2019-12-30 10:24:45 +01:00
|
|
|
/* $OpenBSD: sk-api.h,v 1.6 2019/12/30 09:24:45 djm Exp $ */
|
2019-10-31 22:16:20 +01:00
|
|
|
/*
|
|
|
|
* Copyright (c) 2019 Google LLC
|
|
|
|
*
|
|
|
|
* Permission to use, copy, modify, and distribute this software for any
|
|
|
|
* purpose with or without fee is hereby granted, provided that the above
|
|
|
|
* copyright notice and this permission notice appear in all copies.
|
|
|
|
*
|
|
|
|
* THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
|
|
|
|
* WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
|
|
|
|
* MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
|
|
|
|
* ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
|
|
|
|
* WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
|
|
|
|
* ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
|
|
|
|
* OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef _SK_API_H
|
|
|
|
#define _SK_API_H 1
|
|
|
|
|
|
|
|
#include <stddef.h>
|
2019-11-02 13:25:01 +01:00
|
|
|
#ifdef HAVE_STDINT_H
|
2019-10-31 22:16:20 +01:00
|
|
|
#include <stdint.h>
|
2019-11-02 13:25:01 +01:00
|
|
|
#endif
|
2019-10-31 22:16:20 +01:00
|
|
|
|
|
|
|
/* Flags */
|
|
|
|
#define SSH_SK_USER_PRESENCE_REQD 0x01
|
2019-12-30 10:19:52 +01:00
|
|
|
#define SSH_SK_USER_VERIFICATION_REQD 0x04
|
|
|
|
#define SSH_SK_RESIDENT_KEY 0x20
|
2019-10-31 22:16:20 +01:00
|
|
|
|
2019-11-12 20:32:30 +01:00
|
|
|
/* Algs */
|
|
|
|
#define SSH_SK_ECDSA 0x00
|
|
|
|
#define SSH_SK_ED25519 0x01
|
|
|
|
|
2019-12-30 10:24:45 +01:00
|
|
|
/* Error codes */
|
|
|
|
#define SSH_SK_ERR_GENERAL -1
|
|
|
|
#define SSH_SK_ERR_UNSUPPORTED -2
|
|
|
|
#define SSH_SK_ERR_PIN_REQUIRED -3
|
|
|
|
|
2019-10-31 22:16:20 +01:00
|
|
|
struct sk_enroll_response {
|
|
|
|
uint8_t *public_key;
|
|
|
|
size_t public_key_len;
|
|
|
|
uint8_t *key_handle;
|
|
|
|
size_t key_handle_len;
|
|
|
|
uint8_t *signature;
|
|
|
|
size_t signature_len;
|
|
|
|
uint8_t *attestation_cert;
|
|
|
|
size_t attestation_cert_len;
|
|
|
|
};
|
|
|
|
|
|
|
|
struct sk_sign_response {
|
|
|
|
uint8_t flags;
|
|
|
|
uint32_t counter;
|
|
|
|
uint8_t *sig_r;
|
|
|
|
size_t sig_r_len;
|
|
|
|
uint8_t *sig_s;
|
|
|
|
size_t sig_s_len;
|
|
|
|
};
|
|
|
|
|
2019-12-30 10:21:16 +01:00
|
|
|
struct sk_resident_key {
|
|
|
|
uint8_t alg;
|
|
|
|
size_t slot;
|
|
|
|
char *application;
|
|
|
|
struct sk_enroll_response key;
|
|
|
|
};
|
|
|
|
|
2019-12-30 10:23:28 +01:00
|
|
|
#define SSH_SK_VERSION_MAJOR 0x00030000 /* current API version */
|
2019-10-31 22:16:20 +01:00
|
|
|
#define SSH_SK_VERSION_MAJOR_MASK 0xffff0000
|
|
|
|
|
|
|
|
/* Return the version of the middleware API */
|
|
|
|
uint32_t sk_api_version(void);
|
|
|
|
|
|
|
|
/* Enroll a U2F key (private key generation) */
|
2019-11-12 20:32:30 +01:00
|
|
|
int sk_enroll(int alg, const uint8_t *challenge, size_t challenge_len,
|
2019-12-30 10:23:28 +01:00
|
|
|
const char *application, uint8_t flags, const char *pin,
|
2019-10-31 22:16:20 +01:00
|
|
|
struct sk_enroll_response **enroll_response);
|
|
|
|
|
|
|
|
/* Sign a challenge */
|
2019-11-12 20:32:30 +01:00
|
|
|
int sk_sign(int alg, const uint8_t *message, size_t message_len,
|
2019-10-31 22:16:20 +01:00
|
|
|
const char *application, const uint8_t *key_handle, size_t key_handle_len,
|
2019-12-30 10:23:28 +01:00
|
|
|
uint8_t flags, const char *pin, struct sk_sign_response **sign_response);
|
2019-10-31 22:16:20 +01:00
|
|
|
|
2019-12-30 10:21:16 +01:00
|
|
|
/* Enumerate all resident keys */
|
|
|
|
int sk_load_resident_keys(const char *pin,
|
|
|
|
struct sk_resident_key ***rks, size_t *nrks);
|
|
|
|
|
2019-10-31 22:16:20 +01:00
|
|
|
#endif /* _SK_API_H */
|