merged the modularization branch (credentials) back to trunk

This commit is contained in:
Martin Willi
2008-03-13 14:14:44 +00:00
parent 2df655134c
commit 552cc11b1f
495 changed files with 30378 additions and 23843 deletions
@@ -0,0 +1,19 @@
/*
* Copyright (C) 2007 Martin Willi
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*
* $Id$
*/
#include "private_key.h"
@@ -0,0 +1,143 @@
/*
* Copyright (C) 2007 Martin Willi
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*
* $Id$
*/
/**
* @defgroup private_key private_key
* @{ @ingroup keys
*/
#ifndef PRIVATE_KEY_H_
#define PRIVATE_KEY_H_
typedef struct private_key_t private_key_t;
#include <utils/identification.h>
#include <credentials/keys/public_key.h>
/**
* Abstract private key interface.
*/
struct private_key_t {
/**
* Get the key type.
*
* @return type of the key
*/
key_type_t (*get_type)(private_key_t *this);
/**
* Create a signature over a chunk of data.
*
* @param scheme signature scheme to use
* @param data chunk of data to sign
* @param signature where to allocate created signature
* @return TRUE if signature created
*/
bool (*sign)(private_key_t *this, signature_scheme_t scheme,
chunk_t data, chunk_t *signature);
/**
* Decrypt a chunk of data.
*
* @param crypto chunk containing encrypted data
* @param plain where to allocate decrypted data
* @return TRUE if data decrypted and plaintext allocated
*/
bool (*decrypt)(private_key_t *this, chunk_t crypto, chunk_t *plain);
/**
* Get the strength of the key in bytes.
*
* @return strength of the key in bytes
*/
size_t (*get_keysize) (private_key_t *this);
/**
* Get a unique key identifier, such as a hash over the public key.
*
* @param type type of the key ID to get
* @return unique ID of the key as identification_t, or NULL
*/
identification_t* (*get_id) (private_key_t *this, id_type_t type);
/**
* Get the public part from the private key.
*
* @return public key
*/
public_key_t* (*get_public_key)(private_key_t *this);
/**
* Check if a private key belongs to a public key.
*
* @param public public key
* @return TRUE, if keys belong together
*/
bool (*belongs_to) (private_key_t *this, public_key_t *public);
/**
* Get an encoded form of the private key.
*
* @todo Do we need a encoding type specification?
*
* @return allocated chunk containing encoded private key
*/
chunk_t (*get_encoding)(private_key_t *this);
/**
* Increase the refcount to this private key.
*
* @return this, with an increased refcount
*/
private_key_t* (*get_ref)(private_key_t *this);
/**
* Decrease refcount, destroy private_key if no more references.
*/
void (*destroy)(private_key_t *this);
};
/**
* Read a private key from a file.
*
* @param type type of the key
* @param filename filename to read key from
* @param passphrase passphrase to decrypt an encrypted key
* @return loaded private key, NULL if failed
*/
private_key_t *private_key_create_from_file(key_type_t type, char *filename,
chunk_t passphrase);
/**
* Create a private key from a chunk.
*
* @param type type of the key
* @param chunk chunk to create key from
* @return loaded private key, NULL if failed
*/
private_key_t *private_key_create_from_chunk(key_type_t type, chunk_t chunk);
/**
* Generate a new private key.
*
* @param type type of the key
* @param size key size in bytes
* @return generated private key, NULL if failed
*/
private_key_t *private_key_create_generated(key_type_t type, size_t size);
#endif /* PRIVATE_KEY_H_ @} */
@@ -0,0 +1,32 @@
/*
* Copyright (C) 2007 Martin Willi
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*
* $Id$
*/
#include "public_key.h"
ENUM(key_type_names, KEY_RSA, KEY_RSA,
"RSA"
);
ENUM(signature_scheme_names, SIGN_DEFAULT, SIGN_RSA_EMSA_PKCS1_SHA512,
"DEFAULT",
"RSA_EMSA_PKCS1_MD5",
"RSA_EMSA_PKCS1_SHA1",
"RSA_EMSA_PKCS1_SHA256",
"RSA_EMSA_PKCS1_SHA384",
"RSA_EMSA_PKCS1_SHA512",
);
@@ -0,0 +1,163 @@
/*
* Copyright (C) 2007 Martin Willi
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*
* $Id$
*/
/**
* @defgroup public_key public_key
* @{ @ingroup keys
*/
#ifndef PUBLIC_KEY_H_
#define PUBLIC_KEY_H_
typedef struct public_key_t public_key_t;
typedef enum key_type_t key_type_t;
typedef enum key_id_type_t key_id_type_t;
typedef enum signature_scheme_t signature_scheme_t;
#include <library.h>
#include <utils/identification.h>
/**
* Type of a key pair, the used crypto system
*/
enum key_type_t {
/** key type wildcard */
KEY_ANY,
/** RSA crypto system as in PKCS#1 */
KEY_RSA,
/** DSS, ElGamal, ECDSA, ... */
};
/**
* Enum names for key_type_t
*/
extern enum_name_t *key_type_names;
/**
* Signature scheme for signature creation
*
* EMSA-PKCS1 signatures are from the PKCS#1 standard. They include
* the ASN1-OID of the used hash algorithm.
*/
enum signature_scheme_t {
/** default scheme of that underlying crypto system */
SIGN_DEFAULT,
/** EMSA-PKCS1 with MD5 */
SIGN_RSA_EMSA_PKCS1_MD5,
/** EMSA-PKCS1 signature as in PKCS#1 standard using SHA1 as hash. */
SIGN_RSA_EMSA_PKCS1_SHA1,
/** EMSA-PKCS1 signature as in PKCS#1 standard using SHA256 as hash. */
SIGN_RSA_EMSA_PKCS1_SHA256,
/** EMSA-PKCS1 signature as in PKCS#1 standard using SHA384 as hash. */
SIGN_RSA_EMSA_PKCS1_SHA384,
/** EMSA-PKCS1 signature as in PKCS#1 standard using SHA512 as hash. */
SIGN_RSA_EMSA_PKCS1_SHA512,
};
/**
* Enum names for signature_scheme_t
*/
extern enum_name_t *signature_scheme_names;
/**
* Abstract interface of a public key.
*/
struct public_key_t {
/**
* Get the key type.
*
* @return type of the key
*/
key_type_t (*get_type)(public_key_t *this);
/**
* Verifies a signature against a chunk of data.
*
* @param scheme signature scheme to use for verification, may be default
* @param data data to check signature against
* @param signature signature to check
* @return TRUE if signature matches
*/
bool (*verify)(public_key_t *this, signature_scheme_t scheme,
chunk_t data, chunk_t signature);
/**
* Encrypt a chunk of data.
*
* @param crypto chunk containing plaintext data
* @param plain where to allocate encrypted data
* @return TRUE if data successfully encrypted
*/
bool (*encrypt)(public_key_t *this, chunk_t crypto, chunk_t *plain);
/**
* Get the strength of the key in bytes.
*
* @return strength of the key in bytes
*/
size_t (*get_keysize) (public_key_t *this);
/**
* Get a unique key identifier, such as a hash over the key.
*
* @param type type of the key ID to get
* @return unique ID of the key as identification_t, or NULL
*/
identification_t* (*get_id) (public_key_t *this, id_type_t type);
/**
* Get an encoded form of the key.
*
* @todo Do we need a encoding type specification?
*
* @return allocated chunk containing encoded key
*/
chunk_t (*get_encoding)(public_key_t *this);
/**
* Increase the refcount of the key.
*
* @return this with an increased refcount
*/
public_key_t* (*get_ref)(public_key_t *this);
/**
* Destroy a public_key instance.
*/
void (*destroy)(public_key_t *this);
};
/**
* Read a public key from a file.
*
* @param type type of the key
* @param filename filename to read key from
* @return loaded public key, NULL if failed
*/
public_key_t *public_key_create_from_file(key_type_t type, char *filename);
/**
* Create a public key from a chunk.
*
* @param type type of the key
* @param chunk chunk to create key from
* @return loaded public key, NULL if failed
*/
public_key_t *public_key_create_from_chunk(key_type_t type, chunk_t chunk);
#endif /* PUBLIC_KEY_H_ @} */
@@ -0,0 +1,27 @@
/*
* Copyright (C) 2007 Martin Willi
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*
* $Id$
*/
#include "shared_key.h"
ENUM(shared_key_type_names, SHARED_ANY, SHARED_PIN,
"ANY",
"IKE",
"EAP",
"PRIVATE_KEY_PASS",
"PIN",
);
@@ -0,0 +1,86 @@
/*
* Copyright (C) 2007 Martin Willi
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup shared_key shared_key
* @{ @ingroup keys
*/
#ifndef SHARED_KEY_H_
#define SHARED_KEY_H_
#include <utils/enumerator.h>
#include <utils/identification.h>
typedef struct shared_key_t shared_key_t;
typedef enum shared_key_type_t shared_key_type_t;
/**
* Type of a shared key.
*/
enum shared_key_type_t {
/** wildcard for all keys */
SHARED_ANY,
/** PSK for IKE authentication */
SHARED_IKE,
/** key for a EAP authentication method */
SHARED_EAP,
/** key to decrypt encrypted private keys */
SHARED_PRIVATE_KEY_PASS,
/** PIN to unlock a smartcard */
SHARED_PIN,
};
/**
* enum names for shared_key_type_t
*/
extern enum_name_t *shared_key_type_names;
/**
* A symmetric key shared between multiple owners.
*
* This class is not thread save, do not add owners while others might be
* reading.
*/
struct shared_key_t {
/**
* Get the kind of this key.
*
* @return type of the key
*/
shared_key_type_t (*get_type)(shared_key_t *this);
/**
* Get the shared key data.
*
* @return chunk pointing to the internal key
*/
chunk_t (*get_key)(shared_key_t *this);
/**
* Increase refcount of the key.
*
* @return this with an increased refcount
*/
shared_key_t* (*get_ref)(shared_key_t *this);
/**
* Destroy a shared_key instance if all references are gone.
*/
void (*destroy)(shared_key_t *this);
};
#endif /** SHARED_KEY_H_ @} */