2 * This file is part of PowerDNS or dnsdist.
3 * Copyright -- PowerDNS.COM B.V. and its contributors
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of version 2 of the GNU General Public License as
7 * published by the Free Software Foundation.
9 * In addition, for the avoidance of any doubt, permission is granted to
10 * link this program with OpenSSL and to (re)distribute the binaries
11 * produced as the result of such linking.
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, write to the Free Software
20 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
22 #ifndef PDNS_PKCS11SIGNERS_HH
23 #define PDNS_PKCS11SIGNERS_HH
25 class PKCS11DNSCryptoKeyEngine : public DNSCryptoKeyEngine
29 std::string d_slot_id;
32 std::string d_pub_label;
35 PKCS11DNSCryptoKeyEngine(unsigned int algorithm);
36 ~PKCS11DNSCryptoKeyEngine();
38 bool operator<(const PKCS11DNSCryptoKeyEngine& rhs) const
42 PKCS11DNSCryptoKeyEngine(const PKCS11DNSCryptoKeyEngine& orig);
44 string getName() const override { return "P11 Kit PKCS#11"; };
46 void create(unsigned int bits) override;
48 storvector_t convertToISCVector() const override;
50 std::string sign(const std::string& msg) const override;
52 std::string hash(const std::string& msg) const override;
54 bool verify(const std::string& msg, const std::string& signature) const override;
56 std::string getPubKeyHash() const override;
58 std::string getPublicKeyString() const override;
59 int getBits() const override;
61 void fromISCMap(DNSKEYRecordContent& drc, stormap_t& stormap) override;
63 void fromPEMString(DNSKEYRecordContent& drc, const std::string& raw) override { throw "Unimplemented"; };
64 void fromPublicKeyString(const std::string& content) override { throw "Unimplemented"; };
66 static std::shared_ptr<DNSCryptoKeyEngine> maker(unsigned int algorithm);
69 bool PKCS11ModuleSlotLogin(const std::string& module, const string& tokenId, const std::string& pin);
71 #endif /* PDNS_PKCS11SIGNERS_HH */