Latest update.
This commit is contained in:
@@ -1,56 +0,0 @@
|
||||
=pod
|
||||
|
||||
=head1 NAME
|
||||
|
||||
evp_keymgmt_export_to_provider,
|
||||
evp_keymgmt_clear_pkey_cache
|
||||
- key material provider export for EVP
|
||||
|
||||
=head1 SYNOPSIS
|
||||
|
||||
#include "crypto/evp.h"
|
||||
|
||||
void *evp_keymgmt_export_to_provider(EVP_PKEY *pk, EVP_KEYMGMT *keymgmt);
|
||||
void evp_keymgmt_clear_pkey_cache(EVP_PKEY *pk);
|
||||
|
||||
=head1 DESCRIPTION
|
||||
|
||||
evp_keymgmt_export_to_provider() exports the key material from the
|
||||
given key I<pk> to a provider via a B<EVP_KEYMGMT> interface, if this
|
||||
hasn't already been done.
|
||||
It maintains a cache of provider key references in I<pk> to keep track
|
||||
of all such exports.
|
||||
|
||||
If I<pk> has an assigned legacy key, a check is done to see if any of
|
||||
its key material has changed since last export, i.e. the legacy key's
|
||||
is_dirty() method returns 1.
|
||||
If it has, the cache of already exported keys is cleared, and a new
|
||||
export is made with the new key material.
|
||||
|
||||
evp_keymgmt_clear_pkey_cache() can be used to explicitly clear the
|
||||
cache of provider key references.
|
||||
|
||||
=head1 RETURN VALUES
|
||||
|
||||
evp_keymgmt_export_to_provider() returns a pointer to the appropriate
|
||||
provider side key (created or found again), or NULL on error.
|
||||
|
||||
=head1 NOTES
|
||||
|
||||
"Legacy key" is the term used for any key that has been assigned to an
|
||||
B<EVP_PKEY> with EVP_PKEY_assign_RSA() and similar functions.
|
||||
|
||||
=head1 SEE ALSO
|
||||
|
||||
L<EVP_PKEY_ASN1_METHOD(3)>, L<EVP_PKEY_assign_RSA(3)>
|
||||
|
||||
=head1 COPYRIGHT
|
||||
|
||||
Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.
|
||||
|
||||
Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
this file except in compliance with the License. You can obtain a copy
|
||||
in the file LICENSE in the source distribution or at
|
||||
L<https://www.openssl.org/source/license.html>.
|
||||
|
||||
=cut
|
||||
@@ -1,109 +0,0 @@
|
||||
=pod
|
||||
|
||||
=head1 NAME
|
||||
|
||||
evp_keymgmt_importdomparams, evp_keymgmt_gendomparams,
|
||||
evp_keymgmt_freedomparams,
|
||||
evp_keymgmt_exportdomparams,
|
||||
evp_keymgmt_importdomparams_types, evp_keymgmt_exportdomparams_types,
|
||||
evp_keymgmt_importkey, evp_keymgmt_genkey, evp_keymgmt_loadkey,
|
||||
evp_keymgmt_freekey,
|
||||
evp_keymgmt_exportkey,
|
||||
evp_keymgmt_importkey_types, evp_keymgmt_exportkey_types
|
||||
- internal KEYMGMT support functions
|
||||
|
||||
=head1 SYNOPSIS
|
||||
|
||||
#include "crypto/evp.h"
|
||||
|
||||
void *evp_keymgmt_importdomparams(const EVP_KEYMGMT *keymgmt,
|
||||
const OSSL_PARAM params[]);
|
||||
void *evp_keymgmt_gendomparams(const EVP_KEYMGMT *keymgmt,
|
||||
const OSSL_PARAM params[]);
|
||||
void evp_keymgmt_freedomparams(const EVP_KEYMGMT *keymgmt, void *provdomparams);
|
||||
int evp_keymgmt_exportdomparams(const EVP_KEYMGMT *keymgmt,
|
||||
void *provdomparams, OSSL_PARAM params[]);
|
||||
const OSSL_PARAM *evp_keymgmt_importdomparams_types(const EVP_KEYMGMT *keymgmt);
|
||||
const OSSL_PARAM *evp_keymgmt_exportdomparams_types(const EVP_KEYMGMT *keymgmt);
|
||||
|
||||
void *evp_keymgmt_importkey(const EVP_KEYMGMT *keymgmt,
|
||||
const OSSL_PARAM params[]);
|
||||
void *evp_keymgmt_genkey(const EVP_KEYMGMT *keymgmt, void *domparams,
|
||||
const OSSL_PARAM params[]);
|
||||
void *evp_keymgmt_loadkey(const EVP_KEYMGMT *keymgmt,
|
||||
void *id, size_t idlen);
|
||||
void evp_keymgmt_freekey(const EVP_KEYMGMT *keymgmt, void *provkey);
|
||||
int evp_keymgmt_exportkey(const EVP_KEYMGMT *keymgmt, void *provkey,
|
||||
OSSL_PARAM params[]);
|
||||
const OSSL_PARAM *evp_keymgmt_importkey_types(const EVP_KEYMGMT *keymgmt);
|
||||
const OSSL_PARAM *evp_keymgmt_exportkey_types(const EVP_KEYMGMT *keymgmt);
|
||||
|
||||
=head1 DESCRIPTION
|
||||
|
||||
All these functions are helpers to call the provider's corresponding
|
||||
function.
|
||||
|
||||
evp_keymgmt_importdomparams() calls the method's importdomparams() function.
|
||||
|
||||
evp_keymgmt_gendomparams() calls the method's gendomparams() function.
|
||||
|
||||
evp_keymgmt_freedomparams() calls the method's freedomparams() function.
|
||||
|
||||
evp_keymgmt_exportdomparams() calls the method's exportdomparams()
|
||||
function.
|
||||
|
||||
evp_keymgmt_importdomparams_types() calls the method's
|
||||
importdomparams_types() function.
|
||||
|
||||
evp_keymgmt_exportdomparams_types() calls the method's
|
||||
exportdomparams_types() function.
|
||||
|
||||
evp_keymgmt_importkey() calls the method's importkey()
|
||||
function.
|
||||
|
||||
evp_keymgmt_genkey() calls the method's genkey() function.
|
||||
|
||||
evp_keymgmt_loadkey() calls the method's loadkey() function.
|
||||
|
||||
evp_keymgmt_freekey() calls the method's freekey() function.
|
||||
|
||||
evp_keymgmt_exportkey() calls the method's exportkey()
|
||||
function.
|
||||
|
||||
evp_keymgmt_importkey_types() calls the method's importkey_types() function.
|
||||
|
||||
evp_keymgmt_exportkey_types() calls the method's exportkey_types() function.
|
||||
|
||||
=head1 RETURN VALUES
|
||||
|
||||
evp_keymgmt_importdomparams(), evp_keymgmt_gendomparams() return a pointer
|
||||
to a provider owned set of domparams parameters, or NULL on error.
|
||||
|
||||
evp_keymgmt_importkey(), evp_keymgmt_genkey(), evp_keymgmt_loadkey() return
|
||||
a pointer to a provider owned key, or NULL on error.
|
||||
|
||||
evp_keymgmt_exportdomparams() and evp_keymgmt_exportkey() return 1 on success,
|
||||
or 0 on error.
|
||||
|
||||
evp_keymgmt_importdomparams_types(), evp_keymgmt_exportdomparams_types()
|
||||
return parameter descriptor for importing and exporting domparams
|
||||
parameters, or NULL if there are no such descriptors.
|
||||
|
||||
evp_keymgmt_importkey_types() and evp_keymgmt_exportkey_types()
|
||||
return parameter descriptor for importing and exporting keys, or NULL
|
||||
if there are no such descriptors.
|
||||
|
||||
=head1 HISTORY
|
||||
|
||||
The functions described here were all added in OpenSSL 3.0.
|
||||
|
||||
=head1 COPYRIGHT
|
||||
|
||||
Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.
|
||||
|
||||
Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
this file except in compliance with the License. You can obtain a copy
|
||||
in the file LICENSE in the source distribution or at
|
||||
L<https://www.openssl.org/source/license.html>.
|
||||
|
||||
=cut
|
||||
@@ -0,0 +1,93 @@
|
||||
=pod
|
||||
|
||||
=head1 NAME
|
||||
|
||||
evp_keymgmt_newdata, evp_keymgmt_freedata,
|
||||
evp_keymgmt_get_params, evp_keymgmt_gettable_params,
|
||||
evp_keymgmt_has, evp_keymgmt_validate,
|
||||
evp_keymgmt_import, evp_keymgmt_import_types,
|
||||
evp_keymgmt_export, evp_keymgmt_export_types
|
||||
- internal KEYMGMT interface functions
|
||||
|
||||
=head1 SYNOPSIS
|
||||
|
||||
#include "crypto/evp.h"
|
||||
|
||||
void *evp_keymgmt_newdata(const EVP_KEYMGMT *keymgmt);
|
||||
void evp_keymgmt_freedata(const EVP_KEYMGMT *keymgmt, void *keyddata);
|
||||
int evp_keymgmt_get_params(const EVP_KEYMGMT *keymgmt,
|
||||
void *keydata, OSSL_PARAM params[]);
|
||||
const OSSL_PARAM *evp_keymgmt_gettable_params(const EVP_KEYMGMT *keymgmt);
|
||||
|
||||
|
||||
int evp_keymgmt_has(const EVP_KEYMGMT *keymgmt, void *keyddata, int selection);
|
||||
int evp_keymgmt_validate(const EVP_KEYMGMT *keymgmt, void *keydata,
|
||||
int selection);
|
||||
|
||||
int evp_keymgmt_import(const EVP_KEYMGMT *keymgmt, void *keydata,
|
||||
int selection, const OSSL_PARAM params[]);
|
||||
const OSSL_PARAM *evp_keymgmt_import_types(const EVP_KEYMGMT *keymgmt,
|
||||
int selection);
|
||||
int evp_keymgmt_export(const EVP_KEYMGMT *keymgmt, void *keydata,
|
||||
int selection, OSSL_CALLBACK *param_cb, void *cbarg);
|
||||
const OSSL_PARAM *evp_keymgmt_export_types(const EVP_KEYMGMT *keymgmt,
|
||||
int selection);
|
||||
|
||||
=head1 DESCRIPTION
|
||||
|
||||
All these functions are helpers to call the provider's corresponding
|
||||
function. They all have in common that they take a B<EVP_KEYMGMT> as
|
||||
first argument, which they also retrieve a provider context from when
|
||||
needed. The rest of the arguments are simply passed on to the
|
||||
function they wrap around.
|
||||
|
||||
evp_keymgmt_newdata() calls the method's new() function.
|
||||
|
||||
evp_keymgmt_freedata() calls the method's free() function.
|
||||
|
||||
(the name evp_keymgmt_freedata() was chosen to avoid a clash with
|
||||
EVP_KEYMGMT_free() on case insensitive systems, the name
|
||||
evp_keymgmt_newdata() was chosen for consistency)
|
||||
|
||||
evp_keymgmt_get_params() calls the method's get_params() function.
|
||||
|
||||
evp_keymgmt_gettable_params() calls the method's gettable_params()
|
||||
function.
|
||||
|
||||
evp_keymgmt_has() calls the method's has() function.
|
||||
|
||||
evp_keymgmt_validate() calls the method's validate() function.
|
||||
|
||||
evp_keymgmt_import() calls the method's import() function.
|
||||
|
||||
evp_keymgmt_import_types() calls the method's import_types() function.
|
||||
|
||||
evp_keymgmt_export() calls the method's export() function.
|
||||
|
||||
evp_keymgmt_export_types() calls the method's export_types() function.
|
||||
|
||||
=head1 RETURN VALUES
|
||||
|
||||
evp_keymgmt_newdata() returns a pointer to a provider side key object,
|
||||
or NULL on error.
|
||||
|
||||
evp_keymgmt_gettable_params(), evp_keymgmt_import_types(), and
|
||||
evp_keymgmt_export_types() return parameter descriptor for importing
|
||||
and exporting key data, or NULL if there are no such descriptors.
|
||||
|
||||
All other functions return 1 on success and 0 on error.
|
||||
|
||||
=head1 HISTORY
|
||||
|
||||
The functions described here were all added in OpenSSL 3.0.
|
||||
|
||||
=head1 COPYRIGHT
|
||||
|
||||
Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.
|
||||
|
||||
Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
this file except in compliance with the License. You can obtain a copy
|
||||
in the file LICENSE in the source distribution or at
|
||||
L<https://www.openssl.org/source/license.html>.
|
||||
|
||||
=cut
|
||||
@@ -0,0 +1,71 @@
|
||||
=pod
|
||||
|
||||
=head1 NAME
|
||||
|
||||
evp_keymgmt_util_export_to_provider,
|
||||
evp_keymgmt_util_clear_pkey_cache,
|
||||
evp_keymgmt_util_cache_pkey,
|
||||
evp_keymgmt_util_fromdata
|
||||
- internal KEYMGMT utility functions
|
||||
|
||||
=head1 SYNOPSIS
|
||||
|
||||
#include "crypto/evp.h"
|
||||
|
||||
void *evp_keymgmt_util_export_to_provider(EVP_PKEY *pk, EVP_KEYMGMT *keymgmt);
|
||||
void evp_keymgmt_util_clear_pkey_cache(EVP_PKEY *pk);
|
||||
void evp_keymgmt_util_cache_pkey(EVP_PKEY *pk, size_t index,
|
||||
EVP_KEYMGMT *keymgmt, void *keydata);
|
||||
void *evp_keymgmt_util_fromdata(EVP_PKEY *target, EVP_KEYMGMT *keymgmt,
|
||||
int selection, const OSSL_PARAM params[]);
|
||||
|
||||
=head1 DESCRIPTION
|
||||
|
||||
evp_keymgmt_util_export_to_provider() exports the key material from
|
||||
the given key I<pk> to a provider via a B<EVP_KEYMGMT> interface, if
|
||||
this hasn't already been done.
|
||||
It maintains a cache of provider key references in I<pk> to keep track
|
||||
of all such exports.
|
||||
|
||||
If I<pk> has an assigned legacy key, a check is done to see if any of
|
||||
its key material has changed since last export, i.e. the legacy key's
|
||||
is_dirty() method returns 1.
|
||||
If it has, the cache of already exported keys is cleared, and a new
|
||||
export is made with the new key material.
|
||||
|
||||
evp_keymgmt_util_clear_pkey_cache() can be used to explicitly clear
|
||||
the cache of provider key references.
|
||||
|
||||
evp_keymgmt_util_cache_pkey() can be used to assign a provider key
|
||||
object to a specific cache slot in the given I<target>.
|
||||
I<Use with extreme care>.
|
||||
|
||||
evp_keymgmt_util_fromdata() can be used to add key object data to a
|
||||
given key I<target> via a B<EVP_KEYMGMT> interface. This is used as a
|
||||
helper for L<EVP_PKEY_fromdata(3)>.
|
||||
|
||||
=head1 RETURN VALUES
|
||||
|
||||
evp_keymgmt_export_to_provider() and evp_keymgmt_util_fromdata()
|
||||
return a pointer to the appropriate provider side key (created or
|
||||
found again), or NULL on error.
|
||||
|
||||
=head1 NOTES
|
||||
|
||||
"Legacy key" is the term used for any key that has been assigned to an
|
||||
B<EVP_PKEY> with EVP_PKEY_assign_RSA() and similar functions.
|
||||
|
||||
=head1 SEE ALSO
|
||||
|
||||
L<EVP_PKEY_ASN1_METHOD(3)>, L<EVP_PKEY_assign_RSA(3)>
|
||||
|
||||
=head1 COPYRIGHT
|
||||
|
||||
Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.
|
||||
|
||||
Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
this file except in compliance with the License. You can obtain a copy
|
||||
in the file LICENSE in the source distribution or at
|
||||
L<https://www.openssl.org/source/license.html>.
|
||||
|
||||
=cut
|
||||
@@ -10,8 +10,7 @@ evp_pkey_make_provided - internal EVP_PKEY support functions for providers
|
||||
#include "evp_local.h"
|
||||
|
||||
void *evp_pkey_make_provided(EVP_PKEY *pk, OPENSSL_CTX *libctx,
|
||||
EVP_KEYMGMT **keymgmt, const char *propquery,
|
||||
int domainparams);
|
||||
EVP_KEYMGMT **keymgmt, const char *propquery);
|
||||
|
||||
=head1 DESCRIPTION
|
||||
|
||||
@@ -24,8 +23,6 @@ used for exporting. If not (I<*keymgmt> is NULL), then this function will
|
||||
fetch an B<EVP_KEYMGMT> implicitly, using I<propquery> as property query string.
|
||||
As output from this function, I<*keymgmt> will be assigned the B<EVP_KEYMGMT>
|
||||
that was used, if the export was successful, otherwise it will be assigned NULL.
|
||||
I<domainparams> decides if I<pk> should be considered domain parameters or the
|
||||
actual key.
|
||||
|
||||
=head1 RETURN VALUES
|
||||
|
||||
|
||||
@@ -89,7 +89,7 @@ See the individual functions above.
|
||||
|
||||
=head1 SEE ALSO
|
||||
|
||||
L<OSSL_CMP_CTX_new(3)>, L<ossl_cmp_certreq_new(3)>
|
||||
L<OSSL_CMP_CTX_new(3)>, L<ossl_cmp_certReq_new(3)>
|
||||
|
||||
=head1 HISTORY
|
||||
|
||||
|
||||
Reference in New Issue
Block a user