scapi.h 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211
  1. /*
  2. * scapi.h
  3. *
  4. * Portions of this file are copyrighted by:
  5. * Copyright (c) 2016 VMware, Inc. All rights reserved.
  6. * Use is subject to license terms specified in the COPYING file
  7. * distributed with the Net-SNMP package.
  8. */
  9. #ifndef _SCAPI_H
  10. #define _SCAPI_H
  11. #ifdef NETSNMP_USE_OPENSSL
  12. #include <openssl/ossl_typ.h> /* EVP_MD */
  13. #endif
  14. #ifdef __cplusplus
  15. extern "C" {
  16. #endif
  17. /*
  18. * Authentication/privacy transform bitlengths.
  19. */
  20. #define SNMP_TRANS_AUTHLEN_HMACMD5 128
  21. #define SNMP_TRANS_AUTHLEN_HMACSHA1 160
  22. #define SNMP_TRANS_AUTHLEN_HMAC128SHA224 224 /* OPTIONAL */
  23. #define SNMP_TRANS_AUTHLEN_HMAC192SHA256 256 /* MUST */
  24. #define SNMP_TRANS_AUTHLEN_HMAC256SHA384 384 /* OPTIONAL */
  25. #define SNMP_TRANS_AUTHLEN_HMAC384SHA512 512 /* SHOULD */
  26. #define SNMP_TRANS_AUTHLEN_HMAC96 96
  27. #define SNMP_TRANS_PRIVLEN_1DES 64
  28. #define SNMP_TRANS_PRIVLEN_1DES_IV 64
  29. #ifdef NETSNMP_DRAFT_REEDER_3DES
  30. #define SNMP_TRANS_PRIVLEN_3DESEDE 256
  31. #define SNMP_TRANS_PRIVLEN_3DESEDE_IV 64
  32. #endif /* NETSNMP_DRAFT_REEDER_3DES */
  33. #define SNMP_TRANS_PRIVLEN_AES 128
  34. #define SNMP_TRANS_PRIVLEN_AES_IV 128
  35. #define SNMP_TRANS_PRIVLEN_AES128 SNMP_TRANS_PRIVLEN_AES
  36. #define SNMP_TRANS_PRIVLEN_AES128_IV SNMP_TRANS_PRIVLEN_AES_IV
  37. #define SNMP_TRANS_PRIVLEN_AES192 192
  38. #define SNMP_TRANS_PRIVLEN_AES192_IV 128 /* 192 */
  39. #define SNMP_TRANS_PRIVLEN_AES256 256
  40. #define SNMP_TRANS_PRIVLEN_AES256_IV 128 /* 256 */
  41. typedef struct netsnmp_auth_alg_info_s {
  42. int type;
  43. const char * name;
  44. oid * alg_oid;
  45. int oid_len;
  46. int proper_length;
  47. int mac_length;
  48. } netsnmp_auth_alg_info;
  49. typedef struct netsnmp_priv_alg_info_s {
  50. int type;
  51. const char * name;
  52. oid * alg_oid;
  53. int oid_len;
  54. int proper_length;
  55. int iv_length;
  56. int pad_size;
  57. #ifdef NETSNMP_USE_OPENSSL
  58. const EVP_CIPHER * cipher;
  59. #endif
  60. } netsnmp_priv_alg_info;
  61. /*
  62. * Prototypes.
  63. */
  64. NETSNMP_IMPORT
  65. int sc_get_authtype(const oid * hashoid, u_int hashoid_len);
  66. NETSNMP_IMPORT
  67. int sc_get_proper_auth_length_bytype(int auth_type);
  68. NETSNMP_IMPORT
  69. int sc_get_auth_maclen(int auth_type);
  70. NETSNMP_IMPORT
  71. const char* sc_get_auth_name(int auth_type);
  72. NETSNMP_IMPORT
  73. oid * sc_get_auth_oid(int auth_type, size_t *oid_len);
  74. NETSNMP_IMPORT
  75. const netsnmp_auth_alg_info *
  76. sc_find_auth_alg_byoid(const oid *oid, u_int len);
  77. NETSNMP_IMPORT
  78. const netsnmp_auth_alg_info *
  79. sc_find_auth_alg_bytype(u_int type);
  80. NETSNMP_IMPORT
  81. const netsnmp_auth_alg_info * sc_get_auth_alg_byindex(u_int index);
  82. /** deprectated, use
  83. * sc_get_authtype() + sc_get_proper_auth_length_bytype() */
  84. NETSNMP_IMPORT
  85. int sc_get_properlength(const oid * hashtype,
  86. u_int hashtype_len);
  87. #ifdef NETSNMP_USE_OPENSSL
  88. NETSNMP_IMPORT
  89. const EVP_MD *sc_get_openssl_hashfn(int auth_type);
  90. NETSNMP_IMPORT
  91. const EVP_CIPHER *sc_get_openssl_privfn(int priv_type);
  92. #endif
  93. NETSNMP_IMPORT
  94. int sc_get_privtype(const oid * privtype, u_int privtype_len);
  95. NETSNMP_IMPORT
  96. oid * sc_get_priv_oid(int type, size_t *oid_len);
  97. NETSNMP_IMPORT
  98. int sc_get_proper_priv_length(const oid * privtype,
  99. u_int privtype_len);
  100. NETSNMP_IMPORT
  101. int sc_get_proper_priv_length_bytype(int privtype);
  102. NETSNMP_IMPORT
  103. const netsnmp_priv_alg_info *
  104. sc_get_priv_alg_byoid(const oid *oid, u_int len);
  105. NETSNMP_IMPORT
  106. const netsnmp_priv_alg_info * sc_get_priv_alg_bytype(u_int type);
  107. NETSNMP_IMPORT
  108. const netsnmp_priv_alg_info * sc_get_priv_alg_byindex(u_int index);
  109. NETSNMP_IMPORT
  110. int sc_init(void);
  111. NETSNMP_IMPORT
  112. int sc_shutdown(int majorID, int minorID, void *serverarg,
  113. void *clientarg);
  114. NETSNMP_IMPORT
  115. int sc_random(u_char * buf, size_t * buflen);
  116. NETSNMP_IMPORT
  117. int sc_generate_keyed_hash(const oid * authtype,
  118. size_t authtypelen,
  119. const u_char * key, u_int keylen,
  120. const u_char * message, u_int msglen,
  121. u_char * MAC, size_t * maclen);
  122. NETSNMP_IMPORT
  123. int sc_check_keyed_hash(const oid * authtype,
  124. size_t authtypelen, const u_char * key,
  125. u_int keylen, const u_char * message,
  126. u_int msglen, const u_char * MAC,
  127. u_int maclen);
  128. NETSNMP_IMPORT
  129. int sc_encrypt(const oid * privtype, size_t privtypelen,
  130. u_char * key, u_int keylen,
  131. u_char * iv, u_int ivlen,
  132. const u_char * plaintext, u_int ptlen,
  133. u_char * ciphertext, size_t * ctlen);
  134. NETSNMP_IMPORT
  135. int sc_decrypt(const oid * privtype, size_t privtypelen,
  136. u_char * key, u_int keylen,
  137. u_char * iv, u_int ivlen,
  138. u_char * ciphertext, u_int ctlen,
  139. u_char * plaintext, size_t * ptlen);
  140. NETSNMP_IMPORT
  141. int sc_hash_type(int auth_type, const u_char * buf,
  142. size_t buf_len, u_char * MAC,
  143. size_t * MAC_len);
  144. NETSNMP_IMPORT
  145. int sc_hash(const oid * hashtype, size_t hashtypelen,
  146. const u_char * buf, size_t buf_len,
  147. u_char * MAC, size_t * MAC_len);
  148. NETSNMP_IMPORT
  149. int sc_get_transform_type(oid * hashtype,
  150. u_int hashtype_len,
  151. int (**hash_fn) (const int mode,
  152. void **context,
  153. const u_char *
  154. data,
  155. const int
  156. data_len,
  157. u_char **
  158. digest,
  159. size_t *
  160. digest_len));
  161. /*
  162. * All functions devolve to the following block if we can't do cryptography
  163. */
  164. #define _SCAPI_NOT_CONFIGURED \
  165. { \
  166. snmp_log(LOG_ERR, "Encryption support not enabled.\n"); \
  167. DEBUGMSGTL(("scapi", "SCAPI not configured")); \
  168. return SNMPERR_SC_NOT_CONFIGURED; \
  169. }
  170. /*
  171. * define a transform type if we're using the internal md5 support
  172. */
  173. #ifdef NETSNMP_USE_INTERNAL_MD5
  174. #define INTERNAL_MD5 1
  175. #endif
  176. #ifdef __cplusplus
  177. }
  178. #endif
  179. #endif /* _SCAPI_H */