WSD_SECURITY_CERT_VALIDATION_V1
構造体サイズ=各フィールドのバイト数(x64/x86 で異なる場合は x64/x86 と併記)。x64/x86 列=フィールドのバイトオフセット(HSPで dupptr / lpoke / wpoke 等に使用)。
フィールド
| フィールド | 型 | サイズ | x64 | x86 | 説明 | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| certMatchArray | CERT_CONTEXT** | 8/4 | +0 | +0 | HTTPS サーバーまたはクライアントから提供される証明書と照合する証明書を格納した CERT_CONTEXT 構造体の配列です。検証には 1 つの証明書が一致するだけで十分です。このパラメーターは NULL でもかまいません。 | ||||||||||||||
| dwCertMatchArrayCount | DWORD | 4 | +8 | +4 | certMatchArray 内の証明書の数です。 | ||||||||||||||
| hCertMatchStore | HCERTSTORE | 8/4 | +16 | +8 | HTTPS サーバーまたはクライアントから提供される証明書と照合する証明書を格納した証明書ストアへのハンドルです。検証には 1 つの証明書が一致するだけで十分です。このパラメーターは NULL でもかまいません。 | ||||||||||||||
| hCertIssuerStore | HCERTSTORE | 8/4 | +24 | +12 | HTTPS サーバーまたはクライアントの証明書のチェーン先となるルート証明書を格納した証明書ストアへのハンドルです。証明書が少なくとも 1 つのルート証明書までチェーンしていれば、検証は成功します。このパラメーターは NULL でもかまいません。 | ||||||||||||||
| dwCertCheckOptions | DWORD | 4 | +32 | +16 | 無視する証明書チェックを指定する値のビット単位の OR の組み合わせです。
|
公式ドキュメント
クライアント証明書を HTTPS サーバーの証明書と照合するための条件を表します。
WSD_SECURITY_CERT_VALIDATION_V1 をコード内で直接使用しないでください。代わりに WSD_SECURITY_CERT_VALIDATION を使用すると、Windows のバージョンに基づいて適切なバージョンが選択されます。
解説(Remarks)
この構造体は、WSD_CONFIG_PARAM 構造体の pConfigData メンバーで使用されます。
WSD_CONFIG_PARAM の configParamType が WSD_SECURITY_SSL_SERVER_CERT_VALIDATION の場合、この構造体を使用して SSL サーバーが提示する SSL サーバー証明書を検証できます。
WSD_CONFIG_PARAM の configParamType が WSD_SECURITY_SSL_CLIENT_CERT_VALIDATION の場合、この構造体を使用して SSL クライアントが提示する SSL クライアント証明書を検証できます。
WSD_SECURITY_CERT_VALIDATION は 3 つの証明書照合メカニズムを定義します。 一致とみなされるには、少なくとも 1 つのメカニズムを満たす必要があります。
アプリケーションを Windows 8 OS 向けの Windows 8 SDK でビルドした場合、WSD_SECURITY_CERT_VALIDATION は新しい構造体に解決されます。ただしその結果として、そのアプリケーションは Windows 8 のコンピューターでのみ実行できるようになります。
アプリケーションを Windows 7 OS 向けの Windows 8 SDK でビルドした場合、WSD_SECURITY_CERT_VALIDATION は古い構造体 (WSD_SECURITY_CERT_VALIDATION_V1) に解決されます。このアプリケーションが Windows 7 でサポートされるのは当然ですが、Windows 8 の wsdapi.dll はこの構造体の古いバージョンと新しいバージョンの両方を処理するため、Windows 8 でも動作します。
Windows 7 SDK でビルド済みのアプリケーションは、この構造体の古いバージョンを使用します。Windows 8 の wsdapi.dll は両方のバージョンを処理できるため、Windows 8 でも問題なく実行されます。
Microsoft 公式リファレンス: 英語 (en-us) · 日本語 (ja-jp) · 原文ソース (GitHub)
各言語での定義
#include <windows.h>
// WSD_SECURITY_CERT_VALIDATION_V1 (x64 40 / x86 20 バイト)
typedef struct WSD_SECURITY_CERT_VALIDATION_V1 {
CERT_CONTEXT** certMatchArray;
DWORD dwCertMatchArrayCount;
HCERTSTORE hCertMatchStore;
HCERTSTORE hCertIssuerStore;
DWORD dwCertCheckOptions;
} WSD_SECURITY_CERT_VALIDATION_V1;using System;
using System.Runtime.InteropServices;
[StructLayout(LayoutKind.Sequential, CharSet = CharSet.Unicode)]
public struct WSD_SECURITY_CERT_VALIDATION_V1
{
public IntPtr certMatchArray;
public uint dwCertMatchArrayCount;
public IntPtr hCertMatchStore;
public IntPtr hCertIssuerStore;
public uint dwCertCheckOptions;
}Imports System.Runtime.InteropServices
<StructLayout(LayoutKind.Sequential, CharSet:=CharSet.Unicode)>
Public Structure WSD_SECURITY_CERT_VALIDATION_V1
Public certMatchArray As IntPtr
Public dwCertMatchArrayCount As UInteger
Public hCertMatchStore As IntPtr
Public hCertIssuerStore As IntPtr
Public dwCertCheckOptions As UInteger
End Structureimport ctypes
from ctypes import wintypes
class WSD_SECURITY_CERT_VALIDATION_V1(ctypes.Structure):
_fields_ = [
("certMatchArray", ctypes.c_void_p),
("dwCertMatchArrayCount", wintypes.DWORD),
("hCertMatchStore", ctypes.c_void_p),
("hCertIssuerStore", ctypes.c_void_p),
("dwCertCheckOptions", wintypes.DWORD),
]#[repr(C)]
pub struct WSD_SECURITY_CERT_VALIDATION_V1 {
pub certMatchArray: *mut core::ffi::c_void,
pub dwCertMatchArrayCount: u32,
pub hCertMatchStore: *mut core::ffi::c_void,
pub hCertIssuerStore: *mut core::ffi::c_void,
pub dwCertCheckOptions: u32,
}import "golang.org/x/sys/windows"
type WSD_SECURITY_CERT_VALIDATION_V1 struct {
certMatchArray uintptr
dwCertMatchArrayCount uint32
hCertMatchStore uintptr
hCertIssuerStore uintptr
dwCertCheckOptions uint32
}type
WSD_SECURITY_CERT_VALIDATION_V1 = record
certMatchArray: Pointer;
dwCertMatchArrayCount: DWORD;
hCertMatchStore: Pointer;
hCertIssuerStore: Pointer;
dwCertCheckOptions: DWORD;
end;const WSD_SECURITY_CERT_VALIDATION_V1 = extern struct {
certMatchArray: ?*anyopaque,
dwCertMatchArrayCount: u32,
hCertMatchStore: ?*anyopaque,
hCertIssuerStore: ?*anyopaque,
dwCertCheckOptions: u32,
};type
WSD_SECURITY_CERT_VALIDATION_V1 {.bycopy.} = object
certMatchArray: pointer
dwCertMatchArrayCount: uint32
hCertMatchStore: pointer
hCertIssuerStore: pointer
dwCertCheckOptions: uint32struct WSD_SECURITY_CERT_VALIDATION_V1
{
void* certMatchArray;
uint dwCertMatchArrayCount;
void* hCertMatchStore;
void* hCertIssuerStore;
uint dwCertCheckOptions;
}HSP用 定義
HSP3.7/3.8 は構造体機能が無いため4byte整数配列(dim)+peek/poke で操作(32/64bitでサイズ・位置が異なる場合はタブで分割)。IronHSP は NSTRUCT(#defstruct/stdim/->)で32/64bit共通。
; HSP3.7/3.8 は構造体機能が無いため、4byte整数の配列変数で操作します。(x86 レイアウト)
; WSD_SECURITY_CERT_VALIDATION_V1 サイズ: 20 バイト(x86)
dim st, 5 ; 4byte整数×5(構造体サイズ 20 / 4 切り上げ)
; certMatchArray : CERT_CONTEXT** (+0, 4byte) varptr(st)+0 を基点に操作(4byte:入れ子/配列)
; dwCertMatchArrayCount : DWORD (+4, 4byte) st.1 = 値 / 値 = st.1 (lpoke/lpeek も可)
; hCertMatchStore : HCERTSTORE (+8, 4byte) st.2 = 値 / 値 = st.2 (lpoke/lpeek も可)
; hCertIssuerStore : HCERTSTORE (+12, 4byte) st.3 = 値 / 値 = st.3 (lpoke/lpeek も可)
; dwCertCheckOptions : DWORD (+16, 4byte) st.4 = 値 / 値 = st.4 (lpoke/lpeek も可)
; ※4byte境界の整数は添字 st.N(N=オフセット/4)で読み書き可。それ以外は peek/poke 系を使用。; HSP3.7/3.8 は構造体機能が無いため、4byte整数の配列変数で操作します。(x64 レイアウト)
; WSD_SECURITY_CERT_VALIDATION_V1 サイズ: 40 バイト(x64)
dim st, 10 ; 4byte整数×10(構造体サイズ 40 / 4 切り上げ)
; certMatchArray : CERT_CONTEXT** (+0, 8byte) varptr(st)+0 を基点に操作(8byte:入れ子/配列)
; dwCertMatchArrayCount : DWORD (+8, 4byte) st.2 = 値 / 値 = st.2 (lpoke/lpeek も可)
; hCertMatchStore : HCERTSTORE (+16, 8byte) qpoke st,16,値 / qpeek(st,16) ※IronHSPのみ。3.7/3.8は lpoke st,16,下位 : lpoke st,20,上位
; hCertIssuerStore : HCERTSTORE (+24, 8byte) qpoke st,24,値 / qpeek(st,24) ※IronHSPのみ。3.7/3.8は lpoke st,24,下位 : lpoke st,28,上位
; dwCertCheckOptions : DWORD (+32, 4byte) st.8 = 値 / 値 = st.8 (lpoke/lpeek も可)
; ※4byte境界の整数は添字 st.N(N=オフセット/4)で読み書き可。それ以外は peek/poke 系を使用。; IronHSP は NSTRUCT(構造体)をサポート。32bit/64bit どちらでも同じコードで動作します。
#defstruct global WSD_SECURITY_CERT_VALIDATION_V1
#field intptr certMatchArray
#field int dwCertMatchArrayCount
#field intptr hCertMatchStore
#field intptr hCertIssuerStore
#field int dwCertCheckOptions
#endstruct
stdim st, WSD_SECURITY_CERT_VALIDATION_V1 ; NSTRUCT 変数を確保
st->dwCertMatchArrayCount = 100
mes "dwCertMatchArrayCount=" + st->dwCertMatchArrayCount