1 /* SPDX-License-Identifier: LGPL-2.1-or-later */
7 # include <p11-kit/p11-kit.h>
8 # include <p11-kit/uri.h>
12 #include "openssl-util.h"
13 #include "time-util.h"
15 bool pkcs11_uri_valid(const char *uri
);
18 int uri_from_string(const char *p
, P11KitUri
**ret
);
20 P11KitUri
*uri_from_module_info(const CK_INFO
*info
);
21 P11KitUri
*uri_from_slot_info(const CK_SLOT_INFO
*slot_info
);
22 P11KitUri
*uri_from_token_info(const CK_TOKEN_INFO
*token_info
);
24 DEFINE_TRIVIAL_CLEANUP_FUNC_FULL(P11KitUri
*, p11_kit_uri_free
, NULL
);
25 DEFINE_TRIVIAL_CLEANUP_FUNC_FULL(CK_FUNCTION_LIST
**, p11_kit_modules_finalize_and_release
, NULL
);
27 CK_RV
pkcs11_get_slot_list_malloc(CK_FUNCTION_LIST
*m
, CK_SLOT_ID
**ret_slotids
, CK_ULONG
*ret_n_slotids
);
29 char *pkcs11_token_label(const CK_TOKEN_INFO
*token_info
);
30 char *pkcs11_token_manufacturer_id(const CK_TOKEN_INFO
*token_info
);
31 char *pkcs11_token_model(const CK_TOKEN_INFO
*token_info
);
33 int pkcs11_token_login(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
, CK_SLOT_ID slotid
, const CK_TOKEN_INFO
*token_info
, const char *friendly_name
, const char *icon_name
, const char *key_name
, const char *credential_name
, usec_t until
, bool headless
, char **ret_used_pin
);
35 int pkcs11_token_find_x509_certificate(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
, P11KitUri
*search_uri
, CK_OBJECT_HANDLE
*ret_object
);
37 int pkcs11_token_read_x509_certificate(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
, CK_OBJECT_HANDLE object
, X509
**ret_cert
);
40 int pkcs11_token_find_private_key(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
, P11KitUri
*search_uri
, CK_OBJECT_HANDLE
*ret_object
);
41 int pkcs11_token_decrypt_data(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
, CK_OBJECT_HANDLE object
, const void *encrypted_data
, size_t encrypted_data_size
, void **ret_decrypted_data
, size_t *ret_decrypted_data_size
);
43 int pkcs11_token_acquire_rng(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
);
45 typedef int (*pkcs11_find_token_callback_t
)(CK_FUNCTION_LIST
*m
, CK_SESSION_HANDLE session
, CK_SLOT_ID slotid
, const CK_SLOT_INFO
*slot_info
, const CK_TOKEN_INFO
*token_info
, P11KitUri
*uri
, void *userdata
);
46 int pkcs11_find_token(const char *pkcs11_uri
, pkcs11_find_token_callback_t callback
, void *userdata
);
49 int pkcs11_acquire_certificate(const char *uri
, const char *askpw_friendly_name
, const char *askpw_icon_name
, X509
**ret_cert
, char **ret_pin_used
);
53 const char *friendly_name
;
56 size_t encrypted_key_size
;
58 size_t decrypted_key_size
;
59 bool free_encrypted_key
;
61 } pkcs11_crypt_device_callback_data
;
63 void pkcs11_crypt_device_callback_data_release(pkcs11_crypt_device_callback_data
*data
);
65 int pkcs11_crypt_device_callback(
67 CK_SESSION_HANDLE session
,
69 const CK_SLOT_INFO
*slot_info
,
70 const CK_TOKEN_INFO
*token_info
,
76 int pkcs11_list_tokens(void);
77 int pkcs11_find_token_auto(char **ret
);