passphrase.h 4.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122
  1. /*
  2. * Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.
  3. *
  4. * Licensed under the Apache License 2.0 (the "License"). You may not use
  5. * this file except in compliance with the License. You can obtain a copy
  6. * in the file LICENSE in the source distribution or at
  7. * https://www.openssl.org/source/license.html
  8. */
  9. #ifndef OSSL_INTERNAL_PASSPHRASE_H
  10. # define OSSL_INTERNAL_PASSPHRASE_H
  11. # pragma once
  12. /*
  13. * This is a passphrase reader bridge with bells and whistles.
  14. *
  15. * On one hand, an API may wish to offer all sorts of passphrase callback
  16. * possibilities to users, or may have to do so for historical reasons.
  17. * On the other hand, that same API may have demands from other interfaces,
  18. * notably from the libcrypto <-> provider interface, which uses
  19. * OSSL_PASSPHRASE_CALLBACK consistently.
  20. *
  21. * The structure and functions below are the fundaments for bridging one
  22. * passphrase callback form to another.
  23. *
  24. * In addition, extra features are included (this may be a growing list):
  25. *
  26. * - password caching. This is to be used by APIs where it's likely
  27. * that the same passphrase may be asked for more than once, but the
  28. * user shouldn't get prompted more than once. For example, this is
  29. * useful for OSSL_DECODER, which may have to use a passphrase while
  30. * trying to find out what input it has.
  31. */
  32. /*
  33. * Structure to hold whatever the calling user may specify. This structure
  34. * is intended to be integrated into API specific structures or to be used
  35. * as a local on-stack variable type. Therefore, no functions to allocate
  36. * or freed it on the heap is offered.
  37. */
  38. struct ossl_passphrase_data_st {
  39. enum {
  40. is_expl_passphrase = 1, /* Explicit passphrase given by user */
  41. is_pem_password, /* pem_password_cb given by user */
  42. is_ossl_passphrase, /* OSSL_PASSPHRASE_CALLBACK given by user */
  43. is_ui_method /* UI_METHOD given by user */
  44. } type;
  45. union {
  46. struct {
  47. char *passphrase_copy;
  48. size_t passphrase_len;
  49. } expl_passphrase;
  50. struct {
  51. pem_password_cb *password_cb;
  52. void *password_cbarg;
  53. } pem_password;
  54. struct {
  55. OSSL_PASSPHRASE_CALLBACK *passphrase_cb;
  56. void *passphrase_cbarg;
  57. } ossl_passphrase;
  58. struct {
  59. const UI_METHOD *ui_method;
  60. void *ui_method_data;
  61. } ui_method;
  62. } _;
  63. /*-
  64. * Flags section
  65. */
  66. /* Set to indicate that caching should be done */
  67. unsigned int flag_cache_passphrase:1;
  68. /*-
  69. * Misc section: caches and other
  70. */
  71. char *cached_passphrase;
  72. size_t cached_passphrase_len;
  73. };
  74. /* Structure manipulation */
  75. void ossl_pw_clear_passphrase_data(struct ossl_passphrase_data_st *data);
  76. void ossl_pw_clear_passphrase_cache(struct ossl_passphrase_data_st *data);
  77. int ossl_pw_set_passphrase(struct ossl_passphrase_data_st *data,
  78. const unsigned char *passphrase,
  79. size_t passphrase_len);
  80. int ossl_pw_set_pem_password_cb(struct ossl_passphrase_data_st *data,
  81. pem_password_cb *cb, void *cbarg);
  82. int ossl_pw_set_ossl_passphrase_cb(struct ossl_passphrase_data_st *data,
  83. OSSL_PASSPHRASE_CALLBACK *cb, void *cbarg);
  84. int ossl_pw_set_ui_method(struct ossl_passphrase_data_st *data,
  85. const UI_METHOD *ui_method, void *ui_data);
  86. int ossl_pw_enable_passphrase_caching(struct ossl_passphrase_data_st *data);
  87. int ossl_pw_disable_passphrase_caching(struct ossl_passphrase_data_st *data);
  88. /* Central function for direct calls */
  89. int ossl_pw_get_passphrase(char *pass, size_t pass_size, size_t *pass_len,
  90. const OSSL_PARAM params[], int verify,
  91. struct ossl_passphrase_data_st *data);
  92. /* Callback functions */
  93. /*
  94. * All of these callback expect that the callback argument is a
  95. * struct ossl_passphrase_data_st
  96. */
  97. pem_password_cb ossl_pw_pem_password;
  98. pem_password_cb ossl_pw_pvk_password;
  99. /* One callback for encoding (verification prompt) and one for decoding */
  100. OSSL_PASSPHRASE_CALLBACK ossl_pw_passphrase_callback_enc;
  101. OSSL_PASSPHRASE_CALLBACK ossl_pw_passphrase_callback_dec;
  102. #endif