be80b21d2a
Expand the text on deprecation to be more descriptive and to refer back to openssl_user_macros(7). Incidently, this required a small change in util/find-doc-nits, to have it skip over any line that isn't part of a block (i.e. that hasn't been indented with at least one space. That makes it skip over deprecation text. Reviewed-by: Matthias St. Pierre <Matthias.St.Pierre@ncp-e.com> (Merged from https://github.com/openssl/openssl/pull/7745)
78 lines
2 KiB
Text
78 lines
2 KiB
Text
=pod
|
|
|
|
=head1 NAME
|
|
|
|
RAND_bytes, RAND_priv_bytes, RAND_pseudo_bytes - generate random data
|
|
|
|
=head1 SYNOPSIS
|
|
|
|
#include <openssl/rand.h>
|
|
|
|
int RAND_bytes(unsigned char *buf, int num);
|
|
int RAND_priv_bytes(unsigned char *buf, int num);
|
|
|
|
Deprecated since OpenSSL 1.1.0, can be hidden entirely by defining
|
|
B<OPENSSL_API_COMPAT> with a suitable version value, see
|
|
L<openssl_user_macros(7)>:
|
|
|
|
int RAND_pseudo_bytes(unsigned char *buf, int num);
|
|
|
|
=head1 DESCRIPTION
|
|
|
|
RAND_bytes() puts B<num> cryptographically strong pseudo-random bytes
|
|
into B<buf>.
|
|
|
|
RAND_priv_bytes() has the same semantics as RAND_bytes(). It is intended to
|
|
be used for generating values that should remain private. If using the
|
|
default RAND_METHOD, this function uses a separate "private" PRNG
|
|
instance so that a compromise of the "public" PRNG instance will not
|
|
affect the secrecy of these private values, as described in L<RAND(7)>
|
|
and L<RAND_DRBG(7)>.
|
|
|
|
=head1 NOTES
|
|
|
|
Always check the error return value of RAND_bytes() and
|
|
RAND_priv_bytes() and do not take randomness for granted: an error occurs
|
|
if the CSPRNG has not been seeded with enough randomness to ensure an
|
|
unpredictable byte sequence.
|
|
|
|
=head1 RETURN VALUES
|
|
|
|
RAND_bytes() and RAND_priv_bytes()
|
|
return 1 on success, -1 if not supported by the current
|
|
RAND method, or 0 on other failure. The error code can be
|
|
obtained by L<ERR_get_error(3)>.
|
|
|
|
=head1 HISTORY
|
|
|
|
=over 2
|
|
|
|
=item *
|
|
|
|
RAND_pseudo_bytes() was deprecated in OpenSSL 1.1.0; use RAND_bytes() instead.
|
|
|
|
=item *
|
|
|
|
RAND_priv_bytes() was added in OpenSSL 1.1.1.
|
|
|
|
=back
|
|
|
|
=head1 SEE ALSO
|
|
|
|
L<RAND_add(3)>,
|
|
L<RAND_bytes(3)>,
|
|
L<RAND_priv_bytes(3)>,
|
|
L<ERR_get_error(3)>,
|
|
L<RAND(7)>,
|
|
L<RAND_DRBG(7)>
|
|
|
|
=head1 COPYRIGHT
|
|
|
|
Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved.
|
|
|
|
Licensed under the OpenSSL license (the "License"). You may not use
|
|
this file except in compliance with the License. You can obtain a copy
|
|
in the file LICENSE in the source distribution or at
|
|
L<https://www.openssl.org/source/license.html>.
|
|
|
|
=cut
|