Package apple.security.c
Class Security
- java.lang.Object
-
- apple.security.c.Security
-
public final class Security extends java.lang.Object
-
-
Nested Class Summary
-
Field Summary
Fields Modifier and Type Field Description static doubleSECURITY_TYPE_UNIFICATION
-
Method Summary
All Methods Static Methods Concrete Methods Deprecated Methods Modifier and Type Method Description static @NotNull CFStringRefkSecAttrAccessControl()API-Since: 8.0static @NotNull CFStringRefkSecAttrAccessGroup()API-Since: 3.0static @NotNull CFStringRefkSecAttrAccessGroupToken()[@enum] kSecAttrAccessGroup Value Constants [@constant] kSecAttrAccessGroupToken Represents well-known access group which contains items provided by external token (typically smart card).static @NotNull CFStringRefkSecAttrAccessible()[@enum] Attribute Key Constants Predefined item attribute keys used to get or set values in a dictionary.static @NotNull CFStringRefkSecAttrAccessibleAfterFirstUnlock()API-Since: 4.0static @NotNull CFStringRefkSecAttrAccessibleAfterFirstUnlockThisDeviceOnly()API-Since: 4.0static @NotNull CFStringRefkSecAttrAccessibleAlways()Deprecated.static @NotNull CFStringRefkSecAttrAccessibleAlwaysThisDeviceOnly()Deprecated.static @NotNull CFStringRefkSecAttrAccessibleWhenPasscodeSetThisDeviceOnly()API-Since: 8.0static @NotNull CFStringRefkSecAttrAccessibleWhenUnlocked()[@enum] kSecAttrAccessible Value Constants Predefined item attribute constants used to get or set values in a dictionary.static @NotNull CFStringRefkSecAttrAccessibleWhenUnlockedThisDeviceOnly()API-Since: 4.0static @NotNull CFStringRefkSecAttrAccount()API-Since: 2.0static @NotNull CFStringRefkSecAttrApplicationLabel()API-Since: 2.0static @NotNull CFStringRefkSecAttrApplicationTag()API-Since: 2.0static @NotNull CFStringRefkSecAttrAuthenticationType()API-Since: 2.0static @NotNull CFStringRefkSecAttrAuthenticationTypeDefault()API-Since: 2.0static @NotNull CFStringRefkSecAttrAuthenticationTypeDPA()API-Since: 2.0static @NotNull CFStringRefkSecAttrAuthenticationTypeHTMLForm()API-Since: 2.0static @NotNull CFStringRefkSecAttrAuthenticationTypeHTTPBasic()API-Since: 2.0static @NotNull CFStringRefkSecAttrAuthenticationTypeHTTPDigest()API-Since: 2.0static @NotNull CFStringRefkSecAttrAuthenticationTypeMSN()API-Since: 2.0static @NotNull CFStringRefkSecAttrAuthenticationTypeNTLM()[@enum] kSecAttrAuthenticationType Value Constants Predefined item attribute constants used to get or set values in a dictionary.static @NotNull CFStringRefkSecAttrAuthenticationTypeRPA()API-Since: 2.0static @NotNull CFStringRefkSecAttrCanDecrypt()API-Since: 2.0static @NotNull CFStringRefkSecAttrCanDerive()API-Since: 2.0static @NotNull CFStringRefkSecAttrCanEncrypt()API-Since: 2.0static @NotNull CFStringRefkSecAttrCanSign()API-Since: 2.0static @NotNull CFStringRefkSecAttrCanUnwrap()API-Since: 2.0static @NotNull CFStringRefkSecAttrCanVerify()API-Since: 2.0static @NotNull CFStringRefkSecAttrCanWrap()API-Since: 2.0static @NotNull CFStringRefkSecAttrCertificateEncoding()API-Since: 2.0static @NotNull CFStringRefkSecAttrCertificateType()API-Since: 2.0static @NotNull CFStringRefkSecAttrComment()API-Since: 2.0static @NotNull CFStringRefkSecAttrCreationDate()API-Since: 2.0static @NotNull CFStringRefkSecAttrCreator()API-Since: 2.0static @NotNull CFStringRefkSecAttrDescription()API-Since: 2.0static @NotNull CFStringRefkSecAttrEffectiveKeySize()API-Since: 2.0static @NotNull CFStringRefkSecAttrGeneric()API-Since: 2.0static @NotNull CFStringRefkSecAttrIsExtractable()API-Since: 2.0static @NotNull CFStringRefkSecAttrIsInvisible()API-Since: 2.0static @NotNull CFStringRefkSecAttrIsNegative()API-Since: 2.0static @NotNull CFStringRefkSecAttrIsPermanent()API-Since: 2.0static @NotNull CFStringRefkSecAttrIsSensitive()API-Since: 2.0static @NotNull CFStringRefkSecAttrIssuer()API-Since: 2.0static @NotNull CFStringRefkSecAttrKeyClass()API-Since: 2.0static @NotNull CFStringRefkSecAttrKeyClassPrivate()API-Since: 2.0static @NotNull CFStringRefkSecAttrKeyClassPublic()[@enum] kSecAttrKeyClass Value Constants Predefined item attribute constants used to get or set values in a dictionary.static @NotNull CFStringRefkSecAttrKeyClassSymmetric()API-Since: 2.0static @NotNull CFStringRefkSecAttrKeySizeInBits()API-Since: 2.0static @NotNull CFStringRefkSecAttrKeyType()API-Since: 2.0static @NotNull CFStringRefkSecAttrKeyTypeEC()API-Since: 4.0static @NotNull CFStringRefkSecAttrKeyTypeECSECPrimeRandom()API-Since: 10.0static @NotNull CFStringRefkSecAttrKeyTypeRSA()[@enum] kSecAttrKeyType Value Constants Predefined item attribute constants used to get or set values in a dictionary.static @NotNull CFStringRefkSecAttrLabel()API-Since: 2.0static @NotNull CFStringRefkSecAttrModificationDate()API-Since: 2.0static @NotNull CFStringRefkSecAttrPath()API-Since: 2.0static @NotNull CFStringRefkSecAttrPersistantReference()API-Since: 11.0static @NotNull CFStringRefkSecAttrPersistentReference()API-Since: 11.0static @NotNull CFStringRefkSecAttrPort()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocol()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolAFP()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolAppleTalk()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolDAAP()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolEPPC()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolFTP()[@enum] kSecAttrProtocol Value Constants Predefined item attribute constants used to get or set values in a dictionary.static @NotNull CFStringRefkSecAttrProtocolFTPAccount()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolFTPProxy()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolFTPS()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolHTTP()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolHTTPProxy()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolHTTPS()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolHTTPSProxy()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolIMAP()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolIMAPS()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolIPP()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolIRC()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolIRCS()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolLDAP()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolLDAPS()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolNNTP()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolNNTPS()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolPOP3()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolPOP3S()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolRTSP()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolRTSPProxy()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolSMB()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolSMTP()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolSOCKS()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolSSH()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolTelnet()API-Since: 2.0static @NotNull CFStringRefkSecAttrProtocolTelnetS()API-Since: 2.0static @NotNull CFStringRefkSecAttrPublicKeyHash()API-Since: 2.0static @NotNull CFStringRefkSecAttrSecurityDomain()API-Since: 2.0static @NotNull CFStringRefkSecAttrSerialNumber()API-Since: 2.0static @NotNull CFStringRefkSecAttrServer()API-Since: 2.0static @NotNull CFStringRefkSecAttrService()API-Since: 2.0static @NotNull CFStringRefkSecAttrSubject()API-Since: 2.0static @NotNull CFStringRefkSecAttrSubjectKeyID()API-Since: 2.0static @NotNull CFStringRefkSecAttrSynchronizable()API-Since: 7.0static @NotNull CFStringRefkSecAttrSynchronizableAny()API-Since: 7.0static @NotNull CFStringRefkSecAttrSyncViewHint()API-Since: 9.0static @NotNull CFStringRefkSecAttrTokenID()API-Since: 9.0static @NotNull CFStringRefkSecAttrTokenIDSecureEnclave()[@enum] kSecAttrTokenID Value Constants Predefined item attribute constant used to get or set values in a dictionary.static @NotNull CFStringRefkSecAttrType()API-Since: 2.0static @NotNull CFStringRefkSecClass()[@enum] Class Key Constant Predefined key constant used to get or set item class values in a dictionary.static @NotNull CFStringRefkSecClassCertificate()API-Since: 2.0static @NotNull CFStringRefkSecClassGenericPassword()API-Since: 2.0static @NotNull CFStringRefkSecClassIdentity()API-Since: 2.0static @NotNull CFStringRefkSecClassInternetPassword()[@enum] Class Value Constants Predefined item class constants used to get or set values in a dictionary.static @NotNull CFStringRefkSecClassKey()API-Since: 2.0static @NotNull CFStringRefkSecImportExportPassphrase()[@enum] Import/Export options Predefined key constants used when passing dictionary-based arguments to import/export functions.static @NotNull CFStringRefkSecImportItemCertChain()API-Since: 2.0static @NotNull CFStringRefkSecImportItemIdentity()API-Since: 2.0static @NotNull CFStringRefkSecImportItemKeyID()API-Since: 2.0static @NotNull CFStringRefkSecImportItemLabel()[@enum] Import/Export item description Predefined key constants used to pass back a CFArray with a CFDictionary per item.static @NotNull CFStringRefkSecImportItemTrust()API-Since: 2.0static @NotNull CFStringRefkSecKeyAlgorithmECDHKeyExchangeCofactor()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDHKeyExchangeCofactorX963SHA1()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDHKeyExchangeCofactorX963SHA224()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDHKeyExchangeCofactorX963SHA256()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDHKeyExchangeCofactorX963SHA384()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDHKeyExchangeCofactorX963SHA512()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDHKeyExchangeStandard()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDHKeyExchangeStandardX963SHA1()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDHKeyExchangeStandardX963SHA224()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDHKeyExchangeStandardX963SHA256()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDHKeyExchangeStandardX963SHA384()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDHKeyExchangeStandardX963SHA512()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureDigestRFC4754()API-Since: 17.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureDigestRFC4754SHA1()API-Since: 17.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureDigestRFC4754SHA224()API-Since: 17.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureDigestRFC4754SHA256()API-Since: 17.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureDigestRFC4754SHA384()API-Since: 17.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureDigestRFC4754SHA512()API-Since: 17.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureDigestX962()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureDigestX962SHA1()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureDigestX962SHA224()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureDigestX962SHA256()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureDigestX962SHA384()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureDigestX962SHA512()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureMessageRFC4754SHA1()API-Since: 17.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureMessageRFC4754SHA224()API-Since: 17.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureMessageRFC4754SHA256()API-Since: 17.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureMessageRFC4754SHA384()API-Since: 17.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureMessageRFC4754SHA512()API-Since: 17.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureMessageX962SHA1()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureMessageX962SHA224()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureMessageX962SHA256()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureMessageX962SHA384()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureMessageX962SHA512()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECDSASignatureRFC4754()Deprecated.static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionCofactorVariableIVX963SHA224AESGCM()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionCofactorVariableIVX963SHA256AESGCM()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionCofactorVariableIVX963SHA384AESGCM()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionCofactorVariableIVX963SHA512AESGCM()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionCofactorX963SHA1AESGCM()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionCofactorX963SHA224AESGCM()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionCofactorX963SHA256AESGCM()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionCofactorX963SHA384AESGCM()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionCofactorX963SHA512AESGCM()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionStandardVariableIVX963SHA224AESGCM()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionStandardVariableIVX963SHA256AESGCM()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionStandardVariableIVX963SHA384AESGCM()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionStandardVariableIVX963SHA512AESGCM()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionStandardX963SHA1AESGCM()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionStandardX963SHA224AESGCM()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionStandardX963SHA256AESGCM()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionStandardX963SHA384AESGCM()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmECIESEncryptionStandardX963SHA512AESGCM()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSAEncryptionOAEPSHA1()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSAEncryptionOAEPSHA1AESGCM()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSAEncryptionOAEPSHA224()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSAEncryptionOAEPSHA224AESGCM()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSAEncryptionOAEPSHA256()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSAEncryptionOAEPSHA256AESGCM()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSAEncryptionOAEPSHA384()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSAEncryptionOAEPSHA384AESGCM()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSAEncryptionOAEPSHA512()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSAEncryptionOAEPSHA512AESGCM()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSAEncryptionPKCS1()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSAEncryptionRaw()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureDigestPKCS1v15Raw()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureDigestPKCS1v15SHA1()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureDigestPKCS1v15SHA224()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureDigestPKCS1v15SHA256()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureDigestPKCS1v15SHA384()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureDigestPKCS1v15SHA512()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureDigestPSSSHA1()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureDigestPSSSHA224()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureDigestPSSSHA256()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureDigestPSSSHA384()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureDigestPSSSHA512()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureMessagePKCS1v15SHA1()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureMessagePKCS1v15SHA224()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureMessagePKCS1v15SHA256()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureMessagePKCS1v15SHA384()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureMessagePKCS1v15SHA512()API-Since: 10.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureMessagePSSSHA1()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureMessagePSSSHA224()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureMessagePSSSHA256()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureMessagePSSSHA384()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureMessagePSSSHA512()API-Since: 11.0static @NotNull CFStringRefkSecKeyAlgorithmRSASignatureRaw()API-Since: 10.0static @NotNull CFStringRefkSecKeyKeyExchangeParameterRequestedSize()API-Since: 10.0static @NotNull CFStringRefkSecKeyKeyExchangeParameterSharedInfo()API-Since: 10.0static @NotNull CFStringRefkSecMatchCaseInsensitive()API-Since: 2.0static @NotNull CFStringRefkSecMatchEmailAddressIfPresent()API-Since: 2.0static @NotNull CFStringRefkSecMatchIssuers()API-Since: 2.0static @NotNull CFStringRefkSecMatchItemList()API-Since: 2.0static @NotNull CFStringRefkSecMatchLimit()API-Since: 2.0static @NotNull CFStringRefkSecMatchLimitAll()API-Since: 2.0static @NotNull CFStringRefkSecMatchLimitOne()API-Since: 2.0static @NotNull CFStringRefkSecMatchPolicy()[@enum] Search Constants Predefined search constants used to set values in a query dictionary.static @NotNull CFStringRefkSecMatchSearchList()API-Since: 2.0static @NotNull CFStringRefkSecMatchSubjectContains()API-Since: 2.0static @NotNull CFStringRefkSecMatchTrustedOnly()API-Since: 2.0static @NotNull CFStringRefkSecMatchValidOnDate()API-Since: 2.0static @NotNull CFStringRefkSecPolicyAppleCodeSigning()API-Since: 7.0static @NotNull CFStringRefkSecPolicyAppleEAP()API-Since: 7.0static @NotNull CFStringRefkSecPolicyAppleIDValidation()API-Since: 7.0static @NotNull CFStringRefkSecPolicyAppleIPsec()API-Since: 7.0static @NotNull CFStringRefkSecPolicyApplePassbookSigning()API-Since: 7.0static @NotNull CFStringRefkSecPolicyApplePayIssuerEncryption()API-Since: 9.0static @NotNull CFStringRefkSecPolicyAppleRevocation()API-Since: 7.0static @NotNull CFStringRefkSecPolicyAppleSMIME()API-Since: 7.0static @NotNull CFStringRefkSecPolicyAppleSSL()API-Since: 7.0static @NotNull CFStringRefkSecPolicyAppleTimeStamping()API-Since: 7.0static @NotNull CFStringRefkSecPolicyAppleX509Basic()[@enum] Policy Constants Predefined constants used to specify a policy.static @NotNull CFStringRefkSecPolicyClient()API-Since: 7.0static @NotNull CFStringRefkSecPolicyMacAppStoreReceipt()API-Since: 9.0static @NotNull CFStringRefkSecPolicyName()API-Since: 7.0static @NotNull CFStringRefkSecPolicyOid()[@enum] Policy Value Constants Predefined property key constants used to get or set values in a dictionary for a policy instance.static @NotNull CFStringRefkSecPolicyRevocationFlags()API-Since: 7.0static @NotNull CFStringRefkSecPolicyTeamIdentifier()API-Since: 7.0static @NotNull CFStringRefkSecPrivateKeyAttrs()[@enum] Key Parameter Constants Predefined key constants used to get or set values in a dictionary.static @NotNull CFStringRefkSecPropertyTypeError()API-Since: 7.0static @NotNull CFStringRefkSecPropertyTypeTitle()[@enum] Trust Property Constants Predefined key constants used to obtain values in a per-certificate dictionary of trust evaluation results, as retrieved from a call to SecTrustCopyProperties.static @NotNull CFStringRefkSecPublicKeyAttrs()API-Since: 2.0static @NotNull SecRandomRefkSecRandomDefault()This is a synonym for NULL, if you'd rather use a named constant.static @NotNull CFStringRefkSecReturnAttributes()API-Since: 2.0static @NotNull CFStringRefkSecReturnData()[@enum] Return Type Key Constants Predefined return type keys used to set values in a dictionary.static @NotNull CFStringRefkSecReturnPersistentRef()API-Since: 2.0static @NotNull CFStringRefkSecReturnRef()API-Since: 2.0static @NotNull CFStringRefkSecSharedPassword()[@enum] Credential Key Constants Predefined key constants used to get values in a dictionary of credentials returned by SecRequestWebCredential.static @NotNull CFStringRefkSecTrustCertificateTransparency()API-Since: 9.0static @NotNull CFStringRefkSecTrustCertificateTransparencyWhiteList()Deprecated.static @NotNull CFStringRefkSecTrustEvaluationDate()[@enum] Trust Result Constants Predefined key constants used to obtain values in a dictionary of trust evaluation results for a certificate chain, as retrieved from a call to SecTrustCopyResult.static @NotNull CFStringRefkSecTrustExtendedValidation()API-Since: 7.0static @NotNull CFStringRefkSecTrustOrganizationName()API-Since: 7.0static @NotNull CFStringRefkSecTrustResultValue()API-Since: 7.0static @NotNull CFStringRefkSecTrustRevocationChecked()API-Since: 7.0static @NotNull CFStringRefkSecTrustRevocationValidUntilDate()API-Since: 7.0static @NotNull CFStringRefkSecUseAuthenticationContext()API-Since: 9.0static @NotNull CFStringRefkSecUseAuthenticationUI()API-Since: 9.0static @NotNull CFStringRefkSecUseAuthenticationUIAllow()Deprecated.static @NotNull CFStringRefkSecUseAuthenticationUIFail()Deprecated.static @NotNull CFStringRefkSecUseAuthenticationUISkip()API-Since: 9.0static @NotNull CFStringRefkSecUseDataProtectionKeychain()API-Since: 13.0static @NotNull CFStringRefkSecUseItemList()Deprecated.static @NotNull CFStringRefkSecUseNoAuthenticationUI()Deprecated.static @NotNull CFStringRefkSecUseOperationPrompt()Deprecated.static @NotNull CFStringRefkSecValueData()[@enum] Value Type Key Constants Predefined value type keys used to pass values in a dictionary.static @NotNull CFStringRefkSecValuePersistentRef()API-Since: 2.0static @NotNull CFStringRefkSecValueRef()API-Since: 2.0static @NotNull CFStringRefkSSLSessionConfig_3DES_fallback()Deprecated.static @NotNull CFStringRefkSSLSessionConfig_anonymous()Deprecated.static @NotNull CFStringRefkSSLSessionConfig_ATSv1()Deprecated.static @NotNull CFStringRefkSSLSessionConfig_ATSv1_noPFS()Deprecated.static @NotNull CFStringRefkSSLSessionConfig_default()Deprecated.static @NotNull CFStringRefkSSLSessionConfig_legacy()Deprecated.static @NotNull CFStringRefkSSLSessionConfig_legacy_DHE()Deprecated.static @NotNull CFStringRefkSSLSessionConfig_RC4_fallback()Deprecated.static @NotNull CFStringRefkSSLSessionConfig_standard()Deprecated.static @NotNull CFStringRefkSSLSessionConfig_TLSv1_3DES_fallback()Deprecated.static @NotNull CFStringRefkSSLSessionConfig_TLSv1_fallback()Deprecated.static @NotNull CFStringRefkSSLSessionConfig_TLSv1_RC4_fallback()Deprecated.static @NotNull SecCertificateRefsec_certificate_copy_ref(@NotNull sec_certificate_t certificate)[@function] sec_certificate_copy_ref Copy a retained reference to the underlying `SecCertificateRef` instance.static @Nullable sec_certificate_tsec_certificate_create(@NotNull SecCertificateRef certificate)[@function] sec_certificate_create Create an ARC-able `sec_certificate_t` instance from a `SecCertificateRef`.static booleansec_identity_access_certificates(@NotNull sec_identity_t identity, @NotNull Security.Block_sec_identity_access_certificates handler)[@function] sec_identity_access_certificates Access the certificates associated with the `sec_identity_t` instance.static @Nullable CFArrayRefsec_identity_copy_certificates_ref(@NotNull sec_identity_t identity)[@function] sec_identity_copy_certificates_ref Copy a retained reference to the underlying `CFArrayRef` container of `SecCertificateRef` types.static @Nullable SecIdentityRefsec_identity_copy_ref(@NotNull sec_identity_t identity)[@function] sec_identity_copy_ref Copy a retained reference to the underlying `SecIdentityRef` instance.static @Nullable sec_identity_tsec_identity_create(@NotNull SecIdentityRef identity)[@function] sec_identity_create Create an ARC-able `sec_identity_t` instance from a `SecIdentityRef`.static @Nullable sec_identity_tsec_identity_create_with_certificates(@NotNull SecIdentityRef identity, @NotNull CFArrayRef certificates)[@function] sec_identity_create_with_certificates Create an ARC-able `sec_identity_t` instance from a `SecIdentityRef` and array of SecCertificateRef instances.static booleansec_protocol_metadata_access_distinguished_names(@NotNull sec_protocol_metadata_t metadata, @NotNull Security.Block_sec_protocol_metadata_access_distinguished_names handler)[@function] sec_protocol_metadata_access_distinguished_names Get the X.509 Distinguished Names from the protocol instance peer.static booleansec_protocol_metadata_access_ocsp_response(@NotNull sec_protocol_metadata_t metadata, @NotNull Security.Block_sec_protocol_metadata_access_ocsp_response handler)[@function] sec_protocol_metadata_copy_ocsp_response Get the OCSP response from the protocol instance peer.static booleansec_protocol_metadata_access_peer_certificate_chain(@NotNull sec_protocol_metadata_t metadata, @NotNull Security.Block_sec_protocol_metadata_access_peer_certificate_chain handler)[@function] sec_protocol_metadata_access_peer_certificate_chain Get the certificate chain of the protocol instance peer.static booleansec_protocol_metadata_access_pre_shared_keys(@NotNull sec_protocol_metadata_t metadata, @NotNull Security.Block_sec_protocol_metadata_access_pre_shared_keys handler)[@function] sec_protocol_metadata_access_pre_shared_keys Get the PSKs supported by the local instance.static booleansec_protocol_metadata_access_supported_signature_algorithms(@NotNull sec_protocol_metadata_t metadata, @NotNull Security.Block_sec_protocol_metadata_access_supported_signature_algorithms handler)[@function] sec_protocol_metadata_access_supported_signature_algorithms Get the signature algorithms supported by the peer.static booleansec_protocol_metadata_challenge_parameters_are_equal(@NotNull sec_protocol_metadata_t metadataA, @NotNull sec_protocol_metadata_t metadataB)[@function] sec_protocol_metadata_challenge_parameters_are_equal Compare challenge-relevant information for two `sec_protocol_metadata` instances.static @Nullable dispatch_data_tsec_protocol_metadata_copy_peer_public_key(@NotNull sec_protocol_metadata_t metadata)[@function] sec_protocol_metadata_copy_peer_public_key Get the protocol instance peer's public key.static @Nullable dispatch_data_tsec_protocol_metadata_create_secret(@NotNull sec_protocol_metadata_t metadata, long label_len, @NotNull java.lang.String label, long exporter_length)[@function] sec_protocol_metadata_create_secret Export a secret, e.g., a cryptographic key, derived from the protocol metadata using a label string.static @Nullable dispatch_data_tsec_protocol_metadata_create_secret_with_context(@NotNull sec_protocol_metadata_t metadata, long label_len, @NotNull java.lang.String label, long context_len, @NotNull java.lang.String context, long exporter_length)[@function] sec_protocol_metadata_create_secret_with_context Export a secret, e.g., a cryptographic key, derived from the protocol metadata using a label and context string.static booleansec_protocol_metadata_get_early_data_accepted(@NotNull sec_protocol_metadata_t metadata)[@function] sec_protocol_metadata_get_early_data_accepted Determine if early data was accepted by the peer.static charsec_protocol_metadata_get_negotiated_ciphersuite(@NotNull sec_protocol_metadata_t metadata)Deprecated.static @Nullable java.lang.Stringsec_protocol_metadata_get_negotiated_protocol(@NotNull sec_protocol_metadata_t metadata)[@function] sec_protocol_metadata_get_negotiated_protocol Get the application protocol negotiated, e.g., via the TLS ALPN extension.static intsec_protocol_metadata_get_negotiated_protocol_version(@NotNull sec_protocol_metadata_t metadata)Deprecated.static shortsec_protocol_metadata_get_negotiated_tls_ciphersuite(@NotNull sec_protocol_metadata_t metadata)[@function] sec_protocol_metadata_get_negotiated_tls_ciphersuite Get the negotiated TLS ciphersuite.static shortsec_protocol_metadata_get_negotiated_tls_protocol_version(@NotNull sec_protocol_metadata_t metadata)[@function] sec_protocol_metadata_get_negotiated_tls_protocol_version Get the negotiated TLS version.static @Nullable java.lang.Stringsec_protocol_metadata_get_server_name(@NotNull sec_protocol_metadata_t metadata)[@function] sec_protocol_metadata_get_server_name Obtain the server name offered by a client or server during connection establishmet.static booleansec_protocol_metadata_peers_are_equal(@NotNull sec_protocol_metadata_t metadataA, @NotNull sec_protocol_metadata_t metadataB)[@function] sec_protocol_metadata_peers_are_equal Compare peer information for two `sec_protocol_metadata` instances.static voidsec_protocol_options_add_pre_shared_key(@NotNull sec_protocol_options_t options, @NotNull dispatch_data_t psk, @NotNull dispatch_data_t psk_identity)[@function] sec_protocol_options_add_pre_shared_key Add a pre-shared key (PSK) and its identity to the options.static voidsec_protocol_options_add_tls_application_protocol(@NotNull sec_protocol_options_t options, @NotNull java.lang.String application_protocol)[@function] sec_protocol_options_add_tls_application_protocol Add an application protocol supported by clients of this protocol instance.static voidsec_protocol_options_add_tls_ciphersuite(@NotNull sec_protocol_options_t options, char ciphersuite)Deprecated.static voidsec_protocol_options_add_tls_ciphersuite_group(@NotNull sec_protocol_options_t options, int group)Deprecated.static voidsec_protocol_options_append_tls_ciphersuite(@NotNull sec_protocol_options_t options, short ciphersuite)[@function] sec_protocol_options_append_tls_ciphersuite Append a TLS ciphersuite to the set of enabled ciphersuites.static voidsec_protocol_options_append_tls_ciphersuite_group(@NotNull sec_protocol_options_t options, short group)[@function] sec_protocol_options_append_tls_ciphersuite_group Append a TLS ciphersuite group to the set of enabled ciphersuites.static booleansec_protocol_options_are_equal(@NotNull sec_protocol_options_t optionsA, @NotNull sec_protocol_options_t optionsB)[@function] sec_protocol_options_are_equal Compare two `sec_protocol_options_t` instances.static shortsec_protocol_options_get_default_max_dtls_protocol_version()[@function] sec_protocol_options_get_default_max_tls_protocol_version Get the system default maximum DTLS protocol version.static shortsec_protocol_options_get_default_max_tls_protocol_version()[@function] sec_protocol_options_get_default_max_tls_protocol_version Get the system default maximum TLS protocol version.static shortsec_protocol_options_get_default_min_dtls_protocol_version()[@function] sec_protocol_options_get_default_min_dtls_protocol_version Get the system default minimum DTLS protocol version.static shortsec_protocol_options_get_default_min_tls_protocol_version()[@function] sec_protocol_options_get_default_min_tls_protocol_version Get the system default minimum TLS protocol version.static voidsec_protocol_options_set_challenge_block(@NotNull sec_protocol_options_t options, @NotNull Security.Block_sec_protocol_options_set_challenge_block challenge_block, @NotNull dispatch_queue_t challenge_queue)[@function] sec_protocol_options_set_challenge_block Set the challenge block.static voidsec_protocol_options_set_key_update_block(@NotNull sec_protocol_options_t options, @NotNull Security.Block_sec_protocol_options_set_key_update_block key_update_block, @NotNull dispatch_queue_t key_update_queue)[@function] sec_protocol_options_set_key_update_block Set the key update block.static voidsec_protocol_options_set_local_identity(@NotNull sec_protocol_options_t options, @NotNull sec_identity_t identity)[@function] sec_protocol_options_set_local_identity Set the local identity to be used for this protocol instance.static voidsec_protocol_options_set_max_tls_protocol_version(@NotNull sec_protocol_options_t options, short version)[@function] sec_protocol_options_set_max_tls_protocol_version Set the maximum support TLS version.static voidsec_protocol_options_set_min_tls_protocol_version(@NotNull sec_protocol_options_t options, short version)[@function] sec_protocol_options_set_min_tls_protocol_version Set the minimum support TLS version.static voidsec_protocol_options_set_peer_authentication_required(@NotNull sec_protocol_options_t options, boolean peer_authentication_required)[@function] sec_protocol_options_set_peer_authentication_required Enable or disable peer authentication.static voidsec_protocol_options_set_pre_shared_key_selection_block(@NotNull sec_protocol_options_t options, @NotNull Security.Block_sec_protocol_options_set_pre_shared_key_selection_block psk_selection_block, @NotNull dispatch_queue_t psk_selection_queue)[@function] sec_protocol_options_set_pre_shared_key_selection_block Set the PSK selection block.static voidsec_protocol_options_set_tls_diffie_hellman_parameters(@NotNull sec_protocol_options_t options, @NotNull dispatch_data_t params)Deprecated.static voidsec_protocol_options_set_tls_false_start_enabled(@NotNull sec_protocol_options_t options, boolean false_start_enabled)[@function] sec_protocol_options_set_tls_false_start_enabled Enable or disable TLS False Start.static voidsec_protocol_options_set_tls_is_fallback_attempt(@NotNull sec_protocol_options_t options, boolean is_fallback_attempt)[@function] sec_protocol_options_set_tls_is_fallback_attempt Signal if this is a TLS fallback attempt.static voidsec_protocol_options_set_tls_max_version(@NotNull sec_protocol_options_t options, int version)Deprecated.static voidsec_protocol_options_set_tls_min_version(@NotNull sec_protocol_options_t options, int version)Deprecated.static voidsec_protocol_options_set_tls_ocsp_enabled(@NotNull sec_protocol_options_t options, boolean ocsp_enabled)[@function] nw_protocol_options_set_tls_ocsp_enabled Enable or disable OCSP support.static voidsec_protocol_options_set_tls_pre_shared_key_identity_hint(@NotNull sec_protocol_options_t options, @NotNull dispatch_data_t psk_identity_hint)[@function] sec_protocol_options_set_tls_pre_shared_key_identity_hint Set the PSK identity hint to use by servers when negotiating a PSK ciphersuite.static voidsec_protocol_options_set_tls_renegotiation_enabled(@NotNull sec_protocol_options_t options, boolean renegotiation_enabled)[@function] sec_protocol_options_set_tls_renegotiation_enabled Enable or disable TLS (1.2 and prior) session renegotiation.static voidsec_protocol_options_set_tls_resumption_enabled(@NotNull sec_protocol_options_t options, boolean resumption_enabled)[@function] sec_protocol_options_set_tls_resumption_enabled Enable or disable TLS session resumption.static voidsec_protocol_options_set_tls_sct_enabled(@NotNull sec_protocol_options_t options, boolean sct_enabled)[@function] sec_protocol_options_set_tls_sct_enabled Enable or disable SCT (signed certificate timestamp) support.static voidsec_protocol_options_set_tls_server_name(@NotNull sec_protocol_options_t options, @NotNull java.lang.String server_name)[@function] sec_protocol_options_set_tls_server_name Set the server name to be used when verifying the peer's certificate.static voidsec_protocol_options_set_tls_tickets_enabled(@NotNull sec_protocol_options_t options, boolean tickets_enabled)[@function] sec_protocol_options_set_tls_tickets_enabled Enable or disable TLS session ticket support.static voidsec_protocol_options_set_verify_block(@NotNull sec_protocol_options_t options, @NotNull Security.Block_sec_protocol_options_set_verify_block verify_block, @NotNull dispatch_queue_t verify_block_queue)[@function] sec_protocol_options_set_verify_block Set the verify block.static voidsec_release(org.moe.natj.general.ptr.VoidPtr obj)static org.moe.natj.general.ptr.VoidPtrsec_retain(org.moe.natj.general.ptr.VoidPtr obj)static @NotNull SecTrustRefsec_trust_copy_ref(@NotNull sec_trust_t trust)[@function] sec_trust_copy_ref Copy a retained reference to the underlying `SecTrustRef` instance.static @Nullable sec_trust_tsec_trust_create(@NotNull SecTrustRef trust)[@function] sec_trust_create Create an ARC-able `sec_trust_t` instance from a `SecTrustRef`.static @Nullable SecAccessControlRefSecAccessControlCreateWithFlags(@Nullable CFAllocatorRef allocator, @NotNull org.moe.natj.general.ptr.ConstVoidPtr protection, long flags, @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)[@function] SecAccessControlCreateWithFlags Creates new access control object based on protection type and additional flags.static longSecAccessControlGetTypeID()[@function] SecAccessControlGetTypeID Returns the type identifier of SecAccessControl instances.static voidSecAddSharedWebCredential(@NotNull CFStringRef fqdn, @NotNull CFStringRef account, @Nullable CFStringRef password, @NotNull Security.Block_SecAddSharedWebCredential completionHandler)[@function] SecAddSharedWebCredential Asynchronously store (or update) a shared password for a website.static intSecCertificateCopyCommonName(@NotNull SecCertificateRef certificate, @NotNull org.moe.natj.general.ptr.Ptr<CFStringRef> commonName)[@function] SecCertificateCopyCommonName Retrieves the common name of the subject of a given certificate.static @NotNull CFDataRefSecCertificateCopyData(@NotNull SecCertificateRef certificate)[@function] SecCertificateCopyData Return the DER representation of an X.509 certificate.static intSecCertificateCopyEmailAddresses(@NotNull SecCertificateRef certificate, @NotNull org.moe.natj.general.ptr.Ptr<CFArrayRef> emailAddresses)[@function] SecCertificateCopyEmailAddresses Returns an array of zero or more email addresses for the subject of a given certificate.static @Nullable SecKeyRefSecCertificateCopyKey(@NotNull SecCertificateRef certificate)[@function] SecCertificateCopyKey Retrieves the public key for a given certificate.static @Nullable CFDataRefSecCertificateCopyNormalizedIssuerSequence(@NotNull SecCertificateRef certificate)[@function] SecCertificateCopyNormalizedIssuerSequence Return the certificate's normalized issuer The issuer is a sequence in the format used by SecItemCopyMatching.static @Nullable CFDataRefSecCertificateCopyNormalizedSubjectSequence(@NotNull SecCertificateRef certificate)[@function] SecCertificateCopyNormalizedSubjectSequence Return the certificate's normalized subject The subject is a sequence in the format used by SecItemCopyMatching.static @Nullable SecKeyRefSecCertificateCopyPublicKey(@NotNull SecCertificateRef certificate)Deprecated.static @Nullable CFDataRefSecCertificateCopySerialNumber(@NotNull SecCertificateRef certificate)Deprecated.static @Nullable CFDataRefSecCertificateCopySerialNumberData(@NotNull SecCertificateRef certificate, @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)[@function] SecCertificateCopySerialNumberData Return the certificate's serial number.static @Nullable CFStringRefSecCertificateCopySubjectSummary(@NotNull SecCertificateRef certificate)[@function] SecCertificateCopySubjectSummary Return a simple string which hopefully represents a human understandable summary.static @Nullable SecCertificateRefSecCertificateCreateWithData(@Nullable CFAllocatorRef allocator, @NotNull CFDataRef data)[@function] SecCertificateCreateWithData Create a certificate given it's DER representation as a CFData.static longSecCertificateGetTypeID()[@function] SecCertificateGetTypeID Returns the type identifier of SecCertificate instances.static @Nullable CFStringRefSecCopyErrorMessageString(int status, @Nullable org.moe.natj.general.ptr.VoidPtr reserved)[@function] SecCopyErrorMessageString Returns a string describing the specified error result code.static @Nullable CFStringRefSecCreateSharedWebCredentialPassword()[@function] SecCreateSharedWebCredentialPassword Returns a randomly generated password.static intSecIdentityCopyCertificate(@NotNull SecIdentityRef identityRef, @NotNull org.moe.natj.general.ptr.Ptr<SecCertificateRef> certificateRef)[@function] SecIdentityCopyCertificate Returns a reference to a certificate for the given identity reference.static intSecIdentityCopyPrivateKey(@NotNull SecIdentityRef identityRef, @NotNull org.moe.natj.general.ptr.Ptr<SecKeyRef> privateKeyRef)[@function] SecIdentityCopyPrivateKey Returns the private key associated with an identity.static longSecIdentityGetTypeID()[@function] SecIdentityGetTypeID Returns the type identifier of SecIdentity instances.static intSecItemAdd(@NotNull CFDictionaryRef attributes, @Nullable org.moe.natj.general.ptr.Ptr<org.moe.natj.general.ptr.ConstVoidPtr> result)[@function] SecItemAdd Add one or more items to a keychain.static intSecItemCopyMatching(@NotNull CFDictionaryRef query, @Nullable org.moe.natj.general.ptr.Ptr<org.moe.natj.general.ptr.ConstVoidPtr> result)[@function] SecItemCopyMatching Returns one or more items which match a search query.static intSecItemDelete(@NotNull CFDictionaryRef query)[@function] SecItemDelete Delete zero or more items which match a search query.static intSecItemUpdate(@NotNull CFDictionaryRef query, @NotNull CFDictionaryRef attributesToUpdate)[@function] SecItemUpdate Modify zero or more items which match a search query.static @Nullable CFDictionaryRefSecKeyCopyAttributes(@NotNull SecKeyRef key)[@function] SecKeyCopyAttributes Retrieve keychain attributes of a key.static @Nullable CFDataRefSecKeyCopyExternalRepresentation(@NotNull SecKeyRef key, @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)[@function] SecKeyCopyExternalRepresentation Create an external representation for the given key suitable for the key's type.static @Nullable CFDataRefSecKeyCopyKeyExchangeResult(@NotNull SecKeyRef privateKey, @NotNull CFStringRef algorithm, @NotNull SecKeyRef publicKey, @NotNull CFDictionaryRef parameters, @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)[@function] SecKeyCopyKeyExchangeResult Perform Diffie-Hellman style of key exchange operation, optionally with additional key-derivation steps.static @Nullable SecKeyRefSecKeyCopyPublicKey(@NotNull SecKeyRef key)[@function] SecKeyCopyPublicKey Retrieve the public key from a key pair or private key.static @Nullable CFDataRefSecKeyCreateDecryptedData(@NotNull SecKeyRef key, @NotNull CFStringRef algorithm, @NotNull CFDataRef ciphertext, @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)[@function] SecKeyCreateDecryptedData Decrypt a block of ciphertext.static @Nullable CFDataRefSecKeyCreateEncryptedData(@NotNull SecKeyRef key, @NotNull CFStringRef algorithm, @NotNull CFDataRef plaintext, @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)[@function] SecKeyCreateEncryptedData Encrypt a block of plaintext.static @Nullable SecKeyRefSecKeyCreateRandomKey(@NotNull CFDictionaryRef parameters, @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)[@function] SecKeyCreateRandomKey Generates a new public/private key pair.static @Nullable CFDataRefSecKeyCreateSignature(@NotNull SecKeyRef key, @NotNull CFStringRef algorithm, @NotNull CFDataRef dataToSign, @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)[@function] SecKeyCreateSignature Given a private key and data to sign, generate a digital signature.static @Nullable SecKeyRefSecKeyCreateWithData(@NotNull CFDataRef keyData, @NotNull CFDictionaryRef attributes, @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)[@function] SecKeyCreateWithData Create a SecKey from a well-defined external representation.static intSecKeyDecrypt(@NotNull SecKeyRef key, int padding, @NotNull java.lang.String cipherText, long cipherTextLen, @NotNull org.moe.natj.general.ptr.BytePtr plainText, @NotNull org.moe.natj.general.ptr.NUIntPtr plainTextLen)Deprecated.static intSecKeyEncrypt(@NotNull SecKeyRef key, int padding, @NotNull java.lang.String plainText, long plainTextLen, @NotNull org.moe.natj.general.ptr.BytePtr cipherText, @NotNull org.moe.natj.general.ptr.NUIntPtr cipherTextLen)Deprecated.static intSecKeyGeneratePair(@NotNull CFDictionaryRef parameters, @Nullable org.moe.natj.general.ptr.Ptr<SecKeyRef> publicKey, @Nullable org.moe.natj.general.ptr.Ptr<SecKeyRef> privateKey)Deprecated.static longSecKeyGetBlockSize(@NotNull SecKeyRef key)[@function] SecKeyGetBlockSize Returns block length of the key in bytes.static longSecKeyGetTypeID()[@function] SecKeyGetTypeID Returns the type identifier of SecKey instances.static byteSecKeyIsAlgorithmSupported(@NotNull SecKeyRef key, long operation, @NotNull CFStringRef algorithm)[@function] SecKeyIsAlgorithmSupported Checks whether key supports specified algorithm for specified operation.static intSecKeyRawSign(@NotNull SecKeyRef key, int padding, @NotNull java.lang.String dataToSign, long dataToSignLen, @NotNull org.moe.natj.general.ptr.BytePtr sig, @NotNull org.moe.natj.general.ptr.NUIntPtr sigLen)Deprecated.static intSecKeyRawVerify(@NotNull SecKeyRef key, int padding, @NotNull java.lang.String signedData, long signedDataLen, @NotNull java.lang.String sig, long sigLen)Deprecated.static byteSecKeyVerifySignature(@NotNull SecKeyRef key, @NotNull CFStringRef algorithm, @NotNull CFDataRef signedData, @NotNull CFDataRef signature, @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)[@function] SecKeyVerifySignature Given a public key, data which has been signed, and a signature, verify the signature.static intSecPKCS12Import(@NotNull CFDataRef pkcs12_data, @NotNull CFDictionaryRef options, @NotNull org.moe.natj.general.ptr.Ptr<CFArrayRef> items)[@function] SecPKCS12Import Imports the contents of a PKCS12 formatted blob.static @Nullable CFDictionaryRefSecPolicyCopyProperties(@NotNull SecPolicyRef policyRef)[@function] SecPolicyCopyProperties Returns a dictionary of this policy's properties.static @NotNull SecPolicyRefSecPolicyCreateBasicX509()[@function] SecPolicyCreateBasicX509 Returns a policy object for the default X.509 policy.static @Nullable SecPolicyRefSecPolicyCreateRevocation(long revocationFlags)[@function] SecPolicyCreateRevocation Returns a policy object for checking revocation of certificates.static @NotNull SecPolicyRefSecPolicyCreateSSL(byte server, @Nullable CFStringRef hostname)[@function] SecPolicyCreateSSL Returns a policy object for evaluating SSL certificate chains.static @Nullable SecPolicyRefSecPolicyCreateWithProperties(@NotNull org.moe.natj.general.ptr.ConstVoidPtr policyIdentifier, @Nullable CFDictionaryRef properties)[@function] SecPolicyCreateWithProperties Returns a policy object based on an object identifier for the policy type.static longSecPolicyGetTypeID()[@function] SecPolicyGetTypeID Returns the type identifier of SecPolicy instances.static intSecRandomCopyBytes(@Nullable SecRandomRef rnd, long count, @NotNull org.moe.natj.general.ptr.VoidPtr bytes)[@function] SecRandomCopyBytes Return count random bytes in *bytes, allocated by the caller.static voidSecRequestSharedWebCredential(@Nullable CFStringRef fqdn, @Nullable CFStringRef account, @NotNull Security.Block_SecRequestSharedWebCredential completionHandler)Deprecated.static @Nullable CFArrayRefSecTrustCopyCertificateChain(@NotNull SecTrustRef trust)[@function] SecTrustCopyCertificateChain Returns the certificate trust chainstatic intSecTrustCopyCustomAnchorCertificates(@NotNull SecTrustRef trust, @NotNull org.moe.natj.general.ptr.Ptr<CFArrayRef> anchors)[@function] SecTrustCopyCustomAnchorCertificates Returns an array of custom anchor certificates used by a given trust, as set by a prior call to SecTrustSetAnchorCertificates, or NULL if no custom anchors have been specified.static @Nullable CFDataRefSecTrustCopyExceptions(@NotNull SecTrustRef trust)[@function] SecTrustCopyExceptions Returns an opaque cookie which will allow future evaluations of the current certificate to succeed.static @Nullable SecKeyRefSecTrustCopyKey(@NotNull SecTrustRef trust)[@function] SecTrustCopyKey Return the public key for a leaf certificate after it has been evaluated.static intSecTrustCopyPolicies(@NotNull SecTrustRef trust, @NotNull org.moe.natj.general.ptr.Ptr<CFArrayRef> policies)[@function] SecTrustCopyPolicies Returns an array of policies used for this evaluation.static @Nullable CFArrayRefSecTrustCopyProperties(@NotNull SecTrustRef trust)Deprecated.static @Nullable SecKeyRefSecTrustCopyPublicKey(@NotNull SecTrustRef trust)Deprecated.static @Nullable CFDictionaryRefSecTrustCopyResult(@NotNull SecTrustRef trust)[@function] SecTrustCopyResult Returns a dictionary containing information about the evaluated certificate chain for use by clients.static intSecTrustCreateWithCertificates(@NotNull org.moe.natj.general.ptr.ConstVoidPtr certificates, @Nullable org.moe.natj.general.ptr.ConstVoidPtr policies, @NotNull org.moe.natj.general.ptr.Ptr<SecTrustRef> trust)[@function] SecTrustCreateWithCertificates Creates a trust object based on the given certificates and policies.static intSecTrustEvaluate(@NotNull SecTrustRef trust, @NotNull org.moe.natj.general.ptr.IntPtr result)Deprecated.static intSecTrustEvaluateAsync(@NotNull SecTrustRef trust, @Nullable dispatch_queue_t queue, @NotNull Security.Block_SecTrustEvaluateAsync result)Deprecated.static intSecTrustEvaluateAsyncWithError(@NotNull SecTrustRef trust, @NotNull dispatch_queue_t queue, @NotNull Security.Block_SecTrustEvaluateAsyncWithError result)[@function] SecTrustEvaluateAsyncWithError Evaluates a trust reference asynchronously.static booleanSecTrustEvaluateWithError(@NotNull SecTrustRef trust, @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)[@function] SecTrustEvaluateWithError Evaluates a trust reference synchronously.static @Nullable SecCertificateRefSecTrustGetCertificateAtIndex(@NotNull SecTrustRef trust, long ix)Deprecated.static longSecTrustGetCertificateCount(@NotNull SecTrustRef trust)[@function] SecTrustGetCertificateCount Returns the number of certificates in an evaluated certificate chain.static intSecTrustGetNetworkFetchAllowed(@NotNull SecTrustRef trust, @NotNull org.moe.natj.general.ptr.BytePtr allowFetch)[@function] SecTrustGetNetworkFetchAllowed Returns whether a trust evaluation is permitted to fetch missing intermediate certificates from the network.static intSecTrustGetTrustResult(@NotNull SecTrustRef trust, @NotNull org.moe.natj.general.ptr.IntPtr result)[@function] SecTrustGetTrustResult This function replaces SecTrustGetResult for the purpose of obtaining the current evaluation result of a given trust reference.static longSecTrustGetTypeID()[@function] SecTrustGetTypeID Returns the type identifier of SecTrust instances.static doubleSecTrustGetVerifyTime(@NotNull SecTrustRef trust)[@function] SecTrustGetVerifyTime Returns the verify time.static intSecTrustSetAnchorCertificates(@NotNull SecTrustRef trust, @Nullable CFArrayRef anchorCertificates)[@function] SecTrustSetAnchorCertificates Sets the anchor certificates for a given trust.static intSecTrustSetAnchorCertificatesOnly(@NotNull SecTrustRef trust, byte anchorCertificatesOnly)[@function] SecTrustSetAnchorCertificatesOnly Reenables trusting anchor certificates in addition to those passed in via the SecTrustSetAnchorCertificates API.static booleanSecTrustSetExceptions(@NotNull SecTrustRef trust, @Nullable CFDataRef exceptions)[@function] SecTrustSetExceptions Set a trust cookie to be used for evaluating this certificate chain.static intSecTrustSetNetworkFetchAllowed(@NotNull SecTrustRef trust, byte allowFetch)[@function] SecTrustSetNetworkFetchAllowed Specifies whether a trust evaluation is permitted to fetch missing intermediate certificates from the network.static intSecTrustSetOCSPResponse(@NotNull SecTrustRef trust, @Nullable org.moe.natj.general.ptr.ConstVoidPtr responseData)[@function] SecTrustSetOCSPResponse Attach OCSPResponse data to a trust object.static intSecTrustSetPolicies(@NotNull SecTrustRef trust, @NotNull org.moe.natj.general.ptr.ConstVoidPtr policies)[@function] SecTrustSetPolicies Set the policies for which trust should be verified.static intSecTrustSetSignedCertificateTimestamps(@NotNull SecTrustRef trust, @Nullable CFArrayRef sctArray)[@function] SecTrustSignedCertificateTimestamps Attach SignedCertificateTimestamp data to a trust object.static intSecTrustSetVerifyDate(@NotNull SecTrustRef trust, @NotNull CFDateRef verifyDate)[@function] SecTrustSetVerifyDate Set the date for which the trust should be verified.static intSSLAddDistinguishedName(@NotNull SSLContextRef context, @Nullable org.moe.natj.general.ptr.ConstVoidPtr derDN, long derDNLen)Deprecated.static intSSLClose(@NotNull SSLContextRef context)Deprecated.static longSSLContextGetTypeID()Deprecated.static intSSLCopyALPNProtocols(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.Ptr<CFArrayRef> protocols)Deprecated.static intSSLCopyDistinguishedNames(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.Ptr<CFArrayRef> names)Deprecated.static intSSLCopyPeerTrust(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.Ptr<SecTrustRef> trust)Deprecated.static intSSLCopyRequestedPeerName(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.BytePtr peerName, @NotNull org.moe.natj.general.ptr.NUIntPtr peerNameLen)Deprecated.static intSSLCopyRequestedPeerNameLength(@NotNull SSLContextRef ctx, @NotNull org.moe.natj.general.ptr.NUIntPtr peerNameLen)Deprecated.static @Nullable SSLContextRefSSLCreateContext(@Nullable CFAllocatorRef alloc, int protocolSide, int connectionType)Deprecated.static intSSLGetBufferedReadSize(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.NUIntPtr bufferSize)Deprecated.static intSSLGetClientCertificateState(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.IntPtr clientState)Deprecated.static intSSLGetConnection(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.Ptr<org.moe.natj.general.ptr.ConstVoidPtr> connection)Deprecated.static intSSLGetDatagramWriteSize(@NotNull SSLContextRef dtlsContext, @NotNull org.moe.natj.general.ptr.NUIntPtr bufSize)Deprecated.static intSSLGetEnabledCiphers(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.CharPtr ciphers, @NotNull org.moe.natj.general.ptr.NUIntPtr numCiphers)Deprecated.static intSSLGetMaxDatagramRecordSize(@NotNull SSLContextRef dtlsContext, @NotNull org.moe.natj.general.ptr.NUIntPtr maxSize)Deprecated.static intSSLGetNegotiatedCipher(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.CharPtr cipherSuite)Deprecated.static intSSLGetNegotiatedProtocolVersion(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.IntPtr protocol)Deprecated.static intSSLGetNumberEnabledCiphers(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.NUIntPtr numCiphers)Deprecated.static intSSLGetNumberSupportedCiphers(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.NUIntPtr numCiphers)Deprecated.static intSSLGetPeerDomainName(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.BytePtr peerName, @NotNull org.moe.natj.general.ptr.NUIntPtr peerNameLen)Deprecated.static intSSLGetPeerDomainNameLength(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.NUIntPtr peerNameLen)Deprecated.static intSSLGetPeerID(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.Ptr<org.moe.natj.general.ptr.ConstVoidPtr> peerID, @NotNull org.moe.natj.general.ptr.NUIntPtr peerIDLen)Deprecated.static intSSLGetProtocolVersionMax(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.IntPtr maxVersion)Deprecated.static intSSLGetProtocolVersionMin(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.IntPtr minVersion)Deprecated.static intSSLGetSessionOption(@NotNull SSLContextRef context, int option, @NotNull org.moe.natj.general.ptr.BytePtr value)Deprecated.static intSSLGetSessionState(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.IntPtr state)Deprecated.static intSSLGetSupportedCiphers(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.CharPtr ciphers, @NotNull org.moe.natj.general.ptr.NUIntPtr numCiphers)Deprecated.static intSSLHandshake(@NotNull SSLContextRef context)Deprecated.static intSSLRead(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.VoidPtr data, long dataLength, @NotNull org.moe.natj.general.ptr.NUIntPtr processed)Deprecated.static intSSLReHandshake(@NotNull SSLContextRef context)Deprecated.static intSSLSetALPNProtocols(@NotNull SSLContextRef context, @NotNull CFArrayRef protocols)Deprecated.static intSSLSetCertificate(@NotNull SSLContextRef context, @Nullable CFArrayRef certRefs)Deprecated.static intSSLSetClientSideAuthenticate(@NotNull SSLContextRef context, int auth)Deprecated.static intSSLSetConnection(@NotNull SSLContextRef context, @Nullable org.moe.natj.general.ptr.ConstVoidPtr connection)Deprecated.static intSSLSetDatagramHelloCookie(@NotNull SSLContextRef dtlsContext, @Nullable org.moe.natj.general.ptr.ConstVoidPtr cookie, long cookieLen)Deprecated.static intSSLSetEnabledCiphers(@NotNull SSLContextRef context, @NotNull org.moe.natj.general.ptr.ConstCharPtr ciphers, long numCiphers)Deprecated.static intSSLSetEncryptionCertificate(@NotNull SSLContextRef context, @NotNull CFArrayRef certRefs)Deprecated.static intSSLSetError(@NotNull SSLContextRef context, int status)Deprecated.static intSSLSetIOFuncs(@NotNull SSLContextRef context, @NotNull Security.Function_SSLSetIOFuncs_1 readFunc, @NotNull Security.Function_SSLSetIOFuncs_2 writeFunc)Deprecated.static intSSLSetMaxDatagramRecordSize(@NotNull SSLContextRef dtlsContext, long maxSize)Deprecated.static intSSLSetOCSPResponse(@NotNull SSLContextRef context, @NotNull CFDataRef response)Deprecated.static intSSLSetPeerDomainName(@NotNull SSLContextRef context, @Nullable java.lang.String peerName, long peerNameLen)Deprecated.static intSSLSetPeerID(@NotNull SSLContextRef context, @Nullable org.moe.natj.general.ptr.ConstVoidPtr peerID, long peerIDLen)Deprecated.static intSSLSetProtocolVersionMax(@NotNull SSLContextRef context, int maxVersion)Deprecated.static intSSLSetProtocolVersionMin(@NotNull SSLContextRef context, int minVersion)Deprecated.static intSSLSetSessionConfig(@NotNull SSLContextRef context, @NotNull CFStringRef config)Deprecated.static intSSLSetSessionOption(@NotNull SSLContextRef context, int option, byte value)Deprecated.static intSSLSetSessionTicketsEnabled(@NotNull SSLContextRef context, byte enabled)Deprecated.static intSSLWrite(@NotNull SSLContextRef context, @Nullable org.moe.natj.general.ptr.ConstVoidPtr data, long dataLength, @NotNull org.moe.natj.general.ptr.NUIntPtr processed)Deprecated.
-
-
-
Field Detail
-
SECURITY_TYPE_UNIFICATION
public static final double SECURITY_TYPE_UNIFICATION
- See Also:
- Constant Field Values
-
-
Method Detail
-
SecCertificateGetTypeID
public static long SecCertificateGetTypeID()
[@function] SecCertificateGetTypeID Returns the type identifier of SecCertificate instances.- Returns:
- The CFTypeID of SecCertificate instances. API-Since: 2.0
-
SecCertificateCreateWithData
@Nullable public static @Nullable SecCertificateRef SecCertificateCreateWithData(@Nullable @Nullable CFAllocatorRef allocator, @NotNull @NotNull CFDataRef data)
[@function] SecCertificateCreateWithData Create a certificate given it's DER representation as a CFData.- Parameters:
allocator- CFAllocator to allocate the certificate with.data- DER encoded X.509 certificate.- Returns:
- Return NULL if the passed-in data is not a valid DER-encoded X.509 certificate, return a SecCertificateRef otherwise. API-Since: 2.0
-
SecCertificateCopyData
@NotNull public static @NotNull CFDataRef SecCertificateCopyData(@NotNull @NotNull SecCertificateRef certificate)
[@function] SecCertificateCopyData Return the DER representation of an X.509 certificate.- Parameters:
certificate- SecCertificate object created with SecCertificateCreateWithData().- Returns:
- DER encoded X.509 certificate. API-Since: 2.0
-
SecCertificateCopySubjectSummary
@Nullable public static @Nullable CFStringRef SecCertificateCopySubjectSummary(@NotNull @NotNull SecCertificateRef certificate)
[@function] SecCertificateCopySubjectSummary Return a simple string which hopefully represents a human understandable summary. All the data in this string comes from the certificate itself and thus it's in whatever language the certificate itself is in.- Parameters:
certificate- A reference to the certificate from which to derive the subject summary string.- Returns:
- A CFStringRef which the caller should CFRelease() once it's no longer needed. API-Since: 2.0
-
SecIdentityGetTypeID
public static long SecIdentityGetTypeID()
[@function] SecIdentityGetTypeID Returns the type identifier of SecIdentity instances.- Returns:
- The CFTypeID of SecIdentity instances. API-Since: 2.0
-
SecIdentityCopyCertificate
public static int SecIdentityCopyCertificate(@NotNull @NotNull SecIdentityRef identityRef, @NotNull @NotNull org.moe.natj.general.ptr.Ptr<SecCertificateRef> certificateRef)[@function] SecIdentityCopyCertificate Returns a reference to a certificate for the given identity reference.- Parameters:
identityRef- An identity reference.certificateRef- On return, a pointer to the found certificate reference. You are responsible for releasing this reference by calling the CFRelease function.- Returns:
- A result code. See "Security Error Codes" (SecBase.h). API-Since: 2.0
-
SecIdentityCopyPrivateKey
public static int SecIdentityCopyPrivateKey(@NotNull @NotNull SecIdentityRef identityRef, @NotNull @NotNull org.moe.natj.general.ptr.Ptr<SecKeyRef> privateKeyRef)[@function] SecIdentityCopyPrivateKey Returns the private key associated with an identity.- Parameters:
identityRef- An identity reference.privateKeyRef- On return, a pointer to the private key for the given identity. On iOS, the private key must be of class type kSecAppleKeyItemClass. You are responsible for releasing this reference by calling the CFRelease function.- Returns:
- A result code. See "Security Error Codes" (SecBase.h). API-Since: 2.0
-
SecPKCS12Import
public static int SecPKCS12Import(@NotNull @NotNull CFDataRef pkcs12_data, @NotNull @NotNull CFDictionaryRef options, @NotNull @NotNull org.moe.natj.general.ptr.Ptr<CFArrayRef> items)[@function] SecPKCS12Import Imports the contents of a PKCS12 formatted blob.- Parameters:
pkcs12_data- The PKCS#12 formatted data to be imported.options- A dictionary containing import options. A kSecImportExportPassphrase entry is required at minimum. Only password-based PKCS12 blobs are currently supported.items- On return, an array containing a dictionary for every item extracted. Use kSecImportItem constants to access specific elements of these dictionaries. Your code must CFRelease the array when it is no longer needed.- Returns:
- errSecSuccess in case of success. errSecDecode means either the blob can't be read or it is malformed. errSecAuthFailed means an incorrect password was supplied, or data in the container is damaged. API-Since: 2.0
-
SecAccessControlGetTypeID
public static long SecAccessControlGetTypeID()
[@function] SecAccessControlGetTypeID Returns the type identifier of SecAccessControl instances.- Returns:
- The CFTypeID of SecAccessControl instances. API-Since: 8.0
-
SecAccessControlCreateWithFlags
@Nullable public static @Nullable SecAccessControlRef SecAccessControlCreateWithFlags(@Nullable @Nullable CFAllocatorRef allocator, @NotNull @NotNull org.moe.natj.general.ptr.ConstVoidPtr protection, long flags, @Nullable @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)
[@function] SecAccessControlCreateWithFlags Creates new access control object based on protection type and additional flags. Created access control object should be used as a value for kSecAttrAccessControl attribute in SecItemAdd, SecItemUpdate or SecKeyGeneratePair functions. Accessing keychain items or performing operations on keys which are protected by access control objects can block the execution because of UI which can appear to satisfy the access control conditions, therefore it is recommended to either move those potentially blocking operations out of the main application thread or use combination of kSecUseAuthenticationContext and kSecUseAuthenticationUI attributes to control where the UI interaction can appear.- Parameters:
allocator- Allocator to be used by this instance.protection- Protection class to be used for the item. One of kSecAttrAccessible constants.flags- If no flags are set then all operations are allowed.error- Additional error information filled in case of failure.- Returns:
- Newly created access control object. API-Since: 8.0
-
SecItemCopyMatching
public static int SecItemCopyMatching(@NotNull @NotNull CFDictionaryRef query, @Nullable @Nullable org.moe.natj.general.ptr.Ptr<org.moe.natj.general.ptr.ConstVoidPtr> result)[@function] SecItemCopyMatching Returns one or more items which match a search query. Attributes defining a search are specified by adding key/value pairs to the query dictionary. A typical query consists of: * a kSecClass key, whose value is a constant from the Class Constants section that specifies the class of item(s) to be searched * one or more keys from the "Attribute Key Constants" section, whose value is the attribute data to be matched * one or more keys from the "Search Constants" section, whose value is used to further refine the search * a key from the "Return Type Key Constants" section, specifying the type of results desired Result types are specified as follows: * To obtain the data of a matching item (CFDataRef), specify kSecReturnData with a value of kCFBooleanTrue. * To obtain the attributes of a matching item (CFDictionaryRef), specify kSecReturnAttributes with a value of kCFBooleanTrue. * To obtain a reference to a matching item (SecKeychainItemRef, SecKeyRef, SecCertificateRef, or SecIdentityRef), specify kSecReturnRef with a value of kCFBooleanTrue. Note that returning references is supported only for Certificate, Key or Identity items on iOS, watchOS and tvOS. Similarly, returning references is supported only for Certificate, Key or Identity items on macOS when either kSecUseDataProtectionKeychain is set to true or kSecAttrSynchronizable is set to true. * To obtain a persistent reference to a matching item (CFDataRef), specify kSecReturnPersistentRef with a value of kCFBooleanTrue. Note that unlike normal references, a persistent reference may be stored on disk or passed between processes. * If more than one of these result types is specified, the result is returned as a CFDictionaryRef containing all the requested data. * If a result type is not specified, no results are returned. By default, this function returns only the first match found. To obtain more than one matching item at a time, specify kSecMatchLimit with a value greater than 1. The result will be a CFArrayRef containing up to that number of matching items; the items' types are described above. To filter a provided list of items down to those matching the query, specify a kSecMatchItemList whose value is a CFArray of SecKeychainItemRef, SecKeyRef, SecCertificateRef, or SecIdentityRef items. The objects in the provided array must be of the same type. On iOS, to convert from a persistent item reference to a normal item reference, specify a kSecValuePersistentRef whose value a CFDataRef (the persistent reference), and a kSecReturnRef whose value is kCFBooleanTrue. On OSX, to convert from persistent item references to normal item references, specify a kSecMatchItemList whose value is a CFArray containing one or more CFDataRef elements (the persistent reference), and a kSecReturnRef whose value is kCFBooleanTrue. The objects in the provided array must be of the same type. API-Since: 2.0- Parameters:
query- A dictionary containing an item class specification and optional attributes for controlling the search. See the "Keychain Search Attributes" section for a description of currently defined search attributes.result- On return, a CFTypeRef reference to the found item(s). The exact type of the result is based on the search attributes supplied in the query, as discussed below.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecItemAdd
public static int SecItemAdd(@NotNull @NotNull CFDictionaryRef attributes, @Nullable @Nullable org.moe.natj.general.ptr.Ptr<org.moe.natj.general.ptr.ConstVoidPtr> result)[@function] SecItemAdd Add one or more items to a keychain. Attributes defining an item are specified by adding key/value pairs to the attributes dictionary. To add multiple items to a keychain at once use the kSecUseItemList key with an array of items as its value. This is currently only supported for non password items. On OSX, To add an item to a particular keychain, supply kSecUseKeychain with a SecKeychainRef as its value. On iOS, watchOS & tvOS, Certificate, Key, and Identity items may be added by reference, but neither Internet Passwords nor Generic Passwords may be. Similarly, on macOS with either kSecUseDataProtectionKeychain set to true or kSecAttrSynchronizable set to true, Certificate, Key, and Identity items may be added by reference, but neither Internet Passwords nor Generic Passwords may be. Result types are specified as follows: * To obtain the data of the added item (CFDataRef), specify kSecReturnData with a value of kCFBooleanTrue. * To obtain all the attributes of the added item (CFDictionaryRef), specify kSecReturnAttributes with a value of kCFBooleanTrue. * To obtain a reference to the added item (SecKeychainItemRef, SecKeyRef, SecCertificateRef, or SecIdentityRef), specify kSecReturnRef with a value of kCFBooleanTrue. See also note about kSecReturnRef and macOS. * To obtain a persistent reference to the added item (CFDataRef), specify kSecReturnPersistentRef with a value of kCFBooleanTrue. Note that unlike normal references, a persistent reference may be stored on disk or passed between processes. * If more than one of these result types is specified, the result is returned as a CFDictionaryRef containing all the requested data. * On iOS, if a result type is not specified, no results are returned. On OSX, the added item is returned. API-Since: 2.0- Parameters:
attributes- A dictionary containing an item class specification and optional entries specifying the item's attribute values. See the "Attribute Key Constants" section for a description of currently defined attributes.result- On return, a CFTypeRef reference to the newly added item(s). The exact type of the result is based on the values supplied in attributes, as discussed below. Pass NULL if this result is not required.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecItemUpdate
public static int SecItemUpdate(@NotNull @NotNull CFDictionaryRef query, @NotNull @NotNull CFDictionaryRef attributesToUpdate)[@function] SecItemUpdate Modify zero or more items which match a search query. Attributes defining a search are specified by adding key/value pairs to the query dictionary. API-Since: 2.0- Parameters:
query- A dictionary containing an item class specification and optional attributes for controlling the search. See the "Attribute Constants" and "Search Constants" sections for a description of currently defined search attributes.attributesToUpdate- A dictionary containing one or more attributes whose values should be set to the ones specified. Only real keychain attributes are permitted in this dictionary (no "meta" attributes are allowed.) See the "Attribute Key Constants" section for a description of currently defined value attributes.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecItemDelete
public static int SecItemDelete(@NotNull @NotNull CFDictionaryRef query)[@function] SecItemDelete Delete zero or more items which match a search query. Attributes defining a search are specified by adding key/value pairs to the query dictionary. By default, this function deletes all items matching the specified query. You can change this behavior by specifying one of the follow keys: * To delete an item identified by a transient reference, on iOS, specify kSecValueRef with a item reference. On OS X, give a kSecMatchItemList containing an item reference. * To delete an item identified by a persistent reference, on iOS, specify kSecValuePersistentRef with a persistent reference returned by using the kSecReturnPersistentRef key to SecItemCopyMatching or SecItemAdd. on OSX, use kSecMatchItemList with a persistent reference returned by using the kSecReturnPersistentRef key with SecItemCopyMatching or SecItemAdd. * To delete multiple items specify kSecMatchItemList with an array of references. * If more than one of these result keys is specified, the behavior is undefined. API-Since: 2.0- Parameters:
query- A dictionary containing an item class specification and optional attributes for controlling the search. See the "Attribute Constants" and "Search Constants" sections for a description of currently defined search attributes.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecKeyGetTypeID
public static long SecKeyGetTypeID()
[@function] SecKeyGetTypeID Returns the type identifier of SecKey instances.- Returns:
- The CFTypeID of SecKey instances. API-Since: 2.0
-
SecKeyGeneratePair
@Deprecated public static int SecKeyGeneratePair(@NotNull @NotNull CFDictionaryRef parameters, @Nullable @Nullable org.moe.natj.general.ptr.Ptr<SecKeyRef> publicKey, @Nullable @Nullable org.moe.natj.general.ptr.Ptr<SecKeyRef> privateKey)Deprecated.[@function] SecKeyGeneratePair Generate a private/public keypair. In order to generate a keypair the parameters dictionary must at least contain the following keys: * kSecAttrKeyType with a value of kSecAttrKeyTypeRSA or any other kSecAttrKeyType defined in SecItem.h * kSecAttrKeySizeInBits with a value being a CFNumberRef containing the requested key size in bits. Example sizes for RSA keys are: 512, 768, 1024, 2048. The values below may be set either in the top-level dictionary or in a dictionary that is the value of the kSecPrivateKeyAttrs or kSecPublicKeyAttrs key in the top-level dictionary. Setting these attributes explicitly will override the defaults below. See SecItem.h for detailed information on these attributes including the types of the values. * kSecAttrLabel default NULL * kSecUseKeychain default NULL, which specifies the default keychain * kSecAttrIsPermanent default false if this key is present and has a Boolean value of true, the key or key pair will be added to the keychain. * kSecAttrTokenID default NULL The CFStringRef ID of the token to generate the key or keypair on. This attribute can contain CFStringRef and can be present only in the top-level parameters dictionary. * kSecAttrApplicationTag default NULL * kSecAttrEffectiveKeySize default NULL same as kSecAttrKeySizeInBits * kSecAttrCanEncrypt default false for private keys, true for public keys * kSecAttrCanDecrypt default true for private keys, false for public keys * kSecAttrCanDerive default true * kSecAttrCanSign default true for private keys, false for public keys * kSecAttrCanVerify default false for private keys, true for public keys * kSecAttrCanWrap default false for private keys, true for public keys * kSecAttrCanUnwrap default true for private keys, false for public keys NOTE: The function always saves keys in the keychain on macOS and as such attribute kSecAttrIsPermanent is ignored. The function respects attribute kSecAttrIsPermanent on iOS, tvOS and watchOS. It is recommended to use SecKeyCreateRandomKey() which respects kSecAttrIsPermanent on all platforms. API-Since: 2.0 Deprecated-Since: 15.0 Deprecated-Message: Use SecKeyCreateRandomKey- Parameters:
parameters- A dictionary containing one or more key-value pairs. See the discussion sections below for a complete overview of options.publicKey- On return, a SecKeyRef reference to the public key.privateKey- On return, a SecKeyRef reference to the private key.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecKeyRawSign
@Deprecated public static int SecKeyRawSign(@NotNull @NotNull SecKeyRef key, int padding, @NotNull @NotNull java.lang.String dataToSign, long dataToSignLen, @NotNull @NotNull org.moe.natj.general.ptr.BytePtr sig, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr sigLen)Deprecated.[@function] SecKeyRawSign Given a private key and data to sign, generate a digital signature. If the padding argument is kSecPaddingPKCS1, PKCS1 padding will be performed prior to signing. If this argument is kSecPaddingNone, the incoming data will be signed "as is". When PKCS1 padding is performed, the maximum length of data that can be signed is the value returned by SecKeyGetBlockSize() - 11. NOTE: The behavior this function with kSecPaddingNone is undefined if the first byte of dataToSign is zero; there is no way to verify leading zeroes as they are discarded during the calculation. If you want to generate a proper PKCS1 style signature with DER encoding of the digest type - and the dataToSign is a SHA1 digest - use kSecPaddingPKCS1SHA1. API-Since: 2.0 Deprecated-Since: 15.0 Deprecated-Message: Use SecKeyCreateSignature- Parameters:
key- Private key with which to sign.padding- See Padding Types above, typically kSecPaddingPKCS1SHA1.dataToSign- The data to be signed, typically the digest of the actual data.dataToSignLen- Length of dataToSign in bytes.sig- Pointer to buffer in which the signature will be returned.sigLen- IN/OUT maximum length of sig buffer on input, actualy length of sig on output.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecKeyRawVerify
@Deprecated public static int SecKeyRawVerify(@NotNull @NotNull SecKeyRef key, int padding, @NotNull @NotNull java.lang.String signedData, long signedDataLen, @NotNull @NotNull java.lang.String sig, long sigLen)Deprecated.[@function] SecKeyRawVerify Given a public key, data which has been signed, and a signature, verify the signature. If the padding argument is kSecPaddingPKCS1, PKCS1 padding will be checked during verification. If this argument is kSecPaddingNone, the incoming data will be compared directly to sig. If you are verifying a proper PKCS1-style signature, with DER encoding of the digest type - and the signedData is a SHA1 digest - use kSecPaddingPKCS1SHA1. API-Since: 2.0 Deprecated-Since: 15.0 Deprecated-Message: Use SecKeyVerifySignature- Parameters:
key- Public key with which to verify the signature.padding- See Padding Types above, typically kSecPaddingPKCS1SHA1.signedData- The data over which sig is being verified, typically the digest of the actual data.signedDataLen- Length of signedData in bytes.sig- Pointer to the signature to verify.sigLen- Length of sig in bytes.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecKeyEncrypt
@Deprecated public static int SecKeyEncrypt(@NotNull @NotNull SecKeyRef key, int padding, @NotNull @NotNull java.lang.String plainText, long plainTextLen, @NotNull @NotNull org.moe.natj.general.ptr.BytePtr cipherText, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr cipherTextLen)Deprecated.[@function] SecKeyEncrypt Encrypt a block of plaintext. If the padding argument is kSecPaddingPKCS1 or kSecPaddingOAEP, PKCS1 (respectively kSecPaddingOAEP) padding will be performed prior to encryption. If this argument is kSecPaddingNone, the incoming data will be encrypted "as is". kSecPaddingOAEP is the recommended value. Other value are not recommended for security reason (Padding attack or malleability). When PKCS1 padding is performed, the maximum length of data that can be encrypted is the value returned by SecKeyGetBlockSize() - 11. When memory usage is a critical issue, note that the input buffer (plainText) can be the same as the output buffer (cipherText). API-Since: 2.0 Deprecated-Since: 15.0 Deprecated-Message: Use SecKeyCreateEncryptedData- Parameters:
key- Public key with which to encrypt the data.padding- See Padding Types above, typically kSecPaddingPKCS1.plainText- The data to encrypt.plainTextLen- Length of plainText in bytes, this must be less or equal to the value returned by SecKeyGetBlockSize().cipherText- Pointer to the output buffer.cipherTextLen- On input, specifies how much space is available at cipherText; on return, it is the actual number of cipherText bytes written.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecKeyDecrypt
@Deprecated public static int SecKeyDecrypt(@NotNull @NotNull SecKeyRef key, int padding, @NotNull @NotNull java.lang.String cipherText, long cipherTextLen, @NotNull @NotNull org.moe.natj.general.ptr.BytePtr plainText, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr plainTextLen)Deprecated.[@function] SecKeyDecrypt Decrypt a block of ciphertext. If the padding argument is kSecPaddingPKCS1 or kSecPaddingOAEP, the corresponding padding will be removed after decryption. If this argument is kSecPaddingNone, the decrypted data will be returned "as is". When memory usage is a critical issue, note that the input buffer (plainText) can be the same as the output buffer (cipherText). API-Since: 2.0 Deprecated-Since: 15.0 Deprecated-Message: Use SecKeyCreateDecryptedData- Parameters:
key- Private key with which to decrypt the data.padding- See Padding Types above, typically kSecPaddingPKCS1.cipherText- The data to decrypt.cipherTextLen- Length of cipherText in bytes, this must be less or equal to the value returned by SecKeyGetBlockSize().plainText- Pointer to the output buffer.plainTextLen- On input, specifies how much space is available at plainText; on return, it is the actual number of plainText bytes written.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecKeyGetBlockSize
public static long SecKeyGetBlockSize(@NotNull @NotNull SecKeyRef key)[@function] SecKeyGetBlockSize Returns block length of the key in bytes. If for example key is an RSA key the value returned by this function is the size of the modulus. API-Since: 2.0- Parameters:
key- The key for which the block length is requested.- Returns:
- The block length of the key in bytes.
-
SecKeyCreateRandomKey
@Nullable public static @Nullable SecKeyRef SecKeyCreateRandomKey(@NotNull @NotNull CFDictionaryRef parameters, @Nullable @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)
[@function] SecKeyCreateRandomKey Generates a new public/private key pair. In order to generate a keypair the parameters dictionary must at least contain the following keys: * kSecAttrKeyType with a value being kSecAttrKeyTypeRSA or any other kSecAttrKeyType defined in SecItem.h * kSecAttrKeySizeInBits with a value being a CFNumberRef or CFStringRef containing the requested key size in bits. Example sizes for RSA keys are: 512, 768, 1024, 2048. The values below may be set either in the top-level dictionary or in a dictionary that is the value of the kSecPrivateKeyAttrs or kSecPublicKeyAttrs key in the top-level dictionary. Setting these attributes explicitly will override the defaults below. See SecItem.h for detailed information on these attributes including the types of the values. * kSecAttrLabel default NULL * kSecAttrIsPermanent if this key is present and has a Boolean value of true, the key or key pair will be added to the default keychain. * kSecAttrTokenID if this key should be generated on specified token. This attribute can contain CFStringRef and can be present only in the top-level parameters dictionary. * kSecAttrApplicationTag default NULL * kSecAttrEffectiveKeySize default NULL same as kSecAttrKeySizeInBits * kSecAttrCanEncrypt default false for private keys, true for public keys * kSecAttrCanDecrypt default true for private keys, false for public keys * kSecAttrCanDerive default true * kSecAttrCanSign default true for private keys, false for public keys * kSecAttrCanVerify default false for private keys, true for public keys * kSecAttrCanWrap default false for private keys, true for public keys * kSecAttrCanUnwrap default true for private keys, false for public keys API-Since: 10.0- Parameters:
parameters- A dictionary containing one or more key-value pairs. See the discussion sections below for a complete overview of options.error- On error, will be populated with an error object describing the failure. See "Security Error Codes" (SecBase.h).- Returns:
- Newly generated private key. To get associated public key, use SecKeyCopyPublicKey().
-
SecKeyCreateWithData
@Nullable public static @Nullable SecKeyRef SecKeyCreateWithData(@NotNull @NotNull CFDataRef keyData, @NotNull @NotNull CFDictionaryRef attributes, @Nullable @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)
[@function] SecKeyCreateWithData Create a SecKey from a well-defined external representation. This function does not add keys to any keychain, but the SecKey object it returns can be added to keychain using the SecItemAdd function. The requested data format depend on the type of key (kSecAttrKeyType) being created: * kSecAttrKeyTypeRSA PKCS#1 format, public key can be also in x509 public key format * kSecAttrKeyTypeECSECPrimeRandom ANSI X9.63 format (04 || X || Y [ || K]) API-Since: 10.0- Parameters:
keyData- CFData representing the key. The format of the data depends on the type of key being created.attributes- Dictionary containing attributes describing the key to be imported. The keys in this dictionary are kSecAttr* constants from SecItem.h. Mandatory attributes are: * kSecAttrKeyType * kSecAttrKeyClasserror- On error, will be populated with an error object describing the failure. See "Security Error Codes" (SecBase.h).- Returns:
- A SecKey object representing the key, or NULL on failure.
-
SecKeyCopyExternalRepresentation
@Nullable public static @Nullable CFDataRef SecKeyCopyExternalRepresentation(@NotNull @NotNull SecKeyRef key, @Nullable @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)
[@function] SecKeyCopyExternalRepresentation Create an external representation for the given key suitable for the key's type. This function may fail if the key is not exportable (e.g., bound to a smart card or Secure Enclave). The format in which the key will be exported depends on the type of key: * kSecAttrKeyTypeRSA PKCS#1 format * kSecAttrKeyTypeECSECPrimeRandom ANSI X9.63 format (04 || X || Y [ || K]) API-Since: 10.0- Parameters:
key- The key to be exported.error- On error, will be populated with an error object describing the failure. See "Security Error Codes" (SecBase.h).- Returns:
- A CFData representing the key in a format suitable for that key type.
-
SecKeyCopyAttributes
@Nullable public static @Nullable CFDictionaryRef SecKeyCopyAttributes(@NotNull @NotNull SecKeyRef key)
[@function] SecKeyCopyAttributes Retrieve keychain attributes of a key. The attributes provided by this function are: * kSecAttrCanEncrypt * kSecAttrCanDecrypt * kSecAttrCanDerive * kSecAttrCanSign * kSecAttrCanVerify * kSecAttrKeyClass * kSecAttrKeyType * kSecAttrKeySizeInBits * kSecAttrTokenID * kSecAttrApplicationLabel The set of values is not fixed. Future versions may return more values in this dictionary. API-Since: 10.0- Parameters:
key- The key whose attributes are to be retrieved.- Returns:
- Dictionary containing attributes of the key. The keys that populate this dictionary are defined and discussed in SecItem.h.
-
SecKeyCopyPublicKey
@Nullable public static @Nullable SecKeyRef SecKeyCopyPublicKey(@NotNull @NotNull SecKeyRef key)
[@function] SecKeyCopyPublicKey Retrieve the public key from a key pair or private key. Fails if key does not contain a public key or no public key can be computed from it. API-Since: 10.0- Parameters:
key- The key from which to retrieve a public key.- Returns:
- The public key or NULL if public key is not available for specified key.
-
SecKeyCreateSignature
@Nullable public static @Nullable CFDataRef SecKeyCreateSignature(@NotNull @NotNull SecKeyRef key, @NotNull @NotNull CFStringRef algorithm, @NotNull @NotNull CFDataRef dataToSign, @Nullable @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)
[@function] SecKeyCreateSignature Given a private key and data to sign, generate a digital signature. Computes digital signature using specified key over input data. The operation algorithm further defines the exact format of input data, operation to be performed and output signature. API-Since: 10.0- Parameters:
key- Private key with which to sign.algorithm- One of SecKeyAlgorithm constants suitable to generate signature with this key.dataToSign- The data to be signed, typically the digest of the actual data.error- On error, will be populated with an error object describing the failure. See "Security Error Codes" (SecBase.h).- Returns:
- The signature over dataToSign represented as a CFData, or NULL on failure.
-
SecKeyVerifySignature
public static byte SecKeyVerifySignature(@NotNull @NotNull SecKeyRef key, @NotNull @NotNull CFStringRef algorithm, @NotNull @NotNull CFDataRef signedData, @NotNull @NotNull CFDataRef signature, @Nullable @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)[@function] SecKeyVerifySignature Given a public key, data which has been signed, and a signature, verify the signature. Verifies digital signature operation using specified key and signed data. The operation algorithm further defines the exact format of input data, signature and operation to be performed. API-Since: 10.0- Parameters:
key- Public key with which to verify the signature.algorithm- One of SecKeyAlgorithm constants suitable to verify signature with this key.signedData- The data over which sig is being verified, typically the digest of the actual data.signature- The signature to verify.error- On error, will be populated with an error object describing the failure. See "Security Error Codes" (SecBase.h).- Returns:
- True if the signature was valid, False otherwise.
-
SecKeyCreateEncryptedData
@Nullable public static @Nullable CFDataRef SecKeyCreateEncryptedData(@NotNull @NotNull SecKeyRef key, @NotNull @NotNull CFStringRef algorithm, @NotNull @NotNull CFDataRef plaintext, @Nullable @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)
[@function] SecKeyCreateEncryptedData Encrypt a block of plaintext. Encrypts plaintext data using specified key. The exact type of the operation including the format of input and output data is specified by encryption algorithm. API-Since: 10.0- Parameters:
key- Public key with which to encrypt the data.algorithm- One of SecKeyAlgorithm constants suitable to perform encryption with this key.plaintext- The data to encrypt. The length and format of the data must conform to chosen algorithm, typically be less or equal to the value returned by SecKeyGetBlockSize().error- On error, will be populated with an error object describing the failure. See "Security Error Codes" (SecBase.h).- Returns:
- The ciphertext represented as a CFData, or NULL on failure.
-
SecKeyCreateDecryptedData
@Nullable public static @Nullable CFDataRef SecKeyCreateDecryptedData(@NotNull @NotNull SecKeyRef key, @NotNull @NotNull CFStringRef algorithm, @NotNull @NotNull CFDataRef ciphertext, @Nullable @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)
[@function] SecKeyCreateDecryptedData Decrypt a block of ciphertext. Decrypts ciphertext data using specified key. The exact type of the operation including the format of input and output data is specified by decryption algorithm. API-Since: 10.0- Parameters:
key- Private key with which to decrypt the data.algorithm- One of SecKeyAlgorithm constants suitable to perform decryption with this key.ciphertext- The data to decrypt. The length and format of the data must conform to chosen algorithm, typically be less or equal to the value returned by SecKeyGetBlockSize().error- On error, will be populated with an error object describing the failure. See "Security Error Codes" (SecBase.h).- Returns:
- The plaintext represented as a CFData, or NULL on failure.
-
SecKeyCopyKeyExchangeResult
@Nullable public static @Nullable CFDataRef SecKeyCopyKeyExchangeResult(@NotNull @NotNull SecKeyRef privateKey, @NotNull @NotNull CFStringRef algorithm, @NotNull @NotNull SecKeyRef publicKey, @NotNull @NotNull CFDictionaryRef parameters, @Nullable @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)
[@function] SecKeyCopyKeyExchangeResult Perform Diffie-Hellman style of key exchange operation, optionally with additional key-derivation steps.- Parameters:
algorithm- One of SecKeyAlgorithm constants suitable to perform this operation.publicKey- Remote party's public key.parameters- Dictionary with parameters, see SecKeyKeyExchangeParameter constants. Used algorithm determines the set of required and optional parameters to be used.error- Pointer to an error object on failure. See "Security Error Codes" (SecBase.h).- Returns:
- Result of key exchange operation as a CFDataRef, or NULL on failure. API-Since: 10.0
-
SecKeyIsAlgorithmSupported
public static byte SecKeyIsAlgorithmSupported(@NotNull @NotNull SecKeyRef key, long operation, @NotNull @NotNull CFStringRef algorithm)[@function] SecKeyIsAlgorithmSupported Checks whether key supports specified algorithm for specified operation.- Parameters:
key- Key to queryoperation- Operation type for which the key is queriedalgorithm- Algorithm which is queried- Returns:
- True if key supports specified algorithm for specified operation, False otherwise. API-Since: 10.0
-
SecPolicyGetTypeID
public static long SecPolicyGetTypeID()
[@function] SecPolicyGetTypeID Returns the type identifier of SecPolicy instances.- Returns:
- The CFTypeID of SecPolicy instances. API-Since: 2.0
-
SecPolicyCopyProperties
@Nullable public static @Nullable CFDictionaryRef SecPolicyCopyProperties(@NotNull @NotNull SecPolicyRef policyRef)
[@function] SecPolicyCopyProperties Returns a dictionary of this policy's properties. This function returns the properties for a policy, as set by the policy's construction function or by a prior call to SecPolicySetProperties. API-Since: 7.0- Parameters:
policyRef- A policy reference.- Returns:
- A properties dictionary. See "Policy Value Constants" for a list of currently defined property keys. It is the caller's responsibility to CFRelease this reference when it is no longer needed.
-
SecPolicyCreateBasicX509
@NotNull public static @NotNull SecPolicyRef SecPolicyCreateBasicX509()
[@function] SecPolicyCreateBasicX509 Returns a policy object for the default X.509 policy.- Returns:
- A policy object. The caller is responsible for calling CFRelease on this when it is no longer needed. API-Since: 2.0
-
SecPolicyCreateSSL
@NotNull public static @NotNull SecPolicyRef SecPolicyCreateSSL(byte server, @Nullable @Nullable CFStringRef hostname)
[@function] SecPolicyCreateSSL Returns a policy object for evaluating SSL certificate chains.- Parameters:
server- Passing true for this parameter creates a policy for SSL server certificates.hostname- (Optional) If present, the policy will require the specified hostname to match the hostname in the leaf certificate.- Returns:
- A policy object. The caller is responsible for calling CFRelease on this when it is no longer needed. API-Since: 2.0
-
SecPolicyCreateRevocation
@Nullable public static @Nullable SecPolicyRef SecPolicyCreateRevocation(long revocationFlags)
[@function] SecPolicyCreateRevocation Returns a policy object for checking revocation of certificates. Use this function to create a revocation policy with behavior specified by revocationFlags. See the "Revocation Policy Constants" section for a description of these flags. Note: it is usually not necessary to create a revocation policy yourself unless you wish to override default system behavior (e.g. to force a particular method, or to disable revocation checking entirely.) API-Since: 7.0- Parameters:
revocationFlags- Flags to specify revocation checking options.- Returns:
- A policy object. The caller is responsible for calling CFRelease on this when it is no longer needed.
-
SecPolicyCreateWithProperties
@Nullable public static @Nullable SecPolicyRef SecPolicyCreateWithProperties(@NotNull @NotNull org.moe.natj.general.ptr.ConstVoidPtr policyIdentifier, @Nullable @Nullable CFDictionaryRef properties)
[@function] SecPolicyCreateWithProperties Returns a policy object based on an object identifier for the policy type. See the "Policy Constants" section for a list of defined policy object identifiers.- Parameters:
policyIdentifier- The identifier for the desired policy type.properties- (Optional) A properties dictionary. See "Policy Value Constants" for a list of currently defined property keys.- Returns:
- The returned policy reference, or NULL if the policy could not be created. API-Since: 7.0
-
SecRandomCopyBytes
public static int SecRandomCopyBytes(@Nullable @Nullable SecRandomRef rnd, long count, @NotNull @NotNull org.moe.natj.general.ptr.VoidPtr bytes)[@function] SecRandomCopyBytes Return count random bytes in *bytes, allocated by the caller. It is critical to check the return value for error. If @p rnd is unrecognized or unsupported, @p kSecRandomDefault is used. API-Since: 2.0- Parameters:
rnd- Only @p kSecRandomDefault is supported.count- The number of bytes to generate.bytes- A buffer to fill with random output.- Returns:
- Return 0 on success, any other value on failure.
-
SecAddSharedWebCredential
public static void SecAddSharedWebCredential(@NotNull @NotNull CFStringRef fqdn, @NotNull @NotNull CFStringRef account, @Nullable @Nullable CFStringRef password, @NotNull @NotNull Security.Block_SecAddSharedWebCredential completionHandler)[@function] SecAddSharedWebCredential Asynchronously store (or update) a shared password for a website. This function adds a shared password item which will be accessible by Safari and applications that have the specified fully-qualified domain name in their 'com.apple.developer.associated-domains' entitlement. If a shared password item already exists for the specified website and account, it will be updated with the provided password. To remove a password, pass NULL for the password parameter. Note: since a request involving shared web credentials may potentially require user interaction or other verification to be approved, this function is dispatched asynchronously; your code provides a completion handler that will be called once the results (if any) are available. API-Since: 8.0- Parameters:
fqdn- The fully qualified domain name of the website requiring the password.account- The account name associated with this password.password- The password to be stored. Pass NULL to remove a shared password if it exists.completionHandler- A block which will be invoked when the function has completed. If the shared password was successfully added (or removed), the CFErrorRef parameter passed to the block will be NULL. If the error parameter is non-NULL, an error occurred and the error reference will hold the result. Note: the error reference will be automatically released after this handler is called, though you may optionally retain it for as long as needed.
-
SecRequestSharedWebCredential
@Deprecated public static void SecRequestSharedWebCredential(@Nullable @Nullable CFStringRef fqdn, @Nullable @Nullable CFStringRef account, @NotNull @NotNull Security.Block_SecRequestSharedWebCredential completionHandler)Deprecated.[@function] SecRequestSharedWebCredential Asynchronously obtain one or more shared passwords for a website. This function requests one or more shared passwords for a given website, depending on whether the optional account parameter is supplied. To obtain results, the website specified in the fqdn parameter must be one which matches an entry in the calling application's 'com.apple.developer.associated-domains' entitlement. If matching shared password items are found, the credentials provided to the completionHandler will be a CFArrayRef containing CFDictionaryRef entries. Each dictionary entry will contain the following pairs (see Security/SecItem.h): key: kSecAttrServer value: CFStringRef (the website) key: kSecAttrAccount value: CFStringRef (the account) key: kSecSharedPassword value: CFStringRef (the password) If the found item specifies a non-standard port number (i.e. other than 443 for https), the following key may also be present: key: kSecAttrPort value: CFNumberRef (the port number) Note: since a request involving shared web credentials may potentially require user interaction or other verification to be approved, this function is dispatched asynchronously; your code provides a completion handler that will be called once the results (if any) are available. API-Since: 8.0 Deprecated-Since: 14.0 Deprecated-Message: Use ASAuthorizationController to make an ASAuthorizationPasswordRequest (AuthenticationServices framework)- Parameters:
fqdn- (Optional) Fully qualified domain name of the website for which passwords are being requested. If NULL is passed in this argument, the domain name(s) listed in the calling application's 'com.apple.developer.associated-domains' entitlement are searched implicitly.account- (Optional) Account name for which passwords are being requested. The account may be NULL to request all shared credentials which are available for the site, allowing the caller to discover an existing account.completionHandler- A block which will be called to deliver the requested credentials. If no matching items were found, the credentials array will be empty, and the CFErrorRef parameter will provide the error result. Note: the credentials and error references will be automatically released after this handler is called, though you may optionally retain either for as long as needed.
-
SecCreateSharedWebCredentialPassword
@Nullable public static @Nullable CFStringRef SecCreateSharedWebCredentialPassword()
[@function] SecCreateSharedWebCredentialPassword Returns a randomly generated password.- Returns:
- CFStringRef password in the form xxx-xxx-xxx-xxx where x is taken from the sets "abcdefghkmnopqrstuvwxy", "ABCDEFGHJKLMNPQRSTUVWXYZ", "3456789" with at least one character from each set being present. API-Since: 8.0
-
SecTrustGetTypeID
public static long SecTrustGetTypeID()
[@function] SecTrustGetTypeID Returns the type identifier of SecTrust instances.- Returns:
- The CFTypeID of SecTrust instances. API-Since: 2.0
-
SecTrustCreateWithCertificates
public static int SecTrustCreateWithCertificates(@NotNull @NotNull org.moe.natj.general.ptr.ConstVoidPtr certificates, @Nullable @Nullable org.moe.natj.general.ptr.ConstVoidPtr policies, @NotNull @NotNull org.moe.natj.general.ptr.Ptr<SecTrustRef> trust)[@function] SecTrustCreateWithCertificates Creates a trust object based on the given certificates and policies. If multiple policies are passed in, all policies must verify for the chain to be considered valid. API-Since: 2.0- Parameters:
certificates- The group of certificates to verify. This can either be a CFArrayRef of SecCertificateRef objects or a single SecCertificateRefpolicies- An array of one or more policies. You may pass a SecPolicyRef to represent a single policy.trust- On return, a pointer to the trust management reference.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecTrustSetPolicies
public static int SecTrustSetPolicies(@NotNull @NotNull SecTrustRef trust, @NotNull @NotNull org.moe.natj.general.ptr.ConstVoidPtr policies)[@function] SecTrustSetPolicies Set the policies for which trust should be verified. This function will invalidate the existing trust result, requiring a fresh evaluation for the newly-set policies. API-Since: 6.0- Parameters:
trust- A trust reference.policies- An array of one or more policies. You may pass a SecPolicyRef to represent a single policy.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecTrustCopyPolicies
public static int SecTrustCopyPolicies(@NotNull @NotNull SecTrustRef trust, @NotNull @NotNull org.moe.natj.general.ptr.Ptr<CFArrayRef> policies)[@function] SecTrustCopyPolicies Returns an array of policies used for this evaluation.- Parameters:
trust- A reference to a trust object.policies- On return, an array of policies used by this trust. Call the CFRelease function to release this reference.- Returns:
- A result code. See "Security Error Codes" (SecBase.h). API-Since: 7.0
-
SecTrustSetNetworkFetchAllowed
public static int SecTrustSetNetworkFetchAllowed(@NotNull @NotNull SecTrustRef trust, byte allowFetch)[@function] SecTrustSetNetworkFetchAllowed Specifies whether a trust evaluation is permitted to fetch missing intermediate certificates from the network. By default, network fetch of missing certificates is enabled if the trust evaluation includes the SSL policy, otherwise it is disabled. API-Since: 7.0- Parameters:
trust- A trust reference.allowFetch- If true, and a certificate's issuer is not present in the trust reference but its network location is known, the evaluation is permitted to attempt to download it automatically. Pass false to disable network fetch for this trust evaluation.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecTrustGetNetworkFetchAllowed
public static int SecTrustGetNetworkFetchAllowed(@NotNull @NotNull SecTrustRef trust, @NotNull @NotNull org.moe.natj.general.ptr.BytePtr allowFetch)[@function] SecTrustGetNetworkFetchAllowed Returns whether a trust evaluation is permitted to fetch missing intermediate certificates from the network. By default, network fetch of missing certificates is enabled if the trust evaluation includes the SSL policy, otherwise it is disabled. API-Since: 7.0- Parameters:
trust- A trust reference.allowFetch- On return, the boolean pointed to by this parameter is set to true if the evaluation is permitted to download missing certificates.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecTrustSetAnchorCertificates
public static int SecTrustSetAnchorCertificates(@NotNull @NotNull SecTrustRef trust, @Nullable @Nullable CFArrayRef anchorCertificates)[@function] SecTrustSetAnchorCertificates Sets the anchor certificates for a given trust. Calling this function without also calling SecTrustSetAnchorCertificatesOnly() will disable trusting any anchors other than the ones in anchorCertificates. API-Since: 2.0- Parameters:
trust- A reference to a trust object.anchorCertificates- An array of anchor certificates. Pass NULL to restore the default set of anchor certificates.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecTrustSetAnchorCertificatesOnly
public static int SecTrustSetAnchorCertificatesOnly(@NotNull @NotNull SecTrustRef trust, byte anchorCertificatesOnly)[@function] SecTrustSetAnchorCertificatesOnly Reenables trusting anchor certificates in addition to those passed in via the SecTrustSetAnchorCertificates API.- Parameters:
trust- A reference to a trust object.anchorCertificatesOnly- If true, disables trusting any anchors other than the ones passed in via SecTrustSetAnchorCertificates(). If false, the built in anchor certificates are also trusted.- Returns:
- A result code. See "Security Error Codes" (SecBase.h). API-Since: 2.0
-
SecTrustCopyCustomAnchorCertificates
public static int SecTrustCopyCustomAnchorCertificates(@NotNull @NotNull SecTrustRef trust, @NotNull @NotNull org.moe.natj.general.ptr.Ptr<CFArrayRef> anchors)[@function] SecTrustCopyCustomAnchorCertificates Returns an array of custom anchor certificates used by a given trust, as set by a prior call to SecTrustSetAnchorCertificates, or NULL if no custom anchors have been specified.- Parameters:
trust- A reference to a trust object.anchors- On return, an array of custom anchor certificates (roots) used by this trust, or NULL if no custom anchors have been specified. Call the CFRelease function to release this reference.- Returns:
- A result code. See "Security Error Codes" (SecBase.h). API-Since: 7.0
-
SecTrustSetVerifyDate
public static int SecTrustSetVerifyDate(@NotNull @NotNull SecTrustRef trust, @NotNull @NotNull CFDateRef verifyDate)[@function] SecTrustSetVerifyDate Set the date for which the trust should be verified. This function lets you evaluate certificate validity for a given date (for example, to determine if a signature was valid on the date it was signed, even if the certificate has since expired.) If this function is not called, the time at which SecTrustEvaluate() is called is used implicitly as the verification time. API-Since: 2.0- Parameters:
trust- A reference to a trust object.verifyDate- The date for which to verify trust.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecTrustGetVerifyTime
public static double SecTrustGetVerifyTime(@NotNull @NotNull SecTrustRef trust)[@function] SecTrustGetVerifyTime Returns the verify time. This function retrieves the verification time for the given trust reference, as set by a prior call to SecTrustSetVerifyDate(). If the verification time has not been set, this function returns a value of 0, indicating that the current date/time is implicitly used for verification. API-Since: 2.0- Parameters:
trust- A reference to the trust object being verified.- Returns:
- A CFAbsoluteTime value representing the time at which certificates should be checked for validity.
-
SecTrustEvaluate
@Deprecated public static int SecTrustEvaluate(@NotNull @NotNull SecTrustRef trust, @NotNull @NotNull org.moe.natj.general.ptr.IntPtr result)Deprecated.[@function] SecTrustEvaluate Evaluates a trust reference synchronously. This function will completely evaluate trust before returning, possibly including network access to fetch intermediate certificates or to perform revocation checking. Since this function can block during those operations, you should call it from within a function that is placed on a dispatch queue, or in a separate thread from your application's main run loop. Alternatively, you can use the SecTrustEvaluateAsync function. API-Since: 2.0 Deprecated-Since: 13.0- Parameters:
trust- A reference to the trust object to evaluate.result- A pointer to a result type.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecTrustEvaluateAsync
@Deprecated public static int SecTrustEvaluateAsync(@NotNull @NotNull SecTrustRef trust, @Nullable @Nullable dispatch_queue_t queue, @NotNull @NotNull Security.Block_SecTrustEvaluateAsync result)Deprecated.[@function] SecTrustEvaluateAsync Evaluates a trust reference asynchronously.- Parameters:
trust- A reference to the trust object to evaluate.queue- A dispatch queue on which the result callback should be executed. Pass NULL to use the current dispatch queue.result- A SecTrustCallback block which will be executed when the trust evaluation is complete.- Returns:
- A result code. See "Security Error Codes" (SecBase.h). API-Since: 7.0 Deprecated-Since: 13.0
-
SecTrustGetTrustResult
public static int SecTrustGetTrustResult(@NotNull @NotNull SecTrustRef trust, @NotNull @NotNull org.moe.natj.general.ptr.IntPtr result)[@function] SecTrustGetTrustResult This function replaces SecTrustGetResult for the purpose of obtaining the current evaluation result of a given trust reference. API-Since: 7.0- Parameters:
trust- A reference to a trust object.result- A pointer to the result from the most recent call to SecTrustEvaluate for this trust reference. If SecTrustEvaluate has not been called or trust parameters have changed, the result is kSecTrustResultInvalid.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecTrustCopyPublicKey
@Nullable @Deprecated public static @Nullable SecKeyRef SecTrustCopyPublicKey(@NotNull @NotNull SecTrustRef trust)
Deprecated.[@function] SecTrustCopyPublicKey Return the public key for a leaf certificate after it has been evaluated.- Parameters:
trust- A reference to the trust object which has been evaluated.- Returns:
- The certificate's public key, or NULL if it the public key could not be extracted (this can happen if the public key algorithm is not supported). The caller is responsible for calling CFRelease on the returned key when it is no longer needed. API-Since: 2.0 Deprecated-Since: 14.0
-
SecTrustGetCertificateCount
public static long SecTrustGetCertificateCount(@NotNull @NotNull SecTrustRef trust)[@function] SecTrustGetCertificateCount Returns the number of certificates in an evaluated certificate chain. Important: if the trust reference has not yet been evaluated, this function will evaluate it first before returning. If speed is critical, you may want to call SecTrustGetTrustResult first to make sure that a result other than kSecTrustResultInvalid is present for the trust object. API-Since: 2.0- Parameters:
trust- A reference to a trust object.- Returns:
- The number of certificates in the trust chain, including the anchor.
-
SecTrustGetCertificateAtIndex
@Nullable @Deprecated public static @Nullable SecCertificateRef SecTrustGetCertificateAtIndex(@NotNull @NotNull SecTrustRef trust, long ix)
Deprecated.[@function] SecTrustGetCertificateAtIndex Returns a certificate from the trust chain. This API is fundamentally not thread-safe -- other threads using the same trust object may trigger trust evaluations that release the returned certificate or change the certificate chain as a thread is iterating through the certificate chain. The replacement function SecTrustCopyCertificateChain provides thread-safe results. API-Since: 2.0 Deprecated-Since: 15.0- Parameters:
trust- Reference to a trust object.ix- The index of the requested certificate. Indices run from 0 (leaf) to the anchor (or last certificate found if no anchor was found). The leaf cert (index 0) is always present regardless of whether the trust reference has been evaluated or not.- Returns:
- A SecCertificateRef for the requested certificate.
-
SecTrustCopyExceptions
@Nullable public static @Nullable CFDataRef SecTrustCopyExceptions(@NotNull @NotNull SecTrustRef trust)
[@function] SecTrustCopyExceptions Returns an opaque cookie which will allow future evaluations of the current certificate to succeed. Normally this API should only be called once the errors have been presented to the user and the user decided to trust the current certificate chain regardless of the errors being presented, for the current application/server/protocol combination. API-Since: 4.0- Parameters:
trust- A reference to an evaluated trust object.- Returns:
- An opaque cookie which when passed to SecTrustSetExceptions() will cause a call to SecTrustEvaluate() return kSecTrustResultProceed. This will happen upon subsequent evaluation of the current certificate unless some new error starts happening that wasn't being reported when the cookie was returned from this function (for example, if the certificate expires then evaluation will start failing again until a new cookie is obtained.)
-
SecTrustSetExceptions
public static boolean SecTrustSetExceptions(@NotNull @NotNull SecTrustRef trust, @Nullable @Nullable CFDataRef exceptions)[@function] SecTrustSetExceptions Set a trust cookie to be used for evaluating this certificate chain. Clients of this interface will need to establish the context of this exception to later decide when this exception cookie is to be used. Examples of this context would be the server we are connecting to, the ssid of the wireless network for which this cert is needed, the account for which this cert should be considered valid, and so on. API-Since: 4.0- Parameters:
trust- A reference to a trust object.exceptions- An exceptions cookie as returned by a call to SecTrustCopyExceptions() in the past. You may pass NULL to clear any exceptions which have been previously set on this trust reference.- Returns:
- Upon calling SecTrustEvaluate(), any failures that were present at the time the exceptions object was created are ignored, and instead of returning kSecTrustResultRecoverableTrustFailure, kSecTrustResultProceed will be returned (if the certificate for which exceptions was created matches the current leaf certificate).
-
SecTrustCopyProperties
@Nullable @Deprecated public static @Nullable CFArrayRef SecTrustCopyProperties(@NotNull @NotNull SecTrustRef trust)
Deprecated.[@function] SecTrustCopyProperties Return a property array for this trust evaluation. On macOS, this function returns an ordered array of CFDictionaryRef instances for each certificate in the chain. Indices run from 0 (leaf) to the anchor (or last certificate found if no anchor was found.) On other platforms, this function returns an unordered array of CFDictionary instances. See the "Trust Property Constants" section for a list of currently defined keys. The error information conveyed via this interface is also conveyed via the returned error of SecTrustEvaluateWithError. API-Since: 2.0 Deprecated-Since: 15.0- Parameters:
trust- A reference to a trust object. If the trust has not been evaluated, the returned property array will be empty.- Returns:
- A property array. It is the caller's responsibility to CFRelease the returned array when it is no longer needed.
-
SecTrustCopyResult
@Nullable public static @Nullable CFDictionaryRef SecTrustCopyResult(@NotNull @NotNull SecTrustRef trust)
[@function] SecTrustCopyResult Returns a dictionary containing information about the evaluated certificate chain for use by clients. Returns a dictionary for the overall trust evaluation. See the "Trust Result Constants" section for a list of currently defined keys. API-Since: 7.0- Parameters:
trust- A reference to a trust object.- Returns:
- A dictionary with various fields that can be displayed to the user, or NULL if no additional info is available or the trust has not yet been validated. The caller is responsible for calling CFRelease on the value returned when it is no longer needed.
-
SecTrustSetOCSPResponse
public static int SecTrustSetOCSPResponse(@NotNull @NotNull SecTrustRef trust, @Nullable @Nullable org.moe.natj.general.ptr.ConstVoidPtr responseData)[@function] SecTrustSetOCSPResponse Attach OCSPResponse data to a trust object. Allows the caller to provide OCSPResponse data (which may be obtained during a TLS/SSL handshake, per RFC 3546) as input to a trust evaluation. If this data is available, it can obviate the need to contact an OCSP server for current revocation information. API-Since: 7.0- Parameters:
trust- A reference to a trust object.responseData- This may be either a CFData object containing a single DER-encoded OCSPResponse (per RFC 2560), or a CFArray of these.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SSLContextGetTypeID
@Deprecated public static long SSLContextGetTypeID()
Deprecated.[@function] SSLContextGetTypeID Return the CFTypeID for SSLContext objects.- Returns:
- CFTypeId for SSLContext objects. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLCreateContext
@Nullable @Deprecated public static @Nullable SSLContextRef SSLCreateContext(@Nullable @Nullable CFAllocatorRef alloc, int protocolSide, int connectionType)
Deprecated.[@function] SSLCreateContext Create a new instance of an SSLContextRef using the specified allocator.- Parameters:
alloc- Allocator to use for memory.protooclSide- Client or server indication.connectionType- Type of connection.- Returns:
- A newly allocated SSLContextRef, or NULL on error. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetSessionState
@Deprecated public static int SSLGetSessionState(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.IntPtr state)Deprecated.[@function] SSLGetSessionState Determine the state of an SSL/DTLS session.- Parameters:
context- A valid SSLContextRef.state- Output pointer to store the SSLSessionState.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetSessionOption
@Deprecated public static int SSLSetSessionOption(@NotNull @NotNull SSLContextRef context, int option, byte value)Deprecated.[@function] SSLSetSessionOption Set options for an SSL session. Must be called prior to SSLHandshake(); subsequently cannot be called while session is active.- Parameters:
context- A valid SSLContextRef.option- An option enumeration value.value- Value of the SSLSessionOption.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetSessionOption
@Deprecated public static int SSLGetSessionOption(@NotNull @NotNull SSLContextRef context, int option, @NotNull @NotNull org.moe.natj.general.ptr.BytePtr value)Deprecated.[@function] SSLGetSessionOption Determine current value for the specified option in a given SSL session.- Parameters:
context- A valid SSLContextRef.option- An option enumeration value.value- Pointer to a Boolean where the SSLSessionOption value is stored.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetIOFuncs
@Deprecated public static int SSLSetIOFuncs(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull Security.Function_SSLSetIOFuncs_1 readFunc, @NotNull @NotNull Security.Function_SSLSetIOFuncs_2 writeFunc)Deprecated.[@function] SSLSetIOFuncs Specify functions which do the network I/O. Must be called prior to SSLHandshake(); subsequently cannot be called while a session is active.- Parameters:
context- A valid SSLContextRef.readFunc- Pointer to a SSLReadFunc.writeFunc- Pointer to a SSLWriteFunc.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetSessionConfig
@Deprecated public static int SSLSetSessionConfig(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull CFStringRef config)Deprecated.[@function] SSLSetSessionConfig [@absttact] Set a predefined configuration for the SSL Session [@note] This currently affect enabled protocol versions, enabled ciphersuites, and the kSSLSessionOptionFallback session option.- Parameters:
context- A valid SSLContextRef.config- String name of constant TLS handshake configuration, e.g., kSSLSessionConfig_standard.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 10.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetProtocolVersionMin
@Deprecated public static int SSLSetProtocolVersionMin(@NotNull @NotNull SSLContextRef context, int minVersion)Deprecated.[@function] SSLSetProtocolVersionMin Set the minimum SSL protocol version allowed. Optional. The default is the lower supported protocol. [@note] This can only be called when no session is active. For TLS contexts, legal values for minVersion are : kSSLProtocol3 kTLSProtocol1 kTLSProtocol11 kTLSProtocol12 For DTLS contexts, legal values for minVersion are : kDTLSProtocol1- Parameters:
context- A valid SSLContextRef.minVersion- Minimum TLS protocol version.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetProtocolVersionMin
@Deprecated public static int SSLGetProtocolVersionMin(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.IntPtr minVersion)Deprecated.[@function] SSLGetProtocolVersionMin Get minimum protocol version allowed- Parameters:
context- A valid SSLContextRef.minVersion- Pointer to SSLProtocol value where the minimum protocol version is stored.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetProtocolVersionMax
@Deprecated public static int SSLSetProtocolVersionMax(@NotNull @NotNull SSLContextRef context, int maxVersion)Deprecated.[@function] SSLSetProtocolVersionMax Set the maximum SSL protocol version allowed. Optional. The default is the highest supported protocol. [@note] This can only be called when no session is active. For TLS contexts, legal values for maxVersion are : kSSLProtocol3 kTLSProtocol1 kTLSProtocol11 kTLSProtocol12 For DTLS contexts, legal values for maxVersion are : kDTLSProtocol1- Parameters:
context- A valid SSLContextRef.maxVersion- Maximum TLS protocol version.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetProtocolVersionMax
@Deprecated public static int SSLGetProtocolVersionMax(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.IntPtr maxVersion)Deprecated.[@function] SSLGetProtocolVersionMax Get maximum protocol version allowed- Parameters:
context- A valid SSLContextRef.maxVersion- Pointer to SSLProtocol value where the maximum protocol version is stored.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetCertificate
@Deprecated public static int SSLSetCertificate(@NotNull @NotNull SSLContextRef context, @Nullable @Nullable CFArrayRef certRefs)Deprecated.[@function] SSLSetCertificate Specify this connection's certificate(s). This is mandatory for server connections,and optional for clients. Specifying a certificate for a client enables SSL client-side authentication. The end-entity cert is in certRefs[0]. Specifying a root cert is optional; if it's not specified, the root cert which verifies the cert chain specified here must be present in the system-wide set of trusted anchor certs. The certRefs argument is a CFArray containing SecCertificateRefs, except for certRefs[0], which is a SecIdentityRef. Must be called prior to SSLHandshake(), or immediately after SSLHandshake has returned errSSLClientCertRequested (i.e. before the handshake is resumed by calling SSLHandshake again.) SecureTransport assumes the following: -- The certRef references remain valid for the lifetime of the session. -- The certificate specified in certRefs[0] is capable of signing. -- The required capabilities of the certRef[0], and of the optional cert specified in SSLSetEncryptionCertificate (see below), are highly dependent on the application. For example, to work as a server with Netscape clients, the cert specified here must be capable of both signing and encrypting.- Parameters:
context- A valid SSLContextRef.certRefs- An array of SecCertificateRef instances.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetConnection
@Deprecated public static int SSLSetConnection(@NotNull @NotNull SSLContextRef context, @Nullable @Nullable org.moe.natj.general.ptr.ConstVoidPtr connection)Deprecated.[@function] SSLSetConnection Specify I/O connection - a socket, endpoint, etc., which is managed by caller. On the client side, it's assumed that communication has been established with the desired server on this connection. On the server side, it's assumed that an incoming client request has been established. Must be called prior to SSLHandshake(); subsequently can only be called when no session is active.- Parameters:
context- A valid SSLContextRef.connection- A SSLConnectionRef.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetConnection
@Deprecated public static int SSLGetConnection(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.Ptr<org.moe.natj.general.ptr.ConstVoidPtr> connection)Deprecated.[@function] SSLGetConnection Retrieve the I/O connection managed managed by the caller.- Parameters:
context- A valid SSLContextRef.connection- A SSLConnectionRef pointer.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetPeerDomainName
@Deprecated public static int SSLSetPeerDomainName(@NotNull @NotNull SSLContextRef context, @Nullable @Nullable java.lang.String peerName, long peerNameLen)Deprecated.[@function] SSLSetPeerDomainName Specify the fully qualified doman name of the peer, e.g., "store.apple.com." Optional; used to verify the common name field in peer's certificate. Name is in the form of a C string; NULL termination optional, i.e., peerName[peerNameLen+1] may or may not have a NULL. In any case peerNameLen is the number of bytes of the peer domain name.- Parameters:
context- A valid SSLContextRef.peerName- A C string carrying the peer domain name.peerNameLen- Length of the peer domain name string.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetPeerDomainNameLength
@Deprecated public static int SSLGetPeerDomainNameLength(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr peerNameLen)Deprecated.[@function] SSLGetPeerDomainNameLength Determine the buffer size needed for SSLGetPeerDomainName().- Parameters:
context- A valid SSLContextRef.peerNameLen- Pointer to where the length of the peer domain name string is stored- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetPeerDomainName
@Deprecated public static int SSLGetPeerDomainName(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.BytePtr peerName, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr peerNameLen)Deprecated.[@function] SSLGetPeerDomainName Obtain the value specified in SSLSetPeerDomainName().- Parameters:
context- A valid SSLContextRef.peerName- Pointer to where the peer domain name is stored.peerNameLen- Pointer to where the length of the peer domain name string is stored, up to the length specified by peerNameLen (on input).- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLCopyRequestedPeerName
@Deprecated public static int SSLCopyRequestedPeerName(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.BytePtr peerName, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr peerNameLen)Deprecated.[@function] SSLCopyRequestedPeerName Determine the buffer size needed for SSLCopyRequestedPeerNameLength().- Parameters:
context- A valid SSLContextRef.peerName- Pointer to where the requested peer domain name is stored.peerNameLen- Pointer to where the length of the requested peer domain name string is stored, up to the length specified by peerNameLen (on input).- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 9.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLCopyRequestedPeerNameLength
@Deprecated public static int SSLCopyRequestedPeerNameLength(@NotNull @NotNull SSLContextRef ctx, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr peerNameLen)Deprecated.[@function] SSLCopyRequestedPeerNameLength [Server Only] obtain the hostname specified by the client in the ServerName extension (SNI)- Parameters:
context- A valid SSLContextRef.peerNameLen- Pointer to where the length of the requested peer domain name string is stored, up to the length specified by peerNameLen (on input).- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 9.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetDatagramHelloCookie
@Deprecated public static int SSLSetDatagramHelloCookie(@NotNull @NotNull SSLContextRef dtlsContext, @Nullable @Nullable org.moe.natj.general.ptr.ConstVoidPtr cookie, long cookieLen)Deprecated.[@function] SSLSetDatagramHelloCookie Specify the Datagram TLS Hello Cookie. This is to be called for server side only and is optional. The default is a zero len cookie. The maximum cookieLen is 32 bytes.- Parameters:
context- A valid SSLContextRef.cookie- Pointer to opaque cookie data.cookieLen- Length of cookie data.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetMaxDatagramRecordSize
@Deprecated public static int SSLSetMaxDatagramRecordSize(@NotNull @NotNull SSLContextRef dtlsContext, long maxSize)Deprecated.[@function] SSLSetMaxDatagramRecordSize Specify the maximum record size, including all DTLS record headers. This should be set appropriately to avoid fragmentation of Datagrams during handshake, as fragmented datagrams may be dropped by some network. [@note] This is for Datagram TLS only- Parameters:
context- A valid SSLContextRef.maxSize- Maximum size of datagram record(s).- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetMaxDatagramRecordSize
@Deprecated public static int SSLGetMaxDatagramRecordSize(@NotNull @NotNull SSLContextRef dtlsContext, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr maxSize)Deprecated.[@function] SSLGetMaxDatagramRecordSize Get the maximum record size, including all Datagram TLS record headers. [@note] This is for Datagram TLS only- Parameters:
context- A valid SSLContextRef.maxSize- Pointer where maximum size of datagram record(s) is stored.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetNegotiatedProtocolVersion
@Deprecated public static int SSLGetNegotiatedProtocolVersion(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.IntPtr protocol)Deprecated.[@function] SSLGetNegotiatedProtocolVersion Obtain the actual negotiated protocol version of the active session, which may be different that the value specified in SSLSetProtocolVersion(). Returns kSSLProtocolUnknown if no SSL session is in progress.- Parameters:
context- A valid SSLContextRef.protocol- Pointer where negotiated SSLProtocol is stored.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetNumberSupportedCiphers
@Deprecated public static int SSLGetNumberSupportedCiphers(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr numCiphers)Deprecated.[@function] SSLGetNumberSupportedCiphers Determine number and values of all of the SSLCipherSuites we support. Caller allocates output buffer for SSLGetSupportedCiphers() and passes in its size in *numCiphers. If supplied buffer is too small, errSSLBufferOverflow will be returned.- Parameters:
context- A valid SSLContextRef.numCiphers- Pointer where number of supported ciphers is stored.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetSupportedCiphers
@Deprecated public static int SSLGetSupportedCiphers(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.CharPtr ciphers, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr numCiphers)Deprecated.[@function] SSLGetSupportedCiphers Get the supported ciphers.- Parameters:
context- A valid SSLContextRef.ciphers- Pointer to array of SSLCipherSuite values where supported ciphersuites are stored. This array size is specified by the input value of numCiphers.numCiphers- Pointer where number of supported ciphers is stored.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetEnabledCiphers
@Deprecated public static int SSLSetEnabledCiphers(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.ConstCharPtr ciphers, long numCiphers)Deprecated.[@function] SSLSetEnabledCiphers Specify a (typically) restricted set of SSLCipherSuites to be enabled by the current SSLContext. Can only be called when no session is active. Default set of enabled SSLCipherSuites is the same as the complete set of supported SSLCipherSuites as obtained by SSLGetSupportedCiphers().- Parameters:
context- A valid SSLContextRef.ciphers- Array of enabled SSLCipherSuite values. This array size is specified by the input value of numCiphers.numCiphers- Pointer where number of enabled ciphers is stored.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetNumberEnabledCiphers
@Deprecated public static int SSLGetNumberEnabledCiphers(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr numCiphers)Deprecated.[@function] SSLGetNumberEnabledCiphers Determine number and values of all of the SSLCipherSuites currently enabled. Caller allocates output buffer for SSLGetEnabledCiphers() and passes in its size in *numCiphers. If supplied buffer is too small, errSSLBufferOverflow will be returned.- Parameters:
context- A valid SSLContextRef.numCiphers- Pointer where number of enabled ciphers is stored.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetEnabledCiphers
@Deprecated public static int SSLGetEnabledCiphers(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.CharPtr ciphers, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr numCiphers)Deprecated.[@function] SSLGetEnabledCiphers Get the set of supported ciphersuites.- Parameters:
context- A valid SSLContextRef.ciphers- Pointer to array of SSLCipherSuite values where enabled ciphersuites are stored. This array size is specified by the input value of numCiphers.numCiphers- Pointer where number of enabled ciphers is stored.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLCopyPeerTrust
@Deprecated public static int SSLCopyPeerTrust(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.Ptr<SecTrustRef> trust)Deprecated.[@function] SSLCopyPeerTrust Obtain a SecTrustRef representing peer certificates. Valid anytime, subsequent to a handshake attempt. Caller must CFRelease the returned trust reference. The returned trust reference will have already been evaluated for you, unless one of the following is true: - Your code has disabled automatic certificate verification, by calling SSLSetSessionOption to set kSSLSessionOptionBreakOnServerAuth to true. - Your code has called SSLSetPeerID, and this session has been resumed from an earlier cached session. In these cases, your code should call SecTrustEvaluate prior to examining the peer certificate chain or trust results (see SecTrust.h). [@note] If you have not called SSLHandshake at least once prior to calling this function, the returned trust reference will be NULL.- Parameters:
context- A valid SSLContextRef.trust- Pointer to SecTrustRef where peer's SecTrustRef is copied (retained).- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetPeerID
@Deprecated public static int SSLSetPeerID(@NotNull @NotNull SSLContextRef context, @Nullable @Nullable org.moe.natj.general.ptr.ConstVoidPtr peerID, long peerIDLen)Deprecated.[@function] SSLSetPeerID Specify some data, opaque to this library, which is sufficient to uniquely identify the peer of the current session. An example would be IP address and port, stored in some caller-private manner. To be optionally called prior to SSLHandshake for the current session. This is mandatory if this session is to be resumable. SecureTransport allocates its own copy of the incoming peerID. The data provided in *peerID, while opaque to SecureTransport, is used in a byte-for-byte compare to other previous peerID values set by the current application. Matching peerID blobs result in SecureTransport attempting to resume an SSL session with the same parameters as used in the previous session which specified the same peerID bytes.- Parameters:
context- A valid SSLContextRef.peerID- Opaque peer ID.peerIDLen- Length of opaque peer ID.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetPeerID
@Deprecated public static int SSLGetPeerID(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.Ptr<org.moe.natj.general.ptr.ConstVoidPtr> peerID, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr peerIDLen)Deprecated.[@function] SSLGetPeerID Obtain current PeerID. Returns NULL pointer, zero length if SSLSetPeerID has not been called for this context.- Parameters:
context- A valid SSLContextRef.peerID- Pointer to storage for the peer ID.peerIDLen- Pointer to storage for the peer ID length.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetNegotiatedCipher
@Deprecated public static int SSLGetNegotiatedCipher(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.CharPtr cipherSuite)Deprecated.[@function] SSLGetNegotiatedCipher Obtain the SSLCipherSuite (e.g., SSL_RSA_WITH_DES_CBC_SHA) negotiated for this session. Only valid when a session is active.- Parameters:
context- A valid SSLContextRef.cipherSuite- Pointer to storage for negotiated SSLCipherSuite.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetEncryptionCertificate
@Deprecated public static int SSLSetEncryptionCertificate(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull CFArrayRef certRefs)Deprecated.[@function] SSLSetEncryptionCertificate This function is deprecated in OSX 10.11 and iOS 9.0 and has no effect on the TLS handshake since OSX 10.10 and iOS 8.0. Using separate RSA certificates for encryption and signing is no longer supported.- Parameters:
context- A valid SSLContextRef.certRefs- Array of certificates.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 9.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetClientSideAuthenticate
@Deprecated public static int SSLSetClientSideAuthenticate(@NotNull @NotNull SSLContextRef context, int auth)Deprecated.[@function] SSLSetClientSideAuthenticate Specify requirements for client-side authentication.- Parameters:
context- A valid SSLContextRef.auth- A SSLAuthenticate enumeration value.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLAddDistinguishedName
@Deprecated public static int SSLAddDistinguishedName(@NotNull @NotNull SSLContextRef context, @Nullable @Nullable org.moe.natj.general.ptr.ConstVoidPtr derDN, long derDNLen)Deprecated.[@function] SSLAddDistinguishedName Add a DER-encoded distinguished name to list of acceptable names to be specified in requests for client certificates.- Parameters:
context- A valid SSLContextRef.derDN- A DER-encoded Distinguished Name blob.derDNLen- Length of the Distinguished Name blob.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLCopyDistinguishedNames
@Deprecated public static int SSLCopyDistinguishedNames(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.Ptr<CFArrayRef> names)Deprecated.[@function] SSLCopyDistinguishedNames Obtain the list of acceptable distinguished names as provided by a server (if the SSLContextRef is configured as a client), or as specified by SSLSetCertificateAuthorities (if the SSLContextRef is configured as a server). The returned array contains CFDataRefs, each of which represents one DER-encoded RDN. Caller must CFRelease the returned array.- Parameters:
context- A valid SSLContextRef.names- Pointer to CFArrayRef storage for retained copy of Distinguished Names.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetClientCertificateState
@Deprecated public static int SSLGetClientCertificateState(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.IntPtr clientState)Deprecated.[@function] SSLGetClientCertificateState Obtain client certificate exchange status. Can be called any time. Reflects the *last* client certificate state change; subsequent to a renegotiation attempt by either peer, the state is reset to kSSLClientCertNone.- Parameters:
context- A valid SSLContextRef.clientState- Pointer to SSLClientCertificateState storage.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLHandshake
@Deprecated public static int SSLHandshake(@NotNull @NotNull SSLContextRef context)Deprecated.[@function] SSLHandshake Perform the SSL handshake. On successful return, session is ready for normal secure application I/O via SSLWrite and SSLRead. Interesting error returns: errSSLUnknownRootCert: Peer had a valid cert chain, but the root of the chain is unknown. errSSLNoRootCert: Peer had a cert chain which did not end in a root. errSSLCertExpired: Peer's cert chain had one or more expired certs. errSSLXCertChainInvalid: Peer had an invalid cert chain (i.e., signature verification within the chain failed, or no certs were found). In all of the above errors, the handshake was aborted; the peer's cert chain is available via SSLCopyPeerTrust or SSLCopyPeerCertificates. Other interesting result codes: errSSLPeerAuthCompleted: Peer's cert chain is valid, or was ignored if cert verification was disabled via SSLSetEnableCertVerify. The application may decide to continue with the handshake (by calling SSLHandshake again), or close the connection at this point. errSSLClientCertRequested: The server has requested a client certificate. The client may choose to examine the server's certificate and distinguished name list, then optionally call SSLSetCertificate prior to resuming the handshake by calling SSLHandshake again. A return value of errSSLWouldBlock indicates that SSLHandshake has to be called again (and again and again until something else is returned).- Parameters:
context- A valid SSLContextRef.- Returns:
- errSecSuccess on success, alternative error on failure or incomplete state. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLReHandshake
@Deprecated public static int SSLReHandshake(@NotNull @NotNull SSLContextRef context)Deprecated.[@function] SSLReHandshake Server Only: Request renegotation. This will return an error if the server is already renegotiating, or if the session is closed. After this return without error, the application should call SSLHandshake() and/or SSLRead() as for the original handshake.- Parameters:
context- A valid SSLContextRef.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 10.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLWrite
@Deprecated public static int SSLWrite(@NotNull @NotNull SSLContextRef context, @Nullable @Nullable org.moe.natj.general.ptr.ConstVoidPtr data, long dataLength, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr processed)Deprecated.[@function] SSLWrite Normal application-level write. On both of these, a errSSLWouldBlock return and a partially completed transfer - or even zero bytes transferred - are NOT mutually exclusive.- Parameters:
context- A valid SSLContextRef.data- Pointer to data to write.dataLength- Length of data to write.processed- Pointer to storage indicating how much data was written.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLRead
@Deprecated public static int SSLRead(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.VoidPtr data, long dataLength, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr processed)Deprecated.[@function] SSLRead * @abstract Normal application-level write. Data is mallocd by caller; available size specified in dataLength; actual number of bytes read returned in *processed.- Parameters:
context- A valid SSLContextRef.data- Pointer to storage where data can be read.dataLength- Length of data storage.processed- Pointer to storage indicating how much data was read.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetBufferedReadSize
@Deprecated public static int SSLGetBufferedReadSize(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr bufferSize)Deprecated.[@function] SSLGetBufferedReadSize Determine how much data the client can be guaranteed to obtain via SSLRead() without blocking or causing any low-level read operations to occur.- Parameters:
context- A valid SSLContextRef.bufferSize- Pointer to store the amount of buffered data to be read.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLGetDatagramWriteSize
@Deprecated public static int SSLGetDatagramWriteSize(@NotNull @NotNull SSLContextRef dtlsContext, @NotNull @NotNull org.moe.natj.general.ptr.NUIntPtr bufSize)Deprecated.[@function] SSLGetDatagramWriteSize Determine how much data the application can be guaranteed to write with SSLWrite() without causing fragmentation. The value is based on the maximum Datagram Record size defined by the application with SSLSetMaxDatagramRecordSize(), minus the DTLS Record header size.- Parameters:
context- A valid SSLContextRef (for DTLS).bufferSize- Pointer to store the amount of data that can be written.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLClose
@Deprecated public static int SSLClose(@NotNull @NotNull SSLContextRef context)Deprecated.[@function] SSLClose Terminate current SSL session.- Parameters:
context- A valid SSLContextRef.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
kSecImportExportPassphrase
@NotNull public static @NotNull CFStringRef kSecImportExportPassphrase()
[@enum] Import/Export options Predefined key constants used when passing dictionary-based arguments to import/export functions. [@constant] kSecImportExportPassphrase Specifies a passphrase represented by a CFStringRef to be used when exporting to (or importing from) PKCS#12 format. [@constant] kSecImportExportKeychain On OSX, specifies a keychain represented by a SecKeychainRef to be used as the target when importing from PKCS#12 format. [@constant] kSecImportExportAccess On OSX, specifies an access represented by a SecAccessRef for the initial access (ACL) of a key imported from PKCS#12 format. API-Since: 2.0
-
kSecImportItemLabel
@NotNull public static @NotNull CFStringRef kSecImportItemLabel()
[@enum] Import/Export item description Predefined key constants used to pass back a CFArray with a CFDictionary per item. [@constant] kSecImportItemLabel a CFStringRef representing the item label. This implementation specific identifier cannot be expected to have any format. [@constant] kSecImportItemKeyID a CFDataRef representing the key id. Often the SHA-1 digest of the public key. [@constant] kSecImportItemIdentity a SecIdentityRef representing the identity. [@constant] kSecImportItemTrust a SecTrustRef set up with all relevant certificates. Not guaranteed to succesfully evaluate. [@constant] kSecImportItemCertChain a CFArrayRef holding all relevant certificates for this item's identity API-Since: 2.0
-
kSecImportItemKeyID
@NotNull public static @NotNull CFStringRef kSecImportItemKeyID()
API-Since: 2.0
-
kSecImportItemTrust
@NotNull public static @NotNull CFStringRef kSecImportItemTrust()
API-Since: 2.0
-
kSecImportItemCertChain
@NotNull public static @NotNull CFStringRef kSecImportItemCertChain()
API-Since: 2.0
-
kSecImportItemIdentity
@NotNull public static @NotNull CFStringRef kSecImportItemIdentity()
API-Since: 2.0
-
kSecClass
@NotNull public static @NotNull CFStringRef kSecClass()
[@enum] Class Key Constant Predefined key constant used to get or set item class values in a dictionary. Its value is one of the constants defined in the Value Constants for kSecClass. [@constant] kSecClass Specifies a dictionary key whose value is the item's class code. You use this key to get or set a value of type CFTypeRef that contains the item class code. API-Since: 2.0
-
kSecClassGenericPassword
@NotNull public static @NotNull CFStringRef kSecClassGenericPassword()
API-Since: 2.0
-
kSecClassInternetPassword
@NotNull public static @NotNull CFStringRef kSecClassInternetPassword()
[@enum] Class Value Constants Predefined item class constants used to get or set values in a dictionary. The kSecClass constant is the key and its value is one of the constants defined here. Note: on Mac OS X 10.6, only items of class kSecClassInternetPassword are supported. [@constant] kSecClassInternetPassword Specifies Internet password items. [@constant] kSecClassGenericPassword Specifies generic password items. [@constant] kSecClassCertificate Specifies certificate items. [@constant] kSecClassKey Specifies key items. [@constant] kSecClassIdentity Specifies identity items. API-Since: 2.0
-
kSecClassCertificate
@NotNull public static @NotNull CFStringRef kSecClassCertificate()
API-Since: 2.0
-
kSecClassKey
@NotNull public static @NotNull CFStringRef kSecClassKey()
API-Since: 2.0
-
kSecClassIdentity
@NotNull public static @NotNull CFStringRef kSecClassIdentity()
API-Since: 2.0
-
kSecAttrAccessible
@NotNull public static @NotNull CFStringRef kSecAttrAccessible()
[@enum] Attribute Key Constants Predefined item attribute keys used to get or set values in a dictionary. Not all attributes apply to each item class. The table below lists the currently defined attributes for each item class: kSecClassGenericPassword item attributes: kSecAttrAccess (OS X only) kSecAttrAccessControl kSecAttrAccessGroup (iOS; also OS X if kSecAttrSynchronizable and/or kSecUseDataProtectionKeychain set) kSecAttrAccessible (iOS; also OS X if kSecAttrSynchronizable and/or kSecUseDataProtectionKeychain set) kSecAttrCreationDate kSecAttrModificationDate kSecAttrDescription kSecAttrComment kSecAttrCreator kSecAttrType kSecAttrLabel kSecAttrIsInvisible kSecAttrIsNegative kSecAttrAccount kSecAttrService kSecAttrGeneric kSecAttrSynchronizable kSecClassInternetPassword item attributes: kSecAttrAccess (OS X only) kSecAttrAccessControl kSecAttrAccessGroup (iOS; also OS X if kSecAttrSynchronizable and/or kSecUseDataProtectionKeychain set) kSecAttrAccessible (iOS; also OS X if kSecAttrSynchronizable and/or kSecUseDataProtectionKeychain set) kSecAttrCreationDate kSecAttrModificationDate kSecAttrDescription kSecAttrComment kSecAttrCreator kSecAttrType kSecAttrLabel kSecAttrIsInvisible kSecAttrIsNegative kSecAttrAccount kSecAttrSecurityDomain kSecAttrServer kSecAttrProtocol kSecAttrAuthenticationType kSecAttrPort kSecAttrPath kSecAttrSynchronizable kSecClassCertificate item attributes: kSecAttrAccessible (iOS only) kSecAttrAccessControl (iOS only) kSecAttrAccessGroup (iOS only) kSecAttrCertificateType kSecAttrCertificateEncoding kSecAttrLabel kSecAttrSubject kSecAttrIssuer kSecAttrSerialNumber kSecAttrSubjectKeyID kSecAttrPublicKeyHash kSecAttrSynchronizable kSecClassKey item attributes: kSecAttrAccess (OS X only) kSecAttrAccessControl kSecAttrAccessGroup (iOS; also OS X if kSecAttrSynchronizable and/or kSecUseDataProtectionKeychain set) kSecAttrAccessible (iOS; also OS X if kSecAttrSynchronizable and/or kSecUseDataProtectionKeychain set) kSecAttrKeyClass kSecAttrLabel kSecAttrApplicationLabel kSecAttrIsPermanent kSecAttrApplicationTag kSecAttrKeyType kSecAttrPRF (OS X only) kSecAttrSalt (OS X only) kSecAttrRounds (OS X only) kSecAttrKeySizeInBits kSecAttrEffectiveKeySize kSecAttrCanEncrypt kSecAttrCanDecrypt kSecAttrCanDerive kSecAttrCanSign kSecAttrCanVerify kSecAttrCanWrap kSecAttrCanUnwrap kSecAttrSynchronizable Note that the attributes kSecAttrCan* describe attributes of the key itself at relatively high level. Some of these attributes are mathematical -- for example, a DSA key cannot encrypt. Others are key-level policy issues -- for example, it is good cryptographic hygiene to use an RSA key either for encryption or signing but not both. Compare these to the certificate-level policy values in SecPolicy.h. kSecClassIdentity item attributes: Since an identity is the combination of a private key and a certificate, this class shares attributes of both kSecClassKey and kSecClassCertificate. [@constant] kSecAttrAccessible Specifies a dictionary key whose value indicates when your application needs access to an item's data. You should choose the most restrictive option that meets your application's needs to allow the system to protect that item in the best way possible. See the "kSecAttrAccessible Value Constants" section for a list of values which can be specified. IMPORTANT: This attribute is currently not supported for OS X keychain items, unless the kSecAttrSynchronizable attribute is also present. If both attributes are specified on either OS X or iOS, the value for the kSecAttrAccessible key may only be one whose name does not end with "ThisDeviceOnly", as those cannot sync to another device. [@constant] kSecAttrAccessControl Specifies a dictionary key whose value is SecAccessControl instance which contains access control conditions for item. IMPORTANT: This attribute is mutually exclusive with kSecAttrAccess attribute. [@constant] kSecAttrAccess Specifies a dictionary key whose value is a SecAccessRef describing the access control settings for this item. This key is available on OS X only. [@constant] kSecAttrAccessGroup Specifies a dictionary key whose value is a CFStringRef indicating which access group a item is in. The access groups that a particular application has membership in are determined by two entitlements for that application. The application-identifier entitlement contains the application's single access group, unless there is a keychain-access-groups entitlement present. The latter has as its value a list of access groups; the first item in this list is the default access group. Unless a specific access group is provided as the value of kSecAttrAccessGroup when SecItemAdd is called, new items are created in the application's default access group. Specifying this attribute in SecItemCopyMatching, SecItemUpdate, or SecItemDelete calls limits the search to the specified access group (of which the calling application must be a member to obtain matching results.) To share keychain items between multiple applications, each application must have a common group listed in its keychain-access-groups entitlement, and each must specify this shared access group name as the value for the kSecAttrAccessGroup key in the dictionary passed to SecItem functions. [@constant] kSecAttrSynchronizable Specifies a dictionary key whose value is a CFBooleanRef indicating whether the item in question can be synchronized. To add a new item which can be synced to other devices, or to obtain synchronizable results from a query, supply this key with a value of kCFBooleanTrue. If the key is not supplied, or has a value of kCFBooleanFalse, then no synchronizable items will be added or returned. A predefined value, kSecAttrSynchronizableAny, may be provided instead of kCFBooleanTrue if both synchronizable and non-synchronizable results are desired. IMPORTANT: Specifying the kSecAttrSynchronizable key has several caveats: - Updating or deleting items using the kSecAttrSynchronizable key will affect all copies of the item, not just the one on your local device. Be sure that it makes sense to use the same password on all devices before deciding to make a password synchronizable. - Starting in iOS 14, macOS 11, and watchOS 7, the keychain synchronizes passwords, certificates, and cryptographic keys. Earlier OS versions synchronize only passwords. - Items stored or obtained using the kSecAttrSynchronizable key cannot specify SecAccessRef-based access control with kSecAttrAccess. If a password is intended to be shared between multiple applications, the kSecAttrAccessGroup key must be specified, and each application using this password must have a 'keychain-access-groups' entitlement with the specified access group value. - Items stored or obtained using the kSecAttrSynchronizable key may not also specify a kSecAttrAccessible value which is incompatible with syncing (namely, those whose names end with "ThisDeviceOnly".) - On macOS, when kSecAttrSynchronizable is set to true, returning references is supported only for Certificate, Key or Identity items. - Persistent references to synchronizable items should be avoided; while they may work locally, they cannot be moved between devices, and may not resolve if the item is modified on some other device. - When specifying a query that uses the kSecAttrSynchronizable key, search keys are limited to the item's class and attributes. The only search constant which may be used is kSecMatchLimit; other constants using the kSecMatch prefix are not supported at this time. [@constant] kSecAttrSynchronizableAny Specifies that both synchronizable and non-synchronizable results should be returned from this query. This may be used as a value for the kSecAttrSynchronizable dictionary key in a call to SecItemCopyMatching, SecItemUpdate, or SecItemDelete. [@constant] kSecAttrCreationDate (read-only) Specifies a dictionary key whose value is the item's creation date. You use this key to get a value of type CFDateRef that represents the date the item was created. [@constant] kSecAttrModificationDate (read-only) Specifies a dictionary key whose value is the item's modification date. You use this key to get a value of type CFDateRef that represents the last time the item was updated. [@constant] kSecAttrDescription Specifies a dictionary key whose value is the item's description attribute. You use this key to set or get a value of type CFStringRef that represents a user-visible string describing this particular kind of item (e.g., "disk image password"). [@constant] kSecAttrComment Specifies a dictionary key whose value is the item's comment attribute. You use this key to set or get a value of type CFStringRef containing the user-editable comment for this item. [@constant] kSecAttrCreator Specifies a dictionary key whose value is the item's creator attribute. You use this key to set or get a value of type CFNumberRef that represents the item's creator. This number is the unsigned integer representation of a four-character code (e.g., 'aCrt'). [@constant] kSecAttrType Specifies a dictionary key whose value is the item's type attribute. You use this key to set or get a value of type CFNumberRef that represents the item's type. This number is the unsigned integer representation of a four-character code (e.g., 'aTyp'). [@constant] kSecAttrLabel Specifies a dictionary key whose value is the item's label attribute. You use this key to set or get a value of type CFStringRef containing the user-visible label for this item. [@constant] kSecAttrIsInvisible Specifies a dictionary key whose value is the item's invisible attribute. You use this key to set or get a value of type CFBooleanRef that indicates whether the item is invisible (i.e., should not be displayed.) [@constant] kSecAttrIsNegative Specifies a dictionary key whose value is the item's negative attribute. You use this key to set or get a value of type CFBooleanRef that indicates whether there is a valid password associated with this keychain item. This is useful if your application doesn't want a password for some particular service to be stored in the keychain, but prefers that it always be entered by the user. [@constant] kSecAttrAccount Specifies a dictionary key whose value is the item's account attribute. You use this key to set or get a CFStringRef that contains an account name. (Items of class kSecClassGenericPassword, kSecClassInternetPassword have this attribute.) [@constant] kSecAttrService Specifies a dictionary key whose value is the item's service attribute. You use this key to set or get a CFStringRef that represents the service associated with this item. (Items of class kSecClassGenericPassword have this attribute.) [@constant] kSecAttrGeneric Specifies a dictionary key whose value is the item's generic attribute. You use this key to set or get a value of CFDataRef that contains a user-defined attribute. (Items of class kSecClassGenericPassword have this attribute.) [@constant] kSecAttrSecurityDomain Specifies a dictionary key whose value is the item's security domain attribute. You use this key to set or get a CFStringRef value that represents the Internet security domain. (Items of class kSecClassInternetPassword have this attribute.) [@constant] kSecAttrServer Specifies a dictionary key whose value is the item's server attribute. You use this key to set or get a value of type CFStringRef that contains the server's domain name or IP address. (Items of class kSecClassInternetPassword have this attribute.) [@constant] kSecAttrProtocol Specifies a dictionary key whose value is the item's protocol attribute. You use this key to set or get a value of type CFNumberRef that denotes the protocol for this item (see the SecProtocolType enum in SecKeychainItem.h). (Items of class kSecClassInternetPassword have this attribute.) [@constant] kSecAttrAuthenticationType Specifies a dictionary key whose value is the item's authentication type attribute. You use this key to set or get a value of type CFNumberRef that denotes the authentication scheme for this item (see the kSecAttrAuthenticationType value constants below). [@constant] kSecAttrPort Specifies a dictionary key whose value is the item's port attribute. You use this key to set or get a CFNumberRef value that represents an Internet port number. (Items of class kSecClassInternetPassword have this attribute.) [@constant] kSecAttrPath Specifies a dictionary key whose value is the item's path attribute, typically this is the path component of the URL. You use this key to set or get a CFStringRef value that represents a path. (Items of class kSecClassInternetPassword have this attribute.) [@constant] kSecAttrSubject (read-only) Specifies a dictionary key whose value is the item's subject. You use this key to get a value of type CFDataRef that contains the X.500 subject name of a certificate. (Items of class kSecClassCertificate have this attribute.) [@constant] kSecAttrIssuer (read-only) Specifies a dictionary key whose value is the item's issuer. You use this key to get a value of type CFDataRef that contains the X.500 issuer name of a certificate. (Items of class kSecClassCertificate have this attribute.) [@constant] kSecAttrSerialNumber (read-only) Specifies a dictionary key whose value is the item's serial number. You use this key to get a value of type CFDataRef that contains the serial number data of a certificate. (Items of class kSecClassCertificate have this attribute.) [@constant] kSecAttrSubjectKeyID (read-only) Specifies a dictionary key whose value is the item's subject key ID. You use this key to get a value of type CFDataRef that contains the subject key ID of a certificate. (Items of class kSecClassCertificate have this attribute.) [@constant] kSecAttrPublicKeyHash (read-only) Specifies a dictionary key whose value is the item's public key hash. You use this key to get a value of type CFDataRef that contains the hash of a certificate's public key. (Items of class kSecClassCertificate have this attribute.) [@constant] kSecAttrCertificateType (read-only) Specifies a dictionary key whose value is the item's certificate type. You use this key to get a value of type CFNumberRef that denotes the certificate type (On iOS, currently the value of this attribute must be equal to the version of the X509 certificate. So, 1 for v1, 2 for v2, and 3 for v3 certificates). (On OSX, see the CSSM_CERT_TYPE enum in cssmtype.h). Only items of class kSecClassCertificate have this attribute. [@constant] kSecAttrCertificateEncoding (read-only) Specifies a dictionary key whose value is the item's certificate encoding. You use this key to get a value of type CFNumberRef that denotes the certificate encoding (On iOS, currently only the value 3 meaning kSecAttrCertificateEncodingDER is supported). On OSX, see the CSSM_CERT_ENCODING enum in cssmtype.h. Only items of class kSecClassCertificate have this attribute. [@constant] kSecAttrKeyClass (read only) Specifies a dictionary key whose value is one of kSecAttrKeyClassPublic, kSecAttrKeyClassPrivate or kSecAttrKeyClassSymmetric. [@constant] kSecAttrApplicationLabel Specifies a dictionary key whose value is the key's application label attribute. This is different from the kSecAttrLabel (which is intended to be human-readable). This attribute is used to look up a key programmatically; in particular, for keys of class kSecAttrKeyClassPublic and kSecAttrKeyClassPrivate, the value of this attribute is the hash of the public key. This item is a type of CFDataRef. Legacy keys may contain a UUID in this field as a CFStringRef. [@constant] kSecAttrIsPermanent Specifies a dictionary key whose value is a CFBooleanRef indicating whether the key in question will be stored permanently. [@constant] kSecAttrIsSensitive Specifies a dictionary key whose value is a CFBooleanRef indicating that the key in question can only be exported in a wrapped (encrypted) format. OS X only. [@constant] kSecAttrIsExtractable Specifies a dictionary key whose value is a CFBooleanRef indicating whether the key in question can be exported from its keychain container. OS X only. [@constant] kSecAttrApplicationTag Specifies a dictionary key whose value is a CFDataRef containing private tag data. [@constant] kSecAttrKeyType Specifies a dictionary key whose value is a CFNumberRef indicating the algorithm associated with this key (On iOS, currently only the value 42 is supported, alternatively you can use kSecAttrKeyTypeRSA). (On OSX, see the CSSM_ALGORITHMS enum in cssmtype.h). [@constant] kSecAttrPRF Specifies a dictionary key whose value is the PRF (pseudo-random function) for this key (see "kSecAttrPRF Value Constants".) OS X only. [@constant] kSecAttrSalt Specifies a dictionary key whose value is a CFData containing the salt to use for this key. OS X only. [@constant] kSecAttrRounds Specifies a dictionary key whose value is the number of rounds for the pseudo-random function specified by kSecAttrPRF. OS X only. [@constant] kSecAttrKeySizeInBits Specifies a dictionary key whose value is a CFNumberRef indicating the number of bits in this key. [@constant] kSecAttrEffectiveKeySize Specifies a dictionary key whose value is a CFNumberRef indicating the effective number of bits in this key. For example, a DES key has a kSecAttrKeySizeInBits of 64, but a kSecAttrEffectiveKeySize of 56 bits. [@constant] kSecAttrCanEncrypt Specifies a dictionary key whole value is a CFBooleanRef indicating whether the key in question can be used to encrypt data. [@constant] kSecAttrCanDecrypt Specifies a dictionary key whose value is a CFBooleanRef indicating whether the key in question can be used to decrypt data. [@constant] kSecAttrCanDerive Specifies a dictionary key whole value is a CFBooleanRef indicating whether the key in question can be used to derive another key. [@constant] kSecAttrCanSign Specifies a dictionary key whole value is a CFBooleanRef indicating whether the key in question can be used to create a digital signature. [@constant] kSecAttrCanVerify Specifies a dictionary key whole value is a CFBooleanRef indicating whether the key in question can be used to verify a digital signature. [@constant] kSecAttrCanWrap Specifies a dictionary key whole value is a CFBooleanRef indicating whether the key in question can be used to wrap another key. [@constant] kSecAttrCanUnwrap Specifies a dictionary key whole value is a CFBooleanRef indicating whether the key in question can be used to unwrap another key. [@constant] kSecAttrSyncViewHint Specifies a dictionary key whose value is a CFStringRef. This value is part of the primary key of each item, and can be used to help distiguish Sync Views when defining their queries. iOS and sychronizable items only. [@constant] kSecAttrTokenID Specifies a dictionary key whose presence indicates that item is backed by external token. Value of this attribute is CFStringRef uniquely identifying containing token. When this attribute is not present, item is stored in internal keychain database. Note that once item is created, this attribute cannot be changed - in other words it is not possible to migrate existing items to, from or between tokens. Currently the only available value for this attribute is kSecAttrTokenIDSecureEnclave, which indicates that item (private key) is backed by device's Secure Enclave. API-Since: 4.0
-
kSecAttrAccessControl
@NotNull public static @NotNull CFStringRef kSecAttrAccessControl()
API-Since: 8.0
-
kSecAttrAccessGroup
@NotNull public static @NotNull CFStringRef kSecAttrAccessGroup()
API-Since: 3.0
-
kSecAttrSynchronizable
@NotNull public static @NotNull CFStringRef kSecAttrSynchronizable()
API-Since: 7.0
-
kSecAttrCreationDate
@NotNull public static @NotNull CFStringRef kSecAttrCreationDate()
API-Since: 2.0
-
kSecAttrModificationDate
@NotNull public static @NotNull CFStringRef kSecAttrModificationDate()
API-Since: 2.0
-
kSecAttrDescription
@NotNull public static @NotNull CFStringRef kSecAttrDescription()
API-Since: 2.0
-
kSecAttrComment
@NotNull public static @NotNull CFStringRef kSecAttrComment()
API-Since: 2.0
-
kSecAttrCreator
@NotNull public static @NotNull CFStringRef kSecAttrCreator()
API-Since: 2.0
-
kSecAttrType
@NotNull public static @NotNull CFStringRef kSecAttrType()
API-Since: 2.0
-
kSecAttrLabel
@NotNull public static @NotNull CFStringRef kSecAttrLabel()
API-Since: 2.0
-
kSecAttrIsInvisible
@NotNull public static @NotNull CFStringRef kSecAttrIsInvisible()
API-Since: 2.0
-
kSecAttrIsNegative
@NotNull public static @NotNull CFStringRef kSecAttrIsNegative()
API-Since: 2.0
-
kSecAttrAccount
@NotNull public static @NotNull CFStringRef kSecAttrAccount()
API-Since: 2.0
-
kSecAttrService
@NotNull public static @NotNull CFStringRef kSecAttrService()
API-Since: 2.0
-
kSecAttrGeneric
@NotNull public static @NotNull CFStringRef kSecAttrGeneric()
API-Since: 2.0
-
kSecAttrSecurityDomain
@NotNull public static @NotNull CFStringRef kSecAttrSecurityDomain()
API-Since: 2.0
-
kSecAttrServer
@NotNull public static @NotNull CFStringRef kSecAttrServer()
API-Since: 2.0
-
kSecAttrProtocol
@NotNull public static @NotNull CFStringRef kSecAttrProtocol()
API-Since: 2.0
-
kSecAttrAuthenticationType
@NotNull public static @NotNull CFStringRef kSecAttrAuthenticationType()
API-Since: 2.0
-
kSecAttrPort
@NotNull public static @NotNull CFStringRef kSecAttrPort()
API-Since: 2.0
-
kSecAttrPath
@NotNull public static @NotNull CFStringRef kSecAttrPath()
API-Since: 2.0
-
kSecAttrSubject
@NotNull public static @NotNull CFStringRef kSecAttrSubject()
API-Since: 2.0
-
kSecAttrIssuer
@NotNull public static @NotNull CFStringRef kSecAttrIssuer()
API-Since: 2.0
-
kSecAttrSerialNumber
@NotNull public static @NotNull CFStringRef kSecAttrSerialNumber()
API-Since: 2.0
-
kSecAttrSubjectKeyID
@NotNull public static @NotNull CFStringRef kSecAttrSubjectKeyID()
API-Since: 2.0
-
kSecAttrPublicKeyHash
@NotNull public static @NotNull CFStringRef kSecAttrPublicKeyHash()
API-Since: 2.0
-
kSecAttrCertificateType
@NotNull public static @NotNull CFStringRef kSecAttrCertificateType()
API-Since: 2.0
-
kSecAttrCertificateEncoding
@NotNull public static @NotNull CFStringRef kSecAttrCertificateEncoding()
API-Since: 2.0
-
kSecAttrKeyClass
@NotNull public static @NotNull CFStringRef kSecAttrKeyClass()
API-Since: 2.0
-
kSecAttrApplicationLabel
@NotNull public static @NotNull CFStringRef kSecAttrApplicationLabel()
API-Since: 2.0
-
kSecAttrIsPermanent
@NotNull public static @NotNull CFStringRef kSecAttrIsPermanent()
API-Since: 2.0
-
kSecAttrApplicationTag
@NotNull public static @NotNull CFStringRef kSecAttrApplicationTag()
API-Since: 2.0
-
kSecAttrKeyType
@NotNull public static @NotNull CFStringRef kSecAttrKeyType()
API-Since: 2.0
-
kSecAttrKeySizeInBits
@NotNull public static @NotNull CFStringRef kSecAttrKeySizeInBits()
API-Since: 2.0
-
kSecAttrEffectiveKeySize
@NotNull public static @NotNull CFStringRef kSecAttrEffectiveKeySize()
API-Since: 2.0
-
kSecAttrCanEncrypt
@NotNull public static @NotNull CFStringRef kSecAttrCanEncrypt()
API-Since: 2.0
-
kSecAttrCanDecrypt
@NotNull public static @NotNull CFStringRef kSecAttrCanDecrypt()
API-Since: 2.0
-
kSecAttrCanDerive
@NotNull public static @NotNull CFStringRef kSecAttrCanDerive()
API-Since: 2.0
-
kSecAttrCanSign
@NotNull public static @NotNull CFStringRef kSecAttrCanSign()
API-Since: 2.0
-
kSecAttrCanVerify
@NotNull public static @NotNull CFStringRef kSecAttrCanVerify()
API-Since: 2.0
-
kSecAttrCanWrap
@NotNull public static @NotNull CFStringRef kSecAttrCanWrap()
API-Since: 2.0
-
kSecAttrCanUnwrap
@NotNull public static @NotNull CFStringRef kSecAttrCanUnwrap()
API-Since: 2.0
-
kSecAttrSyncViewHint
@NotNull public static @NotNull CFStringRef kSecAttrSyncViewHint()
API-Since: 9.0
-
kSecAttrTokenID
@NotNull public static @NotNull CFStringRef kSecAttrTokenID()
API-Since: 9.0
-
kSecAttrAccessibleWhenUnlocked
@NotNull public static @NotNull CFStringRef kSecAttrAccessibleWhenUnlocked()
[@enum] kSecAttrAccessible Value Constants Predefined item attribute constants used to get or set values in a dictionary. The kSecAttrAccessible constant is the key and its value is one of the constants defined here. When asking SecItemCopyMatching to return the item's data, the error errSecInteractionNotAllowed will be returned if the item's data is not available until a device unlock occurs. [@constant] kSecAttrAccessibleWhenUnlocked Item data can only be accessed while the device is unlocked. This is recommended for items that only need be accesible while the application is in the foreground. Items with this attribute will migrate to a new device when using encrypted backups. [@constant] kSecAttrAccessibleAfterFirstUnlock Item data can only be accessed once the device has been unlocked after a restart. This is recommended for items that need to be accesible by background applications. Items with this attribute will migrate to a new device when using encrypted backups. [@constant] kSecAttrAccessibleAlways Item data can always be accessed regardless of the lock state of the device. This is not recommended for anything except system use. Items with this attribute will migrate to a new device when using encrypted backups. [@constant] kSecAttrAccessibleWhenPasscodeSetThisDeviceOnly Item data can only be accessed while the device is unlocked. This is recommended for items that only need to be accessible while the application is in the foreground and requires a passcode to be set on the device. Items with this attribute will never migrate to a new device, so after a backup is restored to a new device, these items will be missing. This attribute will not be available on devices without a passcode. Disabling the device passcode will cause all previously protected items to be deleted. [@constant] kSecAttrAccessibleWhenUnlockedThisDeviceOnly Item data can only be accessed while the device is unlocked. This is recommended for items that only need be accesible while the application is in the foreground. Items with this attribute will never migrate to a new device, so after a backup is restored to a new device, these items will be missing. [@constant] kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly Item data can only be accessed once the device has been unlocked after a restart. This is recommended for items that need to be accessible by background applications. Items with this attribute will never migrate to a new device, so after a backup is restored to a new device these items will be missing. [@constant] kSecAttrAccessibleAlwaysThisDeviceOnly Item data can always be accessed regardless of the lock state of the device. This option is not recommended for anything except system use. Items with this attribute will never migrate to a new device, so after a backup is restored to a new device, these items will be missing. API-Since: 4.0
-
kSecAttrAccessibleAfterFirstUnlock
@NotNull public static @NotNull CFStringRef kSecAttrAccessibleAfterFirstUnlock()
API-Since: 4.0
-
kSecAttrAccessibleAlways
@NotNull @Deprecated public static @NotNull CFStringRef kSecAttrAccessibleAlways()
Deprecated.API-Since: 4.0 Deprecated-Since: 12.0 Deprecated-Message: Use an accessibility level that provides some user protection, such as kSecAttrAccessibleAfterFirstUnlock
-
kSecAttrAccessibleWhenPasscodeSetThisDeviceOnly
@NotNull public static @NotNull CFStringRef kSecAttrAccessibleWhenPasscodeSetThisDeviceOnly()
API-Since: 8.0
-
kSecAttrAccessibleWhenUnlockedThisDeviceOnly
@NotNull public static @NotNull CFStringRef kSecAttrAccessibleWhenUnlockedThisDeviceOnly()
API-Since: 4.0
-
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly
@NotNull public static @NotNull CFStringRef kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly()
API-Since: 4.0
-
kSecAttrAccessibleAlwaysThisDeviceOnly
@NotNull @Deprecated public static @NotNull CFStringRef kSecAttrAccessibleAlwaysThisDeviceOnly()
Deprecated.API-Since: 4.0 Deprecated-Since: 12.0 Deprecated-Message: Use an accessibility level that provides some user protection, such as kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly
-
kSecAttrProtocolFTP
@NotNull public static @NotNull CFStringRef kSecAttrProtocolFTP()
[@enum] kSecAttrProtocol Value Constants Predefined item attribute constants used to get or set values in a dictionary. The kSecAttrProtocol constant is the key and its value is one of the constants defined here. [@constant] kSecAttrProtocolFTP. [@constant] kSecAttrProtocolFTPAccount. [@constant] kSecAttrProtocolHTTP. [@constant] kSecAttrProtocolIRC. [@constant] kSecAttrProtocolNNTP. [@constant] kSecAttrProtocolPOP3. [@constant] kSecAttrProtocolSMTP. [@constant] kSecAttrProtocolSOCKS. [@constant] kSecAttrProtocolIMAP. [@constant] kSecAttrProtocolLDAP. [@constant] kSecAttrProtocolAppleTalk. [@constant] kSecAttrProtocolAFP. [@constant] kSecAttrProtocolTelnet. [@constant] kSecAttrProtocolSSH. [@constant] kSecAttrProtocolFTPS. [@constant] kSecAttrProtocolHTTPS. [@constant] kSecAttrProtocolHTTPProxy. [@constant] kSecAttrProtocolHTTPSProxy. [@constant] kSecAttrProtocolFTPProxy. [@constant] kSecAttrProtocolSMB. [@constant] kSecAttrProtocolRTSP. [@constant] kSecAttrProtocolRTSPProxy. [@constant] kSecAttrProtocolDAAP. [@constant] kSecAttrProtocolEPPC. [@constant] kSecAttrProtocolIPP. [@constant] kSecAttrProtocolNNTPS. [@constant] kSecAttrProtocolLDAPS. [@constant] kSecAttrProtocolTelnetS. [@constant] kSecAttrProtocolIMAPS. [@constant] kSecAttrProtocolIRCS. [@constant] kSecAttrProtocolPOP3S. API-Since: 2.0
-
kSecAttrProtocolFTPAccount
@NotNull public static @NotNull CFStringRef kSecAttrProtocolFTPAccount()
API-Since: 2.0
-
kSecAttrProtocolHTTP
@NotNull public static @NotNull CFStringRef kSecAttrProtocolHTTP()
API-Since: 2.0
-
kSecAttrProtocolIRC
@NotNull public static @NotNull CFStringRef kSecAttrProtocolIRC()
API-Since: 2.0
-
kSecAttrProtocolNNTP
@NotNull public static @NotNull CFStringRef kSecAttrProtocolNNTP()
API-Since: 2.0
-
kSecAttrProtocolPOP3
@NotNull public static @NotNull CFStringRef kSecAttrProtocolPOP3()
API-Since: 2.0
-
kSecAttrProtocolSMTP
@NotNull public static @NotNull CFStringRef kSecAttrProtocolSMTP()
API-Since: 2.0
-
kSecAttrProtocolSOCKS
@NotNull public static @NotNull CFStringRef kSecAttrProtocolSOCKS()
API-Since: 2.0
-
kSecAttrProtocolIMAP
@NotNull public static @NotNull CFStringRef kSecAttrProtocolIMAP()
API-Since: 2.0
-
kSecAttrProtocolLDAP
@NotNull public static @NotNull CFStringRef kSecAttrProtocolLDAP()
API-Since: 2.0
-
kSecAttrProtocolAppleTalk
@NotNull public static @NotNull CFStringRef kSecAttrProtocolAppleTalk()
API-Since: 2.0
-
kSecAttrProtocolAFP
@NotNull public static @NotNull CFStringRef kSecAttrProtocolAFP()
API-Since: 2.0
-
kSecAttrProtocolTelnet
@NotNull public static @NotNull CFStringRef kSecAttrProtocolTelnet()
API-Since: 2.0
-
kSecAttrProtocolSSH
@NotNull public static @NotNull CFStringRef kSecAttrProtocolSSH()
API-Since: 2.0
-
kSecAttrProtocolFTPS
@NotNull public static @NotNull CFStringRef kSecAttrProtocolFTPS()
API-Since: 2.0
-
kSecAttrProtocolHTTPS
@NotNull public static @NotNull CFStringRef kSecAttrProtocolHTTPS()
API-Since: 2.0
-
kSecAttrProtocolHTTPProxy
@NotNull public static @NotNull CFStringRef kSecAttrProtocolHTTPProxy()
API-Since: 2.0
-
kSecAttrProtocolHTTPSProxy
@NotNull public static @NotNull CFStringRef kSecAttrProtocolHTTPSProxy()
API-Since: 2.0
-
kSecAttrProtocolFTPProxy
@NotNull public static @NotNull CFStringRef kSecAttrProtocolFTPProxy()
API-Since: 2.0
-
kSecAttrProtocolSMB
@NotNull public static @NotNull CFStringRef kSecAttrProtocolSMB()
API-Since: 2.0
-
kSecAttrProtocolRTSP
@NotNull public static @NotNull CFStringRef kSecAttrProtocolRTSP()
API-Since: 2.0
-
kSecAttrProtocolRTSPProxy
@NotNull public static @NotNull CFStringRef kSecAttrProtocolRTSPProxy()
API-Since: 2.0
-
kSecAttrProtocolDAAP
@NotNull public static @NotNull CFStringRef kSecAttrProtocolDAAP()
API-Since: 2.0
-
kSecAttrProtocolEPPC
@NotNull public static @NotNull CFStringRef kSecAttrProtocolEPPC()
API-Since: 2.0
-
kSecAttrProtocolIPP
@NotNull public static @NotNull CFStringRef kSecAttrProtocolIPP()
API-Since: 2.0
-
kSecAttrProtocolNNTPS
@NotNull public static @NotNull CFStringRef kSecAttrProtocolNNTPS()
API-Since: 2.0
-
kSecAttrProtocolLDAPS
@NotNull public static @NotNull CFStringRef kSecAttrProtocolLDAPS()
API-Since: 2.0
-
kSecAttrProtocolTelnetS
@NotNull public static @NotNull CFStringRef kSecAttrProtocolTelnetS()
API-Since: 2.0
-
kSecAttrProtocolIMAPS
@NotNull public static @NotNull CFStringRef kSecAttrProtocolIMAPS()
API-Since: 2.0
-
kSecAttrProtocolIRCS
@NotNull public static @NotNull CFStringRef kSecAttrProtocolIRCS()
API-Since: 2.0
-
kSecAttrProtocolPOP3S
@NotNull public static @NotNull CFStringRef kSecAttrProtocolPOP3S()
API-Since: 2.0
-
kSecAttrAuthenticationTypeNTLM
@NotNull public static @NotNull CFStringRef kSecAttrAuthenticationTypeNTLM()
[@enum] kSecAttrAuthenticationType Value Constants Predefined item attribute constants used to get or set values in a dictionary. The kSecAttrAuthenticationType constant is the key and its value is one of the constants defined here. [@constant] kSecAttrAuthenticationTypeNTLM. [@constant] kSecAttrAuthenticationTypeMSN. [@constant] kSecAttrAuthenticationTypeDPA. [@constant] kSecAttrAuthenticationTypeRPA. [@constant] kSecAttrAuthenticationTypeHTTPBasic. [@constant] kSecAttrAuthenticationTypeHTTPDigest. [@constant] kSecAttrAuthenticationTypeHTMLForm. [@constant] kSecAttrAuthenticationTypeDefault. API-Since: 2.0
-
kSecAttrAuthenticationTypeMSN
@NotNull public static @NotNull CFStringRef kSecAttrAuthenticationTypeMSN()
API-Since: 2.0
-
kSecAttrAuthenticationTypeDPA
@NotNull public static @NotNull CFStringRef kSecAttrAuthenticationTypeDPA()
API-Since: 2.0
-
kSecAttrAuthenticationTypeRPA
@NotNull public static @NotNull CFStringRef kSecAttrAuthenticationTypeRPA()
API-Since: 2.0
-
kSecAttrAuthenticationTypeHTTPBasic
@NotNull public static @NotNull CFStringRef kSecAttrAuthenticationTypeHTTPBasic()
API-Since: 2.0
-
kSecAttrAuthenticationTypeHTTPDigest
@NotNull public static @NotNull CFStringRef kSecAttrAuthenticationTypeHTTPDigest()
API-Since: 2.0
-
kSecAttrAuthenticationTypeHTMLForm
@NotNull public static @NotNull CFStringRef kSecAttrAuthenticationTypeHTMLForm()
API-Since: 2.0
-
kSecAttrAuthenticationTypeDefault
@NotNull public static @NotNull CFStringRef kSecAttrAuthenticationTypeDefault()
API-Since: 2.0
-
kSecAttrKeyClassPublic
@NotNull public static @NotNull CFStringRef kSecAttrKeyClassPublic()
[@enum] kSecAttrKeyClass Value Constants Predefined item attribute constants used to get or set values in a dictionary. The kSecAttrKeyClass constant is the key and its value is one of the constants defined here. [@constant] kSecAttrKeyClassPublic. [@constant] kSecAttrKeyClassPrivate. [@constant] kSecAttrKeyClassSymmetric. API-Since: 2.0
-
kSecAttrKeyClassPrivate
@NotNull public static @NotNull CFStringRef kSecAttrKeyClassPrivate()
API-Since: 2.0
-
kSecAttrKeyClassSymmetric
@NotNull public static @NotNull CFStringRef kSecAttrKeyClassSymmetric()
API-Since: 2.0
-
kSecAttrKeyTypeRSA
@NotNull public static @NotNull CFStringRef kSecAttrKeyTypeRSA()
[@enum] kSecAttrKeyType Value Constants Predefined item attribute constants used to get or set values in a dictionary. The kSecAttrKeyType constant is the key and its value is one of the constants defined here. [@constant] kSecAttrKeyTypeECSECPrimeRandom. The used curve is P-192, P-256, P-384 or P-521. The size is specified by kSecAttrKeySizeInBits attribute. Curves are defined in FIPS PUB 186-4 standard. [@constant] kSecAttrKeyTypeEC This is the legacy name for kSecAttrKeyTypeECSECPrimeRandom, new applications should not use it. [@constant] kSecAttrKeyTypeDSA (OSX only) [@constant] kSecAttrKeyTypeAES (OSX only) [@constant] kSecAttrKeyType3DES (OSX only) [@constant] kSecAttrKeyTypeRC4 (OSX only) [@constant] kSecAttrKeyTypeRC2 (OSX only) [@constant] kSecAttrKeyTypeCAST (OSX only) [@constant] kSecAttrKeyTypeECDSA (deprecated; use kSecAttrKeyTypeECSECPrimeRandom instead.) (OSX only) API-Since: 2.0
-
kSecAttrKeyTypeEC
@NotNull public static @NotNull CFStringRef kSecAttrKeyTypeEC()
API-Since: 4.0
-
kSecAttrKeyTypeECSECPrimeRandom
@NotNull public static @NotNull CFStringRef kSecAttrKeyTypeECSECPrimeRandom()
API-Since: 10.0
-
kSecAttrSynchronizableAny
@NotNull public static @NotNull CFStringRef kSecAttrSynchronizableAny()
API-Since: 7.0
-
kSecMatchPolicy
@NotNull public static @NotNull CFStringRef kSecMatchPolicy()
[@enum] Search Constants Predefined search constants used to set values in a query dictionary. You can specify a combination of search attributes and item attributes when looking for matching items with the SecItemCopyMatching function. [@constant] kSecMatchPolicy Specifies a dictionary key whose value is a SecPolicyRef. If provided, returned certificates or identities must verify with this policy. [@constant] kSecMatchItemList OS X only. Specifies a dictionary key whose value is a CFArray of SecKeychainItemRef items. If provided, returned items will be limited to the subset which are contained in this list. [@constant] kSecMatchSearchList Specifies a dictionary key whose value is a CFArray of SecKeychainRef items. If provided, the search will be limited to the keychains contained in this list. [@constant] kSecMatchIssuers Specifies a dictionary key whose value is a CFArray of X.500 names (of type CFDataRef). If provided, returned certificates or identities will be limited to those whose certificate chain contains one of the issuers provided in this list. [@constant] kSecMatchEmailAddressIfPresent Specifies a dictionary key whose value is a CFStringRef containing an RFC822 email address. If provided, returned certificates or identities will be limited to those that contain the address in their subject or subject alternative name. [@constant] kSecMatchSubjectContains Specifies a dictionary key whose value is a CFStringRef. If provided, returned certificates or identities will be limited to those containing this string in the subject. [@constant] kSecMatchSubjectStartsWith OS X only. Specifies a dictionary key whose value is a CFStringRef. If provided, returned certificates or identities will be limited to those with subject names that start with this string. [@constant] kSecMatchSubjectEndsWith OS X only. Specifies a dictionary key whose value is a CFStringRef. If provided, returned certificates or identities will be limited to those with subject names that end with this string. [@constant] kSecMatchSubjectWholeString OS X only. Specifies a dictionary key whose value is a CFStringRef. If provided, returned certificates or identities will be limited to those matching this string exactly in the subject. [@constant] kSecMatchCaseInsensitive Specifies a dictionary key whose value is a CFBooleanRef. If this value is kCFBooleanFalse, or is not provided, then case-sensitive string matching is performed. [@constant] kSecMatchDiacriticInsensitive OS X only. Specifies a dictionary key whose value is a CFBooleanRef. If this value is kCFBooleanFalse, or is not provided, then diacritic-sensitive string matching is performed. [@constant] kSecMatchWidthInsensitive OS X only. Specifies a dictionary key whose value is a CFBooleanRef. If this value is kCFBooleanFalse, or is not provided, then string matching is width-sensitive (e.g. 'a' != 0xFF41). [@constant] kSecMatchTrustedOnly Specifies a dictionary key whose value is a CFBooleanRef. If provided with a value of kCFBooleanTrue, only certificates which can be verified back to a trusted anchor will be returned. If this value is kCFBooleanFalse, or is not provided, then both trusted and untrusted certificates may be returned. [@constant] kSecMatchValidOnDate Specifies a dictionary key whose value is of type CFDateRef. If provided, returned keys, certificates or identities will be limited to those which are valid for the given date. Pass a value of kCFNull to indicate the current date. [@constant] kSecMatchLimit Specifies a dictionary key whose value is a CFNumberRef. If provided, this value specifies the maximum number of results to return. If not provided, results are limited to the first item found. Predefined values are provided for a single item (kSecMatchLimitOne) and all matching items (kSecMatchLimitAll). [@constant] kSecMatchLimitOne Specifies that results are limited to the first item found; used as a value for the kSecMatchLimit dictionary key. [@constant] kSecMatchLimitAll Specifies that an unlimited number of results may be returned; used as a value for the kSecMatchLimit dictionary key. API-Since: 2.0
-
kSecMatchItemList
@NotNull public static @NotNull CFStringRef kSecMatchItemList()
API-Since: 2.0
-
kSecMatchSearchList
@NotNull public static @NotNull CFStringRef kSecMatchSearchList()
API-Since: 2.0
-
kSecMatchIssuers
@NotNull public static @NotNull CFStringRef kSecMatchIssuers()
API-Since: 2.0
-
kSecMatchEmailAddressIfPresent
@NotNull public static @NotNull CFStringRef kSecMatchEmailAddressIfPresent()
API-Since: 2.0
-
kSecMatchSubjectContains
@NotNull public static @NotNull CFStringRef kSecMatchSubjectContains()
API-Since: 2.0
-
kSecMatchCaseInsensitive
@NotNull public static @NotNull CFStringRef kSecMatchCaseInsensitive()
API-Since: 2.0
-
kSecMatchTrustedOnly
@NotNull public static @NotNull CFStringRef kSecMatchTrustedOnly()
API-Since: 2.0
-
kSecMatchValidOnDate
@NotNull public static @NotNull CFStringRef kSecMatchValidOnDate()
API-Since: 2.0
-
kSecMatchLimit
@NotNull public static @NotNull CFStringRef kSecMatchLimit()
API-Since: 2.0
-
kSecMatchLimitOne
@NotNull public static @NotNull CFStringRef kSecMatchLimitOne()
API-Since: 2.0
-
kSecMatchLimitAll
@NotNull public static @NotNull CFStringRef kSecMatchLimitAll()
API-Since: 2.0
-
kSecReturnData
@NotNull public static @NotNull CFStringRef kSecReturnData()
[@enum] Return Type Key Constants Predefined return type keys used to set values in a dictionary. You use these keys to specify the type of results which should be returned by the SecItemCopyMatching or SecItemAdd function. You can specify zero or more of these return types. If more than one of these result types is specified, the result is returned as a CFDictionaryRef whose keys are the result types and values are the requested data. [@constant] kSecReturnData Specifies a dictionary key whose value is of type CFBooleanRef. A value of kCFBooleanTrue indicates that the data of an item (CFDataRef) should be returned. For keys and password items, data is secret (encrypted) and may require the user to enter a password for access. [@constant] kSecReturnAttributes Specifies a dictionary key whose value is of type CFBooleanRef. A value of kCFBooleanTrue indicates that the (non-encrypted) attributes of an item (CFDictionaryRef) should be returned. [@constant] kSecReturnRef Specifies a dictionary key whose value is a CFBooleanRef. A value of kCFBooleanTrue indicates that a reference should be returned. Depending on the item class requested, the returned reference(s) may be of type SecKeychainItemRef, SecKeyRef, SecCertificateRef, or SecIdentityRef. Note that returning references is supported only for Certificate, Key or Identity items on iOS, watchOS and tvOS. Similarly, returning references is supported only for Certificate, Key or Identity items on macOS when either kSecUseDataProtectionKeychain is set to true or kSecAttrSynchronizable is set to true. [@constant] kSecReturnPersistentRef Specifies a dictionary key whose value is of type CFBooleanRef. A value of kCFBooleanTrue indicates that a persistent reference to an item (CFDataRef) should be returned. API-Since: 2.0
-
kSecReturnAttributes
@NotNull public static @NotNull CFStringRef kSecReturnAttributes()
API-Since: 2.0
-
kSecReturnRef
@NotNull public static @NotNull CFStringRef kSecReturnRef()
API-Since: 2.0
-
kSecReturnPersistentRef
@NotNull public static @NotNull CFStringRef kSecReturnPersistentRef()
API-Since: 2.0
-
kSecValueData
@NotNull public static @NotNull CFStringRef kSecValueData()
[@enum] Value Type Key Constants Predefined value type keys used to pass values in a dictionary. You can specify zero or more of these types depending on the function you are calling. For SecItemCopyMatching or SecItemAdd these are used as keys in the results dictionary. [@constant] kSecValueData Specifies a dictionary key whose value is of type CFDataRef. For keys and password items, data is secret (encrypted) and may require the user to enter a password for access. [@constant] kSecValueRef Specifies a dictionary key whose value, depending on the item class requested, is of type SecKeychainItemRef, SecKeyRef, SecCertificateRef, or SecIdentityRef. [@constant] kSecValuePersistentRef Specifies a dictionary key whose value is of type CFDataRef. The bytes in this CFDataRef can be stored by the caller and used on a subsequent invocation of the application (or even a different application) to retrieve the item referenced by it. API-Since: 2.0
-
kSecValueRef
@NotNull public static @NotNull CFStringRef kSecValueRef()
API-Since: 2.0
-
kSecValuePersistentRef
@NotNull public static @NotNull CFStringRef kSecValuePersistentRef()
API-Since: 2.0
-
kSecUseItemList
@NotNull @Deprecated public static @NotNull CFStringRef kSecUseItemList()
Deprecated.[@enum] Other Constants Predefined constants used to set values in a dictionary. [@constant] kSecUseItemList Specifies a dictionary key whose value is a CFArray of items. If provided, this array is treated as the set of all possible items to search, or add if the API being called is SecItemAdd. The items in this array may be of type SecKeyRef, SecCertificateRef, SecIdentityRef, or CFDataRef (for a persistent item reference.) The items in the array must all be of the same type. When this attribute is provided, no keychains are searched. [@constant] kSecUseKeychain OS X only. Specifies a dictionary key whose value is a keychain reference. You use this key to specify a value of type SecKeychainRef to which SecItemAdd will add the provided item(s). [@constant] kSecUseOperationPrompt Specifies a dictionary key whose value is a CFStringRef that represents a user-visible string describing the operation for which the application is attempting to authenticate. The application is responsible for the text localization. [@constant] kSecUseNoAuthenticationUI OS X only. Specifies a dictionary key whose value is a CFBooleanRef. If provided with a value of kCFBooleanTrue, the error errSecInteractionNotAllowed will be returned if the item is attempting to authenticate with UI. [@constant] kSecUseAuthenticationUI Specifies a dictionary key whose value is one of kSecUseAuthenticationUIAllow, kSecUseAuthenticationUIFail, kSecUseAuthenticationUISkip. [@constant] kSecUseAuthenticationContext Specifies a dictionary key whose value is LAContext to be used for keychain item authentication. * If the item requires authentication and this key is omitted, a new context will be created just for the purpose of the single call. * If the specified context has been previously authenticated, the operation will succeed without asking user for authentication. * If the specified context has not been previously authenticated, the new authentication will be started on this context, allowing caller to eventually reuse the successfully authenticated context in subsequent keychain operations. [@constant] kSecUseDataProtectionKeychain Specifies a dictionary key whose value is a CFBooleanRef. Set to kCFBooleanTrue to use kSecAttrAccessGroup and/or kSecAttrAccessible on macOS without requiring the item to be marked synchronizable. Note that when kSecUseDataProtectionKeychain is set to true, returning references is supported only for Certificate, Key or Identity items. [@constant] kSecUseUserIndependentKeychain Specifies a dctionary key whose value is a CFBooleanRef indicating whether the item is shared with other personas on the system. API-Since: 2.0 Deprecated-Since: 12.0 Deprecated-Message: Not implemented on this platform
-
kSecUseOperationPrompt
@NotNull @Deprecated public static @NotNull CFStringRef kSecUseOperationPrompt()
Deprecated.API-Since: 8.0 Deprecated-Since: 14.0 Deprecated-Message: Use kSecUseAuthenticationContext and set LAContext.localizedReason property
-
kSecUseNoAuthenticationUI
@NotNull @Deprecated public static @NotNull CFStringRef kSecUseNoAuthenticationUI()
Deprecated.API-Since: 8.0 Deprecated-Since: 9.0 Deprecated-Message: Use kSecUseAuthenticationUI instead.
-
kSecUseAuthenticationUI
@NotNull public static @NotNull CFStringRef kSecUseAuthenticationUI()
API-Since: 9.0
-
kSecUseAuthenticationContext
@NotNull public static @NotNull CFStringRef kSecUseAuthenticationContext()
API-Since: 9.0
-
kSecUseAuthenticationUIAllow
@NotNull @Deprecated public static @NotNull CFStringRef kSecUseAuthenticationUIAllow()
Deprecated.[@enum] kSecUseAuthenticationUI Value Constants Predefined item attribute constants used to get or set values in a dictionary. The kSecUseAuthenticationUI constant is the key and its value is one of the constants defined here. If the key kSecUseAuthenticationUI not provided then kSecUseAuthenticationUIAllow is used as default. [@constant] kSecUseAuthenticationUIAllow Specifies that authenticate UI can appear. [@constant] kSecUseAuthenticationUIFail Specifies that the error errSecInteractionNotAllowed will be returned if an item needs to authenticate with UI [@constant] kSecUseAuthenticationUISkip Specifies that all items which need to authenticate with UI will be silently skipped. This value can be used only with SecItemCopyMatching. API-Since: 9.0 Deprecated-Since: 14.0 Deprecated-Message: Instead of kSecUseAuthenticationUI, use kSecUseAuthenticationContext and set LAContext.interactionNotAllowed property
-
kSecUseAuthenticationUIFail
@NotNull @Deprecated public static @NotNull CFStringRef kSecUseAuthenticationUIFail()
Deprecated.API-Since: 9.0 Deprecated-Since: 14.0 Deprecated-Message: Instead of kSecUseAuthenticationUI, use kSecUseAuthenticationContext and set LAContext.interactionNotAllowed property
-
kSecUseAuthenticationUISkip
@NotNull public static @NotNull CFStringRef kSecUseAuthenticationUISkip()
API-Since: 9.0
-
kSecAttrTokenIDSecureEnclave
@NotNull public static @NotNull CFStringRef kSecAttrTokenIDSecureEnclave()
[@enum] kSecAttrTokenID Value Constants Predefined item attribute constant used to get or set values in a dictionary. The kSecAttrTokenID constant is the key and its value can be kSecAttrTokenIDSecureEnclave. [@constant] kSecAttrTokenIDSecureEnclave Specifies well-known identifier of the token implemented using device's Secure Enclave. The only keychain items supported by the Secure Enclave token are 256-bit elliptic curve keys (kSecAttrKeyTypeECSecPrimeRandom). Keys must be generated on the secure enclave using SecKeyGenerateKeyPair call with kSecAttrTokenID set to kSecAttrTokenIDSecureEnclave in the parameters dictionary, it is not possible to import pregenerated keys to kSecAttrTokenIDSecureEnclave token. API-Since: 9.0
-
kSecAttrAccessGroupToken
@NotNull public static @NotNull CFStringRef kSecAttrAccessGroupToken()
[@enum] kSecAttrAccessGroup Value Constants [@constant] kSecAttrAccessGroupToken Represents well-known access group which contains items provided by external token (typically smart card). This may be used as a value for kSecAttrAccessGroup attribute. Every application has access to this access group so it is not needed to explicitly list it in keychain-access-groups entitlement, but application must explicitly state this access group in keychain queries in order to be able to access items from external tokens. API-Since: 10.0
-
kSecPrivateKeyAttrs
@NotNull public static @NotNull CFStringRef kSecPrivateKeyAttrs()
[@enum] Key Parameter Constants Predefined key constants used to get or set values in a dictionary. These are used to provide explicit parameters to key generation functions when non-default values are desired. See the description of the SecKeyGeneratePair API for usage information. [@constant] kSecPrivateKeyAttrs The value for this key is a CFDictionaryRef containing attributes specific for the private key to be generated. [@constant] kSecPublicKeyAttrs The value for this key is a CFDictionaryRef containing attributes specific for the public key to be generated. API-Since: 2.0
-
kSecPublicKeyAttrs
@NotNull public static @NotNull CFStringRef kSecPublicKeyAttrs()
API-Since: 2.0
-
kSecKeyAlgorithmRSASignatureRaw
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureRaw()
API-Since: 10.0
-
kSecKeyAlgorithmRSASignatureDigestPKCS1v15Raw
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureDigestPKCS1v15Raw()
API-Since: 10.0
-
kSecKeyAlgorithmRSASignatureDigestPKCS1v15SHA1
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureDigestPKCS1v15SHA1()
API-Since: 10.0
-
kSecKeyAlgorithmRSASignatureDigestPKCS1v15SHA224
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureDigestPKCS1v15SHA224()
API-Since: 10.0
-
kSecKeyAlgorithmRSASignatureDigestPKCS1v15SHA256
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureDigestPKCS1v15SHA256()
API-Since: 10.0
-
kSecKeyAlgorithmRSASignatureDigestPKCS1v15SHA384
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureDigestPKCS1v15SHA384()
API-Since: 10.0
-
kSecKeyAlgorithmRSASignatureDigestPKCS1v15SHA512
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureDigestPKCS1v15SHA512()
API-Since: 10.0
-
kSecKeyAlgorithmRSASignatureMessagePKCS1v15SHA1
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureMessagePKCS1v15SHA1()
API-Since: 10.0
-
kSecKeyAlgorithmRSASignatureMessagePKCS1v15SHA224
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureMessagePKCS1v15SHA224()
API-Since: 10.0
-
kSecKeyAlgorithmRSASignatureMessagePKCS1v15SHA256
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureMessagePKCS1v15SHA256()
API-Since: 10.0
-
kSecKeyAlgorithmRSASignatureMessagePKCS1v15SHA384
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureMessagePKCS1v15SHA384()
API-Since: 10.0
-
kSecKeyAlgorithmRSASignatureMessagePKCS1v15SHA512
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureMessagePKCS1v15SHA512()
API-Since: 10.0
-
kSecKeyAlgorithmECDSASignatureRFC4754
@Deprecated @NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureRFC4754()
Deprecated.API-Since: 10.0 Deprecated-Since: 17.0
-
kSecKeyAlgorithmECDSASignatureDigestX962
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureDigestX962()
API-Since: 10.0
-
kSecKeyAlgorithmECDSASignatureDigestX962SHA1
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureDigestX962SHA1()
API-Since: 10.0
-
kSecKeyAlgorithmECDSASignatureDigestX962SHA224
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureDigestX962SHA224()
API-Since: 10.0
-
kSecKeyAlgorithmECDSASignatureDigestX962SHA256
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureDigestX962SHA256()
API-Since: 10.0
-
kSecKeyAlgorithmECDSASignatureDigestX962SHA384
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureDigestX962SHA384()
API-Since: 10.0
-
kSecKeyAlgorithmECDSASignatureDigestX962SHA512
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureDigestX962SHA512()
API-Since: 10.0
-
kSecKeyAlgorithmECDSASignatureMessageX962SHA1
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureMessageX962SHA1()
API-Since: 10.0
-
kSecKeyAlgorithmECDSASignatureMessageX962SHA224
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureMessageX962SHA224()
API-Since: 10.0
-
kSecKeyAlgorithmECDSASignatureMessageX962SHA256
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureMessageX962SHA256()
API-Since: 10.0
-
kSecKeyAlgorithmECDSASignatureMessageX962SHA384
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureMessageX962SHA384()
API-Since: 10.0
-
kSecKeyAlgorithmECDSASignatureMessageX962SHA512
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureMessageX962SHA512()
API-Since: 10.0
-
kSecKeyAlgorithmRSAEncryptionRaw
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSAEncryptionRaw()
API-Since: 10.0
-
kSecKeyAlgorithmRSAEncryptionPKCS1
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSAEncryptionPKCS1()
API-Since: 10.0
-
kSecKeyAlgorithmRSAEncryptionOAEPSHA1
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSAEncryptionOAEPSHA1()
API-Since: 10.0
-
kSecKeyAlgorithmRSAEncryptionOAEPSHA224
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSAEncryptionOAEPSHA224()
API-Since: 10.0
-
kSecKeyAlgorithmRSAEncryptionOAEPSHA256
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSAEncryptionOAEPSHA256()
API-Since: 10.0
-
kSecKeyAlgorithmRSAEncryptionOAEPSHA384
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSAEncryptionOAEPSHA384()
API-Since: 10.0
-
kSecKeyAlgorithmRSAEncryptionOAEPSHA512
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSAEncryptionOAEPSHA512()
API-Since: 10.0
-
kSecKeyAlgorithmRSAEncryptionOAEPSHA1AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSAEncryptionOAEPSHA1AESGCM()
API-Since: 10.0
-
kSecKeyAlgorithmRSAEncryptionOAEPSHA224AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSAEncryptionOAEPSHA224AESGCM()
API-Since: 10.0
-
kSecKeyAlgorithmRSAEncryptionOAEPSHA256AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSAEncryptionOAEPSHA256AESGCM()
API-Since: 10.0
-
kSecKeyAlgorithmRSAEncryptionOAEPSHA384AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSAEncryptionOAEPSHA384AESGCM()
API-Since: 10.0
-
kSecKeyAlgorithmRSAEncryptionOAEPSHA512AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSAEncryptionOAEPSHA512AESGCM()
API-Since: 10.0
-
kSecKeyAlgorithmECIESEncryptionStandardX963SHA1AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionStandardX963SHA1AESGCM()
API-Since: 10.0
-
kSecKeyAlgorithmECIESEncryptionStandardX963SHA224AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionStandardX963SHA224AESGCM()
API-Since: 10.0
-
kSecKeyAlgorithmECIESEncryptionStandardX963SHA256AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionStandardX963SHA256AESGCM()
API-Since: 10.0
-
kSecKeyAlgorithmECIESEncryptionStandardX963SHA384AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionStandardX963SHA384AESGCM()
API-Since: 10.0
-
kSecKeyAlgorithmECIESEncryptionStandardX963SHA512AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionStandardX963SHA512AESGCM()
API-Since: 10.0
-
kSecKeyAlgorithmECIESEncryptionCofactorX963SHA1AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionCofactorX963SHA1AESGCM()
API-Since: 10.0
-
kSecKeyAlgorithmECIESEncryptionCofactorX963SHA224AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionCofactorX963SHA224AESGCM()
API-Since: 10.0
-
kSecKeyAlgorithmECIESEncryptionCofactorX963SHA256AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionCofactorX963SHA256AESGCM()
API-Since: 10.0
-
kSecKeyAlgorithmECIESEncryptionCofactorX963SHA384AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionCofactorX963SHA384AESGCM()
API-Since: 10.0
-
kSecKeyAlgorithmECIESEncryptionCofactorX963SHA512AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionCofactorX963SHA512AESGCM()
API-Since: 10.0
-
kSecKeyAlgorithmECDHKeyExchangeStandard
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDHKeyExchangeStandard()
API-Since: 10.0
-
kSecKeyAlgorithmECDHKeyExchangeStandardX963SHA1
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDHKeyExchangeStandardX963SHA1()
API-Since: 10.0
-
kSecKeyAlgorithmECDHKeyExchangeStandardX963SHA224
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDHKeyExchangeStandardX963SHA224()
API-Since: 10.0
-
kSecKeyAlgorithmECDHKeyExchangeStandardX963SHA256
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDHKeyExchangeStandardX963SHA256()
API-Since: 10.0
-
kSecKeyAlgorithmECDHKeyExchangeStandardX963SHA384
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDHKeyExchangeStandardX963SHA384()
API-Since: 10.0
-
kSecKeyAlgorithmECDHKeyExchangeStandardX963SHA512
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDHKeyExchangeStandardX963SHA512()
API-Since: 10.0
-
kSecKeyAlgorithmECDHKeyExchangeCofactor
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDHKeyExchangeCofactor()
API-Since: 10.0
-
kSecKeyAlgorithmECDHKeyExchangeCofactorX963SHA1
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDHKeyExchangeCofactorX963SHA1()
API-Since: 10.0
-
kSecKeyAlgorithmECDHKeyExchangeCofactorX963SHA224
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDHKeyExchangeCofactorX963SHA224()
API-Since: 10.0
-
kSecKeyAlgorithmECDHKeyExchangeCofactorX963SHA256
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDHKeyExchangeCofactorX963SHA256()
API-Since: 10.0
-
kSecKeyAlgorithmECDHKeyExchangeCofactorX963SHA384
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDHKeyExchangeCofactorX963SHA384()
API-Since: 10.0
-
kSecKeyAlgorithmECDHKeyExchangeCofactorX963SHA512
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDHKeyExchangeCofactorX963SHA512()
API-Since: 10.0
-
kSecKeyKeyExchangeParameterRequestedSize
@NotNull public static @NotNull CFStringRef kSecKeyKeyExchangeParameterRequestedSize()
API-Since: 10.0
-
kSecKeyKeyExchangeParameterSharedInfo
@NotNull public static @NotNull CFStringRef kSecKeyKeyExchangeParameterSharedInfo()
API-Since: 10.0
-
kSecPolicyAppleX509Basic
@NotNull public static @NotNull CFStringRef kSecPolicyAppleX509Basic()
[@enum] Policy Constants Predefined constants used to specify a policy. [@constant] kSecPolicyAppleX509Basic [@constant] kSecPolicyAppleSSL [@constant] kSecPolicyAppleSMIME [@constant] kSecPolicyAppleEAP [@constant] kSecPolicyAppleiChat [@constant] kSecPolicyAppleIPsec [@constant] kSecPolicyApplePKINITClient [@constant] kSecPolicyApplePKINITServer [@constant] kSecPolicyAppleCodeSigning [@constant] kSecPolicyMacAppStoreReceipt [@constant] kSecPolicyAppleIDValidation [@constant] kSecPolicyAppleTimeStamping [@constant] kSecPolicyAppleRevocation [@constant] kSecPolicyApplePassbookSigning [@constant] kSecPolicyApplePayIssuerEncryption API-Since: 7.0
-
kSecPolicyAppleSSL
@NotNull public static @NotNull CFStringRef kSecPolicyAppleSSL()
API-Since: 7.0
-
kSecPolicyAppleSMIME
@NotNull public static @NotNull CFStringRef kSecPolicyAppleSMIME()
API-Since: 7.0
-
kSecPolicyAppleEAP
@NotNull public static @NotNull CFStringRef kSecPolicyAppleEAP()
API-Since: 7.0
-
kSecPolicyAppleIPsec
@NotNull public static @NotNull CFStringRef kSecPolicyAppleIPsec()
API-Since: 7.0
-
kSecPolicyAppleCodeSigning
@NotNull public static @NotNull CFStringRef kSecPolicyAppleCodeSigning()
API-Since: 7.0
-
kSecPolicyMacAppStoreReceipt
@NotNull public static @NotNull CFStringRef kSecPolicyMacAppStoreReceipt()
API-Since: 9.0
-
kSecPolicyAppleIDValidation
@NotNull public static @NotNull CFStringRef kSecPolicyAppleIDValidation()
API-Since: 7.0
-
kSecPolicyAppleTimeStamping
@NotNull public static @NotNull CFStringRef kSecPolicyAppleTimeStamping()
API-Since: 7.0
-
kSecPolicyAppleRevocation
@NotNull public static @NotNull CFStringRef kSecPolicyAppleRevocation()
API-Since: 7.0
-
kSecPolicyApplePassbookSigning
@NotNull public static @NotNull CFStringRef kSecPolicyApplePassbookSigning()
API-Since: 7.0
-
kSecPolicyApplePayIssuerEncryption
@NotNull public static @NotNull CFStringRef kSecPolicyApplePayIssuerEncryption()
API-Since: 9.0
-
kSecPolicyOid
@NotNull public static @NotNull CFStringRef kSecPolicyOid()
[@enum] Policy Value Constants Predefined property key constants used to get or set values in a dictionary for a policy instance. All policies will have the following read-only value: kSecPolicyOid (the policy object identifier) Additional policy values which your code can optionally set: kSecPolicyName (name which must be matched) kSecPolicyClient (evaluate for client, rather than server) kSecPolicyRevocationFlags (only valid for a revocation policy) kSecPolicyTeamIdentifier (only valid for a Passbook signing policy) [@constant] kSecPolicyOid Specifies the policy OID (value is a CFStringRef) [@constant] kSecPolicyName Specifies a CFStringRef (or CFArrayRef of same) containing a name which must be matched in the certificate to satisfy this policy. For SSL/TLS, EAP, and IPSec policies, this specifies the server name which must match the common name of the certificate. For S/MIME, this specifies the RFC822 email address. For Passbook signing, this specifies the pass signer. [@constant] kSecPolicyClient Specifies a CFBooleanRef value that indicates this evaluation should be for a client certificate. If not set (or false), the policy evaluates the certificate as a server certificate. [@constant] kSecPolicyRevocationFlags Specifies a CFNumberRef that holds a kCFNumberCFIndexType bitmask value. See "Revocation Policy Constants" for a description of individual bits in this value. [@constant] kSecPolicyTeamIdentifier Specifies a CFStringRef containing a team identifier which must be matched in the certificate to satisfy this policy. For the Passbook signing policy, this string must match the Organizational Unit field of the certificate subject. API-Since: 7.0
-
kSecPolicyName
@NotNull public static @NotNull CFStringRef kSecPolicyName()
API-Since: 7.0
-
kSecPolicyClient
@NotNull public static @NotNull CFStringRef kSecPolicyClient()
API-Since: 7.0
-
kSecPolicyRevocationFlags
@NotNull public static @NotNull CFStringRef kSecPolicyRevocationFlags()
API-Since: 7.0
-
kSecPolicyTeamIdentifier
@NotNull public static @NotNull CFStringRef kSecPolicyTeamIdentifier()
API-Since: 7.0
-
kSecRandomDefault
@NotNull public static @NotNull SecRandomRef kSecRandomDefault()
This is a synonym for NULL, if you'd rather use a named constant. This refers to a cryptographically secure random number generator. API-Since: 2.0
-
kSecSharedPassword
@NotNull public static @NotNull CFStringRef kSecSharedPassword()
[@enum] Credential Key Constants Predefined key constants used to get values in a dictionary of credentials returned by SecRequestWebCredential. [@constant] kSecSharedPassword Specifies a dictionary key whose value is a shared password. You use this key to get a value of type CFStringRef that contains a password. API-Since: 8.0
-
kSecPropertyTypeTitle
@NotNull public static @NotNull CFStringRef kSecPropertyTypeTitle()
[@enum] Trust Property Constants Predefined key constants used to obtain values in a per-certificate dictionary of trust evaluation results, as retrieved from a call to SecTrustCopyProperties. [@constant] kSecPropertyTypeTitle Specifies a key whose value is a CFStringRef containing the title (display name) of this certificate. [@constant] kSecPropertyTypeError Specifies a key whose value is a CFStringRef containing the reason for a trust evaluation failure. API-Since: 7.0
-
kSecPropertyTypeError
@NotNull public static @NotNull CFStringRef kSecPropertyTypeError()
API-Since: 7.0
-
kSecTrustEvaluationDate
@NotNull public static @NotNull CFStringRef kSecTrustEvaluationDate()
[@enum] Trust Result Constants Predefined key constants used to obtain values in a dictionary of trust evaluation results for a certificate chain, as retrieved from a call to SecTrustCopyResult. [@constant] kSecTrustEvaluationDate This key will be present if a trust evaluation has been performed and results are available. Its value is a CFDateRef representing when the evaluation for this trust object took place. [@constant] kSecTrustExtendedValidation This key will be present and have a value of kCFBooleanTrue if this chain was validated for EV. [@constant] kSecTrustOrganizationName Organization name field of subject of leaf certificate. This field is meant to be displayed to the user as the validated name of the company or entity that owns the certificate if the kSecTrustExtendedValidation key is present. [@constant] kSecTrustResultValue This key will be present if a trust evaluation has been performed. Its value is a CFNumberRef representing the SecTrustResultType result for the evaluation. [@constant] kSecTrustRevocationChecked This key will be present iff this chain had its revocation checked. The value will be a kCFBooleanTrue if revocation checking was successful and none of the certificates in the chain were revoked. The value will be kCFBooleanFalse if no current revocation status could be obtained for one or more certificates in the chain due to connection problems or timeouts. This is a hint to a client to retry revocation checking at a later time. [@constant] kSecTrustRevocationValidUntilDate This key will be present iff kSecTrustRevocationChecked has a value of kCFBooleanTrue. The value will be a CFDateRef representing the earliest date at which the revocation info for one of the certificates in this chain might change. [@constant] kSecTrustCertificateTransparency This key will be present and have a value of kCFBooleanTrue if this chain is CT qualified. [@constant] kSecTrustCertificateTransparencyWhiteList This key will be present and have a value of kCFBooleanTrue if this chain is EV, but not CT qualified, and is permitted as an exception to CT policy requirements. Note: in macOS 10.12 and iOS 10, previously-issued EV certificates were considered exempt from the CT requirement. As those certificates expired, exempting them was no longer needed. This key is deprecated in macOS 10.13 and iOS 11, and is no longer returned in the trust results dictionary as of those releases. API-Since: 7.0
-
kSecTrustExtendedValidation
@NotNull public static @NotNull CFStringRef kSecTrustExtendedValidation()
API-Since: 7.0
-
kSecTrustOrganizationName
@NotNull public static @NotNull CFStringRef kSecTrustOrganizationName()
API-Since: 7.0
-
kSecTrustResultValue
@NotNull public static @NotNull CFStringRef kSecTrustResultValue()
API-Since: 7.0
-
kSecTrustRevocationChecked
@NotNull public static @NotNull CFStringRef kSecTrustRevocationChecked()
API-Since: 7.0
-
kSecTrustRevocationValidUntilDate
@NotNull public static @NotNull CFStringRef kSecTrustRevocationValidUntilDate()
API-Since: 7.0
-
kSecTrustCertificateTransparency
@NotNull public static @NotNull CFStringRef kSecTrustCertificateTransparency()
API-Since: 9.0
-
kSecTrustCertificateTransparencyWhiteList
@NotNull @Deprecated public static @NotNull CFStringRef kSecTrustCertificateTransparencyWhiteList()
Deprecated.API-Since: 10.0 Deprecated-Since: 11.0
-
kSSLSessionConfig_default
@NotNull @Deprecated public static @NotNull CFStringRef kSSLSessionConfig_default()
Deprecated.Default configuration (has 3DES, no RC4) API-Since: 5.0 Deprecated-Since: 11.0 Deprecated-Message: No longer supported. Use Network.framework.
-
kSSLSessionConfig_ATSv1
@NotNull @Deprecated public static @NotNull CFStringRef kSSLSessionConfig_ATSv1()
Deprecated.ATS v1 Config: TLS v1.2, only PFS ciphersuites API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
kSSLSessionConfig_ATSv1_noPFS
@NotNull @Deprecated public static @NotNull CFStringRef kSSLSessionConfig_ATSv1_noPFS()
Deprecated.ATS v1 Config without PFS: TLS v1.2, include non PFS ciphersuites API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
kSSLSessionConfig_standard
@NotNull @Deprecated public static @NotNull CFStringRef kSSLSessionConfig_standard()
Deprecated.TLS v1.2 to TLS v1.0, with default ciphersuites (no 3DES, no RC4) API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
kSSLSessionConfig_RC4_fallback
@NotNull @Deprecated public static @NotNull CFStringRef kSSLSessionConfig_RC4_fallback()
Deprecated.TLS v1.2 to TLS v1.0, with default ciphersuites + RC4 + 3DES API-Since: 5.0 Deprecated-Since: 11.0 Deprecated-Message: No longer supported. Use Network.framework.
-
kSSLSessionConfig_TLSv1_fallback
@NotNull @Deprecated public static @NotNull CFStringRef kSSLSessionConfig_TLSv1_fallback()
Deprecated.TLS v1.0 only, with default ciphersuites + fallback SCSV API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
kSSLSessionConfig_TLSv1_RC4_fallback
@NotNull @Deprecated public static @NotNull CFStringRef kSSLSessionConfig_TLSv1_RC4_fallback()
Deprecated.TLS v1.0, with default ciphersuites + RC4 + 3DES + fallback SCSV API-Since: 5.0 Deprecated-Since: 11.0 Deprecated-Message: No longer supported. Use Network.framework.
-
kSSLSessionConfig_legacy
@NotNull @Deprecated public static @NotNull CFStringRef kSSLSessionConfig_legacy()
Deprecated.TLS v1.2 to TLS v1.0, defaults + RC4 + DHE ciphersuites API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
kSSLSessionConfig_legacy_DHE
@NotNull @Deprecated public static @NotNull CFStringRef kSSLSessionConfig_legacy_DHE()
Deprecated.TLS v1.2 to TLS v1.0, default + RC4 + DHE ciphersuites API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
kSSLSessionConfig_anonymous
@NotNull @Deprecated public static @NotNull CFStringRef kSSLSessionConfig_anonymous()
Deprecated.TLS v1.2, anonymous ciphersuites only API-Since: 5.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
kSSLSessionConfig_3DES_fallback
@NotNull @Deprecated public static @NotNull CFStringRef kSSLSessionConfig_3DES_fallback()
Deprecated.TLS v1.2 to TLS v1.0, has 3DES, no RC4 API-Since: 5.0 Deprecated-Since: 11.0 Deprecated-Message: No longer supported. Use Network.framework.
-
kSSLSessionConfig_TLSv1_3DES_fallback
@NotNull @Deprecated public static @NotNull CFStringRef kSSLSessionConfig_TLSv1_3DES_fallback()
Deprecated.TLS v1.0, with default ciphersuites + 3DES, no RC4 API-Since: 5.0 Deprecated-Since: 11.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SecCertificateCopyCommonName
public static int SecCertificateCopyCommonName(@NotNull @NotNull SecCertificateRef certificate, @NotNull @NotNull org.moe.natj.general.ptr.Ptr<CFStringRef> commonName)[@function] SecCertificateCopyCommonName Retrieves the common name of the subject of a given certificate. All the data in this string comes from the certificate itself, and thus it's in whatever language the certificate itself is in. Note that the certificate's common name field may not be present, or may be inadequate to describe the certificate; for display purposes, you should consider using SecCertificateCopySubjectSummary instead of this function. API-Since: 10.3- Parameters:
certificate- A reference to the certificate from which to retrieve the common name.commonName- On return, a reference to the common name. Your code must release this reference by calling the CFRelease function.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecCertificateCopyEmailAddresses
public static int SecCertificateCopyEmailAddresses(@NotNull @NotNull SecCertificateRef certificate, @NotNull @NotNull org.moe.natj.general.ptr.Ptr<CFArrayRef> emailAddresses)[@function] SecCertificateCopyEmailAddresses Returns an array of zero or more email addresses for the subject of a given certificate.- Parameters:
certificate- A reference to the certificate from which to retrieve the email addresses.emailAddresses- On return, an array of zero or more CFStringRef elements corresponding to each email address found. Your code must release this array reference by calling the CFRelease function.- Returns:
- A result code. See "Security Error Codes" (SecBase.h). API-Since: 10.3
-
SecCertificateCopyNormalizedIssuerSequence
@Nullable public static @Nullable CFDataRef SecCertificateCopyNormalizedIssuerSequence(@NotNull @NotNull SecCertificateRef certificate)
[@function] SecCertificateCopyNormalizedIssuerSequence Return the certificate's normalized issuer The issuer is a sequence in the format used by SecItemCopyMatching. The content returned is a DER-encoded X.509 distinguished name. For a display version of the issuer, call SecCertificateCopyValues. The caller must CFRelease the value returned. API-Since: 10.3- Parameters:
certificate- The certificate from which to get values
-
SecCertificateCopyNormalizedSubjectSequence
@Nullable public static @Nullable CFDataRef SecCertificateCopyNormalizedSubjectSequence(@NotNull @NotNull SecCertificateRef certificate)
[@function] SecCertificateCopyNormalizedSubjectSequence Return the certificate's normalized subject The subject is a sequence in the format used by SecItemCopyMatching. The content returned is a DER-encoded X.509 distinguished name. For a display version of the subject, call SecCertificateCopyValues. The caller must CFRelease the value returned. API-Since: 10.3- Parameters:
certificate- The certificate from which to get values
-
SecCertificateCopyPublicKey
@Nullable @Deprecated public static @Nullable SecKeyRef SecCertificateCopyPublicKey(@NotNull @NotNull SecCertificateRef certificate)
Deprecated.[@function] SecCertificateCopyPublicKey Retrieves the public key for a given certificate. NOTE: Deprecated in iOS 12.0; use SecCertificateCopyKey instead for cross-platform availability. API-Since: 10.3 Deprecated-Since: 12.0- Parameters:
certificate- A reference to the certificate from which to retrieve the public key.- Returns:
- A reference to the public key for the specified certificate. Your code must release this reference by calling the CFRelease function.
-
SecCertificateCopySerialNumberData
@Nullable public static @Nullable CFDataRef SecCertificateCopySerialNumberData(@NotNull @NotNull SecCertificateRef certificate, @Nullable @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)
[@function] SecCertificateCopySerialNumberData Return the certificate's serial number. Return the content of a DER-encoded integer (without the tag and length fields) for this certificate's serial number. The caller must CFRelease the value returned. API-Since: 11.0- Parameters:
certificate- The certificate from which to get values.error- An optional pointer to a CFErrorRef which will be set on return from the function if an error occurred. If not NULL, the caller is responsible for releasing the CFErrorRef.
-
SecCertificateCopySerialNumber
@Nullable @Deprecated public static @Nullable CFDataRef SecCertificateCopySerialNumber(@NotNull @NotNull SecCertificateRef certificate)
Deprecated.[@function] SecCertificateCopySerialNumber Return the certificate's serial number. Return the content of a DER-encoded integer (without the tag and length fields) for this certificate's serial number. The caller must CFRelease the value returned. NOTE: Deprecated in iOS 11.0; use SecCertificateCopySerialNumberData instead for cross-platform availability. API-Since: 10.3 Deprecated-Since: 11.0- Parameters:
certificate- The certificate from which to get values.
-
SSLSetSessionTicketsEnabled
@Deprecated public static int SSLSetSessionTicketsEnabled(@NotNull @NotNull SSLContextRef context, byte enabled)Deprecated.[@function] SSLSetSessionTicketsEnabled Forcibly enable or disable session ticket resumption. [@note] By default, session tickets are disabled.- Parameters:
context- A valid SSLContextRef.enabled- Boolean indicating if ticket support is enabled (true) or not (false).- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 11.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetALPNProtocols
@Deprecated public static int SSLSetALPNProtocols(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull CFArrayRef protocols)Deprecated.[@function] SSLSetALPNProtocols Set the ALPN protocols to be passed in the ALPN negotiation. This is the list of supported application-layer protocols supported. The protocols parameter must be an array of CFStringRef values with ASCII-encoded reprensetations of the supported protocols, e.g., "http/1.1". [@note] See RFC 7301 for more information.- Parameters:
context- A valid SSLContextRef.protocols- Array of CFStringRefs carrying application protocols.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 11.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLCopyALPNProtocols
@Deprecated public static int SSLCopyALPNProtocols(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull org.moe.natj.general.ptr.Ptr<CFArrayRef> protocols)Deprecated.[@function] SSLCopyALPNProtocols Get the ALPN protocols associated with this SSL context. This is the list of supported application-layer protocols supported. The resultant protocols array will contain CFStringRef values containing ASCII-encoded representations of the supported protocols, e.g., "http/1.1". See RFC 7301 for more information. [@note] The `protocols` pointer must be NULL, otherwise the copy will fail. This function will allocate memory for the CFArrayRef container if there is data to provide. Otherwise, the pointer will remain NULL.- Parameters:
context- A valid SSLContextRef.protocols- Pointer to a CFArrayRef where peer ALPN protocols are stored.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 11.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetOCSPResponse
@Deprecated public static int SSLSetOCSPResponse(@NotNull @NotNull SSLContextRef context, @NotNull @NotNull CFDataRef response)Deprecated.[@function] SSLSetOCSPResponse Set the OCSP response for the given SSL session. The response parameter must be a non-NULL CFDataRef containing the bytes of the OCSP response.- Parameters:
context- A valid SSLContextRef.response- CFDataRef carrying OCSP response.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 11.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
SSLSetError
@Deprecated public static int SSLSetError(@NotNull @NotNull SSLContextRef context, int status)Deprecated.[@function] SSLSetError Set the status of a SSLContextRef. This is to be done after handling steps of the SSL handshake such as server certificate validation.- Parameters:
context- A valid SSLContextRef.status- Error status to set internally, which will be translated to an alert.- Returns:
- errSecSuccess on success, alternative error on failure. API-Since: 11.0 Deprecated-Since: 13.0 Deprecated-Message: No longer supported. Use Network.framework.
-
kSecAttrIsSensitive
@NotNull public static @NotNull CFStringRef kSecAttrIsSensitive()
API-Since: 2.0
-
kSecAttrIsExtractable
@NotNull public static @NotNull CFStringRef kSecAttrIsExtractable()
API-Since: 2.0
-
kSecAttrPersistantReference
@NotNull public static @NotNull CFStringRef kSecAttrPersistantReference()
API-Since: 11.0
-
kSecAttrPersistentReference
@NotNull public static @NotNull CFStringRef kSecAttrPersistentReference()
API-Since: 11.0
-
kSecKeyAlgorithmRSASignatureDigestPSSSHA1
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureDigestPSSSHA1()
API-Since: 11.0
-
kSecKeyAlgorithmRSASignatureDigestPSSSHA224
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureDigestPSSSHA224()
API-Since: 11.0
-
kSecKeyAlgorithmRSASignatureDigestPSSSHA256
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureDigestPSSSHA256()
API-Since: 11.0
-
kSecKeyAlgorithmRSASignatureDigestPSSSHA384
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureDigestPSSSHA384()
API-Since: 11.0
-
kSecKeyAlgorithmRSASignatureDigestPSSSHA512
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureDigestPSSSHA512()
API-Since: 11.0
-
kSecKeyAlgorithmRSASignatureMessagePSSSHA1
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureMessagePSSSHA1()
API-Since: 11.0
-
kSecKeyAlgorithmRSASignatureMessagePSSSHA224
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureMessagePSSSHA224()
API-Since: 11.0
-
kSecKeyAlgorithmRSASignatureMessagePSSSHA256
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureMessagePSSSHA256()
API-Since: 11.0
-
kSecKeyAlgorithmRSASignatureMessagePSSSHA384
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureMessagePSSSHA384()
API-Since: 11.0
-
kSecKeyAlgorithmRSASignatureMessagePSSSHA512
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmRSASignatureMessagePSSSHA512()
API-Since: 11.0
-
kSecKeyAlgorithmECIESEncryptionStandardVariableIVX963SHA224AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionStandardVariableIVX963SHA224AESGCM()
API-Since: 11.0
-
kSecKeyAlgorithmECIESEncryptionStandardVariableIVX963SHA256AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionStandardVariableIVX963SHA256AESGCM()
API-Since: 11.0
-
kSecKeyAlgorithmECIESEncryptionStandardVariableIVX963SHA384AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionStandardVariableIVX963SHA384AESGCM()
API-Since: 11.0
-
kSecKeyAlgorithmECIESEncryptionStandardVariableIVX963SHA512AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionStandardVariableIVX963SHA512AESGCM()
API-Since: 11.0
-
kSecKeyAlgorithmECIESEncryptionCofactorVariableIVX963SHA224AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionCofactorVariableIVX963SHA224AESGCM()
API-Since: 11.0
-
kSecKeyAlgorithmECIESEncryptionCofactorVariableIVX963SHA256AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionCofactorVariableIVX963SHA256AESGCM()
API-Since: 11.0
-
kSecKeyAlgorithmECIESEncryptionCofactorVariableIVX963SHA384AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionCofactorVariableIVX963SHA384AESGCM()
API-Since: 11.0
-
kSecKeyAlgorithmECIESEncryptionCofactorVariableIVX963SHA512AESGCM
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECIESEncryptionCofactorVariableIVX963SHA512AESGCM()
API-Since: 11.0
-
SecCopyErrorMessageString
@Nullable public static @Nullable CFStringRef SecCopyErrorMessageString(int status, @Nullable @Nullable org.moe.natj.general.ptr.VoidPtr reserved)
[@function] SecCopyErrorMessageString Returns a string describing the specified error result code. [@reserved] Reserved for future use. Your code should pass NULL in this parameter.- Parameters:
status- An error result code of type OSStatus or CSSM_RETURN, as returned by a Security or CSSM function.- Returns:
- A reference to an error string, or NULL if no error string is available for the specified result code. Your code must release this reference by calling the CFRelease function. API-Since: 11.3
-
SecCertificateCopyKey
@Nullable public static @Nullable SecKeyRef SecCertificateCopyKey(@NotNull @NotNull SecCertificateRef certificate)
[@function] SecCertificateCopyKey Retrieves the public key for a given certificate. RSA and ECDSA public keys are supported. All other public key algorithms are unsupported. API-Since: 12.0- Parameters:
certificate- A reference to the certificate from which to retrieve the public key.- Returns:
- A reference to the public key for the specified certificate. Your code must release this reference by calling the CFRelease function. If the public key has an encoding issue or uses an unsupported algorithm, the returned reference will be null.
-
SecTrustEvaluateWithError
public static boolean SecTrustEvaluateWithError(@NotNull @NotNull SecTrustRef trust, @Nullable @Nullable org.moe.natj.general.ptr.Ptr<CFErrorRef> error)[@function] SecTrustEvaluateWithError Evaluates a trust reference synchronously. This function will completely evaluate trust before returning, possibly including network access to fetch intermediate certificates or to perform revocation checking. Since this function can block during those operations, you should call it from within a function that is placed on a dispatch queue, or in a separate thread from your application's main run loop. If the certificate is trusted and the result is true, the error will be set to NULL. If the certificate is not trusted or the evaluation was unable to complete, the result will be false and the error will be set with a description of the failure. The error contains a code for the most serious error encountered (if multiple trust failures occurred). The localized description indicates the certificate with the most serious problem and the type of error. The underlying error contains a localized description of each certificate in the chain that had an error and all errors found with that certificate. API-Since: 12.0- Parameters:
trust- A reference to the trust object to evaluate.error- A pointer to an error object- Returns:
- A boolean value indicating whether the certificate is trusted
-
SecTrustEvaluateAsyncWithError
public static int SecTrustEvaluateAsyncWithError(@NotNull @NotNull SecTrustRef trust, @NotNull @NotNull dispatch_queue_t queue, @NotNull @NotNull Security.Block_SecTrustEvaluateAsyncWithError result)[@function] SecTrustEvaluateAsyncWithError Evaluates a trust reference asynchronously. If the certificate is trusted, the callback will return a result parameter of true and the error will be set to NULL. If the certificate is not trusted or the evaluation was unable to complete, the result parameter will be false and the error will be set with a description of the failure. The error contains a code for the most serious error encountered (if multiple trust failures occurred). The localized description indicates the certificate with the most serious problem and the type of error. The underlying error contains a localized description of each certificate in the chain that had an error and all errors found with that certificate. API-Since: 13.0- Parameters:
trust- A reference to the trust object to evaluate.queue- A dispatch queue on which the result callback will be executed. Note that this function MUST be called from that queue.result- A SecTrustWithErrorCallback block which will be executed when the trust evaluation is complete. The block is guaranteed to be called exactly once when the result code is errSecSuccess, and not called otherwise. Note that this block may be called synchronously inline if no asynchronous operations are required.- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
SecTrustSetSignedCertificateTimestamps
public static int SecTrustSetSignedCertificateTimestamps(@NotNull @NotNull SecTrustRef trust, @Nullable @Nullable CFArrayRef sctArray)[@function] SecTrustSignedCertificateTimestamps Attach SignedCertificateTimestamp data to a trust object. Allows the caller to provide SCT data (which may be obtained during a TLS/SSL handshake, per RFC 6962) as input to a trust evaluation. API-Since: 12.1.1- Parameters:
trust- A reference to a trust object.sctArray- is a CFArray of CFData objects each containing a SCT (per RFC 6962).- Returns:
- A result code. See "Security Error Codes" (SecBase.h).
-
sec_trust_create
@Nullable public static @Nullable sec_trust_t sec_trust_create(@NotNull @NotNull SecTrustRef trust)
[@function] sec_trust_create Create an ARC-able `sec_trust_t` instance from a `SecTrustRef`.- Parameters:
trust- A `SecTrustRef` instance.- Returns:
- a `sec_trust_t` instance. API-Since: 12.0
-
sec_trust_copy_ref
@NotNull public static @NotNull SecTrustRef sec_trust_copy_ref(@NotNull @NotNull sec_trust_t trust)
[@function] sec_trust_copy_ref Copy a retained reference to the underlying `SecTrustRef` instance.- Parameters:
trust- A `sec_trust_t` instance.- Returns:
- The underlying `SecTrustRef` instance. API-Since: 12.0
-
sec_identity_create
@Nullable public static @Nullable sec_identity_t sec_identity_create(@NotNull @NotNull SecIdentityRef identity)
[@function] sec_identity_create Create an ARC-able `sec_identity_t` instance from a `SecIdentityRef`.- Parameters:
identity- A `SecIdentityRef` instance.- Returns:
- a `sec_identity_t` instance. API-Since: 12.0
-
sec_identity_create_with_certificates
@Nullable public static @Nullable sec_identity_t sec_identity_create_with_certificates(@NotNull @NotNull SecIdentityRef identity, @NotNull @NotNull CFArrayRef certificates)
[@function] sec_identity_create_with_certificates Create an ARC-able `sec_identity_t` instance from a `SecIdentityRef` and array of SecCertificateRef instances.- Parameters:
identity- A `SecIdentityRef` instance.certificates- An array of `SecCertificateRef` instances.- Returns:
- a `sec_identity_t` instance. API-Since: 12.0
-
sec_identity_access_certificates
public static boolean sec_identity_access_certificates(@NotNull @NotNull sec_identity_t identity, @NotNull @NotNull Security.Block_sec_identity_access_certificates handler)[@function] sec_identity_access_certificates Access the certificates associated with the `sec_identity_t` instance.- Parameters:
identity- A `sec_identity_t` instance.handler- A block to invoke one or more times with `sec_certificate_t` instances.- Returns:
- Returns true if the peer certificates were accessible, false otherwise. API-Since: 13.0
-
sec_identity_copy_ref
@Nullable public static @Nullable SecIdentityRef sec_identity_copy_ref(@NotNull @NotNull sec_identity_t identity)
[@function] sec_identity_copy_ref Copy a retained reference to the underlying `SecIdentityRef` instance.- Parameters:
identity- A `sec_identity_t` instance.- Returns:
- The underlying `SecIdentityRef` instance. API-Since: 12.0
-
sec_identity_copy_certificates_ref
@Nullable public static @Nullable CFArrayRef sec_identity_copy_certificates_ref(@NotNull @NotNull sec_identity_t identity)
[@function] sec_identity_copy_certificates_ref Copy a retained reference to the underlying `CFArrayRef` container of `SecCertificateRef` types.- Parameters:
identity- A `sec_identity_t` instance.- Returns:
- The underlying `CFArrayRef` container with `SecCertificateRef` instances. API-Since: 12.0
-
sec_certificate_create
@Nullable public static @Nullable sec_certificate_t sec_certificate_create(@NotNull @NotNull SecCertificateRef certificate)
[@function] sec_certificate_create Create an ARC-able `sec_certificate_t` instance from a `SecCertificateRef`.- Parameters:
certificate- A `SecCertificateRef` instance.- Returns:
- a `sec_certificate_t` instance. API-Since: 12.0
-
sec_certificate_copy_ref
@NotNull public static @NotNull SecCertificateRef sec_certificate_copy_ref(@NotNull @NotNull sec_certificate_t certificate)
[@function] sec_certificate_copy_ref Copy a retained reference to the underlying `SecCertificateRef` instance.- Parameters:
certificate- A `sec_certificate_t` instance.- Returns:
- The underlying `SecCertificateRef` instance. API-Since: 12.0
-
sec_protocol_metadata_get_negotiated_protocol
@Nullable public static @Nullable java.lang.String sec_protocol_metadata_get_negotiated_protocol(@NotNull @NotNull sec_protocol_metadata_t metadata)[@function] sec_protocol_metadata_get_negotiated_protocol Get the application protocol negotiated, e.g., via the TLS ALPN extension.- Parameters:
metadata- A `sec_protocol_metadata_t` instance.- Returns:
- A NULL-terminated string carrying the negotiated protocol. API-Since: 12.0
-
sec_protocol_metadata_copy_peer_public_key
@Nullable public static @Nullable dispatch_data_t sec_protocol_metadata_copy_peer_public_key(@NotNull @NotNull sec_protocol_metadata_t metadata)
[@function] sec_protocol_metadata_copy_peer_public_key Get the protocol instance peer's public key.- Parameters:
metadata- A `sec_protocol_metadata_t` instance.- Returns:
- A `dispatch_data_t` containing the peer's raw public key. API-Since: 12.0
-
sec_protocol_metadata_get_negotiated_tls_protocol_version
public static short sec_protocol_metadata_get_negotiated_tls_protocol_version(@NotNull @NotNull sec_protocol_metadata_t metadata)[@function] sec_protocol_metadata_get_negotiated_tls_protocol_version Get the negotiated TLS version.- Parameters:
metadata- A `sec_protocol_metadata_t` instance.- Returns:
- A `tls_protocol_version_t` value. API-Since: 13.0
-
sec_protocol_metadata_get_negotiated_protocol_version
@Deprecated public static int sec_protocol_metadata_get_negotiated_protocol_version(@NotNull @NotNull sec_protocol_metadata_t metadata)Deprecated.[@function] sec_protocol_metadata_get_negotiated_protocol_version Get the negotiated TLS version.- Parameters:
metadata- A `sec_protocol_metadata_t` instance.- Returns:
- A SSLProtocol enum of the TLS version. API-Since: 12.0 Deprecated-Since: 13.0
-
sec_protocol_metadata_get_negotiated_tls_ciphersuite
public static short sec_protocol_metadata_get_negotiated_tls_ciphersuite(@NotNull @NotNull sec_protocol_metadata_t metadata)[@function] sec_protocol_metadata_get_negotiated_tls_ciphersuite Get the negotiated TLS ciphersuite.- Parameters:
metadata- A `sec_protocol_metadata_t` instance.- Returns:
- A `tls_ciphersuite_t`. API-Since: 13.0
-
sec_protocol_metadata_get_negotiated_ciphersuite
@Deprecated public static char sec_protocol_metadata_get_negotiated_ciphersuite(@NotNull @NotNull sec_protocol_metadata_t metadata)Deprecated.[@function] sec_protocol_metadata_get_negotiated_ciphersuite Get the negotiated TLS ciphersuite.- Parameters:
metadata- A `sec_protocol_metadata_t` instance.- Returns:
- A SSLCipherSuite. API-Since: 12.0 Deprecated-Since: 13.0
-
sec_protocol_metadata_get_early_data_accepted
public static boolean sec_protocol_metadata_get_early_data_accepted(@NotNull @NotNull sec_protocol_metadata_t metadata)[@function] sec_protocol_metadata_get_early_data_accepted Determine if early data was accepted by the peer.- Parameters:
metadata- A `sec_protocol_metadata_t` instance.- Returns:
- A bool indicating if early data was accepted. API-Since: 12.0
-
sec_protocol_metadata_access_peer_certificate_chain
public static boolean sec_protocol_metadata_access_peer_certificate_chain(@NotNull @NotNull sec_protocol_metadata_t metadata, @NotNull @NotNull Security.Block_sec_protocol_metadata_access_peer_certificate_chain handler)[@function] sec_protocol_metadata_access_peer_certificate_chain Get the certificate chain of the protocol instance peer.- Parameters:
metadata- A `sec_protocol_metadata_t` instance.handler- A block to invoke one or more times with sec_certificate_t objects- Returns:
- Returns true if the peer certificates were accessible, false otherwise. API-Since: 12.0
-
sec_protocol_metadata_access_ocsp_response
public static boolean sec_protocol_metadata_access_ocsp_response(@NotNull @NotNull sec_protocol_metadata_t metadata, @NotNull @NotNull Security.Block_sec_protocol_metadata_access_ocsp_response handler)[@function] sec_protocol_metadata_copy_ocsp_response Get the OCSP response from the protocol instance peer.- Parameters:
metadata- A `sec_protocol_metadata_t` instance.handler- A block to invoke one or more times with OCSP data- Returns:
- Returns true if the OSCP response was accessible, false otherwise. API-Since: 12.0
-
sec_protocol_metadata_access_supported_signature_algorithms
public static boolean sec_protocol_metadata_access_supported_signature_algorithms(@NotNull @NotNull sec_protocol_metadata_t metadata, @NotNull @NotNull Security.Block_sec_protocol_metadata_access_supported_signature_algorithms handler)[@function] sec_protocol_metadata_access_supported_signature_algorithms Get the signature algorithms supported by the peer. Clients may call this in response to a challenge block.- Parameters:
metadata- A `sec_protocol_metadata_t` instance.handler- A block to invoke one or more times with OCSP data- Returns:
- Returns true if the supported signature list was accessible, false otherwise. API-Since: 12.0
-
sec_protocol_metadata_access_distinguished_names
public static boolean sec_protocol_metadata_access_distinguished_names(@NotNull @NotNull sec_protocol_metadata_t metadata, @NotNull @NotNull Security.Block_sec_protocol_metadata_access_distinguished_names handler)[@function] sec_protocol_metadata_access_distinguished_names Get the X.509 Distinguished Names from the protocol instance peer.- Parameters:
metadata- A `sec_protocol_metadata_t` instance.handler- A block to invoke one or more times with distinguished_name data- Returns:
- Returns true if the distinguished names were accessible, false otherwise. API-Since: 12.0
-
sec_protocol_metadata_access_pre_shared_keys
public static boolean sec_protocol_metadata_access_pre_shared_keys(@NotNull @NotNull sec_protocol_metadata_t metadata, @NotNull @NotNull Security.Block_sec_protocol_metadata_access_pre_shared_keys handler)[@function] sec_protocol_metadata_access_pre_shared_keys Get the PSKs supported by the local instance.- Parameters:
metadata- A `sec_protocol_metadata_t` instance.handler- A block to invoke one or more times with tuples of dispatch_data_t objects carrying PSKs and their corresponding identities.- Returns:
- Returns true if the PSKs were accessible, false otherwise. API-Since: 13.0
-
sec_protocol_metadata_get_server_name
@Nullable public static @Nullable java.lang.String sec_protocol_metadata_get_server_name(@NotNull @NotNull sec_protocol_metadata_t metadata)[@function] sec_protocol_metadata_get_server_name Obtain the server name offered by a client or server during connection establishmet. This is the value commonly carried in the TLS SNI extesion.- Parameters:
metadata- A `sec_protocol_metadata_t` instance.- Returns:
- Returns A NULL-terminated string carrying the server name, or NULL if none was provided. API-Since: 12.0
-
sec_protocol_metadata_peers_are_equal
public static boolean sec_protocol_metadata_peers_are_equal(@NotNull @NotNull sec_protocol_metadata_t metadataA, @NotNull @NotNull sec_protocol_metadata_t metadataB)[@function] sec_protocol_metadata_peers_are_equal Compare peer information for two `sec_protocol_metadata` instances. This comparison does not include protocol configuration options, e.g., ciphersuites.- Parameters:
metadataA- A `sec_protocol_metadata_t` instance.metadataB- A `sec_protocol_metadata_t` instance.- Returns:
- Returns true if both metadata values refer to the same peer, and false otherwise. API-Since: 12.0
-
sec_protocol_metadata_challenge_parameters_are_equal
public static boolean sec_protocol_metadata_challenge_parameters_are_equal(@NotNull @NotNull sec_protocol_metadata_t metadataA, @NotNull @NotNull sec_protocol_metadata_t metadataB)[@function] sec_protocol_metadata_challenge_parameters_are_equal Compare challenge-relevant information for two `sec_protocol_metadata` instances. This comparison includes all information relevant to a challenge request, including: distinguished names, signature algorithms, and supported certificate types. See Section 7.4.4 of RFC5246 for more details.- Parameters:
metadataA- A `sec_protocol_metadata_t` instance.metadataB- A `sec_protocol_metadata_t` instance.- Returns:
- Returns true if both metadata values have the same challenge parameters. API-Since: 12.0
-
sec_protocol_metadata_create_secret
@Nullable public static @Nullable dispatch_data_t sec_protocol_metadata_create_secret(@NotNull @NotNull sec_protocol_metadata_t metadata, long label_len, @NotNull @NotNull java.lang.String label, long exporter_length)
[@function] sec_protocol_metadata_create_secret Export a secret, e.g., a cryptographic key, derived from the protocol metadata using a label string.- Parameters:
metadata- A `sec_protocol_metadata_t` instance.label_len- Length of the KDF label string.label- KDF label string.exporter_length- Length of the secret to be exported.- Returns:
- Returns a dispatch_data_t object carrying the exported secret. API-Since: 12.0
-
sec_protocol_metadata_create_secret_with_context
@Nullable public static @Nullable dispatch_data_t sec_protocol_metadata_create_secret_with_context(@NotNull @NotNull sec_protocol_metadata_t metadata, long label_len, @NotNull @NotNull java.lang.String label, long context_len, @NotNull @NotNull java.lang.String context, long exporter_length)
[@function] sec_protocol_metadata_create_secret_with_context Export a secret, e.g., a cryptographic key, derived from the protocol metadata using a label and context string.- Parameters:
metadata- A `sec_protocol_metadata_t` instance.label_len- Length of the KDF label string.label- KDF label string.context_len- Length of the KDF context string.context- Constant opaque context valueexporter_length- Length of the secret to be exported.- Returns:
- Returns a dispatch_data_t object carrying the exported secret. API-Since: 12.0
-
sec_protocol_options_are_equal
public static boolean sec_protocol_options_are_equal(@NotNull @NotNull sec_protocol_options_t optionsA, @NotNull @NotNull sec_protocol_options_t optionsB)[@function] sec_protocol_options_are_equal Compare two `sec_protocol_options_t` instances.- Parameters:
optionsA- A `sec_protocol_options_t` instance.optionsB- A `sec_protocol_options_t` instance.- Returns:
- True if equal, and false otherwise. API-Since: 13.0
-
sec_protocol_options_set_local_identity
public static void sec_protocol_options_set_local_identity(@NotNull @NotNull sec_protocol_options_t options, @NotNull @NotNull sec_identity_t identity)[@function] sec_protocol_options_set_local_identity Set the local identity to be used for this protocol instance.- Parameters:
options- A `sec_protocol_options_t` instance.identity- A `sec_identity_t` instance carrying the private key and certificate. API-Since: 12.0
-
sec_protocol_options_append_tls_ciphersuite
public static void sec_protocol_options_append_tls_ciphersuite(@NotNull @NotNull sec_protocol_options_t options, short ciphersuite)[@function] sec_protocol_options_append_tls_ciphersuite Append a TLS ciphersuite to the set of enabled ciphersuites.- Parameters:
options- A `sec_protocol_options_t` instance.ciphersuite- A `tls_ciphersuite_t` value. API-Since: 13.0
-
sec_protocol_options_add_tls_ciphersuite
@Deprecated public static void sec_protocol_options_add_tls_ciphersuite(@NotNull @NotNull sec_protocol_options_t options, char ciphersuite)Deprecated.[@function] sec_protocol_options_add_tls_ciphersuite Add a TLS ciphersuite to the set of enabled ciphersuites.- Parameters:
options- A `sec_protocol_options_t` instance.ciphersuite- A SSLCipherSuite value. API-Since: 12.0 Deprecated-Since: 13.0 Deprecated-Message: Use sec_protocol_options_append_tls_ciphersuite
-
sec_protocol_options_append_tls_ciphersuite_group
public static void sec_protocol_options_append_tls_ciphersuite_group(@NotNull @NotNull sec_protocol_options_t options, short group)[@function] sec_protocol_options_append_tls_ciphersuite_group Append a TLS ciphersuite group to the set of enabled ciphersuites.- Parameters:
options- A `sec_protocol_options_t` instance.group- A tls_ciphersuite_group_t value. API-Since: 13.0
-
sec_protocol_options_add_tls_ciphersuite_group
@Deprecated public static void sec_protocol_options_add_tls_ciphersuite_group(@NotNull @NotNull sec_protocol_options_t options, int group)Deprecated.[@function] sec_protocol_options_add_tls_ciphersuite_group Add a TLS ciphersuite group to the set of enabled ciphersuites.- Parameters:
options- A `sec_protocol_options_t` instance.group- A SSLCipherSuiteGroup value. API-Since: 12.0 Deprecated-Since: 13.0 Deprecated-Message: Use sec_protocol_options_append_tls_ciphersuite_group
-
sec_protocol_options_set_tls_min_version
@Deprecated public static void sec_protocol_options_set_tls_min_version(@NotNull @NotNull sec_protocol_options_t options, int version)Deprecated.[@function] sec_protocol_options_set_tls_min_version Set the minimum support TLS version.- Parameters:
options- A `sec_protocol_options_t` instance.version- A SSLProtocol enum value. API-Since: 12.0 Deprecated-Since: 13.0
-
sec_protocol_options_set_min_tls_protocol_version
public static void sec_protocol_options_set_min_tls_protocol_version(@NotNull @NotNull sec_protocol_options_t options, short version)[@function] sec_protocol_options_set_min_tls_protocol_version Set the minimum support TLS version.- Parameters:
options- A `sec_protocol_options_t` instance.version- A tls_protocol_version_t enum value. API-Since: 13.0
-
sec_protocol_options_get_default_min_tls_protocol_version
public static short sec_protocol_options_get_default_min_tls_protocol_version()
[@function] sec_protocol_options_get_default_min_tls_protocol_version Get the system default minimum TLS protocol version.- Returns:
- The default minimum TLS version. API-Since: 13.0
-
sec_protocol_options_get_default_min_dtls_protocol_version
public static short sec_protocol_options_get_default_min_dtls_protocol_version()
[@function] sec_protocol_options_get_default_min_dtls_protocol_version Get the system default minimum DTLS protocol version.- Returns:
- The default minimum DTLS version. API-Since: 13.0
-
sec_protocol_options_set_tls_max_version
@Deprecated public static void sec_protocol_options_set_tls_max_version(@NotNull @NotNull sec_protocol_options_t options, int version)Deprecated.[@function] sec_protocol_options_set_tls_max_version Set the maximum support TLS version.- Parameters:
options- A `sec_protocol_options_t` instance.version- A SSLProtocol enum value. API-Since: 12.0 Deprecated-Since: 13.0
-
sec_protocol_options_set_max_tls_protocol_version
public static void sec_protocol_options_set_max_tls_protocol_version(@NotNull @NotNull sec_protocol_options_t options, short version)[@function] sec_protocol_options_set_max_tls_protocol_version Set the maximum support TLS version.- Parameters:
options- A `sec_protocol_options_t` instance.version- A tls_protocol_version_t enum value. API-Since: 13.0
-
sec_protocol_options_get_default_max_tls_protocol_version
public static short sec_protocol_options_get_default_max_tls_protocol_version()
[@function] sec_protocol_options_get_default_max_tls_protocol_version Get the system default maximum TLS protocol version.- Returns:
- The default maximum TLS version. API-Since: 13.0
-
sec_protocol_options_get_default_max_dtls_protocol_version
public static short sec_protocol_options_get_default_max_dtls_protocol_version()
[@function] sec_protocol_options_get_default_max_tls_protocol_version Get the system default maximum DTLS protocol version.- Returns:
- The default maximum DTLS version. API-Since: 13.0
-
sec_protocol_options_add_tls_application_protocol
public static void sec_protocol_options_add_tls_application_protocol(@NotNull @NotNull sec_protocol_options_t options, @NotNull @NotNull java.lang.String application_protocol)[@function] sec_protocol_options_add_tls_application_protocol Add an application protocol supported by clients of this protocol instance.- Parameters:
options- A `sec_protocol_options_t` instance.application_protocol- A NULL-terminated string defining the application protocol. API-Since: 12.0
-
sec_protocol_options_set_tls_server_name
public static void sec_protocol_options_set_tls_server_name(@NotNull @NotNull sec_protocol_options_t options, @NotNull @NotNull java.lang.String server_name)[@function] sec_protocol_options_set_tls_server_name Set the server name to be used when verifying the peer's certificate. This will override the server name obtained from the endpoint.- Parameters:
options- A `sec_protocol_options_t` instance.server_name- A NULL-terminated string carrying the server name. API-Since: 12.0
-
sec_protocol_options_set_tls_diffie_hellman_parameters
@Deprecated public static void sec_protocol_options_set_tls_diffie_hellman_parameters(@NotNull @NotNull sec_protocol_options_t options, @NotNull @NotNull dispatch_data_t params)Deprecated.[@function] sec_protocol_options_set_tls_diffie_hellman_parameters Set the supported Diffie-Hellman parameters.- Parameters:
options- A `sec_protocol_options_t` instance.params- A dispatch_data_t containing legacy Diffie-Hellman parameters. API-Since: 12.0 Deprecated-Since: 13.0 Deprecated-Message: DHE ciphersuites are no longer supported
-
sec_protocol_options_add_pre_shared_key
public static void sec_protocol_options_add_pre_shared_key(@NotNull @NotNull sec_protocol_options_t options, @NotNull @NotNull dispatch_data_t psk, @NotNull @NotNull dispatch_data_t psk_identity)[@function] sec_protocol_options_add_pre_shared_key Add a pre-shared key (PSK) and its identity to the options.- Parameters:
options- A `sec_protocol_options_t` instance.psk- A dispatch_data_t containing a PSK blob.psk_identity- A dispatch_data_t containing a PSK identity blob. API-Since: 12.0
-
sec_protocol_options_set_tls_pre_shared_key_identity_hint
public static void sec_protocol_options_set_tls_pre_shared_key_identity_hint(@NotNull @NotNull sec_protocol_options_t options, @NotNull @NotNull dispatch_data_t psk_identity_hint)[@function] sec_protocol_options_set_tls_pre_shared_key_identity_hint Set the PSK identity hint to use by servers when negotiating a PSK ciphersuite. See https://tools.ietf.org/html/rfc4279 for more details.- Parameters:
options- A `sec_protocol_options_t` instance.psk_identity_hint- A dispatch_data_t containing a PSK identity hint. API-Since: 13.0
-
sec_protocol_options_set_tls_tickets_enabled
public static void sec_protocol_options_set_tls_tickets_enabled(@NotNull @NotNull sec_protocol_options_t options, boolean tickets_enabled)[@function] sec_protocol_options_set_tls_tickets_enabled Enable or disable TLS session ticket support.- Parameters:
options- A `sec_protocol_options_t` instance.tickets_enabled- Flag to enable or disable TLS session ticket support. API-Since: 12.0
-
sec_protocol_options_set_tls_is_fallback_attempt
public static void sec_protocol_options_set_tls_is_fallback_attempt(@NotNull @NotNull sec_protocol_options_t options, boolean is_fallback_attempt)[@function] sec_protocol_options_set_tls_is_fallback_attempt Signal if this is a TLS fallback attempt. A fallback attempt is one following a previously failed TLS connection due to version or parameter incompatibility, e.g., when speaking to a server that does not support a client-offered ciphersuite. Clients MUST NOT enable fallback for fresh connections.- Parameters:
options- A `sec_protocol_options_t` instance.is_fallback_attempt- Set a flag indicating that this is a TLS fallback attempt. API-Since: 12.0
-
sec_protocol_options_set_tls_resumption_enabled
public static void sec_protocol_options_set_tls_resumption_enabled(@NotNull @NotNull sec_protocol_options_t options, boolean resumption_enabled)[@function] sec_protocol_options_set_tls_resumption_enabled Enable or disable TLS session resumption.- Parameters:
options- A `sec_protocol_options_t` instance.resumption_enabled- Flag to enable or disable TLS session resumption. API-Since: 12.0
-
sec_protocol_options_set_tls_false_start_enabled
public static void sec_protocol_options_set_tls_false_start_enabled(@NotNull @NotNull sec_protocol_options_t options, boolean false_start_enabled)[@function] sec_protocol_options_set_tls_false_start_enabled Enable or disable TLS False Start.- Parameters:
options- A `sec_protocol_options_t` instance.false_start_enabled- Flag to enable or disable TLS False Start. API-Since: 12.0
-
sec_protocol_options_set_tls_ocsp_enabled
public static void sec_protocol_options_set_tls_ocsp_enabled(@NotNull @NotNull sec_protocol_options_t options, boolean ocsp_enabled)[@function] nw_protocol_options_set_tls_ocsp_enabled Enable or disable OCSP support.- Parameters:
options- A `sec_protocol_options_t` instance.ocsp_enabled- Flag to enable or disable OCSP support. API-Since: 12.0
-
sec_protocol_options_set_tls_sct_enabled
public static void sec_protocol_options_set_tls_sct_enabled(@NotNull @NotNull sec_protocol_options_t options, boolean sct_enabled)[@function] sec_protocol_options_set_tls_sct_enabled Enable or disable SCT (signed certificate timestamp) support.- Parameters:
options- A `sec_protocol_options_t` instance.sct_enabled- Flag to enable or disable SCT support. API-Since: 12.0
-
sec_protocol_options_set_tls_renegotiation_enabled
public static void sec_protocol_options_set_tls_renegotiation_enabled(@NotNull @NotNull sec_protocol_options_t options, boolean renegotiation_enabled)[@function] sec_protocol_options_set_tls_renegotiation_enabled Enable or disable TLS (1.2 and prior) session renegotiation. This defaults to `true`.- Parameters:
options- A `sec_protocol_options_t` instance.renegotiation_enabled- Flag to enable or disable TLS (1.2 and prior) session renegotiation. API-Since: 12.0
-
sec_protocol_options_set_peer_authentication_required
public static void sec_protocol_options_set_peer_authentication_required(@NotNull @NotNull sec_protocol_options_t options, boolean peer_authentication_required)[@function] sec_protocol_options_set_peer_authentication_required Enable or disable peer authentication. Clients default to true, whereas servers default to false.- Parameters:
options- A `sec_protocol_options_t` instance.peer_authentication_required- Flag to enable or disable mandatory peer authentication. API-Since: 12.0
-
kSecUseDataProtectionKeychain
@NotNull public static @NotNull CFStringRef kSecUseDataProtectionKeychain()
API-Since: 13.0
-
sec_protocol_options_set_pre_shared_key_selection_block
public static void sec_protocol_options_set_pre_shared_key_selection_block(@NotNull @NotNull sec_protocol_options_t options, @NotNull @NotNull Security.Block_sec_protocol_options_set_pre_shared_key_selection_block psk_selection_block, @NotNull @NotNull dispatch_queue_t psk_selection_queue)[@function] sec_protocol_options_set_pre_shared_key_selection_block Set the PSK selection block. [@params] psk_selection_queue A `dispatch_queue_t` on which the PSK selection block should be called. API-Since: 13.0- Parameters:
options- A `sec_protocol_options_t` instance.psk_selection_block- A `sec_protocol_pre_shared_key_selection_t` block.
-
sec_protocol_options_set_key_update_block
public static void sec_protocol_options_set_key_update_block(@NotNull @NotNull sec_protocol_options_t options, @NotNull @NotNull Security.Block_sec_protocol_options_set_key_update_block key_update_block, @NotNull @NotNull dispatch_queue_t key_update_queue)[@function] sec_protocol_options_set_key_update_block Set the key update block. [@params] key_update_queue A `dispatch_queue_t` on which the key update block should be called. API-Since: 12.0- Parameters:
options- A `sec_protocol_options_t` instance.key_update_block- A `sec_protocol_key_update_t` block.
-
sec_protocol_options_set_challenge_block
public static void sec_protocol_options_set_challenge_block(@NotNull @NotNull sec_protocol_options_t options, @NotNull @NotNull Security.Block_sec_protocol_options_set_challenge_block challenge_block, @NotNull @NotNull dispatch_queue_t challenge_queue)[@function] sec_protocol_options_set_challenge_block Set the challenge block. [@params] challenge_block A `sec_protocol_challenge_t` block. [@params] challenge_queue A `dispatch_queue_t` on which the challenge block should be called. API-Since: 12.0- Parameters:
options- A `sec_protocol_options_t` instance.
-
sec_protocol_options_set_verify_block
public static void sec_protocol_options_set_verify_block(@NotNull @NotNull sec_protocol_options_t options, @NotNull @NotNull Security.Block_sec_protocol_options_set_verify_block verify_block, @NotNull @NotNull dispatch_queue_t verify_block_queue)[@function] sec_protocol_options_set_verify_block Set the verify block. [@params] verify_block A `sec_protocol_verify_t` block. [@params] verify_block_queue A `dispatch_queue_t` on which the verify block should be called. API-Since: 12.0- Parameters:
options- A `sec_protocol_options_t` instance.
-
SecTrustCopyKey
@Nullable public static @Nullable SecKeyRef SecTrustCopyKey(@NotNull @NotNull SecTrustRef trust)
[@function] SecTrustCopyKey Return the public key for a leaf certificate after it has been evaluated. RSA and ECDSA public keys are supported. All other public key algorithms are unsupported. API-Since: 14.0- Parameters:
trust- A reference to the trust object which has been evaluated.- Returns:
- The certificate's public key, or NULL if it the public key could not be extracted (this can happen if the public key algorithm is not supported). The caller is responsible for calling CFRelease on the returned key when it is no longer needed.
-
SecTrustCopyCertificateChain
@Nullable public static @Nullable CFArrayRef SecTrustCopyCertificateChain(@NotNull @NotNull SecTrustRef trust)
[@function] SecTrustCopyCertificateChain Returns the certificate trust chain- Parameters:
trust- Reference to a trust object.- Returns:
- A CFArray of the SecCertificateRefs for the resulting certificate chain API-Since: 15.0
-
sec_retain
public static org.moe.natj.general.ptr.VoidPtr sec_retain(org.moe.natj.general.ptr.VoidPtr obj)
-
sec_release
public static void sec_release(org.moe.natj.general.ptr.VoidPtr obj)
-
kSecKeyAlgorithmECDSASignatureDigestRFC4754
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureDigestRFC4754()
API-Since: 17.0
-
kSecKeyAlgorithmECDSASignatureDigestRFC4754SHA1
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureDigestRFC4754SHA1()
API-Since: 17.0
-
kSecKeyAlgorithmECDSASignatureDigestRFC4754SHA224
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureDigestRFC4754SHA224()
API-Since: 17.0
-
kSecKeyAlgorithmECDSASignatureDigestRFC4754SHA256
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureDigestRFC4754SHA256()
API-Since: 17.0
-
kSecKeyAlgorithmECDSASignatureDigestRFC4754SHA384
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureDigestRFC4754SHA384()
API-Since: 17.0
-
kSecKeyAlgorithmECDSASignatureDigestRFC4754SHA512
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureDigestRFC4754SHA512()
API-Since: 17.0
-
kSecKeyAlgorithmECDSASignatureMessageRFC4754SHA1
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureMessageRFC4754SHA1()
API-Since: 17.0
-
kSecKeyAlgorithmECDSASignatureMessageRFC4754SHA224
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureMessageRFC4754SHA224()
API-Since: 17.0
-
kSecKeyAlgorithmECDSASignatureMessageRFC4754SHA256
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureMessageRFC4754SHA256()
API-Since: 17.0
-
kSecKeyAlgorithmECDSASignatureMessageRFC4754SHA384
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureMessageRFC4754SHA384()
API-Since: 17.0
-
kSecKeyAlgorithmECDSASignatureMessageRFC4754SHA512
@NotNull public static @NotNull CFStringRef kSecKeyAlgorithmECDSASignatureMessageRFC4754SHA512()
API-Since: 17.0
-
-