1 .\" Automatically generated by Pod::Man v1.37, Pod::Parser v1.14
4 .\" ========================================================================
5 .de Sh \" Subsection heading
13 .de Sp \" Vertical space (when we can't use .PP)
17 .de Vb \" Begin verbatim text
22 .de Ve \" End verbatim text
26 .\" Set up some character translations and predefined strings. \*(-- will
27 .\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left
28 .\" double quote, and \*(R" will give a right double quote. | will give a
29 .\" real vertical bar. \*(C+ will give a nicer C++. Capital omega is used to
30 .\" do unbreakable dashes and therefore won't be available. \*(C` and \*(C'
31 .\" expand to `' in nroff, nothing in troff, for use with C<>.
33 .ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p'
37 . if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch
38 . if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch
51 .\" If the F register is turned on, we'll generate index entries on stderr for
52 .\" titles (.TH), headers (.SH), subsections (.Sh), items (.Ip), and index
53 .\" entries marked with X<> in POD. Of course, you'll have to process the
54 .\" output yourself in some meaningful fashion.
57 . tm Index:\\$1\t\\n%\t"\\$2"
63 .\" For nroff, turn off justification. Always turn off hyphenation; it makes
64 .\" way too many mistakes in technical documents.
68 .\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2).
69 .\" Fear. Run. Save yourself. No user-serviceable parts.
70 . \" fudge factors for nroff and troff
79 . ds #H ((1u-(\\\\n(.fu%2u))*.13m)
85 . \" simple accents for nroff and troff
95 . ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u"
96 . ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u'
97 . ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u'
98 . ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u'
99 . ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u'
100 . ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u'
102 . \" troff and (daisy-wheel) nroff accents
103 .ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V'
104 .ds 8 \h'\*(#H'\(*b\h'-\*(#H'
105 .ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#]
106 .ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H'
107 .ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u'
108 .ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#]
109 .ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#]
110 .ds ae a\h'-(\w'a'u*4/10)'e
111 .ds Ae A\h'-(\w'A'u*4/10)'E
112 . \" corrections for vroff
113 .if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u'
114 .if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u'
115 . \" for low resolution devices (crt and lpr)
116 .if \n(.H>23 .if \n(.V>19 \
129 .\" ========================================================================
131 .IX Title "DH_generate_parameters 3"
132 .TH DH_generate_parameters 3 "2007-03-28" "0.9.8e" "OpenSSL"
134 DH_generate_parameters, DH_check \- generate and check Diffie\-Hellman parameters
136 .IX Header "SYNOPSIS"
138 \& #include <openssl/dh.h>
142 \& DH *DH_generate_parameters(int prime_len, int generator,
143 \& void (*callback)(int, int, void *), void *cb_arg);
147 \& int DH_check(DH *dh, int *codes);
150 .IX Header "DESCRIPTION"
151 \&\fIDH_generate_parameters()\fR generates Diffie-Hellman parameters that can
152 be shared among a group of users, and returns them in a newly
153 allocated \fB\s-1DH\s0\fR structure. The pseudo-random number generator must be
154 seeded prior to calling \fIDH_generate_parameters()\fR.
156 \&\fBprime_len\fR is the length in bits of the safe prime to be generated.
157 \&\fBgenerator\fR is a small number > 1, typically 2 or 5.
159 A callback function may be used to provide feedback about the progress
160 of the key generation. If \fBcallback\fR is not \fB\s-1NULL\s0\fR, it will be
161 called as described in \fIBN_generate_prime\fR\|(3) while a random prime
162 number is generated, and when a prime has been found, \fBcallback(3,
163 0, cb_arg)\fR is called.
165 \&\fIDH_check()\fR validates Diffie-Hellman parameters. It checks that \fBp\fR is
166 a safe prime, and that \fBg\fR is a suitable generator. In the case of an
167 error, the bit flags \s-1DH_CHECK_P_NOT_SAFE_PRIME\s0 or
168 \&\s-1DH_NOT_SUITABLE_GENERATOR\s0 are set in \fB*codes\fR.
169 \&\s-1DH_UNABLE_TO_CHECK_GENERATOR\s0 is set if the generator cannot be
170 checked, i.e. it does not equal 2 or 5.
172 .IX Header "RETURN VALUES"
173 \&\fIDH_generate_parameters()\fR returns a pointer to the \s-1DH\s0 structure, or
174 \&\s-1NULL\s0 if the parameter generation fails. The error codes can be
175 obtained by \fIERR_get_error\fR\|(3).
177 \&\fIDH_check()\fR returns 1 if the check could be performed, 0 otherwise.
180 \&\fIDH_generate_parameters()\fR may run for several hours before finding a
183 The parameters generated by \fIDH_generate_parameters()\fR are not to be
184 used in signature schemes.
187 If \fBgenerator\fR is not 2 or 5, \fBdh\->g\fR=\fBgenerator\fR is not
190 .IX Header "SEE ALSO"
191 \&\fIdh\fR\|(3), \fIERR_get_error\fR\|(3), \fIrand\fR\|(3),
195 \&\fIDH_check()\fR is available in all versions of SSLeay and OpenSSL.
196 The \fBcb_arg\fR argument to \fIDH_generate_parameters()\fR was added in SSLeay 0.9.0.
198 In versions before OpenSSL 0.9.5, \s-1DH_CHECK_P_NOT_STRONG_PRIME\s0 is used
199 instead of \s-1DH_CHECK_P_NOT_SAFE_PRIME\s0.