DH_set_method.pod 3.5 KB
Newer Older
1 2 3 4
=pod

=head1 NAME

5 6
DH_set_default_openssl_method, DH_get_default_openssl_method,
DH_set_method, DH_new_method, DH_OpenSSL - select DH method
7 8 9 10

=head1 SYNOPSIS

 #include <openssl/dh.h>
11
 #include <openssl/engine.h>
12

13
 void DH_set_default_openssl_method(DH_METHOD *meth);
14

15
 DH_METHOD *DH_get_default_openssl_method(void);
16

17
 int DH_set_method(DH *dh, ENGINE *engine);
18

19
 DH *DH_new_method(ENGINE *engine);
20 21 22 23 24 25 26 27 28 29 30 31

 DH_METHOD *DH_OpenSSL(void);

=head1 DESCRIPTION

A B<DH_METHOD> specifies the functions that OpenSSL uses for Diffie-Hellman
operations. By modifying the method, alternative implementations
such as hardware accelerators may be used.

Initially, the default is to use the OpenSSL internal implementation.
DH_OpenSSL() returns a pointer to that method.

32 33 34 35 36 37
DH_set_default_openssl_method() makes B<meth> the default method for all DH
structures created later. B<NB:> This is true only whilst the default engine
for Diffie-Hellman operations remains as "openssl". ENGINEs provide an
encapsulation for implementations of one or more algorithms, and all the DH
functions mentioned here operate within the scope of the default
"openssl" engine.
38

39 40
DH_get_default_openssl_method() returns a pointer to the current default
method for the "openssl" engine.
41

42 43 44 45 46 47
DH_set_method() selects B<engine> as the engine that will be responsible for
all operations using the structure B<dh>. If this function completes successfully,
then the B<dh> structure will have its own functional reference of B<engine>, so
the caller should remember to free their own reference to B<engine> when they are
finished with it. NB: An ENGINE's DH_METHOD can be retrieved (or set) by
ENGINE_get_DH() or ENGINE_set_DH().
48

49 50 51
DH_new_method() allocates and initializes a DH structure so that
B<engine> will be used for the DH operations. If B<engine> is NULL,
the default engine for Diffie-Hellman opertaions is used.
52 53 54 55 56 57 58 59 60 61 62 63 64 65

=head1 THE DH_METHOD STRUCTURE

 typedef struct dh_meth_st
 {
     /* name of the implementation */
	const char *name;

     /* generate private and public DH values for key agreement */
        int (*generate_key)(DH *dh);

     /* compute shared secret */
        int (*compute_key)(unsigned char *key, BIGNUM *pub_key, DH *dh);

U
Ulf Möller 已提交
66
     /* compute r = a ^ p mod m (May be NULL for some implementations) */
67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84
        int (*bn_mod_exp)(DH *dh, BIGNUM *r, BIGNUM *a, const BIGNUM *p,
                                const BIGNUM *m, BN_CTX *ctx,
                                BN_MONT_CTX *m_ctx);

     /* called at DH_new */
        int (*init)(DH *dh);

     /* called at DH_free */
        int (*finish)(DH *dh);

        int flags;

        char *app_data; /* ?? */

 } DH_METHOD;

=head1 RETURN VALUES

85 86
DH_OpenSSL() and DH_get_default_openssl_method() return pointers to the
respective B<DH_METHOD>s.
87

88
DH_set_default_openssl_method() returns no value.
89

90 91
DH_set_method() returns non-zero if the ENGINE associated with B<dh>
was successfully changed to B<engine>.
92

93 94 95
DH_new_method() returns NULL and sets an error code that can be
obtained by L<ERR_get_error(3)|ERR_get_error(3)> if the allocation fails.
Otherwise it returns a pointer to the newly allocated structure.
96 97 98

=head1 SEE ALSO

99
L<dh(3)|dh(3)>, L<DH_new(3)|DH_new(3)>
100 101 102 103 104 105

=head1 HISTORY

DH_set_default_method(), DH_get_default_method(), DH_set_method(),
DH_new_method() and DH_OpenSSL() were added in OpenSSL 0.9.4.

106 107 108 109 110
DH_set_default_openssl_method() and DH_get_default_openssl_method()
replaced DH_set_default_method() and DH_get_default_method() respectively,
and DH_set_method() and DH_new_method() were altered to use B<ENGINE>s
rather than B<DH_METHOD>s during development of OpenSSL 0.9.6.

111
=cut