Blame lib/x509/pkcs7_int.h

Packit aea12f
/*
Packit aea12f
 * Copyright (C) 2003-2016 Free Software Foundation, Inc.
Packit aea12f
 * Copyright (C) 2016 Red Hat, Inc.
Packit aea12f
 *
Packit aea12f
 * Author: Nikos Mavrogiannopoulos
Packit aea12f
 *
Packit aea12f
 * This file is part of GnuTLS.
Packit aea12f
 *
Packit aea12f
 * The GnuTLS is free software; you can redistribute it and/or
Packit aea12f
 * modify it under the terms of the GNU Lesser General Public License
Packit aea12f
 * as published by the Free Software Foundation; either version 2.1 of
Packit aea12f
 * the License, or (at your option) any later version.
Packit aea12f
 *
Packit aea12f
 * This library is distributed in the hope that it will be useful, but
Packit aea12f
 * WITHOUT ANY WARRANTY; without even the implied warranty of
Packit aea12f
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
Packit aea12f
 * Lesser General Public License for more details.
Packit aea12f
 *
Packit aea12f
 * You should have received a copy of the GNU Lesser General Public License
Packit aea12f
 * along with this program.  If not, see <https://www.gnu.org/licenses/>
Packit aea12f
 *
Packit aea12f
 */
Packit aea12f
Packit aea12f
#ifndef GNUTLS_LIB_X509_PKCS7_INT_H
Packit aea12f
#define GNUTLS_LIB_X509_PKCS7_INT_H
Packit aea12f
Packit aea12f
#include <gnutls/x509.h>
Packit aea12f
Packit aea12f
/* PKCS #7
Packit aea12f
 */
Packit aea12f
#define DATA_OID "1.2.840.113549.1.7.1"
Packit aea12f
#define ENC_DATA_OID "1.2.840.113549.1.7.6"
Packit aea12f
Packit aea12f
#define SIGNED_DATA_OID "1.2.840.113549.1.7.2"
Packit aea12f
#define DIGESTED_DATA_OID "1.2.840.113549.1.7.5"
Packit aea12f
Packit aea12f
Packit aea12f
typedef enum schema_id {
Packit aea12f
	PBES2_GENERIC=1,	/* when the algorithm is unknown, temporal use when reading only */
Packit aea12f
	PBES2_DES,		/* the stuff in PKCS #5 */
Packit aea12f
	PBES2_3DES,
Packit aea12f
	PBES2_AES_128,
Packit aea12f
	PBES2_AES_192,
Packit aea12f
	PBES2_AES_256,
Packit aea12f
	PBES2_GOST28147_89_TC26Z,
Packit aea12f
	PBES2_GOST28147_89_CPA,
Packit aea12f
	PBES2_GOST28147_89_CPB,
Packit aea12f
	PBES2_GOST28147_89_CPC,
Packit aea12f
	PBES2_GOST28147_89_CPD,
Packit aea12f
	PKCS12_3DES_SHA1,	/* the stuff in PKCS #12 */
Packit aea12f
	PKCS12_ARCFOUR_SHA1,
Packit aea12f
	PKCS12_RC2_40_SHA1,
Packit aea12f
	PBES1_DES_MD5		/* openssl before 1.1.0 uses that by default */
Packit aea12f
} schema_id;
Packit aea12f
Packit aea12f
struct pkcs_cipher_schema_st {
Packit aea12f
	unsigned int schema;
Packit aea12f
	const char *name;
Packit aea12f
	unsigned int flag;
Packit aea12f
	unsigned int cipher;
Packit aea12f
	unsigned pbes2;
Packit aea12f
	const char *cipher_oid;
Packit aea12f
	const char *write_oid;
Packit aea12f
	const char *desc;
Packit aea12f
	const char *iv_name;
Packit aea12f
	unsigned decrypt_only;
Packit aea12f
};
Packit aea12f
Packit aea12f
const struct pkcs_cipher_schema_st *_gnutls_pkcs_schema_get(schema_id schema);
Packit aea12f
Packit aea12f
struct pbe_enc_params {
Packit aea12f
	gnutls_cipher_algorithm_t cipher;
Packit aea12f
	uint8_t iv[MAX_CIPHER_BLOCK_SIZE];
Packit aea12f
	int iv_size;
Packit aea12f
	char pbes2_oid[MAX_OID_SIZE]; /* when reading params, the OID is stored for info purposes */
Packit aea12f
};
Packit aea12f
Packit aea12f
int
Packit aea12f
_gnutls_decrypt_pbes1_des_md5_data(const char *password,
Packit aea12f
			   unsigned password_len,
Packit aea12f
			   const struct pbkdf2_params *kdf_params,
Packit aea12f
			   const struct pbe_enc_params *enc_params,
Packit Service 991b93
			   const gnutls_datum_t *encrypted_data,
Packit aea12f
			   gnutls_datum_t *decrypted_data);
Packit aea12f
Packit aea12f
int _gnutls_check_pkcs_cipher_schema(const char *oid);
Packit aea12f
Packit aea12f
int
Packit aea12f
_gnutls_pkcs_raw_decrypt_data(schema_id schema, ASN1_TYPE pkcs8_asn,
Packit aea12f
	     const char *root, const char *password,
Packit aea12f
	     const struct pbkdf2_params *kdf_params,
Packit aea12f
	     const struct pbe_enc_params *enc_params,
Packit aea12f
	     gnutls_datum_t *decrypted_data);
Packit aea12f
Packit aea12f
int
Packit aea12f
_gnutls_pkcs_raw_encrypt_data(const gnutls_datum_t * plain,
Packit aea12f
	     const struct pbe_enc_params *enc_params,
Packit Service 991b93
	     const gnutls_datum_t * key, gnutls_datum_t * encrypted);
Packit aea12f
Packit aea12f
int _gnutls_pkcs7_decrypt_data(const gnutls_datum_t * data,
Packit aea12f
			       const char *password, gnutls_datum_t * dec);
Packit aea12f
Packit aea12f
int _gnutls_read_pbkdf1_params(const uint8_t * data, int data_size,
Packit aea12f
		       struct pbkdf2_params *kdf_params,
Packit aea12f
		       struct pbe_enc_params *enc_params);
Packit aea12f
Packit aea12f
int
Packit aea12f
_gnutls_read_pkcs_schema_params(schema_id * schema, const char *password,
Packit aea12f
			const uint8_t * data, int data_size,
Packit aea12f
			struct pbkdf2_params *kdf_params,
Packit aea12f
			struct pbe_enc_params *enc_params);
Packit aea12f
Packit aea12f
int
Packit aea12f
_gnutls_pkcs_write_schema_params(schema_id schema, ASN1_TYPE pkcs8_asn,
Packit aea12f
		    const char *where,
Packit aea12f
		    const struct pbkdf2_params *kdf_params,
Packit aea12f
		    const struct pbe_enc_params *enc_params);
Packit aea12f
Packit aea12f
int
Packit aea12f
_gnutls_pkcs_generate_key(schema_id schema,
Packit aea12f
	     const char *password,
Packit aea12f
	     struct pbkdf2_params *kdf_params,
Packit aea12f
	     struct pbe_enc_params *enc_params, gnutls_datum_t * key);
Packit aea12f
Packit aea12f
int _gnutls_pkcs_flags_to_schema(unsigned int flags);
Packit aea12f
int _gnutls_pkcs7_encrypt_data(schema_id schema,
Packit aea12f
			       const gnutls_datum_t * data,
Packit aea12f
			       const char *password, gnutls_datum_t * enc);
Packit aea12f
Packit aea12f
int
Packit aea12f
_gnutls_pkcs7_data_enc_info(const gnutls_datum_t * data, const struct pkcs_cipher_schema_st **p,
Packit aea12f
	struct pbkdf2_params *kdf_params, char **oid);
Packit aea12f
Packit aea12f
#endif /* GNUTLS_LIB_X509_PKCS7_INT_H */