snmp_secmod.h 5.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183
  1. #ifndef SNMPSECMOD_H
  2. #define SNMPSECMOD_H
  3. #ifdef __cplusplus
  4. extern "C" {
  5. #endif
  6. #include <net-snmp/library/snmp_transport.h>
  7. /* Locally defined security models.
  8. * (Net-SNMP enterprise number = 8072)*256 + local_num
  9. */
  10. #define NETSNMP_SEC_MODEL_KSM 2066432
  11. #define NETSNMP_KSM_SECURITY_MODEL NETSNMP_SEC_MODEL_KSM
  12. #define NETSNMP_TSM_SECURITY_MODEL SNMP_SEC_MODEL_TSM
  13. struct snmp_secmod_def;
  14. /*
  15. * parameter information passed to security model routines
  16. */
  17. struct snmp_secmod_outgoing_params {
  18. int msgProcModel;
  19. u_char *globalData;
  20. size_t globalDataLen;
  21. int maxMsgSize;
  22. int secModel;
  23. u_char *secEngineID;
  24. size_t secEngineIDLen;
  25. char *secName;
  26. size_t secNameLen;
  27. int secLevel;
  28. u_char *scopedPdu;
  29. size_t scopedPduLen;
  30. void *secStateRef;
  31. u_char *secParams;
  32. size_t *secParamsLen;
  33. u_char **wholeMsg;
  34. size_t *wholeMsgLen;
  35. size_t *wholeMsgOffset;
  36. netsnmp_pdu *pdu; /* IN - the pdu getting encoded */
  37. netsnmp_session *session; /* IN - session sending the message */
  38. };
  39. struct snmp_secmod_incoming_params {
  40. int msgProcModel; /* IN */
  41. size_t maxMsgSize; /* IN - Used to calc maxSizeResponse. */
  42. u_char *secParams; /* IN - BER encoded securityParameters. */
  43. int secModel; /* IN */
  44. int secLevel; /* IN - AuthNoPriv; authPriv etc. */
  45. u_char *wholeMsg; /* IN - Original v3 message. */
  46. size_t wholeMsgLen; /* IN - Msg length. */
  47. u_char *secEngineID; /* OUT - Pointer snmpEngineID. */
  48. size_t *secEngineIDLen; /* IN/OUT - Len available; len returned. */
  49. /*
  50. * NOTE: Memory provided by caller.
  51. */
  52. char *secName; /* OUT - Pointer to securityName. */
  53. size_t *secNameLen; /* IN/OUT - Len available; len returned. */
  54. u_char **scopedPdu; /* OUT - Pointer to plaintext scopedPdu. */
  55. size_t *scopedPduLen; /* IN/OUT - Len available; len returned. */
  56. size_t *maxSizeResponse; /* OUT - Max size of Response PDU. */
  57. void **secStateRef; /* OUT - Ref to security state. */
  58. netsnmp_session *sess; /* IN - session which got the message */
  59. netsnmp_pdu *pdu; /* IN - the pdu getting parsed */
  60. u_char msg_flags; /* IN - v3 Message flags. */
  61. };
  62. /*
  63. * function pointers:
  64. */
  65. /*
  66. * free's a given security module's data; called at unregistration time
  67. */
  68. typedef int (SecmodSessionCallback) (netsnmp_session *);
  69. typedef int (SecmodPduCallback) (netsnmp_pdu *);
  70. typedef int (Secmod2PduCallback) (netsnmp_pdu *, netsnmp_pdu *);
  71. typedef int (SecmodOutMsg) (struct snmp_secmod_outgoing_params *);
  72. typedef int (SecmodInMsg) (struct snmp_secmod_incoming_params *);
  73. typedef void (SecmodFreeState) (void *);
  74. typedef void (SecmodHandleReport) (struct session_list *slp,
  75. netsnmp_transport *transport,
  76. netsnmp_session *,
  77. int result,
  78. netsnmp_pdu *origpdu);
  79. typedef int (SecmodDiscoveryMethod) (struct session_list *slp,
  80. netsnmp_session *session);
  81. typedef int (SecmodPostDiscovery) (struct session_list *slp,
  82. netsnmp_session *session);
  83. typedef int (SecmodSessionSetup) (netsnmp_session *in_session,
  84. netsnmp_session *out_session);
  85. /*
  86. * definition of a security module
  87. */
  88. /*
  89. * all of these callback functions except the encoding and decoding
  90. * routines are optional. The rest of them are available if need.
  91. */
  92. struct snmp_secmod_def {
  93. /*
  94. * session maniplation functions
  95. */
  96. SecmodSessionCallback *session_open; /* called in snmp_sess_open() */
  97. SecmodSessionCallback *session_close; /* called in snmp_sess_close() */
  98. SecmodSessionSetup *session_setup;
  99. /*
  100. * pdu manipulation routines
  101. */
  102. SecmodPduCallback *pdu_free; /* called in free_pdu() */
  103. Secmod2PduCallback *pdu_clone; /* called in snmp_clone_pdu() */
  104. SecmodPduCallback *pdu_timeout; /* called when request timesout */
  105. SecmodFreeState *pdu_free_state_ref; /* frees pdu->securityStateRef */
  106. /*
  107. * de/encoding routines: mandatory
  108. */
  109. SecmodOutMsg *encode_reverse; /* encode packet back to front */
  110. SecmodOutMsg *encode_forward; /* encode packet forward */
  111. SecmodInMsg *decode; /* decode & validate incoming */
  112. /*
  113. * error and report handling
  114. */
  115. SecmodHandleReport *handle_report;
  116. /*
  117. * default engineID discovery mechanism
  118. */
  119. SecmodDiscoveryMethod *probe_engineid;
  120. SecmodPostDiscovery *post_probe_engineid;
  121. };
  122. /*
  123. * internal list
  124. */
  125. struct snmp_secmod_list {
  126. int securityModel;
  127. struct snmp_secmod_def *secDef;
  128. struct snmp_secmod_list *next;
  129. };
  130. /*
  131. * register a security service
  132. */
  133. int register_sec_mod(int, const char *,
  134. struct snmp_secmod_def *);
  135. /*
  136. * find a security service definition
  137. */
  138. NETSNMP_IMPORT
  139. struct snmp_secmod_def *find_sec_mod(int);
  140. /*
  141. * register a security service
  142. */
  143. int unregister_sec_mod(int); /* register a security service */
  144. void init_secmod(void);
  145. NETSNMP_IMPORT
  146. void shutdown_secmod(void);
  147. /*
  148. * clears the sec_mod list
  149. */
  150. NETSNMP_IMPORT
  151. void clear_sec_mod(void);
  152. #ifdef __cplusplus
  153. }
  154. #endif
  155. #endif /* SNMPSECMOD_H */