Win32 API 日本語リファレンス
ホームSecurity.Cryptography › CertCreateSelfSignCertificate

CertCreateSelfSignCertificate

関数
自己署名証明書を作成する。
DLLCRYPT32.dll呼出規約winapiSetLastErrorあり対応OSWindows XP 以降

シグネチャ

// CRYPT32.dll
#include <windows.h>

CERT_CONTEXT* CertCreateSelfSignCertificate(
    HCRYPTPROV_OR_NCRYPT_KEY_HANDLE hCryptProvOrNCryptKey,   // optional
    CRYPT_INTEGER_BLOB* pSubjectIssuerBlob,
    CERT_CREATE_SELFSIGN_FLAGS dwFlags,
    CRYPT_KEY_PROV_INFO* pKeyProvInfo,   // optional
    CRYPT_ALGORITHM_IDENTIFIER* pSignatureAlgorithm,   // optional
    SYSTEMTIME* pStartTime,   // optional
    SYSTEMTIME* pEndTime,   // optional
    CERT_EXTENSIONS* pExtensions   // optional
);

パラメーター

名前方向
hCryptProvOrNCryptKeyHCRYPTPROV_OR_NCRYPT_KEY_HANDLEinoptional
pSubjectIssuerBlobCRYPT_INTEGER_BLOB*in
dwFlagsCERT_CREATE_SELFSIGN_FLAGSin
pKeyProvInfoCRYPT_KEY_PROV_INFO*inoptional
pSignatureAlgorithmCRYPT_ALGORITHM_IDENTIFIER*inoptional
pStartTimeSYSTEMTIME*inoptional
pEndTimeSYSTEMTIME*inoptional
pExtensionsCERT_EXTENSIONS*inoptional

戻り値の型: CERT_CONTEXT*

各言語での呼び出し定義

// CRYPT32.dll
#include <windows.h>

CERT_CONTEXT* CertCreateSelfSignCertificate(
    HCRYPTPROV_OR_NCRYPT_KEY_HANDLE hCryptProvOrNCryptKey,   // optional
    CRYPT_INTEGER_BLOB* pSubjectIssuerBlob,
    CERT_CREATE_SELFSIGN_FLAGS dwFlags,
    CRYPT_KEY_PROV_INFO* pKeyProvInfo,   // optional
    CRYPT_ALGORITHM_IDENTIFIER* pSignatureAlgorithm,   // optional
    SYSTEMTIME* pStartTime,   // optional
    SYSTEMTIME* pEndTime,   // optional
    CERT_EXTENSIONS* pExtensions   // optional
);
[DllImport("CRYPT32.dll", SetLastError = true, ExactSpelling = true)]
static extern IntPtr CertCreateSelfSignCertificate(
    UIntPtr hCryptProvOrNCryptKey,   // HCRYPTPROV_OR_NCRYPT_KEY_HANDLE optional
    IntPtr pSubjectIssuerBlob,   // CRYPT_INTEGER_BLOB*
    uint dwFlags,   // CERT_CREATE_SELFSIGN_FLAGS
    IntPtr pKeyProvInfo,   // CRYPT_KEY_PROV_INFO* optional
    IntPtr pSignatureAlgorithm,   // CRYPT_ALGORITHM_IDENTIFIER* optional
    IntPtr pStartTime,   // SYSTEMTIME* optional
    IntPtr pEndTime,   // SYSTEMTIME* optional
    IntPtr pExtensions   // CERT_EXTENSIONS* optional
);
<DllImport("CRYPT32.dll", SetLastError:=True, ExactSpelling:=True)>
Public Shared Function CertCreateSelfSignCertificate(
    hCryptProvOrNCryptKey As UIntPtr,   ' HCRYPTPROV_OR_NCRYPT_KEY_HANDLE optional
    pSubjectIssuerBlob As IntPtr,   ' CRYPT_INTEGER_BLOB*
    dwFlags As UInteger,   ' CERT_CREATE_SELFSIGN_FLAGS
    pKeyProvInfo As IntPtr,   ' CRYPT_KEY_PROV_INFO* optional
    pSignatureAlgorithm As IntPtr,   ' CRYPT_ALGORITHM_IDENTIFIER* optional
    pStartTime As IntPtr,   ' SYSTEMTIME* optional
    pEndTime As IntPtr,   ' SYSTEMTIME* optional
    pExtensions As IntPtr   ' CERT_EXTENSIONS* optional
) As IntPtr
End Function
' hCryptProvOrNCryptKey : HCRYPTPROV_OR_NCRYPT_KEY_HANDLE optional
' pSubjectIssuerBlob : CRYPT_INTEGER_BLOB*
' dwFlags : CERT_CREATE_SELFSIGN_FLAGS
' pKeyProvInfo : CRYPT_KEY_PROV_INFO* optional
' pSignatureAlgorithm : CRYPT_ALGORITHM_IDENTIFIER* optional
' pStartTime : SYSTEMTIME* optional
' pEndTime : SYSTEMTIME* optional
' pExtensions : CERT_EXTENSIONS* optional
Declare PtrSafe Function CertCreateSelfSignCertificate Lib "crypt32" ( _
    ByVal hCryptProvOrNCryptKey As LongPtr, _
    ByVal pSubjectIssuerBlob As LongPtr, _
    ByVal dwFlags As Long, _
    ByVal pKeyProvInfo As LongPtr, _
    ByVal pSignatureAlgorithm As LongPtr, _
    ByVal pStartTime As LongPtr, _
    ByVal pEndTime As LongPtr, _
    ByVal pExtensions As LongPtr) As LongPtr
' VBA7前提(PtrSafe)。32bit Office では LongPtr→Long。Integer=16bit / Long=32bit / LongLong=64bit。
import ctypes
from ctypes import wintypes

CertCreateSelfSignCertificate = ctypes.windll.crypt32.CertCreateSelfSignCertificate
CertCreateSelfSignCertificate.restype = ctypes.c_void_p
CertCreateSelfSignCertificate.argtypes = [
    ctypes.c_size_t,  # hCryptProvOrNCryptKey : HCRYPTPROV_OR_NCRYPT_KEY_HANDLE optional
    ctypes.c_void_p,  # pSubjectIssuerBlob : CRYPT_INTEGER_BLOB*
    wintypes.DWORD,  # dwFlags : CERT_CREATE_SELFSIGN_FLAGS
    ctypes.c_void_p,  # pKeyProvInfo : CRYPT_KEY_PROV_INFO* optional
    ctypes.c_void_p,  # pSignatureAlgorithm : CRYPT_ALGORITHM_IDENTIFIER* optional
    ctypes.c_void_p,  # pStartTime : SYSTEMTIME* optional
    ctypes.c_void_p,  # pEndTime : SYSTEMTIME* optional
    ctypes.c_void_p,  # pExtensions : CERT_EXTENSIONS* optional
]
# GetLastError: use ctypes.GetLastError() (or ctypes.WinDLL(use_last_error=True))
require 'fiddle'
require 'fiddle/import'

lib = Fiddle.dlopen('CRYPT32.dll')
CertCreateSelfSignCertificate = Fiddle::Function.new(
  lib['CertCreateSelfSignCertificate'],
  [
    Fiddle::TYPE_UINTPTR_T,  # hCryptProvOrNCryptKey : HCRYPTPROV_OR_NCRYPT_KEY_HANDLE optional
    Fiddle::TYPE_VOIDP,  # pSubjectIssuerBlob : CRYPT_INTEGER_BLOB*
    -Fiddle::TYPE_INT,  # dwFlags : CERT_CREATE_SELFSIGN_FLAGS
    Fiddle::TYPE_VOIDP,  # pKeyProvInfo : CRYPT_KEY_PROV_INFO* optional
    Fiddle::TYPE_VOIDP,  # pSignatureAlgorithm : CRYPT_ALGORITHM_IDENTIFIER* optional
    Fiddle::TYPE_VOIDP,  # pStartTime : SYSTEMTIME* optional
    Fiddle::TYPE_VOIDP,  # pEndTime : SYSTEMTIME* optional
    Fiddle::TYPE_VOIDP,  # pExtensions : CERT_EXTENSIONS* optional
  ],
  Fiddle::TYPE_VOIDP)
#[link(name = "crypt32")]
extern "system" {
    fn CertCreateSelfSignCertificate(
        hCryptProvOrNCryptKey: usize,  // HCRYPTPROV_OR_NCRYPT_KEY_HANDLE optional
        pSubjectIssuerBlob: *mut CRYPT_INTEGER_BLOB,  // CRYPT_INTEGER_BLOB*
        dwFlags: u32,  // CERT_CREATE_SELFSIGN_FLAGS
        pKeyProvInfo: *mut CRYPT_KEY_PROV_INFO,  // CRYPT_KEY_PROV_INFO* optional
        pSignatureAlgorithm: *mut CRYPT_ALGORITHM_IDENTIFIER,  // CRYPT_ALGORITHM_IDENTIFIER* optional
        pStartTime: *mut SYSTEMTIME,  // SYSTEMTIME* optional
        pEndTime: *mut SYSTEMTIME,  // SYSTEMTIME* optional
        pExtensions: *mut CERT_EXTENSIONS  // CERT_EXTENSIONS* optional
    ) -> *mut CERT_CONTEXT;
}
// crates: windows-sys provides ready-made bindings for this API.
$sig = @"
[DllImport("CRYPT32.dll", SetLastError = true)]
public static extern IntPtr CertCreateSelfSignCertificate(UIntPtr hCryptProvOrNCryptKey, IntPtr pSubjectIssuerBlob, uint dwFlags, IntPtr pKeyProvInfo, IntPtr pSignatureAlgorithm, IntPtr pStartTime, IntPtr pEndTime, IntPtr pExtensions);
"@
$api = Add-Type -MemberDefinition $sig -Name 'CRYPT32_CertCreateSelfSignCertificate' -Namespace Win32 -PassThru
# $api::CertCreateSelfSignCertificate(hCryptProvOrNCryptKey, pSubjectIssuerBlob, dwFlags, pKeyProvInfo, pSignatureAlgorithm, pStartTime, pEndTime, pExtensions)
#uselib "CRYPT32.dll"
#func global CertCreateSelfSignCertificate "CertCreateSelfSignCertificate" sptr, sptr, sptr, sptr, sptr, sptr, sptr, sptr
; CertCreateSelfSignCertificate hCryptProvOrNCryptKey, varptr(pSubjectIssuerBlob), dwFlags, varptr(pKeyProvInfo), varptr(pSignatureAlgorithm), varptr(pStartTime), varptr(pEndTime), varptr(pExtensions)   ; 戻り値は stat
; hCryptProvOrNCryptKey : HCRYPTPROV_OR_NCRYPT_KEY_HANDLE optional -> "sptr"
; pSubjectIssuerBlob : CRYPT_INTEGER_BLOB* -> "sptr"
; dwFlags : CERT_CREATE_SELFSIGN_FLAGS -> "sptr"
; pKeyProvInfo : CRYPT_KEY_PROV_INFO* optional -> "sptr"
; pSignatureAlgorithm : CRYPT_ALGORITHM_IDENTIFIER* optional -> "sptr"
; pStartTime : SYSTEMTIME* optional -> "sptr"
; pEndTime : SYSTEMTIME* optional -> "sptr"
; pExtensions : CERT_EXTENSIONS* optional -> "sptr"
; ※HSP3.7は #func のため戻り値はシステム変数 stat に格納されます。
出力引数:
#uselib "CRYPT32.dll"
#cfunc global CertCreateSelfSignCertificate "CertCreateSelfSignCertificate" sptr, var, int, var, var, var, var, var
; res = CertCreateSelfSignCertificate(hCryptProvOrNCryptKey, pSubjectIssuerBlob, dwFlags, pKeyProvInfo, pSignatureAlgorithm, pStartTime, pEndTime, pExtensions)
; hCryptProvOrNCryptKey : HCRYPTPROV_OR_NCRYPT_KEY_HANDLE optional -> "sptr"
; pSubjectIssuerBlob : CRYPT_INTEGER_BLOB* -> "var"
; dwFlags : CERT_CREATE_SELFSIGN_FLAGS -> "int"
; pKeyProvInfo : CRYPT_KEY_PROV_INFO* optional -> "var"
; pSignatureAlgorithm : CRYPT_ALGORITHM_IDENTIFIER* optional -> "var"
; pStartTime : SYSTEMTIME* optional -> "var"
; pEndTime : SYSTEMTIME* optional -> "var"
; pExtensions : CERT_EXTENSIONS* optional -> "var"
; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。
出力引数:
; CERT_CONTEXT* CertCreateSelfSignCertificate(HCRYPTPROV_OR_NCRYPT_KEY_HANDLE hCryptProvOrNCryptKey, CRYPT_INTEGER_BLOB* pSubjectIssuerBlob, CERT_CREATE_SELFSIGN_FLAGS dwFlags, CRYPT_KEY_PROV_INFO* pKeyProvInfo, CRYPT_ALGORITHM_IDENTIFIER* pSignatureAlgorithm, SYSTEMTIME* pStartTime, SYSTEMTIME* pEndTime, CERT_EXTENSIONS* pExtensions)
#uselib "CRYPT32.dll"
#cfunc global CertCreateSelfSignCertificate "CertCreateSelfSignCertificate" intptr, var, int, var, var, var, var, var
; res = CertCreateSelfSignCertificate(hCryptProvOrNCryptKey, pSubjectIssuerBlob, dwFlags, pKeyProvInfo, pSignatureAlgorithm, pStartTime, pEndTime, pExtensions)
; hCryptProvOrNCryptKey : HCRYPTPROV_OR_NCRYPT_KEY_HANDLE optional -> "intptr"
; pSubjectIssuerBlob : CRYPT_INTEGER_BLOB* -> "var"
; dwFlags : CERT_CREATE_SELFSIGN_FLAGS -> "int"
; pKeyProvInfo : CRYPT_KEY_PROV_INFO* optional -> "var"
; pSignatureAlgorithm : CRYPT_ALGORITHM_IDENTIFIER* optional -> "var"
; pStartTime : SYSTEMTIME* optional -> "var"
; pEndTime : SYSTEMTIME* optional -> "var"
; pExtensions : CERT_EXTENSIONS* optional -> "var"
; ※出力/バッファ引数は var 方式(変数を直接渡す)。varptr 方式にも切替可。
import (
	"golang.org/x/sys/windows"
	"unsafe"
)

var (
	crypt32 = windows.NewLazySystemDLL("CRYPT32.dll")
	procCertCreateSelfSignCertificate = crypt32.NewProc("CertCreateSelfSignCertificate")
)

// hCryptProvOrNCryptKey (HCRYPTPROV_OR_NCRYPT_KEY_HANDLE optional), pSubjectIssuerBlob (CRYPT_INTEGER_BLOB*), dwFlags (CERT_CREATE_SELFSIGN_FLAGS), pKeyProvInfo (CRYPT_KEY_PROV_INFO* optional), pSignatureAlgorithm (CRYPT_ALGORITHM_IDENTIFIER* optional), pStartTime (SYSTEMTIME* optional), pEndTime (SYSTEMTIME* optional), pExtensions (CERT_EXTENSIONS* optional)
r1, _, err := procCertCreateSelfSignCertificate.Call(
	uintptr(hCryptProvOrNCryptKey),
	uintptr(pSubjectIssuerBlob),
	uintptr(dwFlags),
	uintptr(pKeyProvInfo),
	uintptr(pSignatureAlgorithm),
	uintptr(pStartTime),
	uintptr(pEndTime),
	uintptr(pExtensions),
)
_ = err  // syscall.Errno (valid when the call sets last-error)
_ = r1   // CERT_CONTEXT*
function CertCreateSelfSignCertificate(
  hCryptProvOrNCryptKey: NativeUInt;   // HCRYPTPROV_OR_NCRYPT_KEY_HANDLE optional
  pSubjectIssuerBlob: Pointer;   // CRYPT_INTEGER_BLOB*
  dwFlags: DWORD;   // CERT_CREATE_SELFSIGN_FLAGS
  pKeyProvInfo: Pointer;   // CRYPT_KEY_PROV_INFO* optional
  pSignatureAlgorithm: Pointer;   // CRYPT_ALGORITHM_IDENTIFIER* optional
  pStartTime: Pointer;   // SYSTEMTIME* optional
  pEndTime: Pointer;   // SYSTEMTIME* optional
  pExtensions: Pointer   // CERT_EXTENSIONS* optional
): Pointer; stdcall;
  external 'CRYPT32.dll' name 'CertCreateSelfSignCertificate';
result := DllCall("CRYPT32\CertCreateSelfSignCertificate"
    , "UPtr", hCryptProvOrNCryptKey   ; HCRYPTPROV_OR_NCRYPT_KEY_HANDLE optional
    , "Ptr", pSubjectIssuerBlob   ; CRYPT_INTEGER_BLOB*
    , "UInt", dwFlags   ; CERT_CREATE_SELFSIGN_FLAGS
    , "Ptr", pKeyProvInfo   ; CRYPT_KEY_PROV_INFO* optional
    , "Ptr", pSignatureAlgorithm   ; CRYPT_ALGORITHM_IDENTIFIER* optional
    , "Ptr", pStartTime   ; SYSTEMTIME* optional
    , "Ptr", pEndTime   ; SYSTEMTIME* optional
    , "Ptr", pExtensions   ; CERT_EXTENSIONS* optional
    , "Ptr")   ; return: CERT_CONTEXT*
●CertCreateSelfSignCertificate(hCryptProvOrNCryptKey, pSubjectIssuerBlob, dwFlags, pKeyProvInfo, pSignatureAlgorithm, pStartTime, pEndTime, pExtensions) = DLL("CRYPT32.dll", "void* CertCreateSelfSignCertificate(int, void*, dword, void*, void*, void*, void*, void*)")
# 呼び出し: CertCreateSelfSignCertificate(hCryptProvOrNCryptKey, pSubjectIssuerBlob, dwFlags, pKeyProvInfo, pSignatureAlgorithm, pStartTime, pEndTime, pExtensions)
# hCryptProvOrNCryptKey : HCRYPTPROV_OR_NCRYPT_KEY_HANDLE optional -> "int"
# pSubjectIssuerBlob : CRYPT_INTEGER_BLOB* -> "void*"
# dwFlags : CERT_CREATE_SELFSIGN_FLAGS -> "dword"
# pKeyProvInfo : CRYPT_KEY_PROV_INFO* optional -> "void*"
# pSignatureAlgorithm : CRYPT_ALGORITHM_IDENTIFIER* optional -> "void*"
# pStartTime : SYSTEMTIME* optional -> "void*"
# pEndTime : SYSTEMTIME* optional -> "void*"
# pExtensions : CERT_EXTENSIONS* optional -> "void*"
# なでしこ1は32bit・ANSI(Shift_JIS)。文字列=char*(ANSI)、ポインタ/ハンドル=void*(4byte)。