Latest update.
This commit is contained in:
@@ -18,12 +18,11 @@ evp_keymgmt_export, evp_keymgmt_export_types
|
||||
int evp_keymgmt_get_params(const EVP_KEYMGMT *keymgmt,
|
||||
void *keydata, OSSL_PARAM params[]);
|
||||
const OSSL_PARAM *evp_keymgmt_gettable_params(const EVP_KEYMGMT *keymgmt);
|
||||
|
||||
|
||||
|
||||
int evp_keymgmt_has(const EVP_KEYMGMT *keymgmt, void *keyddata, int selection);
|
||||
int evp_keymgmt_validate(const EVP_KEYMGMT *keymgmt, void *keydata,
|
||||
int selection);
|
||||
|
||||
|
||||
int evp_keymgmt_import(const EVP_KEYMGMT *keymgmt, void *keydata,
|
||||
int selection, const OSSL_PARAM params[]);
|
||||
const OSSL_PARAM *evp_keymgmt_import_types(const EVP_KEYMGMT *keymgmt,
|
||||
|
||||
@@ -3,8 +3,10 @@
|
||||
=head1 NAME
|
||||
|
||||
evp_keymgmt_util_export_to_provider,
|
||||
evp_keymgmt_util_clear_pkey_cache,
|
||||
evp_keymgmt_util_cache_pkey,
|
||||
evp_keymgmt_util_find_operation_cache_index,
|
||||
evp_keymgmt_util_clear_operation_cache,
|
||||
evp_keymgmt_util_cache_keydata,
|
||||
evp_keymgmt_util_cache_keyinfo,
|
||||
evp_keymgmt_util_fromdata
|
||||
- internal KEYMGMT utility functions
|
||||
|
||||
@@ -13,32 +15,41 @@ evp_keymgmt_util_fromdata
|
||||
#include "crypto/evp.h"
|
||||
|
||||
void *evp_keymgmt_util_export_to_provider(EVP_PKEY *pk, EVP_KEYMGMT *keymgmt);
|
||||
void evp_keymgmt_util_clear_pkey_cache(EVP_PKEY *pk);
|
||||
void evp_keymgmt_util_cache_pkey(EVP_PKEY *pk, size_t index,
|
||||
EVP_KEYMGMT *keymgmt, void *keydata);
|
||||
size_t evp_keymgmt_util_find_operation_cache_index(EVP_PKEY *pk,
|
||||
EVP_KEYMGMT *keymgmt);
|
||||
void evp_keymgmt_util_clear_operation_cache(EVP_PKEY *pk);
|
||||
void evp_keymgmt_util_cache_keydata(EVP_PKEY *pk, size_t index,
|
||||
EVP_KEYMGMT *keymgmt, void *keydata);
|
||||
void evp_keymgmt_util_cache_keyinfo(EVP_PKEY *pk);
|
||||
void *evp_keymgmt_util_fromdata(EVP_PKEY *target, EVP_KEYMGMT *keymgmt,
|
||||
int selection, const OSSL_PARAM params[]);
|
||||
|
||||
=head1 DESCRIPTION
|
||||
|
||||
evp_keymgmt_util_export_to_provider() exports the key material from
|
||||
the given key I<pk> to a provider via a B<EVP_KEYMGMT> interface, if
|
||||
this hasn't already been done.
|
||||
evp_keymgmt_util_export_to_provider() exports cached key material
|
||||
(provider side key material) from the given key I<pk> to a provider
|
||||
via a B<EVP_KEYMGMT> interface, if this hasn't already been done.
|
||||
It maintains a cache of provider key references in I<pk> to keep track
|
||||
of all such exports.
|
||||
of all provider side keys.
|
||||
|
||||
If I<pk> has an assigned legacy key, a check is done to see if any of
|
||||
its key material has changed since last export, i.e. the legacy key's
|
||||
is_dirty() method returns 1.
|
||||
If it has, the cache of already exported keys is cleared, and a new
|
||||
export is made with the new key material.
|
||||
To export a legacy key, use L<evp_pkey_export_to_provider(3)> instead,
|
||||
as this function ignores any legacy key data.
|
||||
|
||||
evp_keymgmt_util_clear_pkey_cache() can be used to explicitly clear
|
||||
the cache of provider key references.
|
||||
evp_keymgmt_util_find_operation_cache_index() finds the location if
|
||||
I<keymgmt> in I<pk>'s cache of provided keys for operations. If
|
||||
I<keymgmt> is NULL or couldn't be found in the cache, it finds the
|
||||
first empty slot instead if there is any.
|
||||
|
||||
evp_keymgmt_util_cache_pkey() can be used to assign a provider key
|
||||
evp_keymgmt_util_clear_operation_cache() can be used to explicitly
|
||||
clear the cache of operation key references.
|
||||
|
||||
evp_keymgmt_util_cache_keydata() can be used to assign a provider key
|
||||
object to a specific cache slot in the given I<target>.
|
||||
I<Use with extreme care>.
|
||||
I<Use extreme care>.
|
||||
|
||||
evp_keymgmt_util_cache_keyinfo() can be used to get all kinds of
|
||||
information from the provvider "origin" and save it in I<pk>'s
|
||||
information cache.
|
||||
|
||||
evp_keymgmt_util_fromdata() can be used to add key object data to a
|
||||
given key I<target> via a B<EVP_KEYMGMT> interface. This is used as a
|
||||
@@ -50,6 +61,11 @@ evp_keymgmt_export_to_provider() and evp_keymgmt_util_fromdata()
|
||||
return a pointer to the appropriate provider side key (created or
|
||||
found again), or NULL on error.
|
||||
|
||||
evp_keymgmt_util_find_operation_cache_index() returns the index of the
|
||||
operation cache slot. If I<keymgmt> is NULL, or if there is no slot
|
||||
with a match for I<keymgmt>, the index of the first empty slot is
|
||||
returned, or the maximum number of slots if there isn't an empty one.
|
||||
|
||||
=head1 NOTES
|
||||
|
||||
"Legacy key" is the term used for any key that has been assigned to an
|
||||
|
||||
@@ -0,0 +1,75 @@
|
||||
=pod
|
||||
|
||||
=head1 NAME
|
||||
|
||||
evp_pkey_export_to_provider, evp_pkey_upgrade_to_provider
|
||||
- internal EVP_PKEY support functions for providers
|
||||
|
||||
=head1 SYNOPSIS
|
||||
|
||||
/* Only for EVP source */
|
||||
#include "evp_local.h"
|
||||
|
||||
void *evp_pkey_export_to_provider(EVP_PKEY *pk, OPENSSL_CTX *libctx,
|
||||
EVP_KEYMGMT **keymgmt,
|
||||
const char *propquery);
|
||||
void *evp_pkey_upgrade_to_provider(EVP_PKEY *pk, OPENSSL_CTX *libctx,
|
||||
EVP_KEYMGMT **keymgmt,
|
||||
const char *propquery);
|
||||
|
||||
=head1 DESCRIPTION
|
||||
|
||||
This manual uses the term "origin", which is explained in internal
|
||||
L<EVP_PKEY(7)>.
|
||||
|
||||
evp_pkey_export_to_provider() exports the "origin" key contained in I<pk>
|
||||
to its operation cache to make it suitable for an B<EVP_KEYMGMT> given either
|
||||
with I<*keymgmt> or with an implicit fetch using I<libctx> (NULL means the
|
||||
default context), the name of the legacy type of I<pk>, and the I<propquery>
|
||||
(NULL means the default property query settings).
|
||||
|
||||
If I<keymgmt> isn't NULL but I<*keymgmt> is, and the "origin" was successfully
|
||||
exported, then I<*keymgmt> is assigned the implicitly fetched B<EVP_KEYMGMT>.
|
||||
|
||||
evp_pkey_upgrade_to_provider() exports the legacy "origin" key contained in
|
||||
I<pk> to it's provider side counterpart, then clears the legacy "origin" key
|
||||
along with other legacy data, and resets all the caches. Otherwise, it works
|
||||
like evp_pkey_export_to_provider().
|
||||
|
||||
I<evp_pkey_upgrade_to_provider() must be used with great care, only if there's
|
||||
no other way.>
|
||||
Most of the time, it's sufficient to use evp_pkey_export_to_provider(), but in
|
||||
case the key needs modification with data coming from a provided key, the key
|
||||
will need an upgrade.
|
||||
|
||||
=head1 RETURN VALUES
|
||||
|
||||
evp_pkey_export_to_provider() and evp_pkey_upgrade_to_provider() both return
|
||||
the provider key data that was exported if the "origin" was successfully
|
||||
exported to its target. Otherwise, NULL is returned.
|
||||
|
||||
=head1 NOTES
|
||||
|
||||
Some functions calling evp_pkey_export_to_provider() or
|
||||
evp_pkey_upgrade_to_provider() may have received a const key, and may
|
||||
therefore have to cast the key to non-const form to call this function. Since
|
||||
B<EVP_PKEY> is always dynamically allocated, this is OK.
|
||||
|
||||
=head1 SEE ALSO
|
||||
|
||||
L<OPENSSL_CTX(3)>, L<EVP_KEYMGMT(3)>
|
||||
|
||||
=head1 HISTORY
|
||||
|
||||
The functions described here were all added in OpenSSL 3.0.
|
||||
|
||||
=head1 COPYRIGHT
|
||||
|
||||
Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.
|
||||
|
||||
Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
this file except in compliance with the License. You can obtain a copy
|
||||
in the file LICENSE in the source distribution or at
|
||||
L<https://www.openssl.org/source/license.html>.
|
||||
|
||||
=cut
|
||||
@@ -1,55 +0,0 @@
|
||||
=pod
|
||||
|
||||
=head1 NAME
|
||||
|
||||
evp_pkey_make_provided - internal EVP_PKEY support functions for providers
|
||||
|
||||
=head1 SYNOPSIS
|
||||
|
||||
/* Only for EVP source */
|
||||
#include "evp_local.h"
|
||||
|
||||
void *evp_pkey_make_provided(EVP_PKEY *pk, OPENSSL_CTX *libctx,
|
||||
EVP_KEYMGMT **keymgmt, const char *propquery);
|
||||
|
||||
=head1 DESCRIPTION
|
||||
|
||||
evp_pkey_make_provided() ensures that the B<EVP_PKEY> I<pk> is provided within
|
||||
the library context I<libctx> (NULL means the default context). I<keymgmt>
|
||||
may point at a reference to a B<EVP_KEYMGMT>, and works as an input/output
|
||||
parameter.
|
||||
As input to this function, it can be used to specify a B<EVP_KEYMGMT> to be
|
||||
used for exporting. If not (I<*keymgmt> is NULL), then this function will
|
||||
fetch an B<EVP_KEYMGMT> implicitly, using I<propquery> as property query string.
|
||||
As output from this function, I<*keymgmt> will be assigned the B<EVP_KEYMGMT>
|
||||
that was used, if the export was successful, otherwise it will be assigned NULL.
|
||||
|
||||
=head1 RETURN VALUES
|
||||
|
||||
evp_pkey_make_provided() returns the provider key data that was exported if
|
||||
I<pk> was successfully provided. Otherwise, NULL is returned.
|
||||
|
||||
=head1 NOTES
|
||||
|
||||
Some functions calling evp_pkey_make_provided() may have received a const
|
||||
key, and may therefore have to cast the key to non-const form to call this
|
||||
function. Since B<EVP_PKEY> is always dynamically allocated, this is OK.
|
||||
|
||||
=head1 SEE ALSO
|
||||
|
||||
L<OPENSSL_CTX(3)>, L<EVP_KEYMGMT(3)>
|
||||
|
||||
=head1 HISTORY
|
||||
|
||||
The functions described here were all added in OpenSSL 3.0.
|
||||
|
||||
=head1 COPYRIGHT
|
||||
|
||||
Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.
|
||||
|
||||
Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
this file except in compliance with the License. You can obtain a copy
|
||||
in the file LICENSE in the source distribution or at
|
||||
L<https://www.openssl.org/source/license.html>.
|
||||
|
||||
=cut
|
||||
@@ -68,7 +68,7 @@ the variable pointed to by I<level> with the severity level or -1,
|
||||
the variable pointed to by I<func> with the function name string or NULL,
|
||||
the variable pointed to by I<file> with the filename string or NULL, and
|
||||
the variable pointed to by I<line> with the line number or -1.
|
||||
Any string returned via I<*func> and I<*file> must be freeed by the caller.
|
||||
Any string returned via I<*func> and I<*file> must be freed by the caller.
|
||||
|
||||
ossl_cmp_add_error_data() is a macro calling
|
||||
L<ERR_add_error_txt(3)> with the separator being ":".
|
||||
|
||||
@@ -75,7 +75,7 @@ I<val> is stored by value and an expression or auto variable can be used.
|
||||
|
||||
ossl_param_bld_push_BN() is a function that will create an OSSL_PARAM object
|
||||
that holds the specified BIGNUM I<bn>.
|
||||
If I<bn> is marked as being securely allocated, it's OSSL_PARAM representation
|
||||
If I<bn> is marked as being securely allocated, its OSSL_PARAM representation
|
||||
will also be securely allocated.
|
||||
The I<bn> argument is stored by reference and the underlying BIGNUM object
|
||||
must exist until after ossl_param_bld_to_param() has been called.
|
||||
@@ -84,7 +84,7 @@ ossl_param_bld_push_BN_pad() is a function that will create an OSSL_PARAM object
|
||||
that holds the specified BIGNUM I<bn>.
|
||||
The object will be padded to occupy exactly I<sz> bytes, if insufficient space
|
||||
is specified an error results.
|
||||
If I<bn> is marked as being securely allocated, it's OSSL_PARAM representation
|
||||
If I<bn> is marked as being securely allocated, its OSSL_PARAM representation
|
||||
will also be securely allocated.
|
||||
The I<bn> argument is stored by reference and the underlying BIGNUM object
|
||||
must exist until after ossl_param_bld_to_param() has been called.
|
||||
|
||||
@@ -0,0 +1,45 @@
|
||||
=pod
|
||||
|
||||
=head1 NAME
|
||||
|
||||
i2s_ASN1_UTF8STRING,
|
||||
s2i_ASN1_UTF8STRING,
|
||||
- convert objects from/to ASN.1/string representation
|
||||
|
||||
=head1 SYNOPSIS
|
||||
|
||||
=for openssl generic
|
||||
|
||||
char *i2s_ASN1_UTF8STRING(X509V3_EXT_METHOD *method,
|
||||
ASN1_UTF8STRING *utf8);
|
||||
ASN1_UTF8STRING *s2i_ASN1_UTF8STRING(X509V3_EXT_METHOD *method,
|
||||
X509V3_CTX *ctx, const char *str);
|
||||
=head1 DESCRIPTION
|
||||
|
||||
These functions convert OpenSSL objects to and from their ASN.1/string
|
||||
representation. This function is used for B<X509v3> extentions.
|
||||
|
||||
=head1 NOTES
|
||||
|
||||
The letters B<i> and B<s> in B<i2s_ASN1_UTF8STRING>() stand for
|
||||
"internal" (that is, an internal C structure) and string respectively.
|
||||
So B<i2s_ASN1_UTF8STRING>() converts from internal to string.
|
||||
|
||||
=head1 RETURN VALUES
|
||||
|
||||
B<s2i_ASN1_UTF8STRING>() return a valid
|
||||
B<ASN1_UTF8STRING> structure or NULL if an error occurs.
|
||||
|
||||
B<i2s_ASN1_UTF8STRING>() returns the pointer to a UTF-8 string
|
||||
or NULL if an error occurs.
|
||||
|
||||
=head1 COPYRIGHT
|
||||
|
||||
Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.
|
||||
|
||||
Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
this file except in compliance with the License. You can obtain a copy
|
||||
in the file LICENSE in the source distribution or at
|
||||
L<https://www.openssl.org/source/license.html>.
|
||||
|
||||
=cut
|
||||
Reference in New Issue
Block a user