git-subtree-dir: external/nng git-subtree-split: 169221da8d53b2ca4fda76f894bee8505887a7c6
64 lines
2.1 KiB
Text
64 lines
2.1 KiB
Text
= nng_tls_config_ca_file(3tls)
|
|
//
|
|
// Copyright 2018 Staysail Systems, Inc. <info@staysail.tech>
|
|
// Copyright 2018 Capitar IT Group BV <info@capitar.com>
|
|
//
|
|
// This document is supplied under the terms of the MIT License, a
|
|
// copy of which should be located in the distribution where this
|
|
// file was obtained (LICENSE.txt). A copy of the license may also be
|
|
// found online at https://opensource.org/licenses/MIT.
|
|
//
|
|
|
|
== NAME
|
|
|
|
nng_tls_config_ca_file - load certificate authority from file
|
|
|
|
== SYNOPSIS
|
|
|
|
[source, c]
|
|
----
|
|
#include <nng/nng.h>
|
|
#include <nng/supplemental/tls/tls.h>
|
|
|
|
int nng_tls_config_ca_file(nng_tls_config *cfg, const char *path);
|
|
----
|
|
|
|
== DESCRIPTION
|
|
|
|
The `nng_tls_config_ca_file()` function configures the ((certificate authority))
|
|
certificate chain and optional revocation list by loading the certificates
|
|
(and revocation list if present) from a single named file.
|
|
The file must at least one X.509 certificate in
|
|
https://tools.ietf.org/html/rfc7468[PEM]
|
|
format, and may contain multiple such certificates, as well as zero or
|
|
more PEM CRL objects.
|
|
This information is used to validate certificates
|
|
that are presented by peers, when using the configuration _cfg_.
|
|
|
|
NOTE: Certificates *must* be configured when using the authentication mode
|
|
`NNG_TLS_AUTH_MODE_REQUIRED`.
|
|
|
|
TIP: This function may be called multiple times, to add additional chains
|
|
to a configuration, without affecting those added previously.
|
|
|
|
== RETURN VALUES
|
|
|
|
This function returns 0 on success, and non-zero otherwise.
|
|
|
|
== ERRORS
|
|
|
|
[horizontal]
|
|
`NNG_ENOMEM`:: Insufficient memory is available.
|
|
`NNG_EBUSY`:: The configuration _cfg_ is already in use, and cannot be modified.
|
|
`NNG_EINVAL`:: The contents of _path_ are invalid or do not contain a valid PEM certificate.
|
|
`NNG_ENOENT`:: The file _path_ does not exist.
|
|
`NNG_EPERM`:: The file _path_ is not readable.
|
|
|
|
== SEE ALSO
|
|
|
|
[.text-left]
|
|
xref:nng_strerror.3.adoc[nng_strerror(3)],
|
|
xref:nng_tls_config_alloc.3tls.adoc[nng_tls_config_alloc(3tls)],
|
|
xref:nng_tls_config_auth_mode.3tls.adoc[nng_tls_config_auth_mode(3tls)],
|
|
xref:nng_tls_config_ca_chain.3tls.adoc[nng_tls_config_ca_chain(3tls)],
|
|
xref:nng.7.adoc[nng(7)]
|