1 /* crypto/pkcs7/pkcs7.h */
2 /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com)
5 * This package is an SSL implementation written
6 * by Eric Young (eay@cryptsoft.com).
7 * The implementation was written so as to conform with Netscapes SSL.
9 * This library is free for commercial and non-commercial use as long as
10 * the following conditions are aheared to. The following conditions
11 * apply to all code found in this distribution, be it the RC4, RSA,
12 * lhash, DES, etc., code; not just the SSL code. The SSL documentation
13 * included with this distribution is covered by the same copyright terms
14 * except that the holder is Tim Hudson (tjh@cryptsoft.com).
16 * Copyright remains Eric Young's, and as such any Copyright notices in
17 * the code are not to be removed.
18 * If this package is used in a product, Eric Young should be given attribution
19 * as the author of the parts of the library used.
20 * This can be in the form of a textual message at program startup or
21 * in documentation (online or textual) provided with the package.
23 * Redistribution and use in source and binary forms, with or without
24 * modification, are permitted provided that the following conditions
26 * 1. Redistributions of source code must retain the copyright
27 * notice, this list of conditions and the following disclaimer.
28 * 2. Redistributions in binary form must reproduce the above copyright
29 * notice, this list of conditions and the following disclaimer in the
30 * documentation and/or other materials provided with the distribution.
31 * 3. All advertising materials mentioning features or use of this software
32 * must display the following acknowledgement:
33 * "This product includes cryptographic software written by
34 * Eric Young (eay@cryptsoft.com)"
35 * The word 'cryptographic' can be left out if the rouines from the library
36 * being used are not cryptographic related :-).
37 * 4. If you include any Windows specific code (or a derivative thereof) from
38 * the apps directory (application code) you must include an acknowledgement:
39 * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)"
41 * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND
42 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
43 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
44 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
45 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
46 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
47 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
48 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
49 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
50 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
53 * The licence and distribution terms for any publically available version or
54 * derivative of this code cannot be changed. i.e. this code cannot simply be
55 * copied and put under another distribution licence
56 * [including the GNU Public Licence.]
59 #ifndef PROTO_AMISSL_H
60 #include <proto/amissl.h>
61 #endif /* PROTO_AMISSL_H */
63 #ifndef HEADER_PKCS7_H
64 #define HEADER_PKCS7_H
66 #include <openssl/asn1.h>
67 #include <openssl/bio.h>
68 #include <openssl/e_os2.h>
70 #include <openssl/symhacks.h>
71 #include <openssl/ossl_typ.h>
77 #ifdef OPENSSL_SYS_WIN32
78 /* Under Win32 thes are defined in wincrypt.h */
79 #undef PKCS7_ISSUER_AND_SERIAL
80 #undef PKCS7_SIGNER_INFO
86 Digest_Encryption_ID rsaEncryption
87 Key_Encryption_ID rsaEncryption
90 typedef struct pkcs7_issuer_and_serial_st
94 } PKCS7_ISSUER_AND_SERIAL
;
96 typedef struct pkcs7_signer_info_st
98 ASN1_INTEGER
*version
; /* version 1 */
99 PKCS7_ISSUER_AND_SERIAL
*issuer_and_serial
;
100 X509_ALGOR
*digest_alg
;
101 STACK_OF(X509_ATTRIBUTE
) *auth_attr
; /* [ 0 ] */
102 X509_ALGOR
*digest_enc_alg
;
103 ASN1_OCTET_STRING
*enc_digest
;
104 STACK_OF(X509_ATTRIBUTE
) *unauth_attr
; /* [ 1 ] */
106 /* The private key to sign with */
110 DECLARE_STACK_OF(PKCS7_SIGNER_INFO
)
111 DECLARE_ASN1_SET_OF(PKCS7_SIGNER_INFO
)
113 typedef struct pkcs7_recip_info_st
115 ASN1_INTEGER
*version
; /* version 0 */
116 PKCS7_ISSUER_AND_SERIAL
*issuer_and_serial
;
117 X509_ALGOR
*key_enc_algor
;
118 ASN1_OCTET_STRING
*enc_key
;
119 X509
*cert
; /* get the pub-key from this */
122 DECLARE_STACK_OF(PKCS7_RECIP_INFO
)
123 DECLARE_ASN1_SET_OF(PKCS7_RECIP_INFO
)
125 typedef struct pkcs7_signed_st
127 ASN1_INTEGER
*version
; /* version 1 */
128 STACK_OF(X509_ALGOR
) *md_algs
; /* md used */
129 STACK_OF(X509
) *cert
; /* [ 0 ] */
130 STACK_OF(X509_CRL
) *crl
; /* [ 1 ] */
131 STACK_OF(PKCS7_SIGNER_INFO
) *signer_info
;
133 struct pkcs7_st
*contents
;
135 /* The above structure is very very similar to PKCS7_SIGN_ENVELOPE.
136 * How about merging the two */
138 typedef struct pkcs7_enc_content_st
140 ASN1_OBJECT
*content_type
;
141 X509_ALGOR
*algorithm
;
142 ASN1_OCTET_STRING
*enc_data
; /* [ 0 ] */
143 const EVP_CIPHER
*cipher
;
146 typedef struct pkcs7_enveloped_st
148 ASN1_INTEGER
*version
; /* version 0 */
149 STACK_OF(PKCS7_RECIP_INFO
) *recipientinfo
;
150 PKCS7_ENC_CONTENT
*enc_data
;
153 typedef struct pkcs7_signedandenveloped_st
155 ASN1_INTEGER
*version
; /* version 1 */
156 STACK_OF(X509_ALGOR
) *md_algs
; /* md used */
157 STACK_OF(X509
) *cert
; /* [ 0 ] */
158 STACK_OF(X509_CRL
) *crl
; /* [ 1 ] */
159 STACK_OF(PKCS7_SIGNER_INFO
) *signer_info
;
161 PKCS7_ENC_CONTENT
*enc_data
;
162 STACK_OF(PKCS7_RECIP_INFO
) *recipientinfo
;
163 } PKCS7_SIGN_ENVELOPE
;
165 typedef struct pkcs7_digest_st
167 ASN1_INTEGER
*version
; /* version 0 */
168 X509_ALGOR
*md
; /* md used */
169 struct pkcs7_st
*contents
;
170 ASN1_OCTET_STRING
*digest
;
173 typedef struct pkcs7_encrypted_st
175 ASN1_INTEGER
*version
; /* version 0 */
176 PKCS7_ENC_CONTENT
*enc_data
;
179 typedef struct pkcs7_st
181 /* The following is non NULL if it contains ASN1 encoding of
186 #define PKCS7_S_HEADER 0
187 #define PKCS7_S_BODY 1
188 #define PKCS7_S_TAIL 2
189 int state
; /* used during processing */
194 /* content as defined by the type */
195 /* all encryption/message digests are applied to the 'contents',
196 * leaving out the 'type' field. */
201 ASN1_OCTET_STRING
*data
;
203 /* NID_pkcs7_signed */
206 /* NID_pkcs7_enveloped */
207 PKCS7_ENVELOPE
*enveloped
;
209 /* NID_pkcs7_signedAndEnveloped */
210 PKCS7_SIGN_ENVELOPE
*signed_and_enveloped
;
212 /* NID_pkcs7_digest */
213 PKCS7_DIGEST
*digest
;
215 /* NID_pkcs7_encrypted */
216 PKCS7_ENCRYPT
*encrypted
;
223 DECLARE_STACK_OF(PKCS7
)
224 DECLARE_ASN1_SET_OF(PKCS7
)
225 DECLARE_PKCS12_STACK_OF(PKCS7
)
227 #define PKCS7_OP_SET_DETACHED_SIGNATURE 1
228 #define PKCS7_OP_GET_DETACHED_SIGNATURE 2
230 #define PKCS7_get_signed_attributes(si) ((si)->auth_attr)
231 #define PKCS7_get_attributes(si) ((si)->unauth_attr)
233 #define PKCS7_type_is_signed(a) (OBJ_obj2nid((a)->type) == NID_pkcs7_signed)
234 #define PKCS7_type_is_encrypted(a) (OBJ_obj2nid((a)->type) == NID_pkcs7_encrypted)
235 #define PKCS7_type_is_enveloped(a) (OBJ_obj2nid((a)->type) == NID_pkcs7_enveloped)
236 #define PKCS7_type_is_signedAndEnveloped(a) \
237 (OBJ_obj2nid((a)->type) == NID_pkcs7_signedAndEnveloped)
238 #define PKCS7_type_is_data(a) (OBJ_obj2nid((a)->type) == NID_pkcs7_data)
240 #define PKCS7_set_detached(p,v) \
241 PKCS7_ctrl(p,PKCS7_OP_SET_DETACHED_SIGNATURE,v,NULL)
242 #define PKCS7_get_detached(p) \
243 PKCS7_ctrl(p,PKCS7_OP_GET_DETACHED_SIGNATURE,0,NULL)
245 #define PKCS7_is_detached(p7) (PKCS7_type_is_signed(p7) && PKCS7_get_detached(p7))
248 #ifndef PKCS7_ISSUER_AND_SERIAL_digest
249 #define PKCS7_ISSUER_AND_SERIAL_digest(data,type,md,len) \
250 ASN1_digest((int (*)())i2d_PKCS7_ISSUER_AND_SERIAL,type,\
255 /* S/MIME related flags */
257 #define PKCS7_TEXT 0x1
258 #define PKCS7_NOCERTS 0x2
259 #define PKCS7_NOSIGS 0x4
260 #define PKCS7_NOCHAIN 0x8
261 #define PKCS7_NOINTERN 0x10
262 #define PKCS7_NOVERIFY 0x20
263 #define PKCS7_DETACHED 0x40
264 #define PKCS7_BINARY 0x80
265 #define PKCS7_NOATTR 0x100
266 #define PKCS7_NOSMIMECAP 0x200
267 #define PKCS7_NOOLDMIMETYPE 0x400
268 #define PKCS7_CRLFEOL 0x800
270 /* Flags: for compatibility with older code */
272 #define SMIME_TEXT PKCS7_TEXT
273 #define SMIME_NOCERTS PKCS7_NOCERTS
274 #define SMIME_NOSIGS PKCS7_NOSIGS
275 #define SMIME_NOCHAIN PKCS7_NOCHAIN
276 #define SMIME_NOINTERN PKCS7_NOINTERN
277 #define SMIME_NOVERIFY PKCS7_NOVERIFY
278 #define SMIME_DETACHED PKCS7_DETACHED
279 #define SMIME_BINARY PKCS7_BINARY
280 #define SMIME_NOATTR PKCS7_NOATTR
282 DECLARE_ASN1_FUNCTIONS(PKCS7_ISSUER_AND_SERIAL
)
284 #ifndef SSLEAY_MACROS
285 int PKCS7_ISSUER_AND_SERIAL_digest(PKCS7_ISSUER_AND_SERIAL
*data
,const EVP_MD
*type
,
286 unsigned char *md
,unsigned int *len
);
287 #ifndef OPENSSL_NO_FP_API
288 PKCS7
*d2i_PKCS7_fp(FILE *fp
,PKCS7
**p7
);
289 int i2d_PKCS7_fp(FILE *fp
,PKCS7
*p7
);
291 PKCS7
*PKCS7_dup(PKCS7
*p7
);
292 PKCS7
*d2i_PKCS7_bio(BIO
*bp
,PKCS7
**p7
);
293 int i2d_PKCS7_bio(BIO
*bp
,PKCS7
*p7
);
296 DECLARE_ASN1_FUNCTIONS(PKCS7_SIGNER_INFO
)
297 DECLARE_ASN1_FUNCTIONS(PKCS7_RECIP_INFO
)
298 DECLARE_ASN1_FUNCTIONS(PKCS7_SIGNED
)
299 DECLARE_ASN1_FUNCTIONS(PKCS7_ENC_CONTENT
)
300 DECLARE_ASN1_FUNCTIONS(PKCS7_ENVELOPE
)
301 DECLARE_ASN1_FUNCTIONS(PKCS7_SIGN_ENVELOPE
)
302 DECLARE_ASN1_FUNCTIONS(PKCS7_DIGEST
)
303 DECLARE_ASN1_FUNCTIONS(PKCS7_ENCRYPT
)
304 DECLARE_ASN1_FUNCTIONS(PKCS7
)
306 DECLARE_ASN1_ITEM(PKCS7_ATTR_SIGN
)
307 DECLARE_ASN1_ITEM(PKCS7_ATTR_VERIFY
)
310 long PKCS7_ctrl(PKCS7
*p7
, int cmd
, long larg
, char *parg
);
312 int PKCS7_set_type(PKCS7
*p7
, int type
);
313 int PKCS7_set_content(PKCS7
*p7
, PKCS7
*p7_data
);
314 int PKCS7_SIGNER_INFO_set(PKCS7_SIGNER_INFO
*p7i
, X509
*x509
, EVP_PKEY
*pkey
,
316 int PKCS7_add_signer(PKCS7
*p7
, PKCS7_SIGNER_INFO
*p7i
);
317 int PKCS7_add_certificate(PKCS7
*p7
, X509
*x509
);
318 int PKCS7_add_crl(PKCS7
*p7
, X509_CRL
*x509
);
319 int PKCS7_content_new(PKCS7
*p7
, int nid
);
320 int PKCS7_dataVerify(X509_STORE
*cert_store
, X509_STORE_CTX
*ctx
,
321 BIO
*bio
, PKCS7
*p7
, PKCS7_SIGNER_INFO
*si
);
322 int PKCS7_signatureVerify(BIO
*bio
, PKCS7
*p7
, PKCS7_SIGNER_INFO
*si
,
325 BIO
*PKCS7_dataInit(PKCS7
*p7
, BIO
*bio
);
326 int PKCS7_dataFinal(PKCS7
*p7
, BIO
*bio
);
327 BIO
*PKCS7_dataDecode(PKCS7
*p7
, EVP_PKEY
*pkey
, BIO
*in_bio
, X509
*pcert
);
330 PKCS7_SIGNER_INFO
*PKCS7_add_signature(PKCS7
*p7
, X509
*x509
,
331 EVP_PKEY
*pkey
, const EVP_MD
*dgst
);
332 X509
*PKCS7_cert_from_signer_info(PKCS7
*p7
, PKCS7_SIGNER_INFO
*si
);
333 STACK_OF(PKCS7_SIGNER_INFO
) *PKCS7_get_signer_info(PKCS7
*p7
);
335 PKCS7_RECIP_INFO
*PKCS7_add_recipient(PKCS7
*p7
, X509
*x509
);
336 int PKCS7_add_recipient_info(PKCS7
*p7
, PKCS7_RECIP_INFO
*ri
);
337 int PKCS7_RECIP_INFO_set(PKCS7_RECIP_INFO
*p7i
, X509
*x509
);
338 int PKCS7_set_cipher(PKCS7
*p7
, const EVP_CIPHER
*cipher
);
340 PKCS7_ISSUER_AND_SERIAL
*PKCS7_get_issuer_and_serial(PKCS7
*p7
, int idx
);
341 ASN1_OCTET_STRING
*PKCS7_digest_from_attributes(STACK_OF(X509_ATTRIBUTE
) *sk
);
342 int PKCS7_add_signed_attribute(PKCS7_SIGNER_INFO
*p7si
,int nid
,int type
,
344 int PKCS7_add_attribute (PKCS7_SIGNER_INFO
*p7si
, int nid
, int atrtype
,
346 ASN1_TYPE
*PKCS7_get_attribute(PKCS7_SIGNER_INFO
*si
, int nid
);
347 ASN1_TYPE
*PKCS7_get_signed_attribute(PKCS7_SIGNER_INFO
*si
, int nid
);
348 int PKCS7_set_signed_attributes(PKCS7_SIGNER_INFO
*p7si
,
349 STACK_OF(X509_ATTRIBUTE
) *sk
);
350 int PKCS7_set_attributes(PKCS7_SIGNER_INFO
*p7si
,STACK_OF(X509_ATTRIBUTE
) *sk
);
353 PKCS7
*PKCS7_sign(X509
*signcert
, EVP_PKEY
*pkey
, STACK_OF(X509
) *certs
,
354 BIO
*data
, int flags
);
355 int PKCS7_verify(PKCS7
*p7
, STACK_OF(X509
) *certs
, X509_STORE
*store
,
356 BIO
*indata
, BIO
*out
, int flags
);
357 STACK_OF(X509
) *PKCS7_get0_signers(PKCS7
*p7
, STACK_OF(X509
) *certs
, int flags
);
358 PKCS7
*PKCS7_encrypt(STACK_OF(X509
) *certs
, BIO
*in
, const EVP_CIPHER
*cipher
,
360 int PKCS7_decrypt(PKCS7
*p7
, EVP_PKEY
*pkey
, X509
*cert
, BIO
*data
, int flags
);
362 int PKCS7_add_attrib_smimecap(PKCS7_SIGNER_INFO
*si
,
363 STACK_OF(X509_ALGOR
) *cap
);
364 STACK_OF(X509_ALGOR
) *PKCS7_get_smimecap(PKCS7_SIGNER_INFO
*si
);
365 int PKCS7_simple_smimecap(STACK_OF(X509_ALGOR
) *sk
, int nid
, int arg
);
367 int SMIME_write_PKCS7(BIO
*bio
, PKCS7
*p7
, BIO
*data
, int flags
);
368 PKCS7
*SMIME_read_PKCS7(BIO
*bio
, BIO
**bcont
);
369 int SMIME_crlf_copy(BIO
*in
, BIO
*out
, int flags
);
370 int SMIME_text(BIO
*in
, BIO
*out
);
372 /* BEGIN ERROR CODES */
373 /* The following lines are auto generated by the script mkerr.pl. Any changes
374 * made after this point may be overwritten when the script is next run.
376 void ERR_load_PKCS7_strings(void);
378 /* Error codes for the PKCS7 functions. */
380 /* Function codes. */
381 #define PKCS7_F_B64_READ_PKCS7 120
382 #define PKCS7_F_B64_WRITE_PKCS7 121
383 #define PKCS7_F_PKCS7_ADD_ATTRIB_SMIMECAP 118
384 #define PKCS7_F_PKCS7_ADD_CERTIFICATE 100
385 #define PKCS7_F_PKCS7_ADD_CRL 101
386 #define PKCS7_F_PKCS7_ADD_RECIPIENT_INFO 102
387 #define PKCS7_F_PKCS7_ADD_SIGNER 103
388 #define PKCS7_F_PKCS7_CTRL 104
389 #define PKCS7_F_PKCS7_DATADECODE 112
390 #define PKCS7_F_PKCS7_DATAINIT 105
391 #define PKCS7_F_PKCS7_DATASIGN 106
392 #define PKCS7_F_PKCS7_DATAVERIFY 107
393 #define PKCS7_F_PKCS7_DECRYPT 114
394 #define PKCS7_F_PKCS7_ENCRYPT 115
395 #define PKCS7_F_PKCS7_GET0_SIGNERS 124
396 #define PKCS7_F_PKCS7_SET_CIPHER 108
397 #define PKCS7_F_PKCS7_SET_CONTENT 109
398 #define PKCS7_F_PKCS7_SET_TYPE 110
399 #define PKCS7_F_PKCS7_SIGN 116
400 #define PKCS7_F_PKCS7_SIGNATUREVERIFY 113
401 #define PKCS7_F_PKCS7_SIMPLE_SMIMECAP 119
402 #define PKCS7_F_PKCS7_VERIFY 117
403 #define PKCS7_F_SMIME_READ_PKCS7 122
404 #define PKCS7_F_SMIME_TEXT 123
407 #define PKCS7_R_CERTIFICATE_VERIFY_ERROR 117
408 #define PKCS7_R_CIPHER_HAS_NO_OBJECT_IDENTIFIER 144
409 #define PKCS7_R_CIPHER_NOT_INITIALIZED 116
410 #define PKCS7_R_CONTENT_AND_DATA_PRESENT 118
411 #define PKCS7_R_DECODE_ERROR 130
412 #define PKCS7_R_DECRYPTED_KEY_IS_WRONG_LENGTH 100
413 #define PKCS7_R_DECRYPT_ERROR 119
414 #define PKCS7_R_DIGEST_FAILURE 101
415 #define PKCS7_R_ERROR_ADDING_RECIPIENT 120
416 #define PKCS7_R_ERROR_SETTING_CIPHER 121
417 #define PKCS7_R_INVALID_MIME_TYPE 131
418 #define PKCS7_R_INVALID_NULL_POINTER 143
419 #define PKCS7_R_MIME_NO_CONTENT_TYPE 132
420 #define PKCS7_R_MIME_PARSE_ERROR 133
421 #define PKCS7_R_MIME_SIG_PARSE_ERROR 134
422 #define PKCS7_R_MISSING_CERIPEND_INFO 103
423 #define PKCS7_R_NO_CONTENT 122
424 #define PKCS7_R_NO_CONTENT_TYPE 135
425 #define PKCS7_R_NO_MULTIPART_BODY_FAILURE 136
426 #define PKCS7_R_NO_MULTIPART_BOUNDARY 137
427 #define PKCS7_R_NO_RECIPIENT_MATCHES_CERTIFICATE 115
428 #define PKCS7_R_NO_SIGNATURES_ON_DATA 123
429 #define PKCS7_R_NO_SIGNERS 142
430 #define PKCS7_R_NO_SIG_CONTENT_TYPE 138
431 #define PKCS7_R_OPERATION_NOT_SUPPORTED_ON_THIS_TYPE 104
432 #define PKCS7_R_PKCS7_ADD_SIGNATURE_ERROR 124
433 #define PKCS7_R_PKCS7_DATAFINAL_ERROR 125
434 #define PKCS7_R_PKCS7_DATASIGN 126
435 #define PKCS7_R_PKCS7_PARSE_ERROR 139
436 #define PKCS7_R_PKCS7_SIG_PARSE_ERROR 140
437 #define PKCS7_R_PRIVATE_KEY_DOES_NOT_MATCH_CERTIFICATE 127
438 #define PKCS7_R_SIGNATURE_FAILURE 105
439 #define PKCS7_R_SIGNER_CERTIFICATE_NOT_FOUND 128
440 #define PKCS7_R_SIG_INVALID_MIME_TYPE 141
441 #define PKCS7_R_SMIME_TEXT_ERROR 129
442 #define PKCS7_R_UNABLE_TO_FIND_CERTIFICATE 106
443 #define PKCS7_R_UNABLE_TO_FIND_MEM_BIO 107
444 #define PKCS7_R_UNABLE_TO_FIND_MESSAGE_DIGEST 108
445 #define PKCS7_R_UNKNOWN_DIGEST_TYPE 109
446 #define PKCS7_R_UNKNOWN_OPERATION 110
447 #define PKCS7_R_UNSUPPORTED_CIPHER_TYPE 111
448 #define PKCS7_R_UNSUPPORTED_CONTENT_TYPE 112
449 #define PKCS7_R_WRONG_CONTENT_TYPE 113
450 #define PKCS7_R_WRONG_PKCS7_TYPE 114