650d05251336d38e9404f7bc1e9bfd0e294323d2
[strongswan.git] / src / libstrongswan / credentials / builder.h
1 /*
2 * Copyright (C) 2008 Martin Willi
3 * Hochschule fuer Technik Rapperswil
4 *
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; either version 2 of the License, or (at your
8 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
13 * for more details.
14 */
15
16 /**
17 * @defgroup builder builder
18 * @{ @ingroup credentials
19 */
20
21 #ifndef BUILDER_H_
22 #define BUILDER_H_
23
24 typedef struct builder_t builder_t;
25 typedef enum builder_part_t builder_part_t;
26
27 /**
28 * Constructor function which creates a new builder instance.
29 *
30 * @param subtype constructor specific subtype, e.g. certificate_type_t
31 * @return builder to construct a instance of type
32 */
33 typedef builder_t* (*builder_constructor_t)(int subtype);
34
35 #include <library.h>
36
37 /**
38 * Parts to build credentials from.
39 */
40 enum builder_part_t {
41 /** path to a file encoded in any format, char* */
42 BUILD_FROM_FILE,
43 /** file descriptor to read data, encoded in any format, int */
44 BUILD_FROM_FD,
45 /** unix socket of a ssh/pgp agent, char* */
46 BUILD_AGENT_SOCKET,
47 /** DER encoded ASN.1 blob, chunk_t */
48 BUILD_BLOB_ASN1_DER,
49 /** PEM encoded ASN.1/PGP blob, chunk_t */
50 BUILD_BLOB_PEM,
51 /** OpenPGP key blob, chunk_t */
52 BUILD_BLOB_PGP,
53 /** DNS public key blob (RFC 4034, RSA specifc RFC 3110), chunk_t */
54 BUILD_BLOB_DNSKEY,
55 /** passphrase for e.g. PEM decryption, chunk_t */
56 BUILD_PASSPHRASE,
57 /** passphrase callback, chunk_t(*fn)(void *user, int try), void *user.
58 * The callback is invoked until the returned passphrase is accepted, or
59 * a zero-length passphrase is returned. Try starts at 1. */
60 BUILD_PASSPHRASE_CALLBACK,
61 /** key size in bits, as used for key generation, u_int */
62 BUILD_KEY_SIZE,
63 /** private key to use for signing, private_key_t* */
64 BUILD_SIGNING_KEY,
65 /** certificate used for signing, certificate_t* */
66 BUILD_SIGNING_CERT,
67 /** public key to include, public_key_t* */
68 BUILD_PUBLIC_KEY,
69 /** subject for e.g. certificates, identification_t* */
70 BUILD_SUBJECT,
71 /** additional subject name, identification_t* */
72 BUILD_SUBJECT_ALTNAME,
73 /** issuer for e.g. certificates, identification_t* */
74 BUILD_ISSUER,
75 /** additional issuer name, identification_t* */
76 BUILD_ISSUER_ALTNAME,
77 /** notBefore, time_t* */
78 BUILD_NOT_BEFORE_TIME,
79 /** notAfter, time_t* */
80 BUILD_NOT_AFTER_TIME,
81 /** a serial number in binary form, chunk_t */
82 BUILD_SERIAL,
83 /** digest algorithm to be used for signature, int */
84 BUILD_DIGEST_ALG,
85 /** a comma-separated list of ietf group attributes, char* */
86 BUILD_IETF_GROUP_ATTR,
87 /** a ca certificate, certificate_t* */
88 BUILD_CA_CERT,
89 /** a certificate, certificate_t* */
90 BUILD_CERT,
91 /** enforce an additional X509 flag, x509_flag_t */
92 BUILD_X509_FLAG,
93 /** key ID of a key on a smartcard, null terminated char* ([slot:]keyid) */
94 BUILD_SMARTCARD_KEYID,
95 /** pin to access a key on a smartcard, null terminated char* */
96 BUILD_SMARTCARD_PIN,
97 /** modulus (n) of a RSA key, chunk_t */
98 BUILD_RSA_MODULUS,
99 /** public exponent (e) of a RSA key, chunk_t */
100 BUILD_RSA_PUB_EXP,
101 /** private exponent (d) of a RSA key, chunk_t */
102 BUILD_RSA_PRIV_EXP,
103 /** prime 1 (p) of a RSA key (p < q), chunk_t */
104 BUILD_RSA_PRIME1,
105 /** prime 2 (q) of a RSA key (p < q), chunk_t */
106 BUILD_RSA_PRIME2,
107 /** exponent 1 (exp1) of a RSA key, chunk_t */
108 BUILD_RSA_EXP1,
109 /** exponent 2 (exp1) of a RSA key, chunk_t */
110 BUILD_RSA_EXP2,
111 /** coefficient (coeff) of a RSA key, chunk_t */
112 BUILD_RSA_COEFF,
113 /** end of variable argument builder list */
114 BUILD_END,
115 };
116
117 /**
118 * enum names for build_part_t
119 */
120 extern enum_name_t *builder_part_names;
121
122 /**
123 * Credential construction API.
124 *
125 * The builder allows the construction of credentials in a generic and
126 * flexible way.
127 */
128 struct builder_t {
129
130 /**
131 * Add a part to the construct.
132 *
133 * Any added parts are cloned/refcounted by the builder implementation, a
134 * caller may need to free the passed ressources themself.
135 *
136 * @param part kind of part
137 * @param ... part specific variable argument
138 */
139 void (*add)(builder_t *this, builder_part_t part, ...);
140
141 /**
142 * Build the construct with all supplied parts.
143 *
144 * Once build() is called, the builder gets destroyed.
145 *
146 * @return specific interface, as requested with constructor.
147 */
148 void* (*build)(builder_t *this);
149 };
150
151 /**
152 * Helper macro to cancel a build in a builder
153 */
154 #define builder_cancel(builder) { (builder)->add = (void*)nop; \
155 (builder)->build = (void*)builder_free; }
156
157 /**
158 * Helper function for a cancelled build.
159 */
160 void* builder_free(builder_t *this);
161
162 #endif /** BUILDER_H_ @}*/