From b22a7b55d0bc5a7999dccaeacdde745f5ace9d66 Mon Sep 17 00:00:00 2001 From: Michael Biebl Date: Thu, 23 Feb 2023 17:11:22 +0100 Subject: New upstream version 1.42.2 --- docs/libnm/html/NMSetting8021x.html | 4407 +++++++++++++++++++++++++++++++++++ 1 file changed, 4407 insertions(+) create mode 100644 docs/libnm/html/NMSetting8021x.html (limited to 'docs/libnm/html/NMSetting8021x.html') diff --git a/docs/libnm/html/NMSetting8021x.html b/docs/libnm/html/NMSetting8021x.html new file mode 100644 index 00000000..8c881f55 --- /dev/null +++ b/docs/libnm/html/NMSetting8021x.html @@ -0,0 +1,4407 @@ + + + + +NMSetting8021x: libnm Reference Manual + + + + + + + + + + + + + + + + +
+
+
+ + +
+

NMSetting8021x

+

NMSetting8021x — Describes 802.1x-authenticated connection properties

+
+
+

Functions

+
++++ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
+NMSetting * + +nm_setting_802_1x_new () +
+NMSetting8021xCKScheme + +nm_setting_802_1x_check_cert_scheme () +
+guint32 + +nm_setting_802_1x_get_num_eap_methods () +
const char * + +nm_setting_802_1x_get_eap_method () +
+gboolean + +nm_setting_802_1x_add_eap_method () +
+void + +nm_setting_802_1x_remove_eap_method () +
+gboolean + +nm_setting_802_1x_remove_eap_method_by_value () +
+void + +nm_setting_802_1x_clear_eap_methods () +
const char * + +nm_setting_802_1x_get_identity () +
const char * + +nm_setting_802_1x_get_anonymous_identity () +
const char * + +nm_setting_802_1x_get_pac_file () +
+gboolean + +nm_setting_802_1x_get_system_ca_certs () +
const char * + +nm_setting_802_1x_get_ca_path () +
const char * + +nm_setting_802_1x_get_phase2_ca_path () +
+NMSetting8021xCKScheme + +nm_setting_802_1x_get_ca_cert_scheme () +
+GBytes * + +nm_setting_802_1x_get_ca_cert_blob () +
const char * + +nm_setting_802_1x_get_ca_cert_path () +
const char * + +nm_setting_802_1x_get_ca_cert_uri () +
+gboolean + +nm_setting_802_1x_set_ca_cert () +
const char * + +nm_setting_802_1x_get_ca_cert_password () +
+NMSettingSecretFlags + +nm_setting_802_1x_get_ca_cert_password_flags () +
const char * + +nm_setting_802_1x_get_subject_match () +
+guint32 + +nm_setting_802_1x_get_num_altsubject_matches () +
const char * + +nm_setting_802_1x_get_altsubject_match () +
+gboolean + +nm_setting_802_1x_add_altsubject_match () +
+void + +nm_setting_802_1x_remove_altsubject_match () +
+gboolean + +nm_setting_802_1x_remove_altsubject_match_by_value () +
+void + +nm_setting_802_1x_clear_altsubject_matches () +
const char * + +nm_setting_802_1x_get_domain_suffix_match () +
const char * + +nm_setting_802_1x_get_domain_match () +
+NMSetting8021xCKScheme + +nm_setting_802_1x_get_client_cert_scheme () +
+GBytes * + +nm_setting_802_1x_get_client_cert_blob () +
const char * + +nm_setting_802_1x_get_client_cert_path () +
const char * + +nm_setting_802_1x_get_client_cert_uri () +
+gboolean + +nm_setting_802_1x_set_client_cert () +
const char * + +nm_setting_802_1x_get_client_cert_password () +
+NMSettingSecretFlags + +nm_setting_802_1x_get_client_cert_password_flags () +
const char * + +nm_setting_802_1x_get_phase1_peapver () +
const char * + +nm_setting_802_1x_get_phase1_peaplabel () +
const char * + +nm_setting_802_1x_get_phase1_fast_provisioning () +
const char * + +nm_setting_802_1x_get_phase2_auth () +
const char * + +nm_setting_802_1x_get_phase2_autheap () +
+NMSetting8021xCKScheme + +nm_setting_802_1x_get_phase2_ca_cert_scheme () +
+GBytes * + +nm_setting_802_1x_get_phase2_ca_cert_blob () +
const char * + +nm_setting_802_1x_get_phase2_ca_cert_path () +
const char * + +nm_setting_802_1x_get_phase2_ca_cert_uri () +
+gboolean + +nm_setting_802_1x_set_phase2_ca_cert () +
const char * + +nm_setting_802_1x_get_phase2_ca_cert_password () +
+NMSettingSecretFlags + +nm_setting_802_1x_get_phase2_ca_cert_password_flags () +
const char * + +nm_setting_802_1x_get_phase2_subject_match () +
+guint32 + +nm_setting_802_1x_get_num_phase2_altsubject_matches () +
const char * + +nm_setting_802_1x_get_phase2_altsubject_match () +
+gboolean + +nm_setting_802_1x_add_phase2_altsubject_match () +
+void + +nm_setting_802_1x_remove_phase2_altsubject_match () +
+gboolean + +nm_setting_802_1x_remove_phase2_altsubject_match_by_value () +
+void + +nm_setting_802_1x_clear_phase2_altsubject_matches () +
const char * + +nm_setting_802_1x_get_phase2_domain_suffix_match () +
const char * + +nm_setting_802_1x_get_phase2_domain_match () +
+NMSetting8021xCKScheme + +nm_setting_802_1x_get_phase2_client_cert_scheme () +
+GBytes * + +nm_setting_802_1x_get_phase2_client_cert_blob () +
const char * + +nm_setting_802_1x_get_phase2_client_cert_path () +
const char * + +nm_setting_802_1x_get_phase2_client_cert_uri () +
+gboolean + +nm_setting_802_1x_set_phase2_client_cert () +
const char * + +nm_setting_802_1x_get_phase2_client_cert_password () +
+NMSettingSecretFlags + +nm_setting_802_1x_get_phase2_client_cert_password_flags () +
const char * + +nm_setting_802_1x_get_password () +
+NMSettingSecretFlags + +nm_setting_802_1x_get_password_flags () +
+GBytes * + +nm_setting_802_1x_get_password_raw () +
+NMSettingSecretFlags + +nm_setting_802_1x_get_password_raw_flags () +
const char * + +nm_setting_802_1x_get_pin () +
+NMSettingSecretFlags + +nm_setting_802_1x_get_pin_flags () +
+NMSetting8021xCKScheme + +nm_setting_802_1x_get_private_key_scheme () +
+GBytes * + +nm_setting_802_1x_get_private_key_blob () +
const char * + +nm_setting_802_1x_get_private_key_path () +
const char * + +nm_setting_802_1x_get_private_key_uri () +
+gboolean + +nm_setting_802_1x_set_private_key () +
const char * + +nm_setting_802_1x_get_private_key_password () +
+NMSettingSecretFlags + +nm_setting_802_1x_get_private_key_password_flags () +
+NMSetting8021xCKFormat + +nm_setting_802_1x_get_private_key_format () +
+NMSetting8021xCKScheme + +nm_setting_802_1x_get_phase2_private_key_scheme () +
+GBytes * + +nm_setting_802_1x_get_phase2_private_key_blob () +
const char * + +nm_setting_802_1x_get_phase2_private_key_path () +
const char * + +nm_setting_802_1x_get_phase2_private_key_uri () +
+gboolean + +nm_setting_802_1x_set_phase2_private_key () +
const char * + +nm_setting_802_1x_get_phase2_private_key_password () +
+NMSettingSecretFlags + +nm_setting_802_1x_get_phase2_private_key_password_flags () +
+NMSetting8021xCKFormat + +nm_setting_802_1x_get_phase2_private_key_format () +
+NMSetting8021xAuthFlags + +nm_setting_802_1x_get_phase1_auth_flags () +
+int + +nm_setting_802_1x_get_auth_timeout () +
+gboolean + +nm_setting_802_1x_get_optional () +
+
+
+

Types and Values

+
++++ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
#defineNM_SETTING_802_1X_CERT_SCHEME_PREFIX_PATH
#defineNM_SETTING_802_1X_CERT_SCHEME_PREFIX_PKCS11
enumNMSetting8021xCKFormat
enumNMSetting8021xCKScheme
enumNMSetting8021xAuthFlags
#defineNM_SETTING_802_1X_SETTING_NAME
#defineNM_SETTING_802_1X_EAP
#defineNM_SETTING_802_1X_IDENTITY
#defineNM_SETTING_802_1X_ANONYMOUS_IDENTITY
#defineNM_SETTING_802_1X_PAC_FILE
#defineNM_SETTING_802_1X_CA_CERT
#defineNM_SETTING_802_1X_CA_CERT_PASSWORD
#defineNM_SETTING_802_1X_CA_CERT_PASSWORD_FLAGS
#defineNM_SETTING_802_1X_CA_PATH
#defineNM_SETTING_802_1X_SUBJECT_MATCH
#defineNM_SETTING_802_1X_ALTSUBJECT_MATCHES
#defineNM_SETTING_802_1X_DOMAIN_SUFFIX_MATCH
#defineNM_SETTING_802_1X_DOMAIN_MATCH
#defineNM_SETTING_802_1X_CLIENT_CERT
#defineNM_SETTING_802_1X_CLIENT_CERT_PASSWORD
#defineNM_SETTING_802_1X_CLIENT_CERT_PASSWORD_FLAGS
#defineNM_SETTING_802_1X_PHASE1_PEAPVER
#defineNM_SETTING_802_1X_PHASE1_PEAPLABEL
#defineNM_SETTING_802_1X_PHASE1_FAST_PROVISIONING
#defineNM_SETTING_802_1X_PHASE1_AUTH_FLAGS
#defineNM_SETTING_802_1X_PHASE2_AUTH
#defineNM_SETTING_802_1X_PHASE2_AUTHEAP
#defineNM_SETTING_802_1X_PHASE2_CA_CERT
#defineNM_SETTING_802_1X_PHASE2_CA_CERT_PASSWORD
#defineNM_SETTING_802_1X_PHASE2_CA_CERT_PASSWORD_FLAGS
#defineNM_SETTING_802_1X_PHASE2_CA_PATH
#defineNM_SETTING_802_1X_PHASE2_SUBJECT_MATCH
#defineNM_SETTING_802_1X_PHASE2_ALTSUBJECT_MATCHES
#defineNM_SETTING_802_1X_PHASE2_DOMAIN_SUFFIX_MATCH
#defineNM_SETTING_802_1X_PHASE2_DOMAIN_MATCH
#defineNM_SETTING_802_1X_PHASE2_CLIENT_CERT
#defineNM_SETTING_802_1X_PHASE2_CLIENT_CERT_PASSWORD
#defineNM_SETTING_802_1X_PHASE2_CLIENT_CERT_PASSWORD_FLAGS
#defineNM_SETTING_802_1X_PASSWORD
#defineNM_SETTING_802_1X_PASSWORD_FLAGS
#defineNM_SETTING_802_1X_PASSWORD_RAW
#defineNM_SETTING_802_1X_PASSWORD_RAW_FLAGS
#defineNM_SETTING_802_1X_PRIVATE_KEY
#defineNM_SETTING_802_1X_PRIVATE_KEY_PASSWORD
#defineNM_SETTING_802_1X_PRIVATE_KEY_PASSWORD_FLAGS
#defineNM_SETTING_802_1X_PHASE2_PRIVATE_KEY
#defineNM_SETTING_802_1X_PHASE2_PRIVATE_KEY_PASSWORD
#defineNM_SETTING_802_1X_PHASE2_PRIVATE_KEY_PASSWORD_FLAGS
#defineNM_SETTING_802_1X_PIN
#defineNM_SETTING_802_1X_PIN_FLAGS
#defineNM_SETTING_802_1X_SYSTEM_CA_CERTS
#defineNM_SETTING_802_1X_AUTH_TIMEOUT
#defineNM_SETTING_802_1X_OPTIONAL
+
+
+

Object Hierarchy

+
    GEnum
+    ├── NMSetting8021xCKFormat
+    ╰── NMSetting8021xCKScheme
+    GFlags
+    ╰── NMSetting8021xAuthFlags
+
+
+
+

Description

+

The NMSetting8021x object is a NMSetting subclass that describes +properties necessary for connection to 802.1x-authenticated networks, such as +WPA and WPA2 Enterprise Wi-Fi networks and wired 802.1x networks. 802.1x +connections typically use certificates and/or EAP authentication methods to +securely verify, identify, and authenticate the client to the network itself, +instead of simply relying on a widely shared static key.

+

It's a good idea to read up on wpa_supplicant configuration before using this +setting extensively, since most of the options here correspond closely with +the relevant wpa_supplicant configuration options.

+

Furthermore, to get a good idea of 802.1x, EAP, TLS, TTLS, etc and their +applications to Wi-Fi and wired networks, you'll want to get copies of the +following books.

+

802.11 Wireless Networks: The Definitive Guide, Second Edition + Author: Matthew Gast + ISBN: 978-0596100520

+

Cisco Wireless LAN Security + Authors: Krishna Sankar, Sri Sundaralingam, Darrin Miller, and Andrew Balinsky + ISBN: 978-1587051548

+
+
+

Functions

+
+

nm_setting_802_1x_new ()

+
NMSetting *
+nm_setting_802_1x_new (void);
+

Creates a new NMSetting8021x object with default values.

+
+

Returns

+

the new empty NMSetting8021x object

+
+
+
+
+

nm_setting_802_1x_check_cert_scheme ()

+
NMSetting8021xCKScheme
+nm_setting_802_1x_check_cert_scheme (gconstpointer pdata,
+                                     gsize length,
+                                     GError **error);
+

Determines and verifies the blob type. +When setting certificate properties of NMSetting8021x +the blob must be not UNKNOWN (or NULL).

+
+

Parameters

+
+++++ + + + + + + + + + + + + + + + + + +

pdata

the data pointer.

[allow-none]

length

the length of the data

 

error

validation reason.

[allow-none][out]
+
+
+

Returns

+

the scheme of the blob or NM_SETTING_802_1X_CK_SCHEME_UNKNOWN. +For NULL it also returns NM_SETTING_802_1X_CK_SCHEME_UNKNOWN.

+
+

Since: 1.2

+
+
+
+

nm_setting_802_1x_get_num_eap_methods ()

+
guint32
+nm_setting_802_1x_get_num_eap_methods (NMSetting8021x *setting);
+

Returns the number of eap methods allowed for use when connecting to the +network. Generally only one EAP method is used. Use the functions +nm_setting_802_1x_get_eap_method(), nm_setting_802_1x_add_eap_method(), +and nm_setting_802_1x_remove_eap_method() for adding, removing, and retrieving +allowed EAP methods.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the number of allowed EAP methods

+
+
+
+
+

nm_setting_802_1x_get_eap_method ()

+
const char *
+nm_setting_802_1x_get_eap_method (NMSetting8021x *setting,
+                                  guint32 i);
+

Returns the name of the allowed EAP method at index i +.

+
+

Parameters

+
+++++ + + + + + + + + + + + + +

setting

the NMSetting8021x

 

i

the index of the EAP method name to return

 
+
+
+

Returns

+

the name of the allowed EAP method at index i +

+
+
+
+
+

nm_setting_802_1x_add_eap_method ()

+
gboolean
+nm_setting_802_1x_add_eap_method (NMSetting8021x *setting,
+                                  const char *eap);
+

Adds an allowed EAP method. The setting is not valid until at least one +EAP method has been added. See “eap” property for a list of +allowed EAP methods.

+
+

Parameters

+
+++++ + + + + + + + + + + + + +

setting

the NMSetting8021x

 

eap

the name of the EAP method to allow for this connection

 
+
+
+

Returns

+

TRUE if the EAP method was successfully added, FALSE if it was +not a valid method or if it was already allowed.

+
+
+
+
+

nm_setting_802_1x_remove_eap_method ()

+
void
+nm_setting_802_1x_remove_eap_method (NMSetting8021x *setting,
+                                     guint32 i);
+

Removes the allowed EAP method at the specified index.

+
+

Parameters

+
+++++ + + + + + + + + + + + + +

setting

the NMSetting8021x

 

i

the index of the EAP method to remove

 
+
+
+
+
+

nm_setting_802_1x_remove_eap_method_by_value ()

+
gboolean
+nm_setting_802_1x_remove_eap_method_by_value
+                               (NMSetting8021x *setting,
+                                const char *eap);
+

Removes the allowed EAP method method +.

+
+

Parameters

+
+++++ + + + + + + + + + + + + +

setting

the NMSetting8021x

 

eap

the name of the EAP method to remove

 
+
+
+

Returns

+

TRUE if the EAP method was founs and removed, FALSE if it was not.

+
+
+
+
+

nm_setting_802_1x_clear_eap_methods ()

+
void
+nm_setting_802_1x_clear_eap_methods (NMSetting8021x *setting);
+

Clears all allowed EAP methods.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+
+
+

nm_setting_802_1x_get_identity ()

+
const char *
+nm_setting_802_1x_get_identity (NMSetting8021x *setting);
+

Returns the identifier used by some EAP methods (like TLS) to +authenticate the user. Often this is a username or login name.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the user identifier

+
+
+
+
+

nm_setting_802_1x_get_anonymous_identity ()

+
const char *
+nm_setting_802_1x_get_anonymous_identity
+                               (NMSetting8021x *setting);
+

Returns the anonymous identifier used by some EAP methods (like TTLS) to +authenticate the user in the outer unencrypted "phase 1" authentication. The +inner "phase 2" authentication will use the “identity” in +a secure form, if applicable for that EAP method.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the anonymous identifier

+
+
+
+
+

nm_setting_802_1x_get_pac_file ()

+
const char *
+nm_setting_802_1x_get_pac_file (NMSetting8021x *setting);
+

Returns the file containing PAC credentials used by EAP-FAST method.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the PAC file

+
+
+
+
+

nm_setting_802_1x_get_system_ca_certs ()

+
gboolean
+nm_setting_802_1x_get_system_ca_certs (NMSetting8021x *setting);
+

Sets the “system-ca-certs” property. The +“ca-path” and “phase2-ca-path” +properties are ignored if the “system-ca-certs” property is +TRUE, in which case a system-wide CA certificate directory specified at +compile time (using the --system-ca-path configure option) is used in place +of these properties.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

TRUE if a system CA certificate path should be used, FALSE if not

+
+
+
+
+

nm_setting_802_1x_get_ca_path ()

+
const char *
+nm_setting_802_1x_get_ca_path (NMSetting8021x *setting);
+

Returns the path of the CA certificate directory if previously set. Systems +will often have a directory that contains multiple individual CA certificates +which the supplicant can then add to the verification chain. This may be +used in addition to the “ca-cert” property to add more CA +certificates for verifying the network to client.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the CA certificate directory path

+
+
+
+
+

nm_setting_802_1x_get_phase2_ca_path ()

+
const char *
+nm_setting_802_1x_get_phase2_ca_path (NMSetting8021x *setting);
+

Returns the path of the "phase 2" CA certificate directory if previously set. +Systems will often have a directory that contains multiple individual CA +certificates which the supplicant can then add to the verification chain. +This may be used in addition to the “phase2-ca-cert” property +to add more CA certificates for verifying the network to client.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the "phase 2" CA certificate directory path

+
+
+
+
+

nm_setting_802_1x_get_ca_cert_scheme ()

+
NMSetting8021xCKScheme
+nm_setting_802_1x_get_ca_cert_scheme (NMSetting8021x *setting);
+

Returns the scheme used to store the CA certificate. If the returned scheme +is NM_SETTING_802_1X_CK_SCHEME_BLOB, use nm_setting_802_1x_get_ca_cert_blob(); +if NM_SETTING_802_1X_CK_SCHEME_PATH, use nm_setting_802_1x_get_ca_cert_path(); +if NM_SETTING_802_1X_CK_SCHEME_PKCS11, use nm_setting_802_1x_get_ca_cert_uri().

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

scheme used to store the CA certificate (blob or path)

+
+
+
+
+

nm_setting_802_1x_get_ca_cert_blob ()

+
GBytes *
+nm_setting_802_1x_get_ca_cert_blob (NMSetting8021x *setting);
+

Returns the CA certificate blob if the CA certificate is stored using the +NM_SETTING_802_1X_CK_SCHEME_BLOB scheme. Not all EAP methods use a +CA certificate (LEAP for example), and those that can take advantage of the +CA certificate allow it to be unset. Note that lack of a CA certificate +reduces security by allowing man-in-the-middle attacks, because the identity +of the network cannot be confirmed by the client.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the CA certificate data.

+

[transfer none]

+
+
+
+
+

nm_setting_802_1x_get_ca_cert_path ()

+
const char *
+nm_setting_802_1x_get_ca_cert_path (NMSetting8021x *setting);
+

Returns the CA certificate path if the CA certificate is stored using the +NM_SETTING_802_1X_CK_SCHEME_PATH scheme. Not all EAP methods use a +CA certificate (LEAP for example), and those that can take advantage of the +CA certificate allow it to be unset. Note that lack of a CA certificate +reduces security by allowing man-in-the-middle attacks, because the identity +of the network cannot be confirmed by the client.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

path to the CA certificate file

+
+
+
+
+

nm_setting_802_1x_get_ca_cert_uri ()

+
const char *
+nm_setting_802_1x_get_ca_cert_uri (NMSetting8021x *setting);
+

Returns the CA certificate URI analogously to +nm_setting_802_1x_get_ca_cert_blob() and +nm_setting_802_1x_get_ca_cert_path().

+

Currently, it's limited to PKCS11 URIs ('pkcs11' scheme as defined by RFC +7512), but may be extended to other schemes in future (such as 'file' URIs +for local files and 'data' URIs for inline certificate data).

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the URI string

+
+

Since: 1.6

+
+
+
+

nm_setting_802_1x_set_ca_cert ()

+
gboolean
+nm_setting_802_1x_set_ca_cert (NMSetting8021x *setting,
+                               const char *value,
+                               NMSetting8021xCKScheme scheme,
+                               NMSetting8021xCKFormat *out_format,
+                               GError **error);
+

Reads a certificate from disk and sets the “ca-cert” property +with the raw certificate data if using the NM_SETTING_802_1X_CK_SCHEME_BLOB +scheme, or with the path to the certificate file if using the +NM_SETTING_802_1X_CK_SCHEME_PATH scheme.

+
+

Parameters

+
+++++ + + + + + + + + + + + + + + + + + + + + + + + + + + + +

setting

the NMSetting8021x

 

value

when scheme +is set to either NM_SETTING_802_1X_CK_SCHEME_PATH +or NM_SETTING_802_1X_CK_SCHEME_BLOB, pass the path of the CA certificate +file (PEM or DER format). The path must be UTF-8 encoded; use +g_filename_to_utf8() to convert if needed. Passing NULL with any scheme +clears the CA certificate.

 

scheme

desired storage scheme for the certificate

 

out_format

on successful return, the type of the certificate added

 

error

on unsuccessful return, an error

 
+
+
+

Returns

+

TRUE if the operation succeeded, FALSE if it was unsuccessful

+
+
+
+
+

nm_setting_802_1x_get_ca_cert_password ()

+
const char *
+nm_setting_802_1x_get_ca_cert_password
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the password used to access the CA certificate stored in +“ca-cert” property. Only makes sense if the certificate +is stored on a PKCS#11 token that requires a login.

+
+

Since: 1.8

+
+
+
+

nm_setting_802_1x_get_ca_cert_password_flags ()

+
NMSettingSecretFlags
+nm_setting_802_1x_get_ca_cert_password_flags
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the NMSettingSecretFlags pertaining to the +“ca-cert-password”

+
+

Since: 1.8

+
+
+
+

nm_setting_802_1x_get_subject_match ()

+
const char *
+nm_setting_802_1x_get_subject_match (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the “subject-match” property. This is the +substring to be matched against the subject of the authentication +server certificate, or NULL no subject verification is to be +performed.

+
+
+
+
+

nm_setting_802_1x_get_num_altsubject_matches ()

+
guint32
+nm_setting_802_1x_get_num_altsubject_matches
+                               (NMSetting8021x *setting);
+

Returns the number of entries in the +“altsubject-matches” property of this setting.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the number of altsubject-matches entries.

+
+
+
+
+

nm_setting_802_1x_get_altsubject_match ()

+
const char *
+nm_setting_802_1x_get_altsubject_match
+                               (NMSetting8021x *setting,
+                                guint32 i);
+

Returns the altSubjectName match at index i +.

+
+

Parameters

+
+++++ + + + + + + + + + + + + +

setting

the NMSettingConnection

 

i

the zero-based index of the array of altSubjectName matches

 
+
+
+

Returns

+

the altSubjectName match at index i +

+
+
+
+
+

nm_setting_802_1x_add_altsubject_match ()

+
gboolean
+nm_setting_802_1x_add_altsubject_match
+                               (NMSetting8021x *setting,
+                                const char *altsubject_match);
+

Adds an allowed alternate subject name match. Until at least one +match is added, the altSubjectName of the remote authentication +server is not verified.

+
+

Parameters

+
+++++ + + + + + + + + + + + + +

setting

the NMSetting8021x

 

altsubject_match

the altSubjectName to allow for this connection

 
+
+
+

Returns

+

TRUE if the alternative subject name match was +successfully added, FALSE if it was already allowed.

+
+
+
+
+

nm_setting_802_1x_remove_altsubject_match ()

+
void
+nm_setting_802_1x_remove_altsubject_match
+                               (NMSetting8021x *setting,
+                                guint32 i);
+

Removes the allowed altSubjectName at the specified index.

+
+

Parameters

+
+++++ + + + + + + + + + + + + +

setting

the NMSetting8021x

 

i

the index of the altSubjectName match to remove

 
+
+
+
+
+

nm_setting_802_1x_remove_altsubject_match_by_value ()

+
gboolean
+nm_setting_802_1x_remove_altsubject_match_by_value
+                               (NMSetting8021x *setting,
+                                const char *altsubject_match);
+

Removes the allowed altSubjectName altsubject_match +.

+
+

Parameters

+
+++++ + + + + + + + + + + + + +

setting

the NMSetting8021x

 

altsubject_match

the altSubjectName to remove

 
+
+
+

Returns

+

TRUE if the alternative subject name match was found and removed, +FALSE if it was not.

+
+
+
+
+

nm_setting_802_1x_clear_altsubject_matches ()

+
void
+nm_setting_802_1x_clear_altsubject_matches
+                               (NMSetting8021x *setting);
+

Clears all altSubjectName matches.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+
+
+

nm_setting_802_1x_get_domain_suffix_match ()

+
const char *
+nm_setting_802_1x_get_domain_suffix_match
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the “domain-suffix-match” property.

+
+

Since: 1.2

+
+
+
+

nm_setting_802_1x_get_domain_match ()

+
const char *
+nm_setting_802_1x_get_domain_match (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the “domain-match” property.

+
+

Since: 1.24

+
+
+
+

nm_setting_802_1x_get_client_cert_scheme ()

+
NMSetting8021xCKScheme
+nm_setting_802_1x_get_client_cert_scheme
+                               (NMSetting8021x *setting);
+

Returns the scheme used to store the client certificate. If the returned scheme +is NM_SETTING_802_1X_CK_SCHEME_BLOB, use nm_setting_802_1x_get_client_cert_blob(); +if NM_SETTING_802_1X_CK_SCHEME_PATH, use nm_setting_802_1x_get_client_cert_path(); +if NM_SETTING_802_1X_CK_SCHEME_PKCS11, use nm_setting_802_1x_get_client_cert_uri().

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

scheme used to store the client certificate (blob or path)

+
+
+
+
+

nm_setting_802_1x_get_client_cert_blob ()

+
GBytes *
+nm_setting_802_1x_get_client_cert_blob
+                               (NMSetting8021x *setting);
+

Client certificates are used to identify the connecting client to the network +when EAP-TLS is used as either the "phase 1" or "phase 2" 802.1x +authentication method.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the client certificate data.

+

[transfer none]

+
+
+
+
+

nm_setting_802_1x_get_client_cert_path ()

+
const char *
+nm_setting_802_1x_get_client_cert_path
+                               (NMSetting8021x *setting);
+

Client certificates are used to identify the connecting client to the network +when EAP-TLS is used as either the "phase 1" or "phase 2" 802.1x +authentication method.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

path to the client certificate file

+
+
+
+
+

nm_setting_802_1x_get_client_cert_uri ()

+
const char *
+nm_setting_802_1x_get_client_cert_uri (NMSetting8021x *setting);
+

Returns the client certificate URI analogously to +nm_setting_802_1x_get_client_cert_blob() and +nm_setting_802_1x_get_client_cert_path().

+

Currently, it's limited to PKCS11 URIs ('pkcs11' scheme as defined by RFC +7512), but may be extended to other schemes in future (such as 'file' URIs +for local files and 'data' URIs for inline certificate data).

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the URI string

+
+

Since: 1.6

+
+
+
+

nm_setting_802_1x_set_client_cert ()

+
gboolean
+nm_setting_802_1x_set_client_cert (NMSetting8021x *setting,
+                                   const char *value,
+                                   NMSetting8021xCKScheme scheme,
+                                   NMSetting8021xCKFormat *out_format,
+                                   GError **error);
+

Reads a certificate from disk and sets the “client-cert” +property with the raw certificate data if using the +NM_SETTING_802_1X_CK_SCHEME_BLOB scheme, or with the path to the certificate +file if using the NM_SETTING_802_1X_CK_SCHEME_PATH scheme.

+

Client certificates are used to identify the connecting client to the network +when EAP-TLS is used as either the "phase 1" or "phase 2" 802.1x +authentication method.

+
+

Parameters

+
+++++ + + + + + + + + + + + + + + + + + + + + + + + + + + + +

setting

the NMSetting8021x

 

value

when scheme +is set to either NM_SETTING_802_1X_CK_SCHEME_PATH +or NM_SETTING_802_1X_CK_SCHEME_BLOB, pass the path of the client +certificate file (PEM, DER, or PKCS#12 format). The path must be UTF-8 +encoded; use g_filename_to_utf8() to convert if needed. Passing NULL with +any scheme +clears the client certificate.

 

scheme

desired storage scheme for the certificate

 

out_format

on successful return, the type of the certificate added

 

error

on unsuccessful return, an error

 
+
+
+

Returns

+

TRUE if the operation succeeded, FALSE if it was unsuccessful

+
+
+
+
+

nm_setting_802_1x_get_client_cert_password ()

+
const char *
+nm_setting_802_1x_get_client_cert_password
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the password used to access the client certificate stored in +“client-cert” property. Only makes sense if the certificate +is stored on a PKCS#11 token that requires a login.

+
+

Since: 1.8

+
+
+
+

nm_setting_802_1x_get_client_cert_password_flags ()

+
NMSettingSecretFlags
+nm_setting_802_1x_get_client_cert_password_flags
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the NMSettingSecretFlags pertaining to the +“client-cert-password”

+
+

Since: 1.8

+
+
+
+

nm_setting_802_1x_get_phase1_peapver ()

+
const char *
+nm_setting_802_1x_get_phase1_peapver (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the "phase 1" PEAP version to be used when authenticating with +EAP-PEAP as contained in the “phase1-peapver” property. Valid +values are NULL (unset), "0" (PEAP version 0), and "1" (PEAP version 1).

+
+
+
+
+

nm_setting_802_1x_get_phase1_peaplabel ()

+
const char *
+nm_setting_802_1x_get_phase1_peaplabel
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

whether the "phase 1" PEAP label is new-style or old-style, to be +used when authenticating with EAP-PEAP, as contained in the +“phase1-peaplabel” property. Valid values are NULL (unset), +"0" (use old-style label), and "1" (use new-style label). See the +wpa_supplicant documentation for more details.

+
+
+
+
+

nm_setting_802_1x_get_phase1_fast_provisioning ()

+
const char *
+nm_setting_802_1x_get_phase1_fast_provisioning
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

whether "phase 1" PEAP fast provisioning should be used, as specified +by the “phase1-fast-provisioning” property. See the +wpa_supplicant documentation for more details.

+
+
+
+
+

nm_setting_802_1x_get_phase2_auth ()

+
const char *
+nm_setting_802_1x_get_phase2_auth (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the "phase 2" non-EAP (ex MD5) allowed authentication method as +specified by the “phase2-auth” property.

+
+
+
+
+

nm_setting_802_1x_get_phase2_autheap ()

+
const char *
+nm_setting_802_1x_get_phase2_autheap (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the "phase 2" EAP-based (ex TLS) allowed authentication method as +specified by the “phase2-autheap” property.

+
+
+
+
+

nm_setting_802_1x_get_phase2_ca_cert_scheme ()

+
NMSetting8021xCKScheme
+nm_setting_802_1x_get_phase2_ca_cert_scheme
+                               (NMSetting8021x *setting);
+

Returns the scheme used to store the "phase 2" CA certificate. If the +returned scheme is NM_SETTING_802_1X_CK_SCHEME_BLOB, use +nm_setting_802_1x_get_ca_cert_blob(); if NM_SETTING_802_1X_CK_SCHEME_PATH, +use nm_setting_802_1x_get_ca_cert_path(); if NM_SETTING_802_1X_CK_SCHEME_PKCS11, +use nm_setting_802_1x_get_ca_cert_uri().

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

scheme used to store the "phase 2" CA certificate (blob or path)

+
+
+
+
+

nm_setting_802_1x_get_phase2_ca_cert_blob ()

+
GBytes *
+nm_setting_802_1x_get_phase2_ca_cert_blob
+                               (NMSetting8021x *setting);
+

Returns the "phase 2" CA certificate blob if the CA certificate is stored +using the NM_SETTING_802_1X_CK_SCHEME_BLOB scheme. Not all EAP methods use +a CA certificate (LEAP for example), and those that can take advantage of the +CA certificate allow it to be unset. Note that lack of a CA certificate +reduces security by allowing man-in-the-middle attacks, because the identity +of the network cannot be confirmed by the client.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the "phase 2" CA certificate data.

+

[transfer none]

+
+
+
+
+

nm_setting_802_1x_get_phase2_ca_cert_path ()

+
const char *
+nm_setting_802_1x_get_phase2_ca_cert_path
+                               (NMSetting8021x *setting);
+

Returns the "phase 2" CA certificate path if the CA certificate is stored +using the NM_SETTING_802_1X_CK_SCHEME_PATH scheme. Not all EAP methods use +a CA certificate (LEAP for example), and those that can take advantage of the +CA certificate allow it to be unset. Note that lack of a CA certificate +reduces security by allowing man-in-the-middle attacks, because the identity +of the network cannot be confirmed by the client.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

path to the "phase 2" CA certificate file

+
+
+
+
+

nm_setting_802_1x_get_phase2_ca_cert_uri ()

+
const char *
+nm_setting_802_1x_get_phase2_ca_cert_uri
+                               (NMSetting8021x *setting);
+

Returns the "phase 2" CA certificate URI analogously to +nm_setting_802_1x_get_phase2_ca_cert_blob() and +nm_setting_802_1x_get_phase2_ca_cert_path().

+

Currently, it's limited to PKCS#11 URIs ('pkcs11' scheme as defined by RFC +7512), but may be extended to other schemes in future (such as 'file' URIs +for local files and 'data' URIs for inline certificate data).

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the URI string

+
+

Since: 1.6

+
+
+
+

nm_setting_802_1x_set_phase2_ca_cert ()

+
gboolean
+nm_setting_802_1x_set_phase2_ca_cert (NMSetting8021x *setting,
+                                      const char *value,
+                                      NMSetting8021xCKScheme scheme,
+                                      NMSetting8021xCKFormat *out_format,
+                                      GError **error);
+

Reads a certificate from disk and sets the “phase2-ca-cert” +property with the raw certificate data if using the +NM_SETTING_802_1X_CK_SCHEME_BLOB scheme, or with the path to the certificate +file if using the NM_SETTING_802_1X_CK_SCHEME_PATH scheme.

+
+

Parameters

+
+++++ + + + + + + + + + + + + + + + + + + + + + + + + + + + +

setting

the NMSetting8021x

 

value

when scheme +is set to either NM_SETTING_802_1X_CK_SCHEME_PATH +or NM_SETTING_802_1X_CK_SCHEME_BLOB, pass the path of the "phase2" CA +certificate file (PEM or DER format). The path must be UTF-8 encoded; use +g_filename_to_utf8() to convert if needed. Passing NULL with any scheme +clears the "phase2" CA certificate.

 

scheme

desired storage scheme for the certificate

 

out_format

on successful return, the type of the certificate added

 

error

on unsuccessful return, an error

 
+
+
+

Returns

+

TRUE if the operation succeeded, FALSE if it was unsuccessful

+
+
+
+
+

nm_setting_802_1x_get_phase2_ca_cert_password ()

+
const char *
+nm_setting_802_1x_get_phase2_ca_cert_password
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the password used to access the "phase2" CA certificate stored in +“phase2-ca-cert” property. Only makes sense if the certificate +is stored on a PKCS#11 token that requires a login.

+
+

Since: 1.8

+
+
+
+

nm_setting_802_1x_get_phase2_ca_cert_password_flags ()

+
NMSettingSecretFlags
+nm_setting_802_1x_get_phase2_ca_cert_password_flags
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the NMSettingSecretFlags pertaining to the +“phase2-private-key-password”

+
+

Since: 1.8

+
+
+
+

nm_setting_802_1x_get_phase2_subject_match ()

+
const char *
+nm_setting_802_1x_get_phase2_subject_match
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the “phase2-subject-match” property. This is +the substring to be matched against the subject of the "phase 2" +authentication server certificate, or NULL no subject verification +is to be performed.

+
+
+
+
+

nm_setting_802_1x_get_num_phase2_altsubject_matches ()

+
guint32
+nm_setting_802_1x_get_num_phase2_altsubject_matches
+                               (NMSetting8021x *setting);
+

Returns the number of entries in the +“phase2-altsubject-matches” property of this setting.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the number of phase2-altsubject-matches entries.

+
+
+
+
+

nm_setting_802_1x_get_phase2_altsubject_match ()

+
const char *
+nm_setting_802_1x_get_phase2_altsubject_match
+                               (NMSetting8021x *setting,
+                                guint32 i);
+

Returns the "phase 2" altSubjectName match at index i +.

+
+

Parameters

+
+++++ + + + + + + + + + + + + +

setting

the NMSettingConnection

 

i

the zero-based index of the array of "phase 2" altSubjectName matches

 
+
+
+

Returns

+

the "phase 2" altSubjectName match at index i +

+
+
+
+
+

nm_setting_802_1x_add_phase2_altsubject_match ()

+
gboolean
+nm_setting_802_1x_add_phase2_altsubject_match
+                               (NMSetting8021x *setting,
+                                const char *phase2_altsubject_match);
+

Adds an allowed alternate subject name match for "phase 2". Until +at least one match is added, the altSubjectName of the "phase 2" +remote authentication server is not verified.

+
+

Parameters

+
+++++ + + + + + + + + + + + + +

setting

the NMSetting8021x

 

phase2_altsubject_match

the "phase 2" altSubjectName to allow for this +connection

 
+
+
+

Returns

+

TRUE if the "phase 2" alternative subject name match was +successfully added, FALSE if it was already allowed.

+
+
+
+
+

nm_setting_802_1x_remove_phase2_altsubject_match ()

+
void
+nm_setting_802_1x_remove_phase2_altsubject_match
+                               (NMSetting8021x *setting,
+                                guint32 i);
+

Removes the allowed "phase 2" altSubjectName at the specified index.

+
+

Parameters

+
+++++ + + + + + + + + + + + + +

setting

the NMSetting8021x

 

i

the index of the "phase 2" altSubjectName match to remove

 
+
+
+
+
+

nm_setting_802_1x_remove_phase2_altsubject_match_by_value ()

+
gboolean
+nm_setting_802_1x_remove_phase2_altsubject_match_by_value
+                               (NMSetting8021x *setting,
+                                const char *phase2_altsubject_match);
+

Removes the allowed "phase 2" altSubjectName phase2_altsubject_match +.

+
+

Parameters

+
+++++ + + + + + + + + + + + + +

setting

the NMSetting8021x

 

phase2_altsubject_match

the "phase 2" altSubjectName to remove

 
+
+
+

Returns

+

TRUE if the alternative subject name match for "phase 2" was found and removed, +FALSE if it was not.

+
+
+
+
+

nm_setting_802_1x_clear_phase2_altsubject_matches ()

+
void
+nm_setting_802_1x_clear_phase2_altsubject_matches
+                               (NMSetting8021x *setting);
+

Clears all "phase 2" altSubjectName matches.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+
+
+

nm_setting_802_1x_get_phase2_domain_suffix_match ()

+
const char *
+nm_setting_802_1x_get_phase2_domain_suffix_match
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the “phase2-domain-suffix-match” property.

+
+

Since: 1.2

+
+
+
+

nm_setting_802_1x_get_phase2_domain_match ()

+
const char *
+nm_setting_802_1x_get_phase2_domain_match
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the “phase2-domain-match” property.

+
+

Since: 1.24

+
+
+
+

nm_setting_802_1x_get_phase2_client_cert_scheme ()

+
NMSetting8021xCKScheme
+nm_setting_802_1x_get_phase2_client_cert_scheme
+                               (NMSetting8021x *setting);
+

Returns the scheme used to store the "phase 2" client certificate. If the +returned scheme is NM_SETTING_802_1X_CK_SCHEME_BLOB, use +nm_setting_802_1x_get_client_cert_blob(); if +NM_SETTING_802_1X_CK_SCHEME_PATH, use +nm_setting_802_1x_get_client_cert_path(); if +NM_SETTING_802_1X_CK_SCHEME_PKCS11, use +nm_setting_802_1x_get_client_cert_uri().

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

scheme used to store the "phase 2" client certificate (blob or path)

+
+
+
+
+

nm_setting_802_1x_get_phase2_client_cert_blob ()

+
GBytes *
+nm_setting_802_1x_get_phase2_client_cert_blob
+                               (NMSetting8021x *setting);
+

Client certificates are used to identify the connecting client to the network +when EAP-TLS is used as either the "phase 1" or "phase 2" 802.1x +authentication method.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the "phase 2" client certificate data.

+

[transfer none]

+
+
+
+
+

nm_setting_802_1x_get_phase2_client_cert_path ()

+
const char *
+nm_setting_802_1x_get_phase2_client_cert_path
+                               (NMSetting8021x *setting);
+

Client certificates are used to identify the connecting client to the network +when EAP-TLS is used as either the "phase 1" or "phase 2" 802.1x +authentication method.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

path to the "phase 2" client certificate file

+
+
+
+
+

nm_setting_802_1x_get_phase2_client_cert_uri ()

+
const char *
+nm_setting_802_1x_get_phase2_client_cert_uri
+                               (NMSetting8021x *setting);
+

Returns the "phase 2" client certificate URI analogously to +nm_setting_802_1x_get_phase2_ca_cert_blob() and +nm_setting_802_1x_get_phase2_ca_cert_path().

+

Currently, it's limited to PKCS#11 URIs ('pkcs11' scheme as defined by RFC +7512), but may be extended to other schemes in future (such as 'file' URIs +for local files and 'data' URIs for inline certificate data).

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the URI string

+
+

Since: 1.6

+
+
+
+

nm_setting_802_1x_set_phase2_client_cert ()

+
gboolean
+nm_setting_802_1x_set_phase2_client_cert
+                               (NMSetting8021x *setting,
+                                const char *value,
+                                NMSetting8021xCKScheme scheme,
+                                NMSetting8021xCKFormat *out_format,
+                                GError **error);
+

Reads a certificate from disk and sets the “phase2-client-cert” +property with the raw certificate data if using the +NM_SETTING_802_1X_CK_SCHEME_BLOB scheme, or with the path to the certificate +file if using the NM_SETTING_802_1X_CK_SCHEME_PATH scheme.

+

Client certificates are used to identify the connecting client to the network +when EAP-TLS is used as either the "phase 1" or "phase 2" 802.1x +authentication method.

+
+

Parameters

+
+++++ + + + + + + + + + + + + + + + + + + + + + + + + + + + +

setting

the NMSetting8021x

 

value

when scheme +is set to either NM_SETTING_802_1X_CK_SCHEME_PATH +or NM_SETTING_802_1X_CK_SCHEME_BLOB, pass the path of the "phase2" client +certificate file (PEM, DER, or PKCS#12 format). The path must be UTF-8 +encoded; use g_filename_to_utf8() to convert if needed. Passing NULL with +any scheme +clears the "phase2" client certificate.

 

scheme

desired storage scheme for the certificate

 

out_format

on successful return, the type of the certificate added

 

error

on unsuccessful return, an error

 
+
+
+

Returns

+

TRUE if the operation succeeded, FALSE if it was unsuccessful

+
+
+
+
+

nm_setting_802_1x_get_phase2_client_cert_password ()

+
const char *
+nm_setting_802_1x_get_phase2_client_cert_password
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the password used to access the "phase2" client certificate stored in +“phase2-client-cert” property. Only makes sense if the certificate +is stored on a PKCS#11 token that requires a login.

+
+

Since: 1.8

+
+
+
+

nm_setting_802_1x_get_phase2_client_cert_password_flags ()

+
NMSettingSecretFlags
+nm_setting_802_1x_get_phase2_client_cert_password_flags
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the NMSettingSecretFlags pertaining to the +“phase2-client-cert-password”

+
+

Since: 1.8

+
+
+
+

nm_setting_802_1x_get_password ()

+
const char *
+nm_setting_802_1x_get_password (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the password used by the authentication method, if any, as specified +by the “password” property

+
+
+
+
+

nm_setting_802_1x_get_password_flags ()

+
NMSettingSecretFlags
+nm_setting_802_1x_get_password_flags (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the NMSettingSecretFlags pertaining to the “password”

+
+
+
+
+

nm_setting_802_1x_get_password_raw ()

+
GBytes *
+nm_setting_802_1x_get_password_raw (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the password used by the authentication method as a +UTF-8-encoded array of bytes, as specified by the +“password-raw” property.

+

[transfer none]

+
+
+
+
+

nm_setting_802_1x_get_password_raw_flags ()

+
NMSettingSecretFlags
+nm_setting_802_1x_get_password_raw_flags
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the NMSettingSecretFlags pertaining to the +“password-raw”

+
+
+
+
+

nm_setting_802_1x_get_pin ()

+
const char *
+nm_setting_802_1x_get_pin (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the PIN used by the authentication method, if any, as specified +by the “pin” property

+
+
+
+
+

nm_setting_802_1x_get_pin_flags ()

+
NMSettingSecretFlags
+nm_setting_802_1x_get_pin_flags (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the NMSettingSecretFlags pertaining to the +“pin”

+
+
+
+
+

nm_setting_802_1x_get_private_key_scheme ()

+
NMSetting8021xCKScheme
+nm_setting_802_1x_get_private_key_scheme
+                               (NMSetting8021x *setting);
+

Returns the scheme used to store the private key. If the returned scheme is +NM_SETTING_802_1X_CK_SCHEME_BLOB, use +nm_setting_802_1x_get_client_cert_blob(); if +NM_SETTING_802_1X_CK_SCHEME_PATH, use +nm_setting_802_1x_get_client_cert_path(); if +NM_SETTING_802_1X_CK_SCHEME_PKCS11, use +nm_setting_802_1x_get_client_cert_uri().

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

scheme used to store the private key (blob or path)

+
+
+
+
+

nm_setting_802_1x_get_private_key_blob ()

+
GBytes *
+nm_setting_802_1x_get_private_key_blob
+                               (NMSetting8021x *setting);
+

Private keys are used to authenticate the connecting client to the network +when EAP-TLS is used as either the "phase 1" or "phase 2" 802.1x +authentication method.

+

WARNING: the private key property is not a "secret" property, and thus +unencrypted private key data may be readable by unprivileged users. Private +keys should always be encrypted with a private key password.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the private key data.

+

[transfer none]

+
+
+
+
+

nm_setting_802_1x_get_private_key_path ()

+
const char *
+nm_setting_802_1x_get_private_key_path
+                               (NMSetting8021x *setting);
+

Private keys are used to authenticate the connecting client to the network +when EAP-TLS is used as either the "phase 1" or "phase 2" 802.1x +authentication method.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

path to the private key file

+
+
+
+
+

nm_setting_802_1x_get_private_key_uri ()

+
const char *
+nm_setting_802_1x_get_private_key_uri (NMSetting8021x *setting);
+

Returns the private key URI analogously to +nm_setting_802_1x_get_private_key_blob() and +nm_setting_802_1x_get_private_key_path().

+

Currently, it's limited to PKCS#11 URIs ('pkcs11' scheme as defined by RFC +7512), but may be extended to other schemes in future (such as 'file' URIs +for local files and 'data' URIs for inline certificate data).

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the URI string

+
+

Since: 1.6

+
+
+
+

nm_setting_802_1x_set_private_key ()

+
gboolean
+nm_setting_802_1x_set_private_key (NMSetting8021x *setting,
+                                   const char *value,
+                                   const char *password,
+                                   NMSetting8021xCKScheme scheme,
+                                   NMSetting8021xCKFormat *out_format,
+                                   GError **error);
+

Private keys are used to authenticate the connecting client to the network +when EAP-TLS is used as either the "phase 1" or "phase 2" 802.1x +authentication method.

+

This function reads a private key from disk and sets the +“private-key” property with the private key file data if using +the NM_SETTING_802_1X_CK_SCHEME_BLOB scheme, or with the path to the private +key file if using the NM_SETTING_802_1X_CK_SCHEME_PATH scheme.

+

If password + is given, this function attempts to decrypt the private key to +verify that password + is correct, and if it is, updates the +“private-key-password” property with the given password +. If +the decryption is unsuccessful, FALSE is returned, error + is set, and no +internal data is changed. If no password + is given, the private key is +assumed to be valid, no decryption is performed, and the password may be set +at a later time.

+

WARNING: the private key property is not a "secret" property, and thus +unencrypted private key data using the BLOB scheme may be readable by +unprivileged users. Private keys should always be encrypted with a private +key password to prevent unauthorized access to unencrypted private key data.

+
+

Parameters

+
+++++ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +

setting

the NMSetting8021x

 

value

when scheme +is set to either NM_SETTING_802_1X_CK_SCHEME_PATH or +NM_SETTING_802_1X_CK_SCHEME_BLOB, pass the path of the private key file +(PEM, DER, or PKCS#12 format). The path must be UTF-8 encoded; use +g_filename_to_utf8() to convert if needed. Passing NULL with any scheme +clears the private key.

 

password

password used to decrypt the private key, or NULL if the password +is unknown. If the password is given but fails to decrypt the private key, +an error is returned.

 

scheme

desired storage scheme for the private key

 

out_format

on successful return, the type of the private key added

 

error

on unsuccessful return, an error

 
+
+
+

Returns

+

TRUE if the operation succeeded, FALSE if it was unsuccessful

+
+
+
+
+

nm_setting_802_1x_get_private_key_password ()

+
const char *
+nm_setting_802_1x_get_private_key_password
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the private key password used to decrypt the private key if +previously set with nm_setting_802_1x_set_private_key(), or the +“private-key-password” property.

+
+
+
+
+

nm_setting_802_1x_get_private_key_password_flags ()

+
NMSettingSecretFlags
+nm_setting_802_1x_get_private_key_password_flags
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the NMSettingSecretFlags pertaining to the +“private-key-password”

+
+
+
+
+

nm_setting_802_1x_get_private_key_format ()

+
NMSetting8021xCKFormat
+nm_setting_802_1x_get_private_key_format
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the data format of the private key data stored in the +“private-key” property

+
+
+
+
+

nm_setting_802_1x_get_phase2_private_key_scheme ()

+
NMSetting8021xCKScheme
+nm_setting_802_1x_get_phase2_private_key_scheme
+                               (NMSetting8021x *setting);
+

Returns the scheme used to store the "phase 2" private key. If the returned +scheme is NM_SETTING_802_1X_CK_SCHEME_BLOB, use +nm_setting_802_1x_get_client_cert_blob(); if +NM_SETTING_802_1X_CK_SCHEME_PATH, use +nm_setting_802_1x_get_client_cert_path(); if +NM_SETTING_802_1X_CK_SCHEME_PKCS11, use +nm_setting_802_1x_get_client_cert_uri().

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

scheme used to store the "phase 2" private key (blob or path)

+
+
+
+
+

nm_setting_802_1x_get_phase2_private_key_blob ()

+
GBytes *
+nm_setting_802_1x_get_phase2_private_key_blob
+                               (NMSetting8021x *setting);
+

Private keys are used to authenticate the connecting client to the network +when EAP-TLS is used as either the "phase 1" or "phase 2" 802.1x +authentication method.

+

WARNING: the phase2 private key property is not a "secret" property, and thus +unencrypted private key data may be readable by unprivileged users. Private +keys should always be encrypted with a private key password.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the "phase 2" private key data.

+

[transfer none]

+
+
+
+
+

nm_setting_802_1x_get_phase2_private_key_path ()

+
const char *
+nm_setting_802_1x_get_phase2_private_key_path
+                               (NMSetting8021x *setting);
+

Private keys are used to authenticate the connecting client to the network +when EAP-TLS is used as either the "phase 1" or "phase 2" 802.1x +authentication method.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

path to the "phase 2" private key file

+
+
+
+
+

nm_setting_802_1x_get_phase2_private_key_uri ()

+
const char *
+nm_setting_802_1x_get_phase2_private_key_uri
+                               (NMSetting8021x *setting);
+

Returns the "phase 2" private key URI analogously to +nm_setting_802_1x_get_phase2_private_key_blob() and +nm_setting_802_1x_get_phase2_private_key_path().

+

Currently, it's limited to PKCS#11 URIs ('pkcs11' scheme as defined by RFC +7512), but may be extended to other schemes in future (such as 'file' URIs +for local files and 'data' URIs for inline certificate data).

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the URI string

+
+

Since: 1.6

+
+
+
+

nm_setting_802_1x_set_phase2_private_key ()

+
gboolean
+nm_setting_802_1x_set_phase2_private_key
+                               (NMSetting8021x *setting,
+                                const char *value,
+                                const char *password,
+                                NMSetting8021xCKScheme scheme,
+                                NMSetting8021xCKFormat *out_format,
+                                GError **error);
+

Private keys are used to authenticate the connecting client to the network +when EAP-TLS is used as either the "phase 1" or "phase 2" 802.1x +authentication method.

+

This function reads a private key from disk and sets the +“phase2-private-key” property with the private key file data if +using the NM_SETTING_802_1X_CK_SCHEME_BLOB scheme, or with the path to the +private key file if using the NM_SETTING_802_1X_CK_SCHEME_PATH scheme.

+

If password + is given, this function attempts to decrypt the private key to +verify that password + is correct, and if it is, updates the +“phase2-private-key-password” property with the given +password +. If the decryption is unsuccessful, FALSE is returned, error + is +set, and no internal data is changed. If no password + is given, the private +key is assumed to be valid, no decryption is performed, and the password may +be set at a later time.

+

WARNING: the "phase2" private key property is not a "secret" property, and +thus unencrypted private key data using the BLOB scheme may be readable by +unprivileged users. Private keys should always be encrypted with a private +key password to prevent unauthorized access to unencrypted private key data.

+
+

Parameters

+
+++++ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +

setting

the NMSetting8021x

 

value

when scheme +is set to either NM_SETTING_802_1X_CK_SCHEME_PATH or +NM_SETTING_802_1X_CK_SCHEME_BLOB, pass the path of the "phase2" private +key file (PEM, DER, or PKCS#12 format). The path must be UTF-8 encoded; +use g_filename_to_utf8() to convert if needed. Passing NULL with any +scheme +clears the private key.

 

password

password used to decrypt the private key, or NULL if the password +is unknown. If the password is given but fails to decrypt the private key, +an error is returned.

 

scheme

desired storage scheme for the private key

 

out_format

on successful return, the type of the private key added

 

error

on unsuccessful return, an error

 
+
+
+

Returns

+

TRUE if the operation succeeded, FALSE if it was unsuccessful

+
+
+
+
+

nm_setting_802_1x_get_phase2_private_key_password ()

+
const char *
+nm_setting_802_1x_get_phase2_private_key_password
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the private key password used to decrypt the private key if +previously set with nm_setting_802_1x_set_phase2_private_key() or the +“phase2-private-key-password” property.

+
+
+
+
+

nm_setting_802_1x_get_phase2_private_key_password_flags ()

+
NMSettingSecretFlags
+nm_setting_802_1x_get_phase2_private_key_password_flags
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the NMSettingSecretFlags pertaining to the +“phase2-private-key-password”

+
+
+
+
+

nm_setting_802_1x_get_phase2_private_key_format ()

+
NMSetting8021xCKFormat
+nm_setting_802_1x_get_phase2_private_key_format
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the data format of the "phase 2" private key data stored in the +“phase2-private-key” property

+
+
+
+
+

nm_setting_802_1x_get_phase1_auth_flags ()

+
NMSetting8021xAuthFlags
+nm_setting_802_1x_get_phase1_auth_flags
+                               (NMSetting8021x *setting);
+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the authentication flags for "phase 1".

+
+

Since: 1.8

+
+
+
+

nm_setting_802_1x_get_auth_timeout ()

+
int
+nm_setting_802_1x_get_auth_timeout (NMSetting8021x *setting);
+

Returns the value contained in the “auth-timeout” property.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

the configured authentication timeout in seconds. Zero means the +global default value.

+
+

Since: 1.8

+
+
+
+

nm_setting_802_1x_get_optional ()

+
gboolean
+nm_setting_802_1x_get_optional (NMSetting8021x *setting);
+

Returns the value contained in the “optional” property.

+
+

Parameters

+
+++++ + + + + + +

setting

the NMSetting8021x

 
+
+
+

Returns

+

TRUE if the activation should proceed even when the 802.1X +authentication fails; FALSE otherwise

+
+

Since: 1.22

+
+
+
+

Types and Values

+
+

NM_SETTING_802_1X_CERT_SCHEME_PREFIX_PATH

+
#define NM_SETTING_802_1X_CERT_SCHEME_PREFIX_PATH   "file://"
+
+
+
+
+

NM_SETTING_802_1X_CERT_SCHEME_PREFIX_PKCS11

+
#define NM_SETTING_802_1X_CERT_SCHEME_PREFIX_PKCS11 "pkcs11:"
+
+
+
+
+

enum NMSetting8021xCKFormat

+

NMSetting8021xCKFormat values indicate the general type of a certificate +or private key

+
+

Members

+
+++++ + + + + + + + + + + + + + + + + + + + + + + +

NM_SETTING_802_1X_CK_FORMAT_UNKNOWN

+

unknown file format

+
 

NM_SETTING_802_1X_CK_FORMAT_X509

+

file contains an X.509 format certificate

+
 

NM_SETTING_802_1X_CK_FORMAT_RAW_KEY

+

file contains an old-style OpenSSL PEM +or DER private key

+
 

NM_SETTING_802_1X_CK_FORMAT_PKCS12

+

file contains a PKCS#12 certificate +and private key

+
 
+
+
+
+
+

enum NMSetting8021xCKScheme

+

NMSetting8021xCKScheme values indicate how a certificate or private key is +stored in the setting properties, either as a blob of the item's data, or as +a path to a certificate or private key file on the filesystem

+
+

Members

+
+++++ + + + + + + + + + + + + + + + + + + + + + + +

NM_SETTING_802_1X_CK_SCHEME_UNKNOWN

+

unknown certificate or private key +scheme

+
 

NM_SETTING_802_1X_CK_SCHEME_BLOB

+

certificate or key is stored as the raw +item data

+
 

NM_SETTING_802_1X_CK_SCHEME_PATH

+

certificate or key is stored as a path +to a file containing the certificate or key data

+
 

NM_SETTING_802_1X_CK_SCHEME_PKCS11

+

certificate or key is stored as a +URI of an object on a PKCS11 token

+
 
+
+
+
+
+

enum NMSetting8021xAuthFlags

+

NMSetting8021xAuthFlags values indicate which authentication settings +should be used.

+

Before 1.22, this was wrongly marked as a enum and not as a flags +type.

+
+

Members

+
+++++ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +

NM_SETTING_802_1X_AUTH_FLAGS_NONE

+

No flags

+
 

NM_SETTING_802_1X_AUTH_FLAGS_TLS_1_0_DISABLE

+

Disable TLSv1.0

+
 

NM_SETTING_802_1X_AUTH_FLAGS_TLS_1_1_DISABLE

+

Disable TLSv1.1

+
 

NM_SETTING_802_1X_AUTH_FLAGS_TLS_1_2_DISABLE

+

Disable TLSv1.2

+
 

NM_SETTING_802_1X_AUTH_FLAGS_TLS_DISABLE_TIME_CHECKS

+

Disable TLS time checks. Since 1.42.

+
 

NM_SETTING_802_1X_AUTH_FLAGS_TLS_1_3_DISABLE

+

Disable TLSv1.3. Since 1.42.

+
 

NM_SETTING_802_1X_AUTH_FLAGS_TLS_1_0_ENABLE

+

Enable TLSv1.0. Since 1.42.

+
 

NM_SETTING_802_1X_AUTH_FLAGS_TLS_1_1_ENABLE

+

Enable TLSv1.1. Since 1.42.

+
 

NM_SETTING_802_1X_AUTH_FLAGS_TLS_1_2_ENABLE

+

Enable TLSv1.2. Since 1.42.

+
 

NM_SETTING_802_1X_AUTH_FLAGS_TLS_1_3_ENABLE

+

Enable TLSv1.3. Since 1.42.

+
 

NM_SETTING_802_1X_AUTH_FLAGS_ALL

+

All supported flags

+
 
+
+

Since: 1.8

+
+
+
+

NM_SETTING_802_1X_SETTING_NAME

+
#define NM_SETTING_802_1X_SETTING_NAME "802-1x"
+
+
+
+
+

NM_SETTING_802_1X_EAP

+
#define NM_SETTING_802_1X_EAP                               "eap"
+
+
+
+
+

NM_SETTING_802_1X_IDENTITY

+
#define NM_SETTING_802_1X_IDENTITY                          "identity"
+
+
+
+
+

NM_SETTING_802_1X_ANONYMOUS_IDENTITY

+
#define NM_SETTING_802_1X_ANONYMOUS_IDENTITY                "anonymous-identity"
+
+
+
+
+

NM_SETTING_802_1X_PAC_FILE

+
#define NM_SETTING_802_1X_PAC_FILE                          "pac-file"
+
+
+
+
+

NM_SETTING_802_1X_CA_CERT

+
#define NM_SETTING_802_1X_CA_CERT                           "ca-cert"
+
+
+
+
+

NM_SETTING_802_1X_CA_CERT_PASSWORD

+
#define NM_SETTING_802_1X_CA_CERT_PASSWORD                  "ca-cert-password"
+
+
+
+
+

NM_SETTING_802_1X_CA_CERT_PASSWORD_FLAGS

+
#define NM_SETTING_802_1X_CA_CERT_PASSWORD_FLAGS            "ca-cert-password-flags"
+
+
+
+
+

NM_SETTING_802_1X_CA_PATH

+
#define NM_SETTING_802_1X_CA_PATH                           "ca-path"
+
+
+
+
+

NM_SETTING_802_1X_SUBJECT_MATCH

+
#define NM_SETTING_802_1X_SUBJECT_MATCH                     "subject-match"
+
+
+
+
+

NM_SETTING_802_1X_ALTSUBJECT_MATCHES

+
#define NM_SETTING_802_1X_ALTSUBJECT_MATCHES                "altsubject-matches"
+
+
+
+
+

NM_SETTING_802_1X_DOMAIN_SUFFIX_MATCH

+
#define NM_SETTING_802_1X_DOMAIN_SUFFIX_MATCH               "domain-suffix-match"
+
+
+
+
+

NM_SETTING_802_1X_DOMAIN_MATCH

+
#define NM_SETTING_802_1X_DOMAIN_MATCH                      "domain-match"
+
+
+
+
+

NM_SETTING_802_1X_CLIENT_CERT

+
#define NM_SETTING_802_1X_CLIENT_CERT                       "client-cert"
+
+
+
+
+

NM_SETTING_802_1X_CLIENT_CERT_PASSWORD

+
#define NM_SETTING_802_1X_CLIENT_CERT_PASSWORD              "client-cert-password"
+
+
+
+
+

NM_SETTING_802_1X_CLIENT_CERT_PASSWORD_FLAGS

+
#define NM_SETTING_802_1X_CLIENT_CERT_PASSWORD_FLAGS        "client-cert-password-flags"
+
+
+
+
+

NM_SETTING_802_1X_PHASE1_PEAPVER

+
#define NM_SETTING_802_1X_PHASE1_PEAPVER                    "phase1-peapver"
+
+
+
+
+

NM_SETTING_802_1X_PHASE1_PEAPLABEL

+
#define NM_SETTING_802_1X_PHASE1_PEAPLABEL                  "phase1-peaplabel"
+
+
+
+
+

NM_SETTING_802_1X_PHASE1_FAST_PROVISIONING

+
#define NM_SETTING_802_1X_PHASE1_FAST_PROVISIONING          "phase1-fast-provisioning"
+
+
+
+
+

NM_SETTING_802_1X_PHASE1_AUTH_FLAGS

+
#define NM_SETTING_802_1X_PHASE1_AUTH_FLAGS                 "phase1-auth-flags"
+
+
+
+
+

NM_SETTING_802_1X_PHASE2_AUTH

+
#define NM_SETTING_802_1X_PHASE2_AUTH                       "phase2-auth"
+
+
+
+
+

NM_SETTING_802_1X_PHASE2_AUTHEAP

+
#define NM_SETTING_802_1X_PHASE2_AUTHEAP                    "phase2-autheap"
+
+
+
+
+

NM_SETTING_802_1X_PHASE2_CA_CERT

+
#define NM_SETTING_802_1X_PHASE2_CA_CERT                    "phase2-ca-cert"
+
+
+
+
+

NM_SETTING_802_1X_PHASE2_CA_CERT_PASSWORD

+
#define NM_SETTING_802_1X_PHASE2_CA_CERT_PASSWORD           "phase2-ca-cert-password"
+
+
+
+
+

NM_SETTING_802_1X_PHASE2_CA_CERT_PASSWORD_FLAGS

+
#define NM_SETTING_802_1X_PHASE2_CA_CERT_PASSWORD_FLAGS     "phase2-ca-cert-password-flags"
+
+
+
+
+

NM_SETTING_802_1X_PHASE2_CA_PATH

+
#define NM_SETTING_802_1X_PHASE2_CA_PATH                    "phase2-ca-path"
+
+
+
+
+

NM_SETTING_802_1X_PHASE2_SUBJECT_MATCH

+
#define NM_SETTING_802_1X_PHASE2_SUBJECT_MATCH              "phase2-subject-match"
+
+
+
+
+

NM_SETTING_802_1X_PHASE2_ALTSUBJECT_MATCHES

+
#define NM_SETTING_802_1X_PHASE2_ALTSUBJECT_MATCHES         "phase2-altsubject-matches"
+
+
+
+
+

NM_SETTING_802_1X_PHASE2_DOMAIN_SUFFIX_MATCH

+
#define NM_SETTING_802_1X_PHASE2_DOMAIN_SUFFIX_MATCH        "phase2-domain-suffix-match"
+
+
+
+
+

NM_SETTING_802_1X_PHASE2_DOMAIN_MATCH

+
#define NM_SETTING_802_1X_PHASE2_DOMAIN_MATCH               "phase2-domain-match"
+
+
+
+
+

NM_SETTING_802_1X_PHASE2_CLIENT_CERT

+
#define NM_SETTING_802_1X_PHASE2_CLIENT_CERT                "phase2-client-cert"
+
+
+
+
+

NM_SETTING_802_1X_PHASE2_CLIENT_CERT_PASSWORD

+
#define NM_SETTING_802_1X_PHASE2_CLIENT_CERT_PASSWORD       "phase2-client-cert-password"
+
+
+
+
+

NM_SETTING_802_1X_PHASE2_CLIENT_CERT_PASSWORD_FLAGS

+
#define NM_SETTING_802_1X_PHASE2_CLIENT_CERT_PASSWORD_FLAGS "phase2-client-cert-password-flags"
+
+
+
+
+

NM_SETTING_802_1X_PASSWORD

+
#define NM_SETTING_802_1X_PASSWORD                          "password"
+
+
+
+
+

NM_SETTING_802_1X_PASSWORD_FLAGS

+
#define NM_SETTING_802_1X_PASSWORD_FLAGS                    "password-flags"
+
+
+
+
+

NM_SETTING_802_1X_PASSWORD_RAW

+
#define NM_SETTING_802_1X_PASSWORD_RAW                      "password-raw"
+
+
+
+
+

NM_SETTING_802_1X_PASSWORD_RAW_FLAGS

+
#define NM_SETTING_802_1X_PASSWORD_RAW_FLAGS                "password-raw-flags"
+
+
+
+
+

NM_SETTING_802_1X_PRIVATE_KEY

+
#define NM_SETTING_802_1X_PRIVATE_KEY                       "private-key"
+
+
+
+
+

NM_SETTING_802_1X_PRIVATE_KEY_PASSWORD

+
#define NM_SETTING_802_1X_PRIVATE_KEY_PASSWORD              "private-key-password"
+
+
+
+
+

NM_SETTING_802_1X_PRIVATE_KEY_PASSWORD_FLAGS

+
#define NM_SETTING_802_1X_PRIVATE_KEY_PASSWORD_FLAGS        "private-key-password-flags"
+
+
+
+
+

NM_SETTING_802_1X_PHASE2_PRIVATE_KEY

+
#define NM_SETTING_802_1X_PHASE2_PRIVATE_KEY                "phase2-private-key"
+
+
+
+
+

NM_SETTING_802_1X_PHASE2_PRIVATE_KEY_PASSWORD

+
#define NM_SETTING_802_1X_PHASE2_PRIVATE_KEY_PASSWORD       "phase2-private-key-password"
+
+
+
+
+

NM_SETTING_802_1X_PHASE2_PRIVATE_KEY_PASSWORD_FLAGS

+
#define NM_SETTING_802_1X_PHASE2_PRIVATE_KEY_PASSWORD_FLAGS "phase2-private-key-password-flags"
+
+
+
+
+

NM_SETTING_802_1X_PIN

+
#define NM_SETTING_802_1X_PIN                               "pin"
+
+
+
+
+

NM_SETTING_802_1X_PIN_FLAGS

+
#define NM_SETTING_802_1X_PIN_FLAGS                         "pin-flags"
+
+
+
+
+

NM_SETTING_802_1X_SYSTEM_CA_CERTS

+
#define NM_SETTING_802_1X_SYSTEM_CA_CERTS                   "system-ca-certs"
+
+
+
+
+

NM_SETTING_802_1X_AUTH_TIMEOUT

+
#define NM_SETTING_802_1X_AUTH_TIMEOUT                      "auth-timeout"
+
+
+
+
+

NM_SETTING_802_1X_OPTIONAL

+
#define NM_SETTING_802_1X_OPTIONAL                          "optional"
+
+
+
+
+ + + \ No newline at end of file -- cgit 1.3.0-6-gf8a5