blob: 2c9c0f4618925d5103207e785a39038e52f3ac80 [file] [log] [blame]
Paul Kehrer016e08a2014-11-26 09:41:18 -10001.. hazmat::
2
3X.509
4=====
5
Paul Kehrera9d78c12014-11-26 10:59:03 -10006.. currentmodule:: cryptography.x509
Paul Kehrer016e08a2014-11-26 09:41:18 -10007
8X.509 is an ITU-T standard for a `public key infrastructure`_. X.509v3 is
9defined in :rfc:`5280` (which obsoletes :rfc:`2459` and :rfc:`3280`).
10
11Loading
12~~~~~~~
13
14.. function:: load_pem_x509_certificate(data, backend)
15
16 .. versionadded:: 0.7
17
18 Deserialize a certificate from PEM encoded data.
19
20 :param bytes data: The PEM encoded certificate data.
21
22 :param backend: A backend supporting the
23 :class:`~cryptography.hazmat.backends.interfaces.X509Backend`
24 interface.
25
26 :returns: An instance of
27 :class:`~cryptography.hazmat.primitives.interfaces.X509Certificate`.
28
29.. function:: load_der_x509_certificate(data, backend)
30
31 .. versionadded:: 0.7
32
33 Deserialize a certificate from DER encoded data.
34
35 :param bytes data: The DER encoded certificate data.
36
37 :param backend: A backend supporting the
38 :class:`~cryptography.hazmat.backends.interfaces.X509Backend`
39 interface.
40
41 :returns: An instance of
42 :class:`~cryptography.hazmat.primitives.interfaces.X509Certificate`.
43
44.. testsetup::
45
46 pem_data = b"""
47 -----BEGIN CERTIFICATE-----
48 MIIDfDCCAmSgAwIBAgIBAjANBgkqhkiG9w0BAQsFADBFMQswCQYDVQQGEwJVUzEf
49 MB0GA1UEChMWVGVzdCBDZXJ0aWZpY2F0ZXMgMjAxMTEVMBMGA1UEAxMMVHJ1c3Qg
50 QW5jaG9yMB4XDTEwMDEwMTA4MzAwMFoXDTMwMTIzMTA4MzAwMFowQDELMAkGA1UE
51 BhMCVVMxHzAdBgNVBAoTFlRlc3QgQ2VydGlmaWNhdGVzIDIwMTExEDAOBgNVBAMT
52 B0dvb2QgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCQWJpHYo37
53 Xfb7oJSPe+WvfTlzIG21WQ7MyMbGtK/m8mejCzR6c+f/pJhEH/OcDSMsXq8h5kXa
54 BGqWK+vSwD/Pzp5OYGptXmGPcthDtAwlrafkGOS4GqIJ8+k9XGKs+vQUXJKsOk47
55 RuzD6PZupq4s16xaLVqYbUC26UcY08GpnoLNHJZS/EmXw1ZZ3d4YZjNlpIpWFNHn
56 UGmdiGKXUPX/9H0fVjIAaQwjnGAbpgyCumWgzIwPpX+ElFOUr3z7BoVnFKhIXze+
57 VmQGSWxZxvWDUN90Ul0tLEpLgk3OVxUB4VUGuf15OJOpgo1xibINPmWt14Vda2N9
58 yrNKloJGZNqLAgMBAAGjfDB6MB8GA1UdIwQYMBaAFOR9X9FclYYILAWuvnW2ZafZ
59 XahmMB0GA1UdDgQWBBRYAYQkG7wrUpRKPaUQchRR9a86yTAOBgNVHQ8BAf8EBAMC
60 AQYwFwYDVR0gBBAwDjAMBgpghkgBZQMCATABMA8GA1UdEwEB/wQFMAMBAf8wDQYJ
61 KoZIhvcNAQELBQADggEBADWHlxbmdTXNwBL/llwhQqwnazK7CC2WsXBBqgNPWj7m
62 tvQ+aLG8/50Qc2Sun7o2VnwF9D18UUe8Gj3uPUYH+oSI1vDdyKcjmMbKRU4rk0eo
63 3UHNDXwqIVc9CQS9smyV+x1HCwL4TTrq+LXLKx/qVij0Yqk+UJfAtrg2jnYKXsCu
64 FMBQQnWCGrwa1g1TphRp/RmYHnMynYFmZrXtzFz+U9XEA7C+gPq4kqDI/iVfIT1s
65 6lBtdB50lrDVwl2oYfAvW/6sC2se2QleZidUmrziVNP4oEeXINokU6T6p//HM1FG
66 QYw2jOvpKcKtWCSAnegEbgsGYzATKjmPJPJ0npHFqzM=
67 -----END CERTIFICATE-----
68 """.strip()
69
70.. doctest::
71
72 >>> from cryptography.x509 import load_pem_x509_certificate
73 >>> from cryptography.hazmat.backends import default_backend
74 >>> cert = load_pem_x509_certificate(pem_data, default_backend())
75 >>> cert.serial
76 2
77
78Support Classes
79~~~~~~~~~~~~~~~
80
81.. class:: X509Version
82
83 .. versionadded:: 0.7
84
85 An enumeration for X.509 versions.
86
87 .. attribute:: v1
88
89 For version 1 X.509 certificates.
90
91 .. attribute:: v3
92
93 For version 3 X.509 certificates.
94
95
96
97.. _`public key infrastructure`: https://en.wikipedia.org/wiki/Public_key_infrastructure