merged the modularization branch (credentials) back to trunk
This commit is contained in:
@@ -0,0 +1,19 @@
|
||||
/*
|
||||
* Copyright (C) 2007 Martin Willi
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*
|
||||
* $Id$
|
||||
*/
|
||||
|
||||
#include "private_key.h"
|
||||
|
||||
@@ -0,0 +1,143 @@
|
||||
/*
|
||||
* Copyright (C) 2007 Martin Willi
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*
|
||||
* $Id$
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup private_key private_key
|
||||
* @{ @ingroup keys
|
||||
*/
|
||||
|
||||
#ifndef PRIVATE_KEY_H_
|
||||
#define PRIVATE_KEY_H_
|
||||
|
||||
typedef struct private_key_t private_key_t;
|
||||
|
||||
#include <utils/identification.h>
|
||||
#include <credentials/keys/public_key.h>
|
||||
|
||||
/**
|
||||
* Abstract private key interface.
|
||||
*/
|
||||
struct private_key_t {
|
||||
|
||||
/**
|
||||
* Get the key type.
|
||||
*
|
||||
* @return type of the key
|
||||
*/
|
||||
key_type_t (*get_type)(private_key_t *this);
|
||||
|
||||
/**
|
||||
* Create a signature over a chunk of data.
|
||||
*
|
||||
* @param scheme signature scheme to use
|
||||
* @param data chunk of data to sign
|
||||
* @param signature where to allocate created signature
|
||||
* @return TRUE if signature created
|
||||
*/
|
||||
bool (*sign)(private_key_t *this, signature_scheme_t scheme,
|
||||
chunk_t data, chunk_t *signature);
|
||||
/**
|
||||
* Decrypt a chunk of data.
|
||||
*
|
||||
* @param crypto chunk containing encrypted data
|
||||
* @param plain where to allocate decrypted data
|
||||
* @return TRUE if data decrypted and plaintext allocated
|
||||
*/
|
||||
bool (*decrypt)(private_key_t *this, chunk_t crypto, chunk_t *plain);
|
||||
|
||||
/**
|
||||
* Get the strength of the key in bytes.
|
||||
*
|
||||
* @return strength of the key in bytes
|
||||
*/
|
||||
size_t (*get_keysize) (private_key_t *this);
|
||||
|
||||
/**
|
||||
* Get a unique key identifier, such as a hash over the public key.
|
||||
*
|
||||
* @param type type of the key ID to get
|
||||
* @return unique ID of the key as identification_t, or NULL
|
||||
*/
|
||||
identification_t* (*get_id) (private_key_t *this, id_type_t type);
|
||||
|
||||
/**
|
||||
* Get the public part from the private key.
|
||||
*
|
||||
* @return public key
|
||||
*/
|
||||
public_key_t* (*get_public_key)(private_key_t *this);
|
||||
|
||||
/**
|
||||
* Check if a private key belongs to a public key.
|
||||
*
|
||||
* @param public public key
|
||||
* @return TRUE, if keys belong together
|
||||
*/
|
||||
bool (*belongs_to) (private_key_t *this, public_key_t *public);
|
||||
|
||||
/**
|
||||
* Get an encoded form of the private key.
|
||||
*
|
||||
* @todo Do we need a encoding type specification?
|
||||
*
|
||||
* @return allocated chunk containing encoded private key
|
||||
*/
|
||||
chunk_t (*get_encoding)(private_key_t *this);
|
||||
|
||||
/**
|
||||
* Increase the refcount to this private key.
|
||||
*
|
||||
* @return this, with an increased refcount
|
||||
*/
|
||||
private_key_t* (*get_ref)(private_key_t *this);
|
||||
|
||||
/**
|
||||
* Decrease refcount, destroy private_key if no more references.
|
||||
*/
|
||||
void (*destroy)(private_key_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Read a private key from a file.
|
||||
*
|
||||
* @param type type of the key
|
||||
* @param filename filename to read key from
|
||||
* @param passphrase passphrase to decrypt an encrypted key
|
||||
* @return loaded private key, NULL if failed
|
||||
*/
|
||||
private_key_t *private_key_create_from_file(key_type_t type, char *filename,
|
||||
chunk_t passphrase);
|
||||
|
||||
/**
|
||||
* Create a private key from a chunk.
|
||||
*
|
||||
* @param type type of the key
|
||||
* @param chunk chunk to create key from
|
||||
* @return loaded private key, NULL if failed
|
||||
*/
|
||||
private_key_t *private_key_create_from_chunk(key_type_t type, chunk_t chunk);
|
||||
|
||||
/**
|
||||
* Generate a new private key.
|
||||
*
|
||||
* @param type type of the key
|
||||
* @param size key size in bytes
|
||||
* @return generated private key, NULL if failed
|
||||
*/
|
||||
private_key_t *private_key_create_generated(key_type_t type, size_t size);
|
||||
|
||||
#endif /* PRIVATE_KEY_H_ @} */
|
||||
@@ -0,0 +1,32 @@
|
||||
/*
|
||||
* Copyright (C) 2007 Martin Willi
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*
|
||||
* $Id$
|
||||
*/
|
||||
|
||||
#include "public_key.h"
|
||||
|
||||
ENUM(key_type_names, KEY_RSA, KEY_RSA,
|
||||
"RSA"
|
||||
);
|
||||
|
||||
ENUM(signature_scheme_names, SIGN_DEFAULT, SIGN_RSA_EMSA_PKCS1_SHA512,
|
||||
"DEFAULT",
|
||||
"RSA_EMSA_PKCS1_MD5",
|
||||
"RSA_EMSA_PKCS1_SHA1",
|
||||
"RSA_EMSA_PKCS1_SHA256",
|
||||
"RSA_EMSA_PKCS1_SHA384",
|
||||
"RSA_EMSA_PKCS1_SHA512",
|
||||
);
|
||||
|
||||
@@ -0,0 +1,163 @@
|
||||
/*
|
||||
* Copyright (C) 2007 Martin Willi
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*
|
||||
* $Id$
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup public_key public_key
|
||||
* @{ @ingroup keys
|
||||
*/
|
||||
|
||||
#ifndef PUBLIC_KEY_H_
|
||||
#define PUBLIC_KEY_H_
|
||||
|
||||
typedef struct public_key_t public_key_t;
|
||||
typedef enum key_type_t key_type_t;
|
||||
typedef enum key_id_type_t key_id_type_t;
|
||||
typedef enum signature_scheme_t signature_scheme_t;
|
||||
|
||||
#include <library.h>
|
||||
#include <utils/identification.h>
|
||||
|
||||
/**
|
||||
* Type of a key pair, the used crypto system
|
||||
*/
|
||||
enum key_type_t {
|
||||
/** key type wildcard */
|
||||
KEY_ANY,
|
||||
/** RSA crypto system as in PKCS#1 */
|
||||
KEY_RSA,
|
||||
/** DSS, ElGamal, ECDSA, ... */
|
||||
};
|
||||
|
||||
/**
|
||||
* Enum names for key_type_t
|
||||
*/
|
||||
extern enum_name_t *key_type_names;
|
||||
|
||||
/**
|
||||
* Signature scheme for signature creation
|
||||
*
|
||||
* EMSA-PKCS1 signatures are from the PKCS#1 standard. They include
|
||||
* the ASN1-OID of the used hash algorithm.
|
||||
*/
|
||||
enum signature_scheme_t {
|
||||
/** default scheme of that underlying crypto system */
|
||||
SIGN_DEFAULT,
|
||||
/** EMSA-PKCS1 with MD5 */
|
||||
SIGN_RSA_EMSA_PKCS1_MD5,
|
||||
/** EMSA-PKCS1 signature as in PKCS#1 standard using SHA1 as hash. */
|
||||
SIGN_RSA_EMSA_PKCS1_SHA1,
|
||||
/** EMSA-PKCS1 signature as in PKCS#1 standard using SHA256 as hash. */
|
||||
SIGN_RSA_EMSA_PKCS1_SHA256,
|
||||
/** EMSA-PKCS1 signature as in PKCS#1 standard using SHA384 as hash. */
|
||||
SIGN_RSA_EMSA_PKCS1_SHA384,
|
||||
/** EMSA-PKCS1 signature as in PKCS#1 standard using SHA512 as hash. */
|
||||
SIGN_RSA_EMSA_PKCS1_SHA512,
|
||||
};
|
||||
|
||||
/**
|
||||
* Enum names for signature_scheme_t
|
||||
*/
|
||||
extern enum_name_t *signature_scheme_names;
|
||||
|
||||
/**
|
||||
* Abstract interface of a public key.
|
||||
*/
|
||||
struct public_key_t {
|
||||
|
||||
/**
|
||||
* Get the key type.
|
||||
*
|
||||
* @return type of the key
|
||||
*/
|
||||
key_type_t (*get_type)(public_key_t *this);
|
||||
|
||||
/**
|
||||
* Verifies a signature against a chunk of data.
|
||||
*
|
||||
* @param scheme signature scheme to use for verification, may be default
|
||||
* @param data data to check signature against
|
||||
* @param signature signature to check
|
||||
* @return TRUE if signature matches
|
||||
*/
|
||||
bool (*verify)(public_key_t *this, signature_scheme_t scheme,
|
||||
chunk_t data, chunk_t signature);
|
||||
|
||||
/**
|
||||
* Encrypt a chunk of data.
|
||||
*
|
||||
* @param crypto chunk containing plaintext data
|
||||
* @param plain where to allocate encrypted data
|
||||
* @return TRUE if data successfully encrypted
|
||||
*/
|
||||
bool (*encrypt)(public_key_t *this, chunk_t crypto, chunk_t *plain);
|
||||
|
||||
/**
|
||||
* Get the strength of the key in bytes.
|
||||
*
|
||||
* @return strength of the key in bytes
|
||||
*/
|
||||
size_t (*get_keysize) (public_key_t *this);
|
||||
|
||||
/**
|
||||
* Get a unique key identifier, such as a hash over the key.
|
||||
*
|
||||
* @param type type of the key ID to get
|
||||
* @return unique ID of the key as identification_t, or NULL
|
||||
*/
|
||||
identification_t* (*get_id) (public_key_t *this, id_type_t type);
|
||||
|
||||
/**
|
||||
* Get an encoded form of the key.
|
||||
*
|
||||
* @todo Do we need a encoding type specification?
|
||||
*
|
||||
* @return allocated chunk containing encoded key
|
||||
*/
|
||||
chunk_t (*get_encoding)(public_key_t *this);
|
||||
|
||||
/**
|
||||
* Increase the refcount of the key.
|
||||
*
|
||||
* @return this with an increased refcount
|
||||
*/
|
||||
public_key_t* (*get_ref)(public_key_t *this);
|
||||
|
||||
/**
|
||||
* Destroy a public_key instance.
|
||||
*/
|
||||
void (*destroy)(public_key_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Read a public key from a file.
|
||||
*
|
||||
* @param type type of the key
|
||||
* @param filename filename to read key from
|
||||
* @return loaded public key, NULL if failed
|
||||
*/
|
||||
public_key_t *public_key_create_from_file(key_type_t type, char *filename);
|
||||
|
||||
/**
|
||||
* Create a public key from a chunk.
|
||||
*
|
||||
* @param type type of the key
|
||||
* @param chunk chunk to create key from
|
||||
* @return loaded public key, NULL if failed
|
||||
*/
|
||||
public_key_t *public_key_create_from_chunk(key_type_t type, chunk_t chunk);
|
||||
|
||||
#endif /* PUBLIC_KEY_H_ @} */
|
||||
@@ -0,0 +1,27 @@
|
||||
/*
|
||||
* Copyright (C) 2007 Martin Willi
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*
|
||||
* $Id$
|
||||
*/
|
||||
|
||||
#include "shared_key.h"
|
||||
|
||||
ENUM(shared_key_type_names, SHARED_ANY, SHARED_PIN,
|
||||
"ANY",
|
||||
"IKE",
|
||||
"EAP",
|
||||
"PRIVATE_KEY_PASS",
|
||||
"PIN",
|
||||
);
|
||||
|
||||
@@ -0,0 +1,86 @@
|
||||
/*
|
||||
* Copyright (C) 2007 Martin Willi
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup shared_key shared_key
|
||||
* @{ @ingroup keys
|
||||
*/
|
||||
|
||||
#ifndef SHARED_KEY_H_
|
||||
#define SHARED_KEY_H_
|
||||
|
||||
#include <utils/enumerator.h>
|
||||
#include <utils/identification.h>
|
||||
|
||||
typedef struct shared_key_t shared_key_t;
|
||||
typedef enum shared_key_type_t shared_key_type_t;
|
||||
|
||||
/**
|
||||
* Type of a shared key.
|
||||
*/
|
||||
enum shared_key_type_t {
|
||||
/** wildcard for all keys */
|
||||
SHARED_ANY,
|
||||
/** PSK for IKE authentication */
|
||||
SHARED_IKE,
|
||||
/** key for a EAP authentication method */
|
||||
SHARED_EAP,
|
||||
/** key to decrypt encrypted private keys */
|
||||
SHARED_PRIVATE_KEY_PASS,
|
||||
/** PIN to unlock a smartcard */
|
||||
SHARED_PIN,
|
||||
};
|
||||
|
||||
/**
|
||||
* enum names for shared_key_type_t
|
||||
*/
|
||||
extern enum_name_t *shared_key_type_names;
|
||||
|
||||
/**
|
||||
* A symmetric key shared between multiple owners.
|
||||
*
|
||||
* This class is not thread save, do not add owners while others might be
|
||||
* reading.
|
||||
*/
|
||||
struct shared_key_t {
|
||||
|
||||
/**
|
||||
* Get the kind of this key.
|
||||
*
|
||||
* @return type of the key
|
||||
*/
|
||||
shared_key_type_t (*get_type)(shared_key_t *this);
|
||||
|
||||
/**
|
||||
* Get the shared key data.
|
||||
*
|
||||
* @return chunk pointing to the internal key
|
||||
*/
|
||||
chunk_t (*get_key)(shared_key_t *this);
|
||||
|
||||
/**
|
||||
* Increase refcount of the key.
|
||||
*
|
||||
* @return this with an increased refcount
|
||||
*/
|
||||
shared_key_t* (*get_ref)(shared_key_t *this);
|
||||
|
||||
/**
|
||||
* Destroy a shared_key instance if all references are gone.
|
||||
*/
|
||||
void (*destroy)(shared_key_t *this);
|
||||
};
|
||||
|
||||
#endif /** SHARED_KEY_H_ @} */
|
||||
Reference in New Issue
Block a user