Manpage logo

libressl-X509_check_issued - check whether a certificate was issued using a given CA certificate


X509_CHECK_ISSUED(3) Library Functions Manual X509_CHECK_ISSUED(3)

NAME

X509_check_issued — check whether a certificate was issued using a given CA certificate

SYNOPSIS

library “libcrypto” #include <openssl/x509v3.h>

int

X509_check_issued(X509 *issuer, X509 *subject);

DESCRIPTION

This function checks whether the certificate subject was issued using the CA certificate issuer. It does the following checks:

•

match the issuer field of subject against the subject field of issuer

•

if authorityKeyIdentifier is present in the subject certificate, compare it to the subjectKeyIdentifier of issuer

•

check the keyUsage field of issuer.

RETURN VALUES

This function returns X509_V_OK if the certificate subject is issued by issuer, or some X509_V_ERR* constant to indicate an error.

SEE ALSO

X509_check_ca(3), X509_new(3), X509_verify_cert(3)

HISTORY

X509_check_issued() first appeared in OpenSSL 0.9.6 and has been available since OpenBSD 2.9. GNU June 8, 2025 X509_CHECK_ISSUED(3)


Updated 2026-06-01 - jenkler.se | uex.se