cert_util.h 8.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231
  1. #ifndef NETSNMP_CERT_UTIL_H
  2. #if defined(NETSNMP_USE_OPENSSL) && defined(HAVE_LIBSSL)
  3. #ifndef HEADER_SSL_H
  4. #error "must include <openssl/ssl.h> before cert_util.h"
  5. #endif
  6. #ifndef HEADER_X509_H
  7. #error "must include <openssl/x509.h> before cert_util.h"
  8. #endif
  9. #ifdef __cplusplus
  10. extern "C" {
  11. #endif
  12. /*************************************************************************
  13. *
  14. * netsnmp_cert structures, defines and function definitions
  15. *
  16. *************************************************************************/
  17. void netsnmp_certs_init(void);
  18. NETSNMP_IMPORT
  19. void netsnmp_certs_agent_init(void);
  20. void netsnmp_certs_shutdown(void);
  21. void netsnmp_certs_load(void);
  22. netsnmp_container *netsnmp_cert_get_trustlist(void);
  23. typedef struct netsnmp_cert_common_s {
  24. char *dir;
  25. char *filename;
  26. u_char type;
  27. u_char allowed_uses;
  28. u_char _pad[2]; /* for future use */
  29. } netsnmp_cert_common;
  30. typedef struct netsnmp_key_s {
  31. netsnmp_cert_common info;
  32. EVP_PKEY *okey;
  33. struct netsnmp_cert_s *cert;
  34. } netsnmp_key;
  35. typedef struct netsnmp_cert_s {
  36. netsnmp_cert_common info;
  37. X509 *ocert;
  38. netsnmp_key *key;
  39. struct netsnmp_cert_s *issuer_cert;
  40. char *issuer;
  41. char *subject;
  42. char *fingerprint;
  43. char *common_name;
  44. u_char hash_type;
  45. u_char _pad[3]; /* for future use */
  46. } netsnmp_cert;
  47. /** types */
  48. enum { NS_CERT_TYPE_UNKNOWN = 0, NS_CERT_TYPE_PEM, NS_CERT_TYPE_DER,
  49. NS_CERT_TYPE_PKCS12, NS_CERT_TYPE_KEY };
  50. /** uses */
  51. #define NS_CERT_IDENTITY 0x0001
  52. #define NS_CERT_REMOTE_PEER 0x0002
  53. #define NS_CERT_RESERVED1 0x0004
  54. #define NS_CERT_CA 0x0008
  55. /** source */
  56. #define NS_CERTKEY_DEFAULT 0x000 /* get default from DS store */
  57. #define NS_CERTKEY_FILE 0x001 /* filename/full path */
  58. #define NS_CERTKEY_FINGERPRINT 0x002 /* public key fingerprint */
  59. #define NS_CERTKEY_CA 0x004 /* trusted CA */
  60. #define NS_CERTKEY_SAN_RFC822 0x008 /* subj alt name: rfc822 */
  61. #define NS_CERTKEY_SAN_DNS 0x010 /* subj alt name: DNS */
  62. #define NS_CERTKEY_SAN_IPADDR 0x020 /* subj alt name: IP address */
  63. #define NS_CERTKEY_COMMON_NAME 0x040 /* common name */
  64. #define NS_CERTKEY_TARGET_PARAM 0x080 /* tlstmParamsTable */
  65. #define NS_CERTKEY_TARGET_ADDR 0x100 /* tlstmAddrTable */
  66. #define NS_CERTKEY_MULTIPLE 0x200 /* try multiple sources */
  67. /** RFC 5246 hash algorithms (Section 7.4.1.4.1) */
  68. #define NS_HASH_NONE 0
  69. #define NS_HASH_MD5 1
  70. #define NS_HASH_SHA1 2
  71. #define NS_HASH_SHA224 3
  72. #define NS_HASH_SHA256 4
  73. #define NS_HASH_SHA384 5
  74. #define NS_HASH_SHA512 6
  75. #define NS_HASH_MAX NS_HASH_SHA512
  76. /** SNMP-TLS-TM-MIB */
  77. #define SNMPTLSFINGERPRINT_MAX_LEN 255
  78. /*************************************************************************
  79. * netsnmp_cert function definitions
  80. *************************************************************************/
  81. NETSNMP_IMPORT
  82. netsnmp_cert *netsnmp_cert_find(int what, int where, void *hint);
  83. int netsnmp_cert_check_vb_fingerprint(const netsnmp_variable_list *var);
  84. void netsnmp_fp_lowercase_and_strip_colon(char *fp);
  85. int netsnmp_cert_parse_hash_type(const char *str);
  86. int netsnmp_tls_fingerprint_build(int hash_type, const char *hex_fp,
  87. u_char **tls_fp, size_t *tls_fp_len,
  88. int allow_realloc);
  89. int netsnmp_tls_fingerprint_parse(const u_char *binary_fp, int fp_len,
  90. char **fp_str_ptr, u_int *fp_str_len,
  91. int allow_realloc, u_char *hash_type_ptr);
  92. int netsnmp_cert_trust(SSL_CTX *ctx, netsnmp_cert *thiscert);
  93. int netsnmp_cert_trust_ca(SSL_CTX *ctx, netsnmp_cert *thiscertsrootca);
  94. /*************************************************************************
  95. *
  96. * certificate to Transport Security Name mapping (netsnmp_cert_map)
  97. *
  98. *************************************************************************/
  99. #define TSNM_tlstmCertSpecified 1
  100. #define TSNM_tlstmCertSANRFC822Name 2
  101. #define TSNM_tlstmCertSANDNSName 3
  102. #define TSNM_tlstmCertSANIpAddress 4
  103. #define TSNM_tlstmCertSANAny 5
  104. #define TSNM_tlstmCertCommonName 6
  105. #define TSNM_tlstmCert_MAX TSNM_tlstmCertCommonName
  106. #define NSCM_FROM_CONFIG 0x0001
  107. #define NSCM_FROM_MIB 0x0002
  108. #define NSCM_NONVOLATILE 0x0004
  109. typedef struct netsnmp_cert_map_s {
  110. int priority;
  111. char *fingerprint;
  112. int mapType;
  113. char *data;
  114. char hashType;
  115. char flags;
  116. X509 *ocert;
  117. } netsnmp_cert_map;
  118. netsnmp_cert_map *netsnmp_cert_map_alloc(char *fp, X509 *ocert);
  119. void netsnmp_cert_map_free(netsnmp_cert_map *cert_map);
  120. int netsnmp_cert_map_add(netsnmp_cert_map *map);
  121. int netsnmp_cert_map_remove(netsnmp_cert_map *map);
  122. netsnmp_cert_map *netsnmp_cert_map_find(netsnmp_cert_map *map);
  123. void netsnmp_cert_map_container_free(netsnmp_container *c);
  124. netsnmp_container *netsnmp_cert_map_container_create(int with_fp);
  125. netsnmp_container *netsnmp_cert_map_container(void);
  126. netsnmp_cert_map *netsnmp_certToTSN_parse_common(char **line);
  127. int netsnmp_cert_get_secname_maps(netsnmp_container *cm);
  128. /*************************************************************************
  129. *
  130. * snmpTlstmParamsTable data
  131. *
  132. *************************************************************************/
  133. typedef struct snmpTlstmParams_s {
  134. char *name;
  135. char *fingerprint;
  136. char hashType;
  137. u_char flags;
  138. u_char fingerprint_len;
  139. } snmpTlstmParams;
  140. #define TLSTM_PARAMS_FROM_CONFIG 0x01
  141. #define TLSTM_PARAMS_FROM_MIB 0x02
  142. #define TLSTM_PARAMS_NONVOLATILE 0x04
  143. /** ine TLSTM_PARAMS_XXX 0x08 */
  144. snmpTlstmParams *netsnmp_tlstmParams_create(const char *tag, int hashType,
  145. const char *fp, int fp_len);
  146. void netsnmp_tlstmParams_free(snmpTlstmParams *stp);
  147. snmpTlstmParams *netsnmp_tlstmParams_restore_common(char **line);
  148. netsnmp_container *netsnmp_tlstmParams_container(void);
  149. int netsnmp_tlstmParams_add(snmpTlstmParams *stp);
  150. int netsnmp_tlstmParams_remove(snmpTlstmParams *stp);
  151. snmpTlstmParams *netsnmp_tlstmParams_find(snmpTlstmParams *stp);
  152. /*************************************************************************
  153. *
  154. * snmpTlstmAddrTable data
  155. *
  156. *************************************************************************/
  157. typedef struct snmpTlstmAddr_s {
  158. char *name;
  159. char *fingerprint;
  160. char *identity;
  161. u_char hashType;
  162. u_char flags;
  163. } snmpTlstmAddr;
  164. #define TLSTM_ADDR_FROM_CONFIG 0x01
  165. #define TLSTM_ADDR_FROM_MIB 0x02
  166. #define TLSTM_ADDR_NONVOLATILE 0x04
  167. /** ine TLSTM_ADDR_XXX 0x08 */
  168. int netsnmp_tlstmAddr_restore_common(char **line, char *name,
  169. size_t *name_len, char *id,
  170. size_t *id_len, char *fp,
  171. size_t *fp_len, u_char *ht);
  172. netsnmp_container *netsnmp_tlstmAddr_container(void);
  173. snmpTlstmAddr *netsnmp_tlstmAddr_find(snmpTlstmAddr *entry);
  174. snmpTlstmAddr *netsnmp_tlstmAddr_create(char *targetAddrName);
  175. void netsnmp_tlstmAddr_free(snmpTlstmAddr *entry);
  176. int netsnmp_tlstmAddr_add(snmpTlstmAddr *entry);
  177. int netsnmp_tlstmAddr_remove(snmpTlstmAddr *entry);
  178. NETSNMP_IMPORT
  179. char *netsnmp_tlstmAddr_get_serverId(const char *name);
  180. #ifdef __cplusplus
  181. }
  182. #endif
  183. #endif /* defined(NETSNMP_USE_OPENSSL) && defined(HAVE_LIBSSL) */
  184. #endif /* NETSNMP_CERT_UTIL_H */