1 /* SPDX-License-Identifier: LGPL-2.1-or-later */
5 # include <openssl/evp.h>
6 # include <openssl/x509.h>
11 # include <p11-kit/p11-kit.h>
12 # include <p11-kit/uri.h>
15 #include "ask-password-api.h"
17 #include "time-util.h"
19 bool pkcs11_uri_valid(const char *uri
);
23 extern char *(*sym_p11_kit_module_get_name
)(CK_FUNCTION_LIST
*module
);
24 extern void (*sym_p11_kit_modules_finalize_and_release
)(CK_FUNCTION_LIST
**modules
);
25 extern CK_FUNCTION_LIST
**(*sym_p11_kit_modules_load_and_initialize
)(int flags
);
26 extern const char *(*sym_p11_kit_strerror
)(CK_RV rv
);
27 extern int (*sym_p11_kit_uri_format
)(P11KitUri
*uri
, P11KitUriType uri_type
, char **string
);
28 extern void (*sym_p11_kit_uri_free
)(P11KitUri
*uri
);
29 extern CK_ATTRIBUTE_PTR (*sym_p11_kit_uri_get_attributes
)(P11KitUri
*uri
, CK_ULONG
*n_attrs
);
30 extern CK_ATTRIBUTE_PTR (*sym_p11_kit_uri_get_attribute
)(P11KitUri
*uri
, CK_ATTRIBUTE_TYPE attr_type
);
31 extern int (*sym_p11_kit_uri_set_attribute
)(P11KitUri
*uri
, CK_ATTRIBUTE_PTR attr
);
32 extern CK_INFO_PTR (*sym_p11_kit_uri_get_module_info
)(P11KitUri
*uri
);
33 extern CK_SLOT_INFO_PTR (*sym_p11_kit_uri_get_slot_info
)(P11KitUri
*uri
);
34 extern CK_TOKEN_INFO_PTR (*sym_p11_kit_uri_get_token_info
)(P11KitUri
*uri
);
35 extern int (*sym_p11_kit_uri_match_token_info
)(const P11KitUri
*uri
, const CK_TOKEN_INFO
*token_info
);
36 extern const char *(*sym_p11_kit_uri_message
)(int code
);
37 extern P11KitUri
*(*sym_p11_kit_uri_new
)(void);
38 extern int (*sym_p11_kit_uri_parse
)(const char *string
, P11KitUriType uri_type
, P11KitUri
*uri
);
40 int uri_from_string(const char *p
, P11KitUri
**ret
);
42 P11KitUri
*uri_from_module_info(const CK_INFO
*info
);
43 P11KitUri
*uri_from_slot_info(const CK_SLOT_INFO
*slot_info
);
44 P11KitUri
*uri_from_token_info(const CK_TOKEN_INFO
*token_info
);
46 DEFINE_TRIVIAL_CLEANUP_FUNC_FULL(P11KitUri
*, sym_p11_kit_uri_free
, NULL
);
47 DEFINE_TRIVIAL_CLEANUP_FUNC_FULL(CK_FUNCTION_LIST
**, sym_p11_kit_modules_finalize_and_release
, NULL
);
49 CK_RV
pkcs11_get_slot_list_malloc(CK_FUNCTION_LIST
*m
, CK_SLOT_ID
**ret_slotids
, CK_ULONG
*ret_n_slotids
);
51 char *pkcs11_token_label(const CK_TOKEN_INFO
*token_info
);
52 char *pkcs11_token_manufacturer_id(const CK_TOKEN_INFO
*token_info
);
53 char *pkcs11_token_model(const CK_TOKEN_INFO
*token_info
);
55 int pkcs11_token_login_by_pin(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
, const CK_TOKEN_INFO
*token_info
, const char *token_label
, const void *pin
, size_t pin_size
);
56 int pkcs11_token_login(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
, CK_SLOT_ID slotid
, const CK_TOKEN_INFO
*token_info
, const char *friendly_name
, const char *icon_name
, const char *key_name
, const char *credential_name
, usec_t until
, AskPasswordFlags ask_password_flags
, bool headless
, char **ret_used_pin
);
58 int pkcs11_token_find_related_object(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
, CK_OBJECT_HANDLE prototype
, CK_OBJECT_CLASS
class, CK_OBJECT_HANDLE
*ret_object
);
59 int pkcs11_token_find_x509_certificate(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
, P11KitUri
*search_uri
, CK_OBJECT_HANDLE
*ret_object
);
61 int pkcs11_token_read_public_key(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
, CK_OBJECT_HANDLE object
, EVP_PKEY
**ret_pkey
);
62 int pkcs11_token_read_x509_certificate(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
, CK_OBJECT_HANDLE object
, X509
**ret_cert
);
65 int pkcs11_token_find_private_key(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
, P11KitUri
*search_uri
, CK_OBJECT_HANDLE
*ret_object
);
66 int pkcs11_token_decrypt_data(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
, CK_OBJECT_HANDLE object
, const void *encrypted_data
, size_t encrypted_data_size
, void **ret_decrypted_data
, size_t *ret_decrypted_data_size
);
68 int pkcs11_token_acquire_rng(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
);
70 typedef int (*pkcs11_find_token_callback_t
)(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
, CK_SLOT_ID slotid
, const CK_SLOT_INFO
*slot_info
, const CK_TOKEN_INFO
*token_info
, P11KitUri
*uri
, void *userdata
);
71 int pkcs11_find_token(const char *pkcs11_uri
, pkcs11_find_token_callback_t callback
, void *userdata
);
74 int pkcs11_acquire_public_key(const char *uri
, const char *askpw_friendly_name
, const char *askpw_icon_name
, EVP_PKEY
**ret_pkey
, char **ret_pin_used
);
78 const char *friendly_name
;
81 size_t encrypted_key_size
;
83 size_t decrypted_key_size
;
84 bool free_encrypted_key
;
86 AskPasswordFlags askpw_flags
;
87 } pkcs11_crypt_device_callback_data
;
89 void pkcs11_crypt_device_callback_data_release(pkcs11_crypt_device_callback_data
*data
);
91 int pkcs11_crypt_device_callback(
93 CK_SESSION_HANDLE session
,
95 const CK_SLOT_INFO
*slot_info
,
96 const CK_TOKEN_INFO
*token_info
,
100 int dlopen_p11kit(void);
104 static inline int dlopen_p11kit(void) {
105 return log_error_errno(SYNTHETIC_ERRNO(EOPNOTSUPP
), "p11kit support is not compiled in.");
111 const char *friendly_name
;
114 AskPasswordFlags askpw_flags
;
115 } systemd_pkcs11_plugin_params
;
117 int pkcs11_list_tokens(void);
118 int pkcs11_find_token_auto(char **ret
);