abstract.h 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677
  1. /*
  2. * Copyright (C) 2010-2012 Free Software Foundation, Inc.
  3. * Copyright (C) 2015-2017 Red Hat, Inc.
  4. *
  5. * Author: Nikos Mavrogiannopoulos
  6. *
  7. * This file is part of GnuTLS.
  8. *
  9. * The GnuTLS is free software; you can redistribute it and/or
  10. * modify it under the terms of the GNU Lesser General Public License
  11. * as published by the Free Software Foundation; either version 2.1 of
  12. * the License, or (at your option) any later version.
  13. *
  14. * This library is distributed in the hope that it will be useful, but
  15. * WITHOUT ANY WARRANTY; without even the implied warranty of
  16. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  17. * Lesser General Public License for more details.
  18. *
  19. * You should have received a copy of the GNU Lesser General Public License
  20. * along with this program. If not, see <http://www.gnu.org/licenses/>
  21. *
  22. */
  23. #ifndef __GNUTLS_ABSTRACT_H
  24. #define __GNUTLS_ABSTRACT_H
  25. #include <gnutls/gnutls.h>
  26. #include <gnutls/x509.h>
  27. #include <gnutls/pkcs11.h>
  28. #include <gnutls/openpgp.h>
  29. #include <gnutls/tpm.h>
  30. /* *INDENT-OFF* */
  31. #ifdef __cplusplus
  32. extern "C" {
  33. #endif
  34. /* *INDENT-ON* */
  35. /* Public key operations */
  36. #define GNUTLS_PUBKEY_VERIFY_FLAG_TLS_RSA GNUTLS_PUBKEY_VERIFY_FLAG_TLS1_RSA
  37. /**
  38. * gnutls_pubkey_flags:
  39. * @GNUTLS_PUBKEY_DISABLE_CALLBACKS: The following flag disables call to PIN callbacks. Only
  40. * relevant to TPM keys.
  41. * @GNUTLS_PUBKEY_GET_OPENPGP_FINGERPRINT: request an OPENPGP fingerprint instead of the default.
  42. *
  43. * Enumeration of different certificate import flags.
  44. */
  45. typedef enum gnutls_pubkey_flags {
  46. GNUTLS_PUBKEY_DISABLE_CALLBACKS = 1 << 2,
  47. GNUTLS_PUBKEY_GET_OPENPGP_FINGERPRINT = 1 << 3
  48. } gnutls_pubkey_flags_t;
  49. /**
  50. * gnutls_abstract_export_flags:
  51. * @GNUTLS_EXPORT_FLAG_NO_LZ: do not prepend a leading zero to exported values
  52. *
  53. * Enumeration of different certificate import flags.
  54. */
  55. typedef enum gnutls_abstract_export_flags {
  56. GNUTLS_EXPORT_FLAG_NO_LZ = 1
  57. } gnutls_abstract_export_flags_t;
  58. #define GNUTLS_PUBKEY_VERIFY_FLAG_TLS1_RSA GNUTLS_VERIFY_USE_TLS1_RSA
  59. typedef int (*gnutls_privkey_sign_func) (gnutls_privkey_t key,
  60. void *userdata,
  61. const gnutls_datum_t *raw_data,
  62. gnutls_datum_t * signature);
  63. typedef int (*gnutls_privkey_decrypt_func) (gnutls_privkey_t key,
  64. void *userdata,
  65. const gnutls_datum_t *ciphertext,
  66. gnutls_datum_t * plaintext);
  67. /* to be called to sign pre-hashed data. The input will be
  68. * the output of the hash (such as SHA256) corresponding to
  69. * the signature algorithm. The algorithm GNUTLS_SIGN_RSA_RAW
  70. * will be provided when RSA PKCS#1 DigestInfo structure is provided
  71. * as data (when this is called from a TLS 1.0 or 1.1 session).
  72. */
  73. typedef int (*gnutls_privkey_sign_hash_func) (gnutls_privkey_t key,
  74. gnutls_sign_algorithm_t algo,
  75. void *userdata,
  76. unsigned int flags,
  77. const gnutls_datum_t *hash,
  78. gnutls_datum_t * signature);
  79. /* to be called to sign data. The input data will be
  80. * the data to be signed (and hashed), with the provided
  81. * signature algorithm. This function is used for algorithms
  82. * like ed25519 which cannot take pre-hashed data as input.
  83. */
  84. typedef int (*gnutls_privkey_sign_data_func) (gnutls_privkey_t key,
  85. gnutls_sign_algorithm_t algo,
  86. void *userdata,
  87. unsigned int flags,
  88. const gnutls_datum_t *data,
  89. gnutls_datum_t * signature);
  90. typedef void (*gnutls_privkey_deinit_func) (gnutls_privkey_t key,
  91. void *userdata);
  92. #define GNUTLS_SIGN_ALGO_TO_FLAGS(sig) (unsigned int)((sig)<<20)
  93. #define GNUTLS_FLAGS_TO_SIGN_ALGO(flags) (unsigned int)((flags)>>20)
  94. /* Should return the public key algorithm (gnutls_pk_algorithm_t) */
  95. #define GNUTLS_PRIVKEY_INFO_PK_ALGO 1
  96. /* Should return the preferred signature algorithm (gnutls_sign_algorithm_t) or 0. */
  97. #define GNUTLS_PRIVKEY_INFO_SIGN_ALGO (1<<1)
  98. /* Should return true (1) or false (0) if the provided sign algorithm
  99. * (obtained with GNUTLS_FLAGS_TO_SIGN_ALGO) is supported.
  100. */
  101. #define GNUTLS_PRIVKEY_INFO_HAVE_SIGN_ALGO (1<<2)
  102. /* returns information on the public key associated with userdata */
  103. typedef int (*gnutls_privkey_info_func) (gnutls_privkey_t key, unsigned int flags, void *userdata);
  104. int gnutls_pubkey_init(gnutls_pubkey_t * key);
  105. void gnutls_pubkey_deinit(gnutls_pubkey_t key);
  106. int gnutls_pubkey_verify_params(gnutls_pubkey_t key);
  107. void gnutls_pubkey_set_pin_function(gnutls_pubkey_t key,
  108. gnutls_pin_callback_t fn,
  109. void *userdata);
  110. int gnutls_pubkey_get_pk_algorithm(gnutls_pubkey_t key,
  111. unsigned int *bits);
  112. int
  113. gnutls_pubkey_set_spki(gnutls_pubkey_t key,
  114. const gnutls_x509_spki_t spki,
  115. unsigned int flags);
  116. int
  117. gnutls_pubkey_get_spki(gnutls_pubkey_t key,
  118. const gnutls_x509_spki_t spki,
  119. unsigned int flags);
  120. int gnutls_pubkey_import_x509(gnutls_pubkey_t key,
  121. gnutls_x509_crt_t crt, unsigned int flags);
  122. int gnutls_pubkey_import_x509_crq(gnutls_pubkey_t key,
  123. gnutls_x509_crq_t crq,
  124. unsigned int flags);
  125. int gnutls_pubkey_import_pkcs11(gnutls_pubkey_t key,
  126. gnutls_pkcs11_obj_t obj,
  127. unsigned int flags);
  128. int gnutls_pubkey_import_openpgp(gnutls_pubkey_t key,
  129. gnutls_openpgp_crt_t crt,
  130. unsigned int flags);
  131. int gnutls_pubkey_import_openpgp_raw(gnutls_pubkey_t pkey,
  132. const gnutls_datum_t * data,
  133. gnutls_openpgp_crt_fmt_t
  134. format,
  135. const gnutls_openpgp_keyid_t
  136. keyid, unsigned int flags);
  137. int gnutls_pubkey_import_x509_raw(gnutls_pubkey_t pkey,
  138. const gnutls_datum_t * data,
  139. gnutls_x509_crt_fmt_t format,
  140. unsigned int flags);
  141. int
  142. gnutls_pubkey_import_privkey(gnutls_pubkey_t key,
  143. gnutls_privkey_t pkey,
  144. unsigned int usage, unsigned int flags);
  145. int
  146. gnutls_pubkey_import_tpm_url(gnutls_pubkey_t pkey,
  147. const char *url,
  148. const char *srk_password, unsigned int flags);
  149. int
  150. gnutls_pubkey_import_url(gnutls_pubkey_t key, const char *url,
  151. unsigned int flags);
  152. int
  153. gnutls_pubkey_import_tpm_raw(gnutls_pubkey_t pkey,
  154. const gnutls_datum_t * fdata,
  155. gnutls_tpmkey_fmt_t format,
  156. const char *srk_password, unsigned int flags);
  157. int gnutls_pubkey_get_preferred_hash_algorithm(gnutls_pubkey_t key,
  158. gnutls_digest_algorithm_t
  159. * hash, unsigned int *mand);
  160. #define gnutls_pubkey_get_pk_rsa_raw gnutls_pubkey_export_rsa_raw
  161. int gnutls_pubkey_export_rsa_raw(gnutls_pubkey_t key,
  162. gnutls_datum_t * m, gnutls_datum_t * e);
  163. int gnutls_pubkey_export_rsa_raw2(gnutls_pubkey_t key,
  164. gnutls_datum_t * m, gnutls_datum_t * e,
  165. unsigned flags);
  166. #define gnutls_pubkey_get_pk_dsa_raw gnutls_pubkey_export_dsa_raw
  167. int gnutls_pubkey_export_dsa_raw(gnutls_pubkey_t key,
  168. gnutls_datum_t * p,
  169. gnutls_datum_t * q,
  170. gnutls_datum_t * g, gnutls_datum_t * y);
  171. int gnutls_pubkey_export_dsa_raw2(gnutls_pubkey_t key,
  172. gnutls_datum_t * p,
  173. gnutls_datum_t * q,
  174. gnutls_datum_t * g, gnutls_datum_t * y,
  175. unsigned flags);
  176. int gnutls_pubkey_export_ecc_raw2(gnutls_pubkey_t key,
  177. gnutls_ecc_curve_t * curve,
  178. gnutls_datum_t * x, gnutls_datum_t * y,
  179. unsigned flags);
  180. #define gnutls_pubkey_get_pk_ecc_raw gnutls_pubkey_export_ecc_raw
  181. int gnutls_pubkey_export_ecc_raw(gnutls_pubkey_t key,
  182. gnutls_ecc_curve_t * curve,
  183. gnutls_datum_t * x, gnutls_datum_t * y);
  184. #define gnutls_pubkey_get_pk_ecc_x962 gnutls_pubkey_export_ecc_x962
  185. int gnutls_pubkey_export_ecc_x962(gnutls_pubkey_t key,
  186. gnutls_datum_t * parameters,
  187. gnutls_datum_t * ecpoint);
  188. int gnutls_pubkey_export(gnutls_pubkey_t key,
  189. gnutls_x509_crt_fmt_t format,
  190. void *output_data, size_t * output_data_size);
  191. int gnutls_pubkey_export2(gnutls_pubkey_t key,
  192. gnutls_x509_crt_fmt_t format,
  193. gnutls_datum_t * out);
  194. int gnutls_pubkey_get_key_id(gnutls_pubkey_t key,
  195. unsigned int flags,
  196. unsigned char *output_data,
  197. size_t * output_data_size);
  198. int
  199. gnutls_pubkey_get_openpgp_key_id(gnutls_pubkey_t key,
  200. unsigned int flags,
  201. unsigned char *output_data,
  202. size_t * output_data_size,
  203. unsigned int *subkey);
  204. int gnutls_pubkey_get_key_usage(gnutls_pubkey_t key, unsigned int *usage);
  205. int gnutls_pubkey_set_key_usage(gnutls_pubkey_t key, unsigned int usage);
  206. int gnutls_pubkey_import(gnutls_pubkey_t key,
  207. const gnutls_datum_t * data,
  208. gnutls_x509_crt_fmt_t format);
  209. #define gnutls_pubkey_import_pkcs11_url(key, url, flags) gnutls_pubkey_import_url(key, url, flags)
  210. int gnutls_pubkey_import_dsa_raw(gnutls_pubkey_t key,
  211. const gnutls_datum_t * p,
  212. const gnutls_datum_t * q,
  213. const gnutls_datum_t * g,
  214. const gnutls_datum_t * y);
  215. int gnutls_pubkey_import_rsa_raw(gnutls_pubkey_t key,
  216. const gnutls_datum_t * m,
  217. const gnutls_datum_t * e);
  218. int
  219. gnutls_pubkey_import_ecc_x962(gnutls_pubkey_t key,
  220. const gnutls_datum_t * parameters,
  221. const gnutls_datum_t * ecpoint);
  222. int
  223. gnutls_pubkey_import_ecc_raw(gnutls_pubkey_t key,
  224. gnutls_ecc_curve_t curve,
  225. const gnutls_datum_t * x,
  226. const gnutls_datum_t * y);
  227. int
  228. gnutls_pubkey_encrypt_data(gnutls_pubkey_t key,
  229. unsigned int flags,
  230. const gnutls_datum_t * plaintext,
  231. gnutls_datum_t * ciphertext);
  232. int gnutls_x509_crt_set_pubkey(gnutls_x509_crt_t crt, gnutls_pubkey_t key);
  233. int gnutls_x509_crq_set_pubkey(gnutls_x509_crq_t crq, gnutls_pubkey_t key);
  234. int
  235. gnutls_pubkey_verify_hash2(gnutls_pubkey_t key,
  236. gnutls_sign_algorithm_t algo,
  237. unsigned int flags,
  238. const gnutls_datum_t * hash,
  239. const gnutls_datum_t * signature);
  240. int
  241. gnutls_pubkey_verify_data2(gnutls_pubkey_t pubkey,
  242. gnutls_sign_algorithm_t algo,
  243. unsigned int flags,
  244. const gnutls_datum_t * data,
  245. const gnutls_datum_t * signature);
  246. /* Private key operations */
  247. int gnutls_privkey_init(gnutls_privkey_t * key);
  248. void gnutls_privkey_deinit(gnutls_privkey_t key);
  249. /* macros to allow specifying a subgroup and group size in gnutls_privkey_generate()
  250. * and gnutls_x509_privkey_generate() */
  251. #define GNUTLS_SUBGROUP_TO_BITS(group, subgroup) (unsigned int)((subgroup<<16)|(group))
  252. #define GNUTLS_BITS_TO_SUBGROUP(bits) ((bits >> 16) & 0xFFFF)
  253. #define GNUTLS_BITS_TO_GROUP(bits) (bits & 0xFFFF)
  254. #define GNUTLS_BITS_HAVE_SUBGROUP(bits) ((bits) & 0xFFFF0000)
  255. int
  256. gnutls_privkey_generate (gnutls_privkey_t key,
  257. gnutls_pk_algorithm_t algo, unsigned int bits,
  258. unsigned int flags);
  259. int
  260. gnutls_privkey_generate2(gnutls_privkey_t pkey,
  261. gnutls_pk_algorithm_t algo, unsigned int bits,
  262. unsigned int flags, const gnutls_keygen_data_st *data, unsigned data_size);
  263. int
  264. gnutls_privkey_set_spki(gnutls_privkey_t key,
  265. const gnutls_x509_spki_t spki,
  266. unsigned int flags);
  267. int
  268. gnutls_privkey_get_spki(gnutls_privkey_t key,
  269. const gnutls_x509_spki_t spki,
  270. unsigned int flags);
  271. int gnutls_privkey_verify_seed(gnutls_privkey_t key, gnutls_digest_algorithm_t, const void *seed, size_t seed_size);
  272. int gnutls_privkey_get_seed(gnutls_privkey_t key, gnutls_digest_algorithm_t*, void *seed, size_t *seed_size);
  273. int gnutls_privkey_verify_params(gnutls_privkey_t key);
  274. void gnutls_privkey_set_flags(gnutls_privkey_t key, unsigned int flags);
  275. void gnutls_privkey_set_pin_function (gnutls_privkey_t key,
  276. gnutls_pin_callback_t fn, void *userdata);
  277. int gnutls_privkey_get_pk_algorithm(gnutls_privkey_t key,
  278. unsigned int *bits);
  279. gnutls_privkey_type_t gnutls_privkey_get_type(gnutls_privkey_t key);
  280. int gnutls_privkey_status(gnutls_privkey_t key);
  281. /**
  282. * gnutls_privkey_flags:
  283. * @GNUTLS_PRIVKEY_SIGN_FLAG_TLS1_RSA: Make an RSA signature on the hashed data as in the TLS protocol.
  284. * @GNUTLS_PRIVKEY_SIGN_FLAG_RSA_PSS: Make an RSA signature on the hashed data with the PSS padding.
  285. * @GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE: Make an RSA-PSS signature on the hashed data with reproducible parameters (zero salt).
  286. * @GNUTLS_PRIVKEY_IMPORT_AUTO_RELEASE: When importing a private key, automatically
  287. * release it when the structure it was imported is released.
  288. * @GNUTLS_PRIVKEY_IMPORT_COPY: Copy required values during import.
  289. * @GNUTLS_PRIVKEY_DISABLE_CALLBACKS: The following flag disables call to PIN callbacks etc.
  290. * Only relevant to TPM keys.
  291. * @GNUTLS_PRIVKEY_FLAG_PROVABLE: When generating a key involving prime numbers, use provable primes; a seed may be required.
  292. * @GNUTLS_PRIVKEY_FLAG_CA: The generated private key is going to be used as a CA (relevant for RSA-PSS keys).
  293. * @GNUTLS_PRIVKEY_FLAG_EXPORT_COMPAT: Keys generated or imported as provable require an extended format which cannot be read by previous versions
  294. * of gnutls or other applications. By setting this flag the key will be exported in a backwards compatible way,
  295. * even if the information about the seed used will be lost.
  296. *
  297. * Enumeration of different certificate import flags.
  298. */
  299. typedef enum gnutls_privkey_flags {
  300. GNUTLS_PRIVKEY_IMPORT_AUTO_RELEASE = 1,
  301. GNUTLS_PRIVKEY_IMPORT_COPY = 1 << 1,
  302. GNUTLS_PRIVKEY_DISABLE_CALLBACKS = 1 << 2,
  303. GNUTLS_PRIVKEY_SIGN_FLAG_TLS1_RSA = 1 << 4,
  304. GNUTLS_PRIVKEY_FLAG_PROVABLE = 1 << 5,
  305. GNUTLS_PRIVKEY_FLAG_EXPORT_COMPAT = 1 << 6,
  306. GNUTLS_PRIVKEY_SIGN_FLAG_RSA_PSS = 1 << 7,
  307. GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE = 1 << 8,
  308. GNUTLS_PRIVKEY_FLAG_CA = 1 << 9
  309. } gnutls_privkey_flags_t;
  310. int gnutls_privkey_import_pkcs11(gnutls_privkey_t pkey,
  311. gnutls_pkcs11_privkey_t key,
  312. unsigned int flags);
  313. int gnutls_privkey_import_x509(gnutls_privkey_t pkey,
  314. gnutls_x509_privkey_t key,
  315. unsigned int flags);
  316. int gnutls_privkey_import_openpgp(gnutls_privkey_t pkey,
  317. gnutls_openpgp_privkey_t key,
  318. unsigned int flags);
  319. int gnutls_privkey_export_x509(gnutls_privkey_t pkey,
  320. gnutls_x509_privkey_t * key);
  321. int gnutls_privkey_export_openpgp(gnutls_privkey_t pkey,
  322. gnutls_openpgp_privkey_t * key);
  323. int
  324. gnutls_privkey_export_pkcs11(gnutls_privkey_t pkey,
  325. gnutls_pkcs11_privkey_t *key);
  326. int gnutls_privkey_import_openpgp_raw(gnutls_privkey_t pkey,
  327. const gnutls_datum_t * data,
  328. gnutls_openpgp_crt_fmt_t
  329. format,
  330. const gnutls_openpgp_keyid_t
  331. keyid, const char *password);
  332. int gnutls_privkey_import_x509_raw(gnutls_privkey_t pkey,
  333. const gnutls_datum_t * data,
  334. gnutls_x509_crt_fmt_t format,
  335. const char *password,
  336. unsigned int flags);
  337. int
  338. gnutls_privkey_import_tpm_raw(gnutls_privkey_t pkey,
  339. const gnutls_datum_t * fdata,
  340. gnutls_tpmkey_fmt_t format,
  341. const char *srk_password,
  342. const char *key_password,
  343. unsigned int flags);
  344. int
  345. gnutls_privkey_import_tpm_url(gnutls_privkey_t pkey,
  346. const char *url,
  347. const char *srk_password,
  348. const char *key_password,
  349. unsigned int flags);
  350. int gnutls_privkey_import_url(gnutls_privkey_t key,
  351. const char *url, unsigned int flags);
  352. #if 0
  353. /* for documentation purposes */
  354. int gnutls_privkey_import_pkcs11_url(gnutls_privkey_t key, const char *url);
  355. #endif
  356. #define gnutls_privkey_import_pkcs11_url(key, url) gnutls_privkey_import_url(key, url, 0)
  357. int
  358. gnutls_privkey_import_ext(gnutls_privkey_t pkey,
  359. gnutls_pk_algorithm_t pk,
  360. void *userdata,
  361. gnutls_privkey_sign_func sign_func,
  362. gnutls_privkey_decrypt_func
  363. decrypt_func, unsigned int flags);
  364. int
  365. gnutls_privkey_import_ext2(gnutls_privkey_t pkey,
  366. gnutls_pk_algorithm_t pk,
  367. void *userdata,
  368. gnutls_privkey_sign_func sign_func,
  369. gnutls_privkey_decrypt_func
  370. decrypt_func,
  371. gnutls_privkey_deinit_func deinit_func,
  372. unsigned int flags);
  373. int
  374. gnutls_privkey_import_ext3(gnutls_privkey_t pkey,
  375. void *userdata,
  376. gnutls_privkey_sign_func sign_func,
  377. gnutls_privkey_decrypt_func decrypt_func,
  378. gnutls_privkey_deinit_func deinit_func,
  379. gnutls_privkey_info_func info_func,
  380. unsigned int flags);
  381. int
  382. gnutls_privkey_import_ext4(gnutls_privkey_t pkey,
  383. void *userdata,
  384. gnutls_privkey_sign_data_func sign_data_func,
  385. gnutls_privkey_sign_hash_func sign_hash_func,
  386. gnutls_privkey_decrypt_func decrypt_func,
  387. gnutls_privkey_deinit_func deinit_func,
  388. gnutls_privkey_info_func info_func,
  389. unsigned int flags);
  390. int gnutls_privkey_import_dsa_raw(gnutls_privkey_t key,
  391. const gnutls_datum_t * p,
  392. const gnutls_datum_t * q,
  393. const gnutls_datum_t * g,
  394. const gnutls_datum_t * y,
  395. const gnutls_datum_t * x);
  396. int gnutls_privkey_import_rsa_raw(gnutls_privkey_t key,
  397. const gnutls_datum_t * m,
  398. const gnutls_datum_t * e,
  399. const gnutls_datum_t * d,
  400. const gnutls_datum_t * p,
  401. const gnutls_datum_t * q,
  402. const gnutls_datum_t * u,
  403. const gnutls_datum_t * e1,
  404. const gnutls_datum_t * e2);
  405. int gnutls_privkey_import_ecc_raw(gnutls_privkey_t key,
  406. gnutls_ecc_curve_t curve,
  407. const gnutls_datum_t * x,
  408. const gnutls_datum_t * y,
  409. const gnutls_datum_t * k);
  410. int gnutls_privkey_sign_data(gnutls_privkey_t signer,
  411. gnutls_digest_algorithm_t hash,
  412. unsigned int flags,
  413. const gnutls_datum_t * data,
  414. gnutls_datum_t * signature);
  415. int gnutls_privkey_sign_data2(gnutls_privkey_t signer,
  416. gnutls_sign_algorithm_t algo,
  417. unsigned int flags,
  418. const gnutls_datum_t * data,
  419. gnutls_datum_t * signature);
  420. #define gnutls_privkey_sign_raw_data(key, flags, data, sig) \
  421. gnutls_privkey_sign_hash ( key, 0, GNUTLS_PRIVKEY_SIGN_FLAG_TLS1_RSA, data, sig)
  422. int gnutls_privkey_sign_hash(gnutls_privkey_t signer,
  423. gnutls_digest_algorithm_t hash_algo,
  424. unsigned int flags,
  425. const gnutls_datum_t * hash_data,
  426. gnutls_datum_t * signature);
  427. int gnutls_privkey_sign_hash2(gnutls_privkey_t signer,
  428. gnutls_sign_algorithm_t algo,
  429. unsigned int flags,
  430. const gnutls_datum_t * hash_data,
  431. gnutls_datum_t * signature);
  432. int gnutls_privkey_decrypt_data(gnutls_privkey_t key,
  433. unsigned int flags,
  434. const gnutls_datum_t * ciphertext,
  435. gnutls_datum_t * plaintext);
  436. int
  437. gnutls_privkey_export_rsa_raw(gnutls_privkey_t key,
  438. gnutls_datum_t * m, gnutls_datum_t * e,
  439. gnutls_datum_t * d, gnutls_datum_t * p,
  440. gnutls_datum_t * q, gnutls_datum_t * u,
  441. gnutls_datum_t * e1,
  442. gnutls_datum_t * e2);
  443. int
  444. gnutls_privkey_export_rsa_raw2(gnutls_privkey_t key,
  445. gnutls_datum_t * m, gnutls_datum_t * e,
  446. gnutls_datum_t * d, gnutls_datum_t * p,
  447. gnutls_datum_t * q, gnutls_datum_t * u,
  448. gnutls_datum_t * e1,
  449. gnutls_datum_t * e2, unsigned flags);
  450. int
  451. gnutls_privkey_export_dsa_raw(gnutls_privkey_t key,
  452. gnutls_datum_t * p, gnutls_datum_t * q,
  453. gnutls_datum_t * g, gnutls_datum_t * y,
  454. gnutls_datum_t * x);
  455. int
  456. gnutls_privkey_export_dsa_raw2(gnutls_privkey_t key,
  457. gnutls_datum_t * p, gnutls_datum_t * q,
  458. gnutls_datum_t * g, gnutls_datum_t * y,
  459. gnutls_datum_t * x, unsigned flags);
  460. int
  461. gnutls_privkey_export_ecc_raw(gnutls_privkey_t key,
  462. gnutls_ecc_curve_t * curve,
  463. gnutls_datum_t * x,
  464. gnutls_datum_t * y,
  465. gnutls_datum_t * k);
  466. int
  467. gnutls_privkey_export_ecc_raw2(gnutls_privkey_t key,
  468. gnutls_ecc_curve_t * curve,
  469. gnutls_datum_t * x,
  470. gnutls_datum_t * y,
  471. gnutls_datum_t * k,
  472. unsigned flags);
  473. int gnutls_x509_crt_privkey_sign(gnutls_x509_crt_t crt,
  474. gnutls_x509_crt_t issuer,
  475. gnutls_privkey_t issuer_key,
  476. gnutls_digest_algorithm_t dig,
  477. unsigned int flags);
  478. int gnutls_x509_crl_privkey_sign(gnutls_x509_crl_t crl,
  479. gnutls_x509_crt_t issuer,
  480. gnutls_privkey_t issuer_key,
  481. gnutls_digest_algorithm_t dig,
  482. unsigned int flags);
  483. int gnutls_x509_crq_privkey_sign(gnutls_x509_crq_t crq,
  484. gnutls_privkey_t key,
  485. gnutls_digest_algorithm_t dig,
  486. unsigned int flags);
  487. /**
  488. * gnutls_pcert_st:
  489. * @pubkey: public key of parsed certificate.
  490. * @cert: certificate itself of parsed certificate
  491. * @type: type of certificate, a #gnutls_certificate_type_t type.
  492. *
  493. * A parsed certificate.
  494. */
  495. typedef struct gnutls_pcert_st {
  496. gnutls_pubkey_t pubkey;
  497. gnutls_datum_t cert;
  498. gnutls_certificate_type_t type;
  499. } gnutls_pcert_st;
  500. /* Do not initialize the "cert" element of
  501. * the certificate */
  502. #define GNUTLS_PCERT_NO_CERT 1
  503. int gnutls_pcert_import_x509(gnutls_pcert_st * pcert,
  504. gnutls_x509_crt_t crt, unsigned int flags);
  505. int gnutls_pcert_import_x509_list(gnutls_pcert_st * pcert,
  506. gnutls_x509_crt_t *crt, unsigned *ncrt,
  507. unsigned int flags);
  508. int gnutls_pcert_export_x509(gnutls_pcert_st * pcert,
  509. gnutls_x509_crt_t * crt);
  510. int
  511. gnutls_pcert_list_import_x509_raw(gnutls_pcert_st * pcerts,
  512. unsigned int *pcert_max,
  513. const gnutls_datum_t * data,
  514. gnutls_x509_crt_fmt_t format,
  515. unsigned int flags);
  516. int gnutls_pcert_import_x509_raw(gnutls_pcert_st * pcert,
  517. const gnutls_datum_t * cert,
  518. gnutls_x509_crt_fmt_t format,
  519. unsigned int flags);
  520. int gnutls_pcert_import_openpgp_raw(gnutls_pcert_st * pcert,
  521. const gnutls_datum_t * cert,
  522. gnutls_openpgp_crt_fmt_t
  523. format,
  524. gnutls_openpgp_keyid_t keyid,
  525. unsigned int flags);
  526. int gnutls_pcert_import_openpgp(gnutls_pcert_st * pcert,
  527. gnutls_openpgp_crt_t crt,
  528. unsigned int flags);
  529. int gnutls_pcert_export_openpgp(gnutls_pcert_st * pcert,
  530. gnutls_openpgp_crt_t * crt);
  531. void gnutls_pcert_deinit(gnutls_pcert_st * pcert);
  532. /* For certificate credentials */
  533. /* This is the same as gnutls_certificate_retrieve_function()
  534. * but retrieves a gnutls_pcert_st which requires much less processing
  535. * within the library.
  536. */
  537. typedef int gnutls_certificate_retrieve_function2(gnutls_session_t,
  538. const gnutls_datum_t *req_ca_rdn,
  539. int nreqs,
  540. const gnutls_pk_algorithm_t *pk_algos,
  541. int pk_algos_length,
  542. gnutls_pcert_st**,
  543. unsigned int *pcert_length,
  544. gnutls_privkey_t *privkey);
  545. void gnutls_certificate_set_retrieve_function2
  546. (gnutls_certificate_credentials_t cred,
  547. gnutls_certificate_retrieve_function2 * func);
  548. int
  549. gnutls_certificate_set_key(gnutls_certificate_credentials_t res,
  550. const char **names,
  551. int names_size,
  552. gnutls_pcert_st * pcert_list,
  553. int pcert_list_size, gnutls_privkey_t key);
  554. int
  555. gnutls_pubkey_print(gnutls_pubkey_t pubkey,
  556. gnutls_certificate_print_formats_t format,
  557. gnutls_datum_t * out);
  558. /* *INDENT-OFF* */
  559. #ifdef __cplusplus
  560. }
  561. #endif
  562. /* *INDENT-ON* */
  563. #endif