1 .\" $NetBSD: libcrypto.pl,v 1.3 2007/11/27 22:16:03 christos Exp $
3 .\" Automatically generated by Pod::Man 2.16 (Pod::Simple 3.05)
6 .\" ========================================================================
7 .de Sh \" Subsection heading
15 .de Sp \" Vertical space (when we can't use .PP)
19 .de Vb \" Begin verbatim text
24 .de Ve \" End verbatim text
28 .\" Set up some character translations and predefined strings. \*(-- will
29 .\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left
30 .\" double quote, and \*(R" will give a right double quote. \*(C+ will
31 .\" give a nicer C++. Capital omega is used to do unbreakable dashes and
32 .\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff,
33 .\" nothing in troff, for use with C<>.
35 .ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p'
39 . if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch
40 . if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch
53 .\" Escape single quotes in literal strings from groff's Unicode transform.
57 .\" If the F register is turned on, we'll generate index entries on stderr for
58 .\" titles (.TH), headers (.SH), subsections (.Sh), items (.Ip), and index
59 .\" entries marked with X<> in POD. Of course, you'll have to process the
60 .\" output yourself in some meaningful fashion.
63 . tm Index:\\$1\t\\n%\t"\\$2"
73 .\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2).
74 .\" Fear. Run. Save yourself. No user-serviceable parts.
75 . \" fudge factors for nroff and troff
84 . ds #H ((1u-(\\\\n(.fu%2u))*.13m)
90 . \" simple accents for nroff and troff
100 . ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u"
101 . ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u'
102 . ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u'
103 . ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u'
104 . ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u'
105 . ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u'
107 . \" troff and (daisy-wheel) nroff accents
108 .ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V'
109 .ds 8 \h'\*(#H'\(*b\h'-\*(#H'
110 .ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#]
111 .ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H'
112 .ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u'
113 .ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#]
114 .ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#]
115 .ds ae a\h'-(\w'a'u*4/10)'e
116 .ds Ae A\h'-(\w'A'u*4/10)'E
117 . \" corrections for vroff
118 .if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u'
119 .if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u'
120 . \" for low resolution devices (crt and lpr)
121 .if \n(.H>23 .if \n(.V>19 \
134 .\" ========================================================================
136 .IX Title "DH_generate_parameters 3"
137 .TH DH_generate_parameters 3 "2002-09-25" "1.1.0-dev" "OpenSSL"
138 .\" For nroff, turn off justification. Always turn off hyphenation; it makes
139 .\" way too many mistakes in technical documents.
143 DH_generate_parameters, DH_check \- generate and check Diffie\-Hellman parameters
147 .IX Header "SYNOPSIS"
149 \& #include <openssl/dh.h>
151 \& DH *DH_generate_parameters(int prime_len, int generator,
152 \& void (*callback)(int, int, void *), void *cb_arg);
154 \& int DH_check(DH *dh, int *codes);
157 .IX Header "DESCRIPTION"
158 \&\fIDH_generate_parameters()\fR generates Diffie-Hellman parameters that can
159 be shared among a group of users, and returns them in a newly
160 allocated \fB\s-1DH\s0\fR structure. The pseudo-random number generator must be
161 seeded prior to calling \fIDH_generate_parameters()\fR.
163 \&\fBprime_len\fR is the length in bits of the safe prime to be generated.
164 \&\fBgenerator\fR is a small number > 1, typically 2 or 5.
166 A callback function may be used to provide feedback about the progress
167 of the key generation. If \fBcallback\fR is not \fB\s-1NULL\s0\fR, it will be
168 called as described in \fIBN_generate_prime\fR\|(3) while a random prime
169 number is generated, and when a prime has been found, \fBcallback(3,
170 0, cb_arg)\fR is called.
172 \&\fIDH_check()\fR validates Diffie-Hellman parameters. It checks that \fBp\fR is
173 a safe prime, and that \fBg\fR is a suitable generator. In the case of an
174 error, the bit flags \s-1DH_CHECK_P_NOT_SAFE_PRIME\s0 or
175 \&\s-1DH_NOT_SUITABLE_GENERATOR\s0 are set in \fB*codes\fR.
176 \&\s-1DH_UNABLE_TO_CHECK_GENERATOR\s0 is set if the generator cannot be
177 checked, i.e. it does not equal 2 or 5.
179 .IX Header "RETURN VALUES"
180 \&\fIDH_generate_parameters()\fR returns a pointer to the \s-1DH\s0 structure, or
181 \&\s-1NULL\s0 if the parameter generation fails. The error codes can be
182 obtained by \fIERR_get_error\fR\|(3).
184 \&\fIDH_check()\fR returns 1 if the check could be performed, 0 otherwise.
187 \&\fIDH_generate_parameters()\fR may run for several hours before finding a
190 The parameters generated by \fIDH_generate_parameters()\fR are not to be
191 used in signature schemes.
194 If \fBgenerator\fR is not 2 or 5, \fBdh\->g\fR=\fBgenerator\fR is not
197 .IX Header "SEE ALSO"
198 \&\fIopenssl_dh\fR\|(3), \fIERR_get_error\fR\|(3), \fIopenssl_rand\fR\|(3),
202 \&\fIDH_check()\fR is available in all versions of SSLeay and OpenSSL.
203 The \fBcb_arg\fR argument to \fIDH_generate_parameters()\fR was added in SSLeay 0.9.0.
205 In versions before OpenSSL 0.9.5, \s-1DH_CHECK_P_NOT_STRONG_PRIME\s0 is used
206 instead of \s-1DH_CHECK_P_NOT_SAFE_PRIME\s0.