this must be used. It is not possible to enumerate all
+available certificates in the store.
+.SS "Windows certificate store features"
+.IX Subsection "Windows certificate store features"
+Apart from diverse constraints present in the certificates themselves, the
+Windows certificate store also has the ability to associate additional
+constraining properties alongside a certificate in the store. This includes
+both documented and undocumented capabilities:
+.IP \(bu 4
+The documented capability to override EKU
+.IP \(bu 4
+The undocumented capability to add name constraints
+.IP \(bu 4
+The undocumented capability to override the certificate expiry date
+.PP
+\&\fISuch constraints are not checked by this OSSL_STORE implementation, and
+thereby not honoured\fR.
+.PP
+However, once extracted with \fBOSSL_STORE_load\fR\|(3), certificates that have
+constraints in their X.509 extensions will go through the usual constraint
+checks when used by OpenSSL, and are thereby honoured.
+.SH "SEE ALSO"
+.IX Header "SEE ALSO"
+\&\fBossl_store\fR\|(7), \fBOSSL_STORE_open_ex\fR\|(3), \fBOSSL_STORE_SEARCH\fR\|(3)
+.SH HISTORY
+.IX Header "HISTORY"
+The winstore (\f(CW\*(C`org.openssl.winstore\*(C'\fR) implementation was added in OpenSSL
+3.2.0.
+.SH NOTES
+.IX Header "NOTES"
+OpenSSL uses \fBOSSL_DECODER\fR\|(3) implementations under the hood.
+To influence what \fBOSSL_DECODER\fR\|(3) implementations are used, it\*(Aqs advisable
+to use \fBOSSL_STORE_open_ex\fR\|(3) and set the \fIpropq\fR argument.
+.SH COPYRIGHT
+.IX Header "COPYRIGHT"
+Copyright 2024 The OpenSSL Project Authors. All Rights Reserved.
+.PP
+Licensed under the Apache License 2.0 (the "License"). You may not use
+this file except in compliance with the License. You can obtain a copy
+in the file LICENSE in the source distribution or at
+<https://www.openssl.org/source/license.html>.