/* This Source Code Form is subject to the terms of the Mozilla Public *License,v.2.0.IfacopyoftheMPLwasnotdistributedwiththis
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */ #ifndef _SECMODT_H_ #define _SECMODT_H_ 1
/* find a better home for these... */ externconst SEC_ASN1Template SECKEY_PointerToEncryptedPrivateKeyInfoTemplate[];
SEC_ASN1_CHOOSER_DECLARE(SECKEY_PointerToEncryptedPrivateKeyInfoTemplate) externconst SEC_ASN1Template SECKEY_EncryptedPrivateKeyInfoTemplate[];
SEC_ASN1_CHOOSER_DECLARE(SECKEY_EncryptedPrivateKeyInfoTemplate) externconst SEC_ASN1Template SECKEY_PrivateKeyInfoTemplate[];
SEC_ASN1_CHOOSER_DECLARE(SECKEY_PrivateKeyInfoTemplate) externconst SEC_ASN1Template SECKEY_PointerToPrivateKeyInfoTemplate[];
SEC_ASN1_CHOOSER_DECLARE(SECKEY_PointerToPrivateKeyInfoTemplate)
SEC_END_PROTOS
/* PKCS11 needs to be included */ typedefstruct SECMODModuleStr SECMODModule; typedefstruct SECMODModuleListStr SECMODModuleList; typedef NSSRWLock SECMODListLock; typedefstruct PK11SlotInfoStr PK11SlotInfo; /* defined in secmodti.h */ typedefstruct NSSUTILPreSlotInfoStr PK11PreSlotInfo; /* defined in secmodti.h */ typedefstruct PK11SymKeyStr PK11SymKey; /* defined in secmodti.h */ typedefstruct PK11ContextStr PK11Context; /* defined in secmodti.h */ typedefstruct PK11SlotListStr PK11SlotList; typedefstruct PK11SlotListElementStr PK11SlotListElement; typedefstruct PK11RSAGenParamsStr PK11RSAGenParams; typedefunsignedlong SECMODModuleID; typedefstruct PK11DefaultArrayEntryStr PK11DefaultArrayEntry; typedefstruct PK11GenericObjectStr PK11GenericObject; typedefvoid (*PK11FreeDataFunc)(void *);
struct SECMODModuleStr {
PLArenaPool *arena;
PRBool internal; /* true of internally linked modules, false
* for the loaded modules */
PRBool loaded; /* Set to true if module has been loaded */
PRBool isFIPS; /* Set to true if module is finst internal */ char *dllName; /* name of the shared library which implements
* this module */ char *commonName; /* name of the module to display to the user */ void *library; /* pointer to the library. opaque. used only by
* pk11load.c */ void *functionList; /* The PKCS #11 function table */
PRLock *refLock; /* only used pk11db.c */ int refCount; /* Module reference count */
PK11SlotInfo **slots; /* array of slot points attached to this mod*/ int slotCount; /* count of slot in above array */
PK11PreSlotInfo *slotInfo; /* special info about slots default settings */ int slotInfoCount; /* count */
SECMODModuleID moduleID; /* ID so we can find this module again */
PRBool isThreadSafe; unsignedlong ssl[2]; /* SSL cipher enable flags */ char *libraryParams; /* Module specific parameters */ void *moduleDBFunc; /* function to return module configuration data*/
SECMODModule *parent; /* module that loaded us */
PRBool isCritical; /* This module must load successfully */
PRBool isModuleDB; /* this module has lists of PKCS #11 modules */
PRBool moduleDBOnly; /* this module only has lists of PKCS #11 modules */ int trustOrder; /* order for this module's certificate trust rollup */ int cipherOrder; /* order for cipher operations */ unsignedlong evControlMask; /* control the running and shutdown of slot
* events (SECMOD_WaitForAnyTokenEvent) */
CK_VERSION cryptokiVersion; /* version of this library */
CK_FLAGS flags; /* pkcs11 v3 flags */ /* Warning this could go way in future versions of NSS
* when FIPS indicators wind up in the functionList */
CK_NSS_GetFIPSStatus fipsIndicator;
};
struct PK11RSAGenParamsStr { int keySizeInBits; unsignedlong pe;
};
typedefenum {
PK11CertListUnique = 0, /* get one instance of all certs */
PK11CertListUser = 1, /* get all instances of user certs */
PK11CertListRootUnique = 2, /* get one instance of CA certs without a private key. *deprecated.UsePK11CertListCAUnique
*/
PK11CertListCA = 3, /* get all instances of CA certs */
PK11CertListCAUnique = 4, /* get one instance of CA certs */
PK11CertListUserUnique = 5, /* get one instance of user certs */
PK11CertListAll = 6/* get all instances of all certs */
} PK11CertListType;
/* *Entryintothearraywhichlistsallthelegalbitsforthedefaultflags *intheslot,theirdefinition,andthePKCS#11mechanismtheyrepresent. *Alwaysstaticallyallocated.
*/ struct PK11DefaultArrayEntryStr { constchar *name; unsignedlong flag; unsignedlong mechanism; /* this is a long so we don't include the
* whole pkcs 11 world to use this header */
};
/* *WhatistheoriginofagivenKey.Normallythisdoesn'tmatter,but *thefortezzacodeneedstoknowifitneedstoinvoketheSSL3fortezza *hack.
*/ typedefenum {
PK11_OriginNULL = 0, /* There is not key, it's a null SymKey */
PK11_OriginDerive = 1, /* Key was derived from some other key */
PK11_OriginGenerated = 2, /* Key was generated (also PBE keys) */
PK11_OriginFortezzaHack = 3, /* Key was marked for fortezza hack */
PK11_OriginUnwrap = 4/* Key was unwrapped or decrypted */
} PK11Origin;
/* function pointer type for password callback function. *ThistypeispassedintoPK11_SetPasswordFunc()
*/ typedefchar *(PR_CALLBACK *PK11PasswordFunc)(PK11SlotInfo *slot, PRBool retry, void *arg); typedef PRBool(PR_CALLBACK *PK11VerifyPasswordFunc)(PK11SlotInfo *slot, void *arg); typedef PRBool(PR_CALLBACK *PK11IsLoggedInFunc)(PK11SlotInfo *slot, void *arg);
/* *Specialstringsthepasswordcallbackfunctioncanreturnonlyif *theslotisanprotectedauthpathslot.
*/ #define PK11_PW_RETRY "RETRY"/* an failed attempt to authenticate \ *hasalreadybeenmade,justretry\
* the operation */ #define PK11_PW_AUTHENTICATED "AUTH"/* a successful attempt to authenticate \ *hascompleted.Continuewithout\
* another call to C_Login */ /* All other non-null values mean that that NSS could call C_Login to force *theauthentication.Thefollowingdefineistoaidapplicationsin
* documenting that is what it's trying to do */ #define PK11_PW_TRY "TRY"/* Default: a prompt has been presented \ *totheuser,initiateaC_Login\
* to authenticate the token */
/* These need to be global, leave some open fields so we can 'expand'
* these without breaking binary compatibility */ struct PK11MergeLogNodeStr {
PK11MergeLogNode *next; /* next entry in the list */
PK11MergeLogNode *prev; /* last entry in the list */
PK11GenericObject *object; /* object that failed */ int error; /* what the error was */
CK_RV reserved1; unsignedlong reserved2; /* future flags */ unsignedlong reserved3; /* future scalar */ void *reserved4; /* future pointer */ void *reserved5; /* future expansion pointer */
};
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.