|
Packit Service |
31306d |
/*
|
|
Packit Service |
31306d |
* This file is part of the SSH Library
|
|
Packit Service |
31306d |
*
|
|
Packit Service |
31306d |
* Copyright (c) 2010 by Aris Adamantiadis
|
|
Packit Service |
31306d |
*
|
|
Packit Service |
31306d |
* This library is free software; you can redistribute it and/or
|
|
Packit Service |
31306d |
* modify it under the terms of the GNU Lesser General Public
|
|
Packit Service |
31306d |
* License as published by the Free Software Foundation; either
|
|
Packit Service |
31306d |
* version 2.1 of the License, or (at your option) any later version.
|
|
Packit Service |
31306d |
*
|
|
Packit Service |
31306d |
* This library is distributed in the hope that it will be useful,
|
|
Packit Service |
31306d |
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
Packit Service |
31306d |
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
Packit Service |
31306d |
* Lesser General Public License for more details.
|
|
Packit Service |
31306d |
*
|
|
Packit Service |
31306d |
* You should have received a copy of the GNU Lesser General Public
|
|
Packit Service |
31306d |
* License along with this library; if not, write to the Free Software
|
|
Packit Service |
31306d |
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
|
|
Packit Service |
31306d |
*/
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
#ifndef PKI_H_
|
|
Packit Service |
31306d |
#define PKI_H_
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
#include "libssh/priv.h"
|
|
Packit Service |
31306d |
#ifdef HAVE_OPENSSL_EC_H
|
|
Packit Service |
31306d |
#include <openssl/ec.h>
|
|
Packit Service |
31306d |
#endif
|
|
Packit Service |
31306d |
#ifdef HAVE_OPENSSL_ECDSA_H
|
|
Packit Service |
31306d |
#include <openssl/ecdsa.h>
|
|
Packit Service |
31306d |
#endif
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
#include "libssh/crypto.h"
|
|
Packit Service |
31306d |
#ifdef HAVE_OPENSSL_ED25519
|
|
Packit Service |
31306d |
/* If using OpenSSL implementation, define the signature lenght which would be
|
|
Packit Service |
31306d |
* defined in libssh/ed25519.h otherwise */
|
|
Packit Service |
31306d |
#define ED25519_SIG_LEN 64
|
|
Packit Service |
31306d |
#else
|
|
Packit Service |
31306d |
#include "libssh/ed25519.h"
|
|
Packit Service |
31306d |
#endif
|
|
Packit Service |
31306d |
/* This definition is used for both OpenSSL and internal implementations */
|
|
Packit Service |
31306d |
#define ED25519_KEY_LEN 32
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
#define MAX_PUBKEY_SIZE 0x100000 /* 1M */
|
|
Packit Service |
31306d |
#define MAX_PRIVKEY_SIZE 0x400000 /* 4M */
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
#define SSH_KEY_FLAG_EMPTY 0x0
|
|
Packit Service |
31306d |
#define SSH_KEY_FLAG_PUBLIC 0x0001
|
|
Packit Service |
31306d |
#define SSH_KEY_FLAG_PRIVATE 0x0002
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
struct ssh_key_struct {
|
|
Packit Service |
31306d |
enum ssh_keytypes_e type;
|
|
Packit Service |
31306d |
int flags;
|
|
Packit Service |
31306d |
const char *type_c; /* Don't free it ! it is static */
|
|
Packit Service |
31306d |
int ecdsa_nid;
|
|
Packit Service |
31306d |
#if defined(HAVE_LIBGCRYPT)
|
|
Packit Service |
31306d |
gcry_sexp_t dsa;
|
|
Packit Service |
31306d |
gcry_sexp_t rsa;
|
|
Packit Service |
31306d |
gcry_sexp_t ecdsa;
|
|
Packit Service |
31306d |
#elif defined(HAVE_LIBMBEDCRYPTO)
|
|
Packit Service |
31306d |
mbedtls_pk_context *rsa;
|
|
Packit Service |
31306d |
mbedtls_ecdsa_context *ecdsa;
|
|
Packit Service |
31306d |
void *dsa;
|
|
Packit Service |
31306d |
#elif defined(HAVE_LIBCRYPTO)
|
|
Packit Service |
31306d |
DSA *dsa;
|
|
Packit Service |
31306d |
RSA *rsa;
|
|
Packit Service |
31306d |
# if defined(HAVE_OPENSSL_ECC)
|
|
Packit Service |
31306d |
EC_KEY *ecdsa;
|
|
Packit Service |
31306d |
# else
|
|
Packit Service |
31306d |
void *ecdsa;
|
|
Packit Service |
31306d |
# endif /* HAVE_OPENSSL_EC_H */
|
|
Packit Service |
31306d |
#endif /* HAVE_LIBGCRYPT */
|
|
Packit Service |
31306d |
#ifdef HAVE_OPENSSL_ED25519
|
|
Packit Service |
31306d |
uint8_t *ed25519_pubkey;
|
|
Packit Service |
31306d |
uint8_t *ed25519_privkey;
|
|
Packit Service |
31306d |
#else
|
|
Packit Service |
31306d |
ed25519_pubkey *ed25519_pubkey;
|
|
Packit Service |
31306d |
ed25519_privkey *ed25519_privkey;
|
|
Packit Service |
31306d |
#endif
|
|
Packit Service |
31306d |
void *cert;
|
|
Packit Service |
31306d |
enum ssh_keytypes_e cert_type;
|
|
Packit Service |
31306d |
};
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
struct ssh_signature_struct {
|
|
Packit Service |
31306d |
enum ssh_keytypes_e type;
|
|
Packit Service |
31306d |
enum ssh_digest_e hash_type;
|
|
Packit Service |
31306d |
const char *type_c;
|
|
Packit Service |
31306d |
#if defined(HAVE_LIBGCRYPT)
|
|
Packit Service |
31306d |
gcry_sexp_t dsa_sig;
|
|
Packit Service |
31306d |
gcry_sexp_t rsa_sig;
|
|
Packit Service |
31306d |
gcry_sexp_t ecdsa_sig;
|
|
Packit Service |
31306d |
#elif defined(HAVE_LIBMBEDCRYPTO)
|
|
Packit Service |
31306d |
ssh_string rsa_sig;
|
|
Packit Service |
31306d |
struct mbedtls_ecdsa_sig ecdsa_sig;
|
|
Packit Service |
31306d |
#endif /* HAVE_LIBGCRYPT */
|
|
Packit Service |
31306d |
#ifndef HAVE_OPENSSL_ED25519
|
|
Packit Service |
31306d |
ed25519_signature *ed25519_sig;
|
|
Packit Service |
31306d |
#endif
|
|
Packit Service |
31306d |
ssh_string raw_sig;
|
|
Packit Service |
31306d |
};
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
typedef struct ssh_signature_struct *ssh_signature;
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
/* SSH Key Functions */
|
|
Packit Service |
31306d |
ssh_key ssh_key_dup(const ssh_key key);
|
|
Packit Service |
31306d |
void ssh_key_clean (ssh_key key);
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
const char *
|
|
Packit Service |
31306d |
ssh_key_get_signature_algorithm(ssh_session session,
|
|
Packit Service |
31306d |
enum ssh_keytypes_e type);
|
|
Packit Service |
31306d |
enum ssh_keytypes_e ssh_key_type_from_signature_name(const char *name);
|
|
Packit Service |
31306d |
enum ssh_keytypes_e ssh_key_type_plain(enum ssh_keytypes_e type);
|
|
Packit Service |
31306d |
enum ssh_digest_e ssh_key_type_to_hash(ssh_session session,
|
|
Packit Service |
31306d |
enum ssh_keytypes_e type);
|
|
Packit Service |
31306d |
enum ssh_digest_e ssh_key_hash_from_name(const char *name);
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
#define is_ecdsa_key_type(t) \
|
|
Packit Service |
31306d |
((t) >= SSH_KEYTYPE_ECDSA_P256 && (t) <= SSH_KEYTYPE_ECDSA_P521)
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
#define is_cert_type(kt)\
|
|
Packit Service |
31306d |
((kt) == SSH_KEYTYPE_DSS_CERT01 ||\
|
|
Packit Service |
31306d |
(kt) == SSH_KEYTYPE_RSA_CERT01 ||\
|
|
Packit Service |
31306d |
((kt) >= SSH_KEYTYPE_ECDSA_P256_CERT01 &&\
|
|
Packit Service |
31306d |
(kt) <= SSH_KEYTYPE_ED25519_CERT01))
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
/* SSH Signature Functions */
|
|
Packit Service |
31306d |
ssh_signature ssh_signature_new(void);
|
|
Packit Service |
31306d |
void ssh_signature_free(ssh_signature sign);
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
int ssh_pki_export_signature_blob(const ssh_signature sign,
|
|
Packit Service |
31306d |
ssh_string *sign_blob);
|
|
Packit Service |
31306d |
int ssh_pki_import_signature_blob(const ssh_string sig_blob,
|
|
Packit Service |
31306d |
const ssh_key pubkey,
|
|
Packit Service |
31306d |
ssh_signature *psig);
|
|
Packit Service |
31306d |
int ssh_pki_signature_verify(ssh_session session,
|
|
Packit Service |
31306d |
ssh_signature sig,
|
|
Packit Service |
31306d |
const ssh_key key,
|
|
Packit Service |
31306d |
const unsigned char *digest,
|
|
Packit Service |
31306d |
size_t dlen);
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
/* SSH Public Key Functions */
|
|
Packit Service |
31306d |
int ssh_pki_export_pubkey_blob(const ssh_key key,
|
|
Packit Service |
31306d |
ssh_string *pblob);
|
|
Packit Service |
31306d |
int ssh_pki_import_pubkey_blob(const ssh_string key_blob,
|
|
Packit Service |
31306d |
ssh_key *pkey);
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
int ssh_pki_import_cert_blob(const ssh_string cert_blob,
|
|
Packit Service |
31306d |
ssh_key *pkey);
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
/* SSH Signing Functions */
|
|
Packit Service |
31306d |
ssh_string ssh_pki_do_sign(ssh_session session, ssh_buffer sigbuf,
|
|
Packit Service |
31306d |
const ssh_key privatekey, enum ssh_digest_e hash_type);
|
|
Packit Service |
31306d |
ssh_string ssh_pki_do_sign_agent(ssh_session session,
|
|
Packit Service |
31306d |
struct ssh_buffer_struct *buf,
|
|
Packit Service |
31306d |
const ssh_key pubkey);
|
|
Packit Service |
31306d |
ssh_string ssh_srv_pki_do_sign_sessionid(ssh_session session,
|
|
Packit Service |
31306d |
const ssh_key privkey,
|
|
Packit Service |
31306d |
const enum ssh_digest_e digest);
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
/* Temporary functions, to be removed after migration to ssh_key */
|
|
Packit Service |
31306d |
ssh_public_key ssh_pki_convert_key_to_publickey(const ssh_key key);
|
|
Packit Service |
31306d |
ssh_private_key ssh_pki_convert_key_to_privatekey(const ssh_key key);
|
|
Packit Service |
31306d |
|
|
Packit Service |
31306d |
int ssh_key_algorithm_allowed(ssh_session session, const char *type);
|
|
Packit Service |
31306d |
#endif /* PKI_H_ */
|