1 .\" Copyright (c) 2008, Sun Microsystems, Inc. All rights reserved.
2 .\" Copyright 2016 Jason King.
4 .\" The contents of this file are subject to the terms of the Common Development and Distribution License (the "License"). You may not use this file except in compliance with the License.
5 .\" You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE or http://www.opensolaris.org/os/licensing. See the License for the specific language governing permissions and limitations under the License.
6 .\" When distributing Covered Code, include this CDDL HEADER in each file and include the License file at usr/src/OPENSOLARIS.LICENSE. If applicable, add the following below this CDDL HEADER, with the fields enclosed by brackets "[]" replaced with your own identifying information: Portions Copyright [yyyy] [name of copyright owner]
12 .Nd PKCS#11 Cryptographic Framework library
15 .In security/cryptoki.h
20 library implements the RSA Security Inc. PKCS#11
21 Cryptographic Token Interface (Cryptoki), v2.40 specification by using plug-ins
24 Each plug-in, which also implements RSA PKCS#11 v2.40, represents one or more
29 library provides a special slot called the meta slot.
30 The meta slot provides a virtual union of capabilities of all other slots.
31 When available, the meta slot is always the first slot provided by
34 The meta slot feature can be configured either system-wide or by individual
36 System-wide configuration for meta slot features is done with the
39 User configuration for meta slot features is performed with environment
42 By default, the following is the system-wide configuration for meta slot.
44 Meta slot provides token-based object support with the Software RSA PKCS#11
46 .Pf ( Xr pkcs11_softtoken 5 ) .
48 allowed to move sensitive token objects to other slots if that is necessary to
51 Users can overwrite one or more system-wide configuration options for meta slot
52 using these environment variables.
55 .Ev ${METASLOT_OBJECTSTORE_SLOT}
57 .Ev ${METASLOT_OBJECTSTORE_TOKEN}
58 environment variables are used to specify an alternate token object store.
59 A user can specify either slot-description in
60 .Ev ${METASLOT_OBJECTSTORE_SLOT}
62 .Ev ${METASLOT_OBJECTSTORE_TOKEN} , or both.
63 Valid values for slot-description and token-label are available from output of
65 .Bd -literal -offset indent
70 .Ev ${METASLOT_ENABLED}
71 environment variable is used to specify whether
72 the user wants to turn the metaslot feature on or off.
73 Only two values are recognized.
74 The value "true" means meta slot will be on.
75 The value "false" means meta slot will be off.
78 .Ev ${METASLOT_AUTO_KEY_MIGRATE}
79 environment variable is used to specify
80 whether the user wants sensitive token objects to move to other slots for
81 cryptographic operations.
82 Only two values are recognized.
83 The value "true" means meta slot will migrate sensitive token objects to other
85 The value "false" means meta slot will not migrate sensitive token objects to
86 other slots even if it is necessary.
88 When the meta slot feature is enabled, the slot that provides token-based
89 object support is not shown as one of the available slots.
90 All of its functionality can be used with the meta slot.
92 This library filters the list of mechanisms available from plug-ins based on
96 This library provides entry points for all PKCS#11 v2.40 functions.
97 See the PKCS#11 v2.40 specifications at
98 .Lk http://www.oasis-open.org.
100 Plug-ins are added to
105 script during execution of
107 The available mechanisms are administered by the
111 Plug-ins must have all of their library dependancies specified, including
113 Libraries that have unresolved symbols, including those from
115 will be rejected and a message will be sent to
119 Due to U.S. Export regulations, all plug-ins are required to be
120 cryptographically signed using the
124 Any plug-in that is not signed or is not a compatible version of PKCS#11 will
127 When a plug-in is dropped, the administrator is alerted by the
132 .In security/pkcs11f.h
133 header contains function definitions.
135 .In security/pkcs11t.h
136 header contains type definitions.
137 Applications can include either of these headers in place of
138 .In security/pkcs11.h ,
139 which contains both function and type definitions.
143 provides the public interfaces defined below.
146 for additional information on shared object interfaces.
147 .Ss "PKCS#11 Standard"
149 .\" Use SUNW_C_GetMechSession for the first column so both sections will
150 .\" line up better when rendered
152 .Bl -column -offset indent ".Sy SUNW_C_GetMechSession" ".Sy C_DecryptDigestUpdate"
153 .It Sy C_CloseAllSessions Ta Sy C_CloseSession
154 .It Sy C_CopyObject Ta Sy C_CreateObject
155 .It Sy C_Decrypt Ta Sy C_DecryptDigestUpdate
156 .It Sy C_DecryptFinal Ta Sy C_DecryptInit
157 .It Sy C_DecryptUpdate Ta Sy C_DecryptVerifyUpdate
158 .It Sy C_DeriveKey Ta Sy C_DestroyObject
159 .It Sy C_Digest Ta Sy C_DigestEncryptUpdate
160 .It Sy C_DigestFinal Ta Sy C_DigestInit
161 .It Sy C_DigestKey Ta Sy C_DigestUpdate
162 .It Sy C_Encrypt Ta Sy C_EncryptFinal
163 .It Sy C_EncryptInit Ta Sy C_EncryptUpdate
164 .It Sy C_Finalize Ta Sy C_FindObjects
165 .It Sy C_FindObjectsFinal Ta Sy C_FindObjectsInit
166 .It Sy C_GenerateKey Ta Sy C_GenerateKeyPair
167 .It Sy C_GenerateRandom Ta Sy C_GetAttributeValue
168 .It Sy C_GetFunctionList Ta Sy C_GetInfo
169 .It Sy C_GetMechanismInfo Ta Sy C_GetMechanismList
170 .It Sy C_GetObjectSize Ta Sy C_GetOperationState
171 .It Sy C_GetSessionInfo Ta Sy C_GetSlotInfo
172 .It Sy C_GetSlotList Ta Sy C_GetTokenInfo
173 .It Sy C_InitPIN Ta Sy C_InitToken
174 .It Sy C_Initialize Ta Sy C_Login
175 .It Sy C_Logout Ta Sy C_OpenSession
176 .It Sy C_SeedRandom Ta Sy C_SetAttributeValue
177 .It Sy C_SetOperationState Ta Sy C_SetPIN
178 .It Sy C_Sign Ta Sy C_SignEncryptUpdate
179 .It Sy C_SignFinal Ta Sy C_SignInit
180 .It Sy C_SignRecover Ta Sy C_SignRecoverInit
181 .It Sy C_SignUpdate Ta Sy C_UnwrapKey
182 .It Sy C_Verify Ta Sy C_VerifyFinal
183 .It Sy C_VerifyInit Ta Sy C_VerifyRecover
184 .It Sy C_VerifyRecoverInit Ta Sy C_VerifyUpdate
185 .It Sy C_WaitForSlotEvent Ta Sy C_WrapKey
187 .Ss "SUNW Extensions"
188 .Bl -column -offset indent ".Sy SUNW_C_GetMechSession" ".Sy C_DecryptDigestUpdate"
189 .It Sy SUNW_C_GetMechSession Ta Sy SUNW_C_KeyToObject
192 .Bl -tag -compact -width Pa
193 .It Pa /usr/lib/libpkcs11.so.1
195 .It Pa /usr/lib/64/libpkcs11.so.1
201 for descriptions of the following attributes:
202 .Sh INTERFACE STABILITY
205 The SUNW Extension functions are MT-Safe.
206 The PKCS#11 Standard functions are MT-Safe with exceptions.
207 See Section 2.5.3 of PKCS#11 Cryptographic Token Usage Guide v2.40 and
208 Section 5.1.5 of PKCS#11 Cryptographic Token Interface Base Standard v2.40
210 The PKCS#11 Standard functions conform to PKCS#11 Cryptographic Token
211 Interface Profiles v2.40 Extended Provider.
217 .Xr SUNW_C_GetMechSession 3EXT ,
219 .Xr pkcs11_kernel 5 ,
220 .Xr pkcs11_softtoken 5
222 .%T "PKCS#11 Cryptographic Token Interface Base Specification v2.40 Plus Errata 01"
223 .%U http://docs.oasis-open.org/pkcs11/pkcs11-base/v2.40/errata01/os/pkcs11-base-v2.40-errata01-os.html
226 .%T "PKCS#11 Cryptographic Token Interface Profiles v2.40"
227 .%U http://docs.oasis-open.org/pkcs11/pkcs11-profiles/v2.40/pkcs11-profiles-v2.40.html
230 .%T "PKCS#11 Cryptographic Token Interface Usage Guide v2.40"
231 .%U http://docs.oasis-open.org/pkcs11/pkcs11-ug/v2.40/pkcs11-ug-v2.40.html
234 If an application calls
235 .Fn C_WaitForSlotEvent
240 must create threads internally.
242 .Dv CKF_LIBRARY_CANT_CREATE_OS_THREADS
244 .Fn C_WaitForSlotEvent
246 .Dv CKR_FUNCTION_FAILED .
248 The PKCS#11 library does not work with Netscape 4.\fIx\fR but does work with
249 more recent versions of Netscape and Mozilla.
253 might have been called by both an application and a
254 library, it is not safe for a library or its plugins to call
256 A library can be finished calling functions from
258 while an application might not.