|
Packit |
549fdc |
/*
|
|
Packit |
549fdc |
* Copyright (C) 2003-2016 Free Software Foundation, Inc.
|
|
Packit |
549fdc |
* Copyright (C) 2016 Red Hat, Inc.
|
|
Packit |
549fdc |
*
|
|
Packit |
549fdc |
* Author: Nikos Mavrogiannopoulos
|
|
Packit |
549fdc |
*
|
|
Packit |
549fdc |
* This file is part of GnuTLS.
|
|
Packit |
549fdc |
*
|
|
Packit |
549fdc |
* The GnuTLS is free software; you can redistribute it and/or
|
|
Packit |
549fdc |
* modify it under the terms of the GNU Lesser General Public License
|
|
Packit |
549fdc |
* as published by the Free Software Foundation; either version 2.1 of
|
|
Packit |
549fdc |
* the License, or (at your option) any later version.
|
|
Packit |
549fdc |
*
|
|
Packit |
549fdc |
* This library is distributed in the hope that it will be useful, but
|
|
Packit |
549fdc |
* WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
Packit |
549fdc |
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
Packit |
549fdc |
* Lesser General Public License for more details.
|
|
Packit |
549fdc |
*
|
|
Packit |
549fdc |
* You should have received a copy of the GNU Lesser General Public License
|
|
Packit |
549fdc |
* along with this program. If not, see <http://www.gnu.org/licenses/>
|
|
Packit |
549fdc |
*
|
|
Packit |
549fdc |
*/
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
#ifndef PKCS7_INT_H
|
|
Packit |
549fdc |
#define PKCS7_INT_H
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
#include <gnutls/x509.h>
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
/* PKCS #7
|
|
Packit |
549fdc |
*/
|
|
Packit |
549fdc |
#define DATA_OID "1.2.840.113549.1.7.1"
|
|
Packit |
549fdc |
#define ENC_DATA_OID "1.2.840.113549.1.7.6"
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
#define SIGNED_DATA_OID "1.2.840.113549.1.7.2"
|
|
Packit |
549fdc |
#define DIGESTED_DATA_OID "1.2.840.113549.1.7.5"
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
typedef enum schema_id {
|
|
Packit |
549fdc |
PBES2_GENERIC=1, /* when the algorithm is unknown, temporal use when reading only */
|
|
Packit |
549fdc |
PBES2_DES, /* the stuff in PKCS #5 */
|
|
Packit |
549fdc |
PBES2_3DES,
|
|
Packit |
549fdc |
PBES2_AES_128,
|
|
Packit |
549fdc |
PBES2_AES_192,
|
|
Packit |
549fdc |
PBES2_AES_256,
|
|
Packit |
549fdc |
PKCS12_3DES_SHA1, /* the stuff in PKCS #12 */
|
|
Packit |
549fdc |
PKCS12_ARCFOUR_SHA1,
|
|
Packit |
549fdc |
PKCS12_RC2_40_SHA1,
|
|
Packit |
549fdc |
PBES1_DES_MD5 /* openssl before 1.1.0 uses that by default */
|
|
Packit |
549fdc |
} schema_id;
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
struct pkcs_cipher_schema_st {
|
|
Packit |
549fdc |
unsigned int schema;
|
|
Packit |
549fdc |
const char *name;
|
|
Packit |
549fdc |
unsigned int flag;
|
|
Packit |
549fdc |
unsigned int cipher;
|
|
Packit |
549fdc |
unsigned pbes2;
|
|
Packit |
549fdc |
const char *cipher_oid;
|
|
Packit |
549fdc |
const char *write_oid;
|
|
Packit |
549fdc |
const char *desc;
|
|
Packit |
549fdc |
unsigned decrypt_only;
|
|
Packit |
549fdc |
};
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
const struct pkcs_cipher_schema_st *_gnutls_pkcs_schema_get(schema_id schema);
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
struct pbe_enc_params {
|
|
Packit |
549fdc |
gnutls_cipher_algorithm_t cipher;
|
|
Packit |
549fdc |
uint8_t iv[MAX_CIPHER_BLOCK_SIZE];
|
|
Packit |
549fdc |
int iv_size;
|
|
Packit |
549fdc |
char pbes2_oid[MAX_OID_SIZE]; /* when reading params, the OID is stored for info purposes */
|
|
Packit |
549fdc |
};
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
int
|
|
Packit |
549fdc |
_gnutls_decrypt_pbes1_des_md5_data(const char *password,
|
|
Packit |
549fdc |
unsigned password_len,
|
|
Packit |
549fdc |
const struct pbkdf2_params *kdf_params,
|
|
Packit |
549fdc |
const struct pbe_enc_params *enc_params,
|
|
Packit |
549fdc |
gnutls_datum_t *encrypted_data, /* overwritten */
|
|
Packit |
549fdc |
gnutls_datum_t *decrypted_data);
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
int _gnutls_check_pkcs_cipher_schema(const char *oid);
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
int
|
|
Packit |
549fdc |
_gnutls_pkcs_raw_decrypt_data(schema_id schema, ASN1_TYPE pkcs8_asn,
|
|
Packit |
549fdc |
const char *root, const char *password,
|
|
Packit |
549fdc |
const struct pbkdf2_params *kdf_params,
|
|
Packit |
549fdc |
const struct pbe_enc_params *enc_params,
|
|
Packit |
549fdc |
gnutls_datum_t *decrypted_data);
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
int
|
|
Packit |
549fdc |
_gnutls_pkcs_raw_encrypt_data(const gnutls_datum_t * plain,
|
|
Packit |
549fdc |
const struct pbe_enc_params *enc_params,
|
|
Packit |
549fdc |
gnutls_datum_t * key, gnutls_datum_t * encrypted);
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
int _gnutls_pkcs7_decrypt_data(const gnutls_datum_t * data,
|
|
Packit |
549fdc |
const char *password, gnutls_datum_t * dec);
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
int _gnutls_read_pbkdf1_params(const uint8_t * data, int data_size,
|
|
Packit |
549fdc |
struct pbkdf2_params *kdf_params,
|
|
Packit |
549fdc |
struct pbe_enc_params *enc_params);
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
int
|
|
Packit |
549fdc |
_gnutls_read_pkcs_schema_params(schema_id * schema, const char *password,
|
|
Packit |
549fdc |
const uint8_t * data, int data_size,
|
|
Packit |
549fdc |
struct pbkdf2_params *kdf_params,
|
|
Packit |
549fdc |
struct pbe_enc_params *enc_params);
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
int
|
|
Packit |
549fdc |
_gnutls_pkcs_write_schema_params(schema_id schema, ASN1_TYPE pkcs8_asn,
|
|
Packit |
549fdc |
const char *where,
|
|
Packit |
549fdc |
const struct pbkdf2_params *kdf_params,
|
|
Packit |
549fdc |
const struct pbe_enc_params *enc_params);
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
int
|
|
Packit |
549fdc |
_gnutls_pkcs_generate_key(schema_id schema,
|
|
Packit |
549fdc |
const char *password,
|
|
Packit |
549fdc |
struct pbkdf2_params *kdf_params,
|
|
Packit |
549fdc |
struct pbe_enc_params *enc_params, gnutls_datum_t * key);
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
int _gnutls_pkcs_flags_to_schema(unsigned int flags);
|
|
Packit |
549fdc |
int _gnutls_pkcs7_encrypt_data(schema_id schema,
|
|
Packit |
549fdc |
const gnutls_datum_t * data,
|
|
Packit |
549fdc |
const char *password, gnutls_datum_t * enc);
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
int
|
|
Packit |
549fdc |
_gnutls_pkcs7_data_enc_info(const gnutls_datum_t * data, const struct pkcs_cipher_schema_st **p,
|
|
Packit |
549fdc |
struct pbkdf2_params *kdf_params, char **oid);
|
|
Packit |
549fdc |
|
|
Packit |
549fdc |
#endif
|