Updated PKCS#7 parser/generator in libstrongswan.
[strongswan.git] / src / libstrongswan / crypto / pkcs7.h
1 /*
2 * Copyright (C) 2005 Jan Hutter, Martin Willi
3 * Copyright (C) 2002-2008 Andreas Steffen
4 * Hochschule fuer Technik Rapperswil, Switzerland
5 *
6 * This program is free software; you can redistribute it and/or modify it
7 * under the terms of the GNU General Public License as published by the
8 * Free Software Foundation; either version 2 of the License, or (at your
9 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
10 *
11 * This program is distributed in the hope that it will be useful, but
12 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
13 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
14 * for more details.
15 */
16
17 /**
18 * @defgroup pkcs7 pkcs7
19 * @{ @ingroup crypto
20 */
21
22 #ifndef PKCS7_H_
23 #define PKCS7_H_
24
25 typedef struct pkcs7_t pkcs7_t;
26
27 #include <library.h>
28 #include <credentials/keys/private_key.h>
29 #include <crypto/pkcs9.h>
30 #include <crypto/crypters/crypter.h>
31 #include <utils/enumerator.h>
32
33 /**
34 * PKCS#7 contentInfo object.
35 */
36 struct pkcs7_t {
37
38 /**
39 * Check if the PKCS#7 contentType is data
40 *
41 * @return TRUE if the contentType is data
42 */
43 bool (*is_data) (pkcs7_t *this);
44
45 /**
46 * Check if the PKCS#7 contentType is signedData
47 *
48 * @return TRUE if the contentType is signedData
49 */
50 bool (*is_signedData) (pkcs7_t *this);
51
52 /**
53 * Check if the PKCS#7 contentType is envelopedData
54 *
55 * @return TRUE if the contentType is envelopedData
56 */
57 bool (*is_envelopedData) (pkcs7_t *this);
58
59 /**
60 * Parse a PKCS#7 data content.
61 *
62 * @return TRUE if parsing was successful
63 */
64 bool (*parse_data) (pkcs7_t *this);
65
66 /**
67 * Parse a PKCS#7 signedData content.
68 *
69 * @param cacert cacert used to verify the signature
70 * @return TRUE if parsing was successful
71 */
72 bool (*parse_signedData) (pkcs7_t *this, certificate_t *cacert);
73
74 /**
75 * Parse a PKCS#7 envelopedData content.
76 *
77 * @param serialNumber serialNumber of the request
78 * @param key private key used to decrypt the symmetric key
79 * @return TRUE if parsing was successful
80 */
81 bool (*parse_envelopedData) (pkcs7_t *this, chunk_t serialNumber,
82 private_key_t *key);
83
84 /**
85 * Returns the parsed data object
86 *
87 * @return chunk containing the data object
88 */
89 chunk_t (*get_data) (pkcs7_t *this);
90
91 /**
92 * Returns the a DER-encoded contentInfo object
93 *
94 * @return chunk containing the contentInfo object
95 */
96 chunk_t (*get_contentInfo) (pkcs7_t *this);
97
98 /**
99 * Create an enumerator for the certificates.
100 *
101 * @return enumerator for the certificates
102 */
103 enumerator_t *(*create_certificate_enumerator) (pkcs7_t *this);
104
105 /**
106 * Add a certificate.
107 *
108 * @param cert certificate to be included (gets adopted)
109 */
110 void (*set_certificate) (pkcs7_t *this, certificate_t *cert);
111
112 /**
113 * Add authenticated attributes.
114 *
115 * @param attributes attributes to be included
116 */
117 void (*set_attributes) (pkcs7_t *this, pkcs9_t *attributes);
118
119 /**
120 * Build a data object
121 *
122 * @return TRUE if build was successful
123 */
124 bool (*build_data) (pkcs7_t *this);
125
126 /**
127 * Build an envelopedData object
128 *
129 * @param cert receivers's certificate
130 * @param alg encryption algorithm
131 * @param key_size key size to use
132 * @return TRUE if build was successful
133 */
134 bool (*build_envelopedData) (pkcs7_t *this, certificate_t *cert,
135 encryption_algorithm_t alg, size_t key_size);
136
137 /**
138 * Build an signedData object
139 *
140 * @param key signer's private key
141 * @param alg digest algorithm used for signature
142 * @return TRUE if build was successful
143 */
144 bool (*build_signedData) (pkcs7_t *this, private_key_t *key,
145 hash_algorithm_t alg);
146
147 /**
148 * Destroys the contentInfo object.
149 */
150 void (*destroy) (pkcs7_t *this);
151 };
152
153 /**
154 * Read a PKCS#7 contentInfo object from a DER encoded chunk.
155 *
156 * @param chunk chunk containing DER encoded data
157 * @param level ASN.1 parsing start level
158 * @return created pkcs7_contentInfo object, or NULL if invalid.
159 */
160 pkcs7_t *pkcs7_create_from_chunk(chunk_t chunk, u_int level);
161
162 /**
163 * Create a PKCS#7 contentInfo object
164 *
165 * @param data chunk containing data
166 * @return created pkcs7_contentInfo object.
167 */
168 pkcs7_t *pkcs7_create_from_data(chunk_t data);
169
170 #endif /** PKCS7_H_ @}*/