Win32 API 日本語リファレンス
ホームDevices.WebServicesOnDevices › WSD_SECURITY_CERT_VALIDATION_V1

WSD_SECURITY_CERT_VALIDATION_V1

構造体
サイズx64: 40 バイト / x86: 20 バイト

サイズ=各フィールドのバイト数(x64/x86 で異なる場合は x64/x86 と併記)。x64/x86 列=フィールドのバイトオフセット(HSPで dupptr / lpoke / wpoke 等に使用)。

フィールド

フィールドサイズx64x86説明
certMatchArrayCERT_CONTEXT**8/4+0+0HTTPS サーバーまたはクライアントから提供される証明書と照合する証明書を格納した CERT_CONTEXT 構造体の配列です。検証には 1 つの証明書が一致するだけで十分です。このパラメーターは NULL でもかまいません。
dwCertMatchArrayCountDWORD4+8+4certMatchArray 内の証明書の数です。
hCertMatchStoreHCERTSTORE8/4+16+8HTTPS サーバーまたはクライアントから提供される証明書と照合する証明書を格納した証明書ストアへのハンドルです。検証には 1 つの証明書が一致するだけで十分です。このパラメーターは NULL でもかまいません。
hCertIssuerStoreHCERTSTORE8/4+24+12HTTPS サーバーまたはクライアントの証明書のチェーン先となるルート証明書を格納した証明書ストアへのハンドルです。証明書が少なくとも 1 つのルート証明書までチェーンしていれば、検証は成功します。このパラメーターは NULL でもかまいません。
dwCertCheckOptionsDWORD4+32+16

無視する証明書チェックを指定する値のビット単位の OR の組み合わせです。

意味
WSDAPI_SSL_CERT_DEFAULT_CHECKS
0x0
失効した証明書のエラーを処理します。
WSDAPI_SSL_CERT_IGNORE_REVOCATION
0x1
失効した証明書のエラーを無視します。
WSDAPI_SSL_CERT_IGNORE_EXPIRY
0x2
有効期限が切れた証明書のエラーを無視します。
WSDAPI_SSL_CERT_IGNORE_WRONG_USAGE
0x4
証明書の用途に関するエラーを無視します。
WSDAPI_SSL_CERT_IGNORE_UNKNOWN_CA
0x8
不明な証明機関のエラーを無視します。
WSDAPI_SSL_CERT_IGNORE_INVALID_CN
0x10
コモンネームが無効な証明書のエラーを無視します。

公式ドキュメント

クライアント証明書を HTTPS サーバーの証明書と照合するための条件を表します。

WSD_SECURITY_CERT_VALIDATION_V1 をコード内で直接使用しないでください。代わりに WSD_SECURITY_CERT_VALIDATION を使用すると、Windows のバージョンに基づいて適切なバージョンが選択されます。

解説(Remarks)

この構造体は、WSD_CONFIG_PARAM 構造体の pConfigData メンバーで使用されます。

WSD_CONFIG_PARAMconfigParamTypeWSD_SECURITY_SSL_SERVER_CERT_VALIDATION の場合、この構造体を使用して SSL サーバーが提示する SSL サーバー証明書を検証できます。

WSD_CONFIG_PARAMconfigParamTypeWSD_SECURITY_SSL_CLIENT_CERT_VALIDATION の場合、この構造体を使用して SSL クライアントが提示する SSL クライアント証明書を検証できます。

WSD_SECURITY_CERT_VALIDATION は 3 つの証明書照合メカニズムを定義します。 一致とみなされるには、少なくとも 1 つのメカニズムを満たす必要があります。

アプリケーションを Windows 8 OS 向けの Windows 8 SDK でビルドした場合、WSD_SECURITY_CERT_VALIDATION は新しい構造体に解決されます。ただしその結果として、そのアプリケーションは Windows 8 のコンピューターでのみ実行できるようになります。

アプリケーションを Windows 7 OS 向けの Windows 8 SDK でビルドした場合、WSD_SECURITY_CERT_VALIDATION は古い構造体 (WSD_SECURITY_CERT_VALIDATION_V1) に解決されます。このアプリケーションが Windows 7 でサポートされるのは当然ですが、Windows 8 の wsdapi.dll はこの構造体の古いバージョンと新しいバージョンの両方を処理するため、Windows 8 でも動作します。

Windows 7 SDK でビルド済みのアプリケーションは、この構造体の古いバージョンを使用します。Windows 8 の wsdapi.dll は両方のバージョンを処理できるため、Windows 8 でも問題なく実行されます。

出典・ライセンス: 上記「公式ドキュメント」の内容は Microsoft の Win32 API ドキュメント(MicrosoftDocs/sdk-api)を日本語に翻訳・改変したものです。© Microsoft Corporation. CC BY 4.0 で提供。
Microsoft 公式リファレンス: 英語 (en-us) · 日本語 (ja-jp) · 原文ソース (GitHub)

各言語での定義

#include <windows.h>

// WSD_SECURITY_CERT_VALIDATION_V1  (x64 40 / x86 20 バイト)
typedef struct WSD_SECURITY_CERT_VALIDATION_V1 {
    CERT_CONTEXT** certMatchArray;
    DWORD dwCertMatchArrayCount;
    HCERTSTORE hCertMatchStore;
    HCERTSTORE hCertIssuerStore;
    DWORD dwCertCheckOptions;
} WSD_SECURITY_CERT_VALIDATION_V1;
using System;
using System.Runtime.InteropServices;

[StructLayout(LayoutKind.Sequential, CharSet = CharSet.Unicode)]
public struct WSD_SECURITY_CERT_VALIDATION_V1
{
    public IntPtr certMatchArray;
    public uint dwCertMatchArrayCount;
    public IntPtr hCertMatchStore;
    public IntPtr hCertIssuerStore;
    public uint dwCertCheckOptions;
}
Imports System.Runtime.InteropServices

<StructLayout(LayoutKind.Sequential, CharSet:=CharSet.Unicode)>
Public Structure WSD_SECURITY_CERT_VALIDATION_V1
    Public certMatchArray As IntPtr
    Public dwCertMatchArrayCount As UInteger
    Public hCertMatchStore As IntPtr
    Public hCertIssuerStore As IntPtr
    Public dwCertCheckOptions As UInteger
End Structure
import ctypes
from ctypes import wintypes

class WSD_SECURITY_CERT_VALIDATION_V1(ctypes.Structure):
    _fields_ = [
        ("certMatchArray", ctypes.c_void_p),
        ("dwCertMatchArrayCount", wintypes.DWORD),
        ("hCertMatchStore", ctypes.c_void_p),
        ("hCertIssuerStore", ctypes.c_void_p),
        ("dwCertCheckOptions", wintypes.DWORD),
    ]
#[repr(C)]
pub struct WSD_SECURITY_CERT_VALIDATION_V1 {
    pub certMatchArray: *mut core::ffi::c_void,
    pub dwCertMatchArrayCount: u32,
    pub hCertMatchStore: *mut core::ffi::c_void,
    pub hCertIssuerStore: *mut core::ffi::c_void,
    pub dwCertCheckOptions: u32,
}
import "golang.org/x/sys/windows"

type WSD_SECURITY_CERT_VALIDATION_V1 struct {
	certMatchArray uintptr
	dwCertMatchArrayCount uint32
	hCertMatchStore uintptr
	hCertIssuerStore uintptr
	dwCertCheckOptions uint32
}
type
  WSD_SECURITY_CERT_VALIDATION_V1 = record
    certMatchArray: Pointer;
    dwCertMatchArrayCount: DWORD;
    hCertMatchStore: Pointer;
    hCertIssuerStore: Pointer;
    dwCertCheckOptions: DWORD;
  end;
const WSD_SECURITY_CERT_VALIDATION_V1 = extern struct {
    certMatchArray: ?*anyopaque,
    dwCertMatchArrayCount: u32,
    hCertMatchStore: ?*anyopaque,
    hCertIssuerStore: ?*anyopaque,
    dwCertCheckOptions: u32,
};
type
  WSD_SECURITY_CERT_VALIDATION_V1 {.bycopy.} = object
    certMatchArray: pointer
    dwCertMatchArrayCount: uint32
    hCertMatchStore: pointer
    hCertIssuerStore: pointer
    dwCertCheckOptions: uint32
struct WSD_SECURITY_CERT_VALIDATION_V1
{
    void* certMatchArray;
    uint dwCertMatchArrayCount;
    void* hCertMatchStore;
    void* hCertIssuerStore;
    uint dwCertCheckOptions;
}

HSP用 定義

HSP3.7/3.8 は構造体機能が無いため4byte整数配列(dim)+peek/poke で操作(32/64bitでサイズ・位置が異なる場合はタブで分割)。IronHSP は NSTRUCT(#defstruct/stdim/->)で32/64bit共通。

; HSP3.7/3.8 は構造体機能が無いため、4byte整数の配列変数で操作します。(x86 レイアウト)
; WSD_SECURITY_CERT_VALIDATION_V1 サイズ: 20 バイト(x86)
dim st, 5    ; 4byte整数×5(構造体サイズ 20 / 4 切り上げ)
; certMatchArray : CERT_CONTEXT** (+0, 4byte)  varptr(st)+0 を基点に操作(4byte:入れ子/配列)
; dwCertMatchArrayCount : DWORD (+4, 4byte)  st.1 = 値  /  値 = st.1   (lpoke/lpeek も可)
; hCertMatchStore : HCERTSTORE (+8, 4byte)  st.2 = 値  /  値 = st.2   (lpoke/lpeek も可)
; hCertIssuerStore : HCERTSTORE (+12, 4byte)  st.3 = 値  /  値 = st.3   (lpoke/lpeek も可)
; dwCertCheckOptions : DWORD (+16, 4byte)  st.4 = 値  /  値 = st.4   (lpoke/lpeek も可)
; ※4byte境界の整数は添字 st.N(N=オフセット/4)で読み書き可。それ以外は peek/poke 系を使用。
; HSP3.7/3.8 は構造体機能が無いため、4byte整数の配列変数で操作します。(x64 レイアウト)
; WSD_SECURITY_CERT_VALIDATION_V1 サイズ: 40 バイト(x64)
dim st, 10    ; 4byte整数×10(構造体サイズ 40 / 4 切り上げ)
; certMatchArray : CERT_CONTEXT** (+0, 8byte)  varptr(st)+0 を基点に操作(8byte:入れ子/配列)
; dwCertMatchArrayCount : DWORD (+8, 4byte)  st.2 = 値  /  値 = st.2   (lpoke/lpeek も可)
; hCertMatchStore : HCERTSTORE (+16, 8byte)  qpoke st,16,値 / qpeek(st,16)  ※IronHSPのみ。3.7/3.8は lpoke st,16,下位 : lpoke st,20,上位
; hCertIssuerStore : HCERTSTORE (+24, 8byte)  qpoke st,24,値 / qpeek(st,24)  ※IronHSPのみ。3.7/3.8は lpoke st,24,下位 : lpoke st,28,上位
; dwCertCheckOptions : DWORD (+32, 4byte)  st.8 = 値  /  値 = st.8   (lpoke/lpeek も可)
; ※4byte境界の整数は添字 st.N(N=オフセット/4)で読み書き可。それ以外は peek/poke 系を使用。
; IronHSP は NSTRUCT(構造体)をサポート。32bit/64bit どちらでも同じコードで動作します。
#defstruct global WSD_SECURITY_CERT_VALIDATION_V1
    #field intptr certMatchArray
    #field int dwCertMatchArrayCount
    #field intptr hCertMatchStore
    #field intptr hCertIssuerStore
    #field int dwCertCheckOptions
#endstruct

stdim st, WSD_SECURITY_CERT_VALIDATION_V1        ; NSTRUCT 変数を確保
st->dwCertMatchArrayCount = 100
mes "dwCertMatchArrayCount=" + st->dwCertMatchArrayCount