17c478bd9Sstevel@tonic-gate /* 27c478bd9Sstevel@tonic-gate * CDDL HEADER START 37c478bd9Sstevel@tonic-gate * 47c478bd9Sstevel@tonic-gate * The contents of this file are subject to the terms of the 5c892ebf1Skrishna * Common Development and Distribution License (the "License"). 6c892ebf1Skrishna * You may not use this file except in compliance with the License. 77c478bd9Sstevel@tonic-gate * 87c478bd9Sstevel@tonic-gate * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 97c478bd9Sstevel@tonic-gate * or http://www.opensolaris.org/os/licensing. 107c478bd9Sstevel@tonic-gate * See the License for the specific language governing permissions 117c478bd9Sstevel@tonic-gate * and limitations under the License. 127c478bd9Sstevel@tonic-gate * 137c478bd9Sstevel@tonic-gate * When distributing Covered Code, include this CDDL HEADER in each 147c478bd9Sstevel@tonic-gate * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 157c478bd9Sstevel@tonic-gate * If applicable, add the following below this CDDL HEADER, with the 167c478bd9Sstevel@tonic-gate * fields enclosed by brackets "[]" replaced with your own identifying 177c478bd9Sstevel@tonic-gate * information: Portions Copyright [yyyy] [name of copyright owner] 187c478bd9Sstevel@tonic-gate * 197c478bd9Sstevel@tonic-gate * CDDL HEADER END 207c478bd9Sstevel@tonic-gate */ 217c478bd9Sstevel@tonic-gate /* 22160abee0Sda73024 * Copyright 2008 Sun Microsystems, Inc. All rights reserved. 237c478bd9Sstevel@tonic-gate * Use is subject to license terms. 247c478bd9Sstevel@tonic-gate */ 257c478bd9Sstevel@tonic-gate 267c478bd9Sstevel@tonic-gate #ifndef _SYS_CRYPTO_COMMON_H 277c478bd9Sstevel@tonic-gate #define _SYS_CRYPTO_COMMON_H 287c478bd9Sstevel@tonic-gate 297c478bd9Sstevel@tonic-gate /* 307c478bd9Sstevel@tonic-gate * Header file for the common data structures of the cryptographic framework 317c478bd9Sstevel@tonic-gate */ 327c478bd9Sstevel@tonic-gate 337c478bd9Sstevel@tonic-gate #ifdef __cplusplus 347c478bd9Sstevel@tonic-gate extern "C" { 357c478bd9Sstevel@tonic-gate #endif 367c478bd9Sstevel@tonic-gate 377c478bd9Sstevel@tonic-gate #include <sys/types.h> 387c478bd9Sstevel@tonic-gate #include <sys/uio.h> 397c478bd9Sstevel@tonic-gate #include <sys/stream.h> 407c478bd9Sstevel@tonic-gate #include <sys/mutex.h> 417c478bd9Sstevel@tonic-gate #include <sys/condvar.h> 427c478bd9Sstevel@tonic-gate 437c478bd9Sstevel@tonic-gate 447c478bd9Sstevel@tonic-gate /* Cryptographic Mechanisms */ 457c478bd9Sstevel@tonic-gate 467c478bd9Sstevel@tonic-gate #define CRYPTO_MAX_MECH_NAME 32 477c478bd9Sstevel@tonic-gate typedef char crypto_mech_name_t[CRYPTO_MAX_MECH_NAME]; 487c478bd9Sstevel@tonic-gate 497c478bd9Sstevel@tonic-gate typedef uint64_t crypto_mech_type_t; 507c478bd9Sstevel@tonic-gate 517c478bd9Sstevel@tonic-gate typedef struct crypto_mechanism { 527c478bd9Sstevel@tonic-gate crypto_mech_type_t cm_type; /* mechanism type */ 537c478bd9Sstevel@tonic-gate caddr_t cm_param; /* mech. parameter */ 547c478bd9Sstevel@tonic-gate size_t cm_param_len; /* mech. parameter len */ 557c478bd9Sstevel@tonic-gate } crypto_mechanism_t; 567c478bd9Sstevel@tonic-gate 57f317a3a3Skrishna #ifdef _SYSCALL32 58f317a3a3Skrishna 59f317a3a3Skrishna typedef struct crypto_mechanism32 { 60f317a3a3Skrishna crypto_mech_type_t cm_type; /* mechanism type */ 61f317a3a3Skrishna caddr32_t cm_param; /* mech. parameter */ 62f317a3a3Skrishna size32_t cm_param_len; /* mech. parameter len */ 63f317a3a3Skrishna } crypto_mechanism32_t; 64f317a3a3Skrishna 65f317a3a3Skrishna #endif /* _SYSCALL32 */ 66f317a3a3Skrishna 671e9884acSmcpowers #ifdef _KERNEL 68d2b32306Smcpowers /* CK_AES_CTR_PARAMS provides parameters to the CKM_AES_CTR mechanism */ 69d2b32306Smcpowers typedef struct CK_AES_CTR_PARAMS { 70d2b32306Smcpowers ulong_t ulCounterBits; 71d2b32306Smcpowers uint8_t cb[16]; 72d2b32306Smcpowers } CK_AES_CTR_PARAMS; 731e9884acSmcpowers #endif 74d2b32306Smcpowers 75d2b32306Smcpowers /* CK_AES_CCM_PARAMS provides parameters to the CKM_AES_CCM mechanism */ 76d2b32306Smcpowers typedef struct CK_AES_CCM_PARAMS { 77d2b32306Smcpowers ulong_t ulMACSize; 78d2b32306Smcpowers ulong_t ulNonceSize; 79d2b32306Smcpowers ulong_t ulAuthDataSize; 80d2b32306Smcpowers ulong_t ulDataSize; /* used for plaintext or ciphertext */ 81d2b32306Smcpowers uchar_t *nonce; 82d2b32306Smcpowers uchar_t *authData; 83d2b32306Smcpowers } CK_AES_CCM_PARAMS; 84d2b32306Smcpowers 85*4d703b5cSMark Powers /* CK_AES_GCM_PARAMS provides parameters to the CKM_AES_GCM mechanism */ 86*4d703b5cSMark Powers typedef struct CK_AES_GCM_PARAMS { 87*4d703b5cSMark Powers uchar_t *pIv; 88*4d703b5cSMark Powers ulong_t ulIvLen; 89*4d703b5cSMark Powers ulong_t ulIvBits; 90*4d703b5cSMark Powers uchar_t *pAAD; 91*4d703b5cSMark Powers ulong_t ulAADLen; 92*4d703b5cSMark Powers ulong_t ulTagBits; 93*4d703b5cSMark Powers } CK_AES_GCM_PARAMS; 94*4d703b5cSMark Powers 958d4583b0Sfr41279 #ifdef _KERNEL 968d4583b0Sfr41279 /* 978d4583b0Sfr41279 * CK_ECDH1_DERIVE_PARAMS provides the parameters to the 988d4583b0Sfr41279 * CKM_ECDH1_KEY_DERIVE mechanism 998d4583b0Sfr41279 */ 1008d4583b0Sfr41279 typedef struct CK_ECDH1_DERIVE_PARAMS { 1018d4583b0Sfr41279 ulong_t kdf; 1028d4583b0Sfr41279 ulong_t ulSharedDataLen; 1038d4583b0Sfr41279 uchar_t *pSharedData; 1048d4583b0Sfr41279 ulong_t ulPublicDataLen; 1058d4583b0Sfr41279 uchar_t *pPublicData; 1068d4583b0Sfr41279 } CK_ECDH1_DERIVE_PARAMS; 1078d4583b0Sfr41279 #endif 1088d4583b0Sfr41279 109d2b32306Smcpowers #ifdef _KERNEL 110d2b32306Smcpowers #ifdef _SYSCALL32 111d2b32306Smcpowers 112d2b32306Smcpowers /* needed for 32-bit applications running on 64-bit kernels */ 113d2b32306Smcpowers typedef struct CK_AES_CTR_PARAMS32 { 114d2b32306Smcpowers uint32_t ulCounterBits; 115d2b32306Smcpowers uint8_t cb[16]; 116d2b32306Smcpowers } CK_AES_CTR_PARAMS32; 117d2b32306Smcpowers 118d2b32306Smcpowers /* needed for 32-bit applications running on 64-bit kernels */ 119d2b32306Smcpowers typedef struct CK_AES_CCM_PARAMS32 { 120d2b32306Smcpowers uint32_t ulMACSize; 121d2b32306Smcpowers uint32_t ulNonceSize; 122d2b32306Smcpowers uint32_t ulAuthDataSize; 123d2b32306Smcpowers uint32_t ulDataSize; 124d2b32306Smcpowers caddr32_t nonce; 125d2b32306Smcpowers caddr32_t authData; 126d2b32306Smcpowers } CK_AES_CCM_PARAMS32; 127d2b32306Smcpowers 128*4d703b5cSMark Powers /* needed for 32-bit applications running on 64-bit kernels */ 129*4d703b5cSMark Powers typedef struct CK_AES_GCM_PARAMS32 { 130*4d703b5cSMark Powers caddr32_t pIv; 131*4d703b5cSMark Powers uint32_t ulIvLen; 132*4d703b5cSMark Powers uint32_t ulIvBits; 133*4d703b5cSMark Powers caddr32_t pAAD; 134*4d703b5cSMark Powers uint32_t ulAADLen; 135*4d703b5cSMark Powers uint32_t ulTagBits; 136*4d703b5cSMark Powers } CK_AES_GCM_PARAMS32; 137*4d703b5cSMark Powers 1388d4583b0Sfr41279 typedef struct CK_ECDH1_DERIVE_PARAMS32 { 1398d4583b0Sfr41279 uint32_t kdf; 1408d4583b0Sfr41279 uint32_t ulSharedDataLen; 1418d4583b0Sfr41279 caddr32_t pSharedData; 1428d4583b0Sfr41279 uint32_t ulPublicDataLen; 1438d4583b0Sfr41279 caddr32_t pPublicData; 1448d4583b0Sfr41279 } CK_ECDH1_DERIVE_PARAMS32; 1458d4583b0Sfr41279 146d2b32306Smcpowers #endif /* _SYSCALL32 */ 147d2b32306Smcpowers #endif /* _KERNEL */ 148d2b32306Smcpowers 1497c478bd9Sstevel@tonic-gate /* 1506a1073f8Skrishna * The measurement unit bit flag for a mechanism's minimum or maximum key size. 1517c478bd9Sstevel@tonic-gate * The unit are mechanism dependant. It can be in bits or in bytes. 1527c478bd9Sstevel@tonic-gate */ 1537c478bd9Sstevel@tonic-gate typedef uint32_t crypto_keysize_unit_t; 1547c478bd9Sstevel@tonic-gate 1556a1073f8Skrishna /* 1566a1073f8Skrishna * The following bit flags are valid in cm_mech_flags field in 1576a1073f8Skrishna * the crypto_mech_info_t structure of the SPI. 1586a1073f8Skrishna * 1596a1073f8Skrishna * Only the first two bit flags are valid in mi_keysize_unit 1606a1073f8Skrishna * field in the crypto_mechanism_info_t structure of the API. 1616a1073f8Skrishna */ 1627c478bd9Sstevel@tonic-gate #define CRYPTO_KEYSIZE_UNIT_IN_BITS 0x00000001 1637c478bd9Sstevel@tonic-gate #define CRYPTO_KEYSIZE_UNIT_IN_BYTES 0x00000002 1646a1073f8Skrishna #define CRYPTO_CAN_SHARE_OPSTATE 0x00000004 /* supports sharing */ 1657c478bd9Sstevel@tonic-gate 1667c478bd9Sstevel@tonic-gate 1677c478bd9Sstevel@tonic-gate /* Mechanisms supported out-of-the-box */ 1685151fb12Sdarrenm #define SUN_CKM_MD4 "CKM_MD4" 1697c478bd9Sstevel@tonic-gate #define SUN_CKM_MD5 "CKM_MD5" 1707c478bd9Sstevel@tonic-gate #define SUN_CKM_MD5_HMAC "CKM_MD5_HMAC" 1717c478bd9Sstevel@tonic-gate #define SUN_CKM_MD5_HMAC_GENERAL "CKM_MD5_HMAC_GENERAL" 1727c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA1 "CKM_SHA_1" 1737c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA1_HMAC "CKM_SHA_1_HMAC" 1747c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA1_HMAC_GENERAL "CKM_SHA_1_HMAC_GENERAL" 1757c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA256 "CKM_SHA256" 1767c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA256_HMAC "CKM_SHA256_HMAC" 1777c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA256_HMAC_GENERAL "CKM_SHA256_HMAC_GENERAL" 1787c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA384 "CKM_SHA384" 1797c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA384_HMAC "CKM_SHA384_HMAC" 1807c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA384_HMAC_GENERAL "CKM_SHA384_HMAC_GENERAL" 1817c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA512 "CKM_SHA512" 1827c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA512_HMAC "CKM_SHA512_HMAC" 1837c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA512_HMAC_GENERAL "CKM_SHA512_HMAC_GENERAL" 1847c478bd9Sstevel@tonic-gate #define SUN_CKM_DES_CBC "CKM_DES_CBC" 1857c478bd9Sstevel@tonic-gate #define SUN_CKM_DES3_CBC "CKM_DES3_CBC" 1867c478bd9Sstevel@tonic-gate #define SUN_CKM_DES_ECB "CKM_DES_ECB" 1877c478bd9Sstevel@tonic-gate #define SUN_CKM_DES3_ECB "CKM_DES3_ECB" 188f66d273dSizick #define SUN_CKM_BLOWFISH_CBC "CKM_BLOWFISH_CBC" 189f66d273dSizick #define SUN_CKM_BLOWFISH_ECB "CKM_BLOWFISH_ECB" 1907c478bd9Sstevel@tonic-gate #define SUN_CKM_AES_CBC "CKM_AES_CBC" 1917c478bd9Sstevel@tonic-gate #define SUN_CKM_AES_ECB "CKM_AES_ECB" 192894b2776Smcpowers #define SUN_CKM_AES_CTR "CKM_AES_CTR" 1937fb8ff4bSktung #define SUN_CKM_AES_CCM "CKM_AES_CCM" 194*4d703b5cSMark Powers #define SUN_CKM_AES_GCM "CKM_AES_GCM" 1957c478bd9Sstevel@tonic-gate #define SUN_CKM_RC4 "CKM_RC4" 1967c478bd9Sstevel@tonic-gate #define SUN_CKM_RSA_PKCS "CKM_RSA_PKCS" 1977c478bd9Sstevel@tonic-gate #define SUN_CKM_RSA_X_509 "CKM_RSA_X_509" 1987c478bd9Sstevel@tonic-gate #define SUN_CKM_MD5_RSA_PKCS "CKM_MD5_RSA_PKCS" 1997c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA1_RSA_PKCS "CKM_SHA1_RSA_PKCS" 200f66d273dSizick #define SUN_CKM_SHA256_RSA_PKCS "CKM_SHA256_RSA_PKCS" 201f66d273dSizick #define SUN_CKM_SHA384_RSA_PKCS "CKM_SHA384_RSA_PKCS" 202f66d273dSizick #define SUN_CKM_SHA512_RSA_PKCS "CKM_SHA512_RSA_PKCS" 203f9fbec18Smcpowers #define SUN_CKM_EC_KEY_PAIR_GEN "CKM_EC_KEY_PAIR_GEN" 204f9fbec18Smcpowers #define SUN_CKM_ECDH1_DERIVE "CKM_ECDH1_DERIVE" 205f9fbec18Smcpowers #define SUN_CKM_ECDSA_SHA1 "CKM_ECDSA_SHA1" 206f9fbec18Smcpowers #define SUN_CKM_ECDSA "CKM_ECDSA" 2077c478bd9Sstevel@tonic-gate 2086a1073f8Skrishna /* Shared operation context format for CKM_RC4 */ 2096a1073f8Skrishna typedef struct { 21055553f71Sda73024 #if defined(__amd64) 21155553f71Sda73024 uint32_t i, j; 21255553f71Sda73024 uint32_t arr[256]; 21355553f71Sda73024 #else 21455553f71Sda73024 uchar_t arr[256]; 21555553f71Sda73024 uchar_t i, j; 21655553f71Sda73024 #endif /* __amd64 */ 2176a1073f8Skrishna uint64_t pad; /* For 64-bit alignment */ 2186a1073f8Skrishna } arcfour_state_t; 2196a1073f8Skrishna 2207c478bd9Sstevel@tonic-gate /* Data arguments of cryptographic operations */ 2217c478bd9Sstevel@tonic-gate 2227c478bd9Sstevel@tonic-gate typedef enum crypto_data_format { 2237c478bd9Sstevel@tonic-gate CRYPTO_DATA_RAW = 1, 2247c478bd9Sstevel@tonic-gate CRYPTO_DATA_UIO, 2257c478bd9Sstevel@tonic-gate CRYPTO_DATA_MBLK 2267c478bd9Sstevel@tonic-gate } crypto_data_format_t; 2277c478bd9Sstevel@tonic-gate 2287c478bd9Sstevel@tonic-gate typedef struct crypto_data { 2297c478bd9Sstevel@tonic-gate crypto_data_format_t cd_format; /* Format identifier */ 2307c478bd9Sstevel@tonic-gate off_t cd_offset; /* Offset from the beginning */ 2317c478bd9Sstevel@tonic-gate size_t cd_length; /* # of bytes in use */ 2327c478bd9Sstevel@tonic-gate caddr_t cd_miscdata; /* ancillary data */ 2337c478bd9Sstevel@tonic-gate union { 2347c478bd9Sstevel@tonic-gate /* Raw format */ 2357c478bd9Sstevel@tonic-gate iovec_t cdu_raw; /* Pointer and length */ 2367c478bd9Sstevel@tonic-gate 2377c478bd9Sstevel@tonic-gate /* uio scatter-gather format */ 2387c478bd9Sstevel@tonic-gate uio_t *cdu_uio; 2397c478bd9Sstevel@tonic-gate 2407c478bd9Sstevel@tonic-gate /* mblk scatter-gather format */ 2417c478bd9Sstevel@tonic-gate mblk_t *cdu_mp; /* The mblk chain */ 2427c478bd9Sstevel@tonic-gate 2437c478bd9Sstevel@tonic-gate } cdu; /* Crypto Data Union */ 2447c478bd9Sstevel@tonic-gate } crypto_data_t; 2457c478bd9Sstevel@tonic-gate 2467c478bd9Sstevel@tonic-gate #define cd_raw cdu.cdu_raw 2477c478bd9Sstevel@tonic-gate #define cd_uio cdu.cdu_uio 2487c478bd9Sstevel@tonic-gate #define cd_mp cdu.cdu_mp 2497c478bd9Sstevel@tonic-gate 2507c478bd9Sstevel@tonic-gate typedef struct crypto_dual_data { 2517c478bd9Sstevel@tonic-gate crypto_data_t dd_data; /* The data */ 2527c478bd9Sstevel@tonic-gate off_t dd_offset2; /* Used by dual operation */ 2537c478bd9Sstevel@tonic-gate size_t dd_len2; /* # of bytes to take */ 2547c478bd9Sstevel@tonic-gate } crypto_dual_data_t; 2557c478bd9Sstevel@tonic-gate 2567c478bd9Sstevel@tonic-gate #define dd_format dd_data.cd_format 2577c478bd9Sstevel@tonic-gate #define dd_offset1 dd_data.cd_offset 2587c478bd9Sstevel@tonic-gate #define dd_len1 dd_data.cd_length 2597c478bd9Sstevel@tonic-gate #define dd_miscdata dd_data.cd_miscdata 2607c478bd9Sstevel@tonic-gate #define dd_raw dd_data.cd_raw 2617c478bd9Sstevel@tonic-gate #define dd_uio dd_data.cd_uio 2627c478bd9Sstevel@tonic-gate #define dd_mp dd_data.cd_mp 2637c478bd9Sstevel@tonic-gate 2647c478bd9Sstevel@tonic-gate /* The keys, and their contents */ 2657c478bd9Sstevel@tonic-gate 2667c478bd9Sstevel@tonic-gate typedef enum { 2677c478bd9Sstevel@tonic-gate CRYPTO_KEY_RAW = 1, /* ck_data is a cleartext key */ 2687c478bd9Sstevel@tonic-gate CRYPTO_KEY_REFERENCE, /* ck_obj_id is an opaque reference */ 2697c478bd9Sstevel@tonic-gate CRYPTO_KEY_ATTR_LIST /* ck_attrs is a list of object attributes */ 2707c478bd9Sstevel@tonic-gate } crypto_key_format_t; 2717c478bd9Sstevel@tonic-gate 2727c478bd9Sstevel@tonic-gate typedef uint64_t crypto_attr_type_t; 2737c478bd9Sstevel@tonic-gate 2747c478bd9Sstevel@tonic-gate /* Attribute types to use for passing a RSA public key or a private key. */ 2757c478bd9Sstevel@tonic-gate #define SUN_CKA_MODULUS 0x00000120 2767c478bd9Sstevel@tonic-gate #define SUN_CKA_MODULUS_BITS 0x00000121 2777c478bd9Sstevel@tonic-gate #define SUN_CKA_PUBLIC_EXPONENT 0x00000122 2787c478bd9Sstevel@tonic-gate #define SUN_CKA_PRIVATE_EXPONENT 0x00000123 2797c478bd9Sstevel@tonic-gate #define SUN_CKA_PRIME_1 0x00000124 2807c478bd9Sstevel@tonic-gate #define SUN_CKA_PRIME_2 0x00000125 2817c478bd9Sstevel@tonic-gate #define SUN_CKA_EXPONENT_1 0x00000126 2827c478bd9Sstevel@tonic-gate #define SUN_CKA_EXPONENT_2 0x00000127 2837c478bd9Sstevel@tonic-gate #define SUN_CKA_COEFFICIENT 0x00000128 2847c478bd9Sstevel@tonic-gate #define SUN_CKA_PRIME 0x00000130 2857c478bd9Sstevel@tonic-gate #define SUN_CKA_SUBPRIME 0x00000131 2867c478bd9Sstevel@tonic-gate #define SUN_CKA_BASE 0x00000132 2877c478bd9Sstevel@tonic-gate 288f9fbec18Smcpowers #define CKK_EC 0x00000003 289f9fbec18Smcpowers #define CKK_GENERIC_SECRET 0x00000010 290f9fbec18Smcpowers #define CKK_RC4 0x00000012 291f9fbec18Smcpowers #define CKK_AES 0x0000001F 292f9fbec18Smcpowers #define CKK_DES 0x00000013 293f9fbec18Smcpowers #define CKK_DES2 0x00000014 294f9fbec18Smcpowers #define CKK_DES3 0x00000015 295f9fbec18Smcpowers 296f9fbec18Smcpowers #define CKO_PUBLIC_KEY 0x00000002 297f9fbec18Smcpowers #define CKO_PRIVATE_KEY 0x00000003 298f9fbec18Smcpowers #define CKA_CLASS 0x00000000 299f9fbec18Smcpowers #define CKA_VALUE 0x00000011 300f9fbec18Smcpowers #define CKA_KEY_TYPE 0x00000100 301f9fbec18Smcpowers #define CKA_VALUE_LEN 0x00000161 302f9fbec18Smcpowers #define CKA_EC_PARAMS 0x00000180 303f9fbec18Smcpowers #define CKA_EC_POINT 0x00000181 304f9fbec18Smcpowers 3057c478bd9Sstevel@tonic-gate typedef uint32_t crypto_object_id_t; 3067c478bd9Sstevel@tonic-gate 3077c478bd9Sstevel@tonic-gate typedef struct crypto_object_attribute { 3087c478bd9Sstevel@tonic-gate crypto_attr_type_t oa_type; /* attribute type */ 3097c478bd9Sstevel@tonic-gate caddr_t oa_value; /* attribute value */ 3107c478bd9Sstevel@tonic-gate ssize_t oa_value_len; /* length of attribute value */ 3117c478bd9Sstevel@tonic-gate } crypto_object_attribute_t; 3127c478bd9Sstevel@tonic-gate 3137c478bd9Sstevel@tonic-gate typedef struct crypto_key { 3147c478bd9Sstevel@tonic-gate crypto_key_format_t ck_format; /* format identifier */ 3157c478bd9Sstevel@tonic-gate union { 3167c478bd9Sstevel@tonic-gate /* for CRYPTO_KEY_RAW ck_format */ 3177c478bd9Sstevel@tonic-gate struct { 3187c478bd9Sstevel@tonic-gate uint_t cku_v_length; /* # of bits in ck_data */ 3197c478bd9Sstevel@tonic-gate void *cku_v_data; /* ptr to key value */ 3207c478bd9Sstevel@tonic-gate } cku_key_value; 3217c478bd9Sstevel@tonic-gate 3227c478bd9Sstevel@tonic-gate /* for CRYPTO_KEY_REFERENCE ck_format */ 3237c478bd9Sstevel@tonic-gate crypto_object_id_t cku_key_id; /* reference to object key */ 3247c478bd9Sstevel@tonic-gate 3257c478bd9Sstevel@tonic-gate /* for CRYPTO_KEY_ATTR_LIST ck_format */ 3267c478bd9Sstevel@tonic-gate struct { 3277c478bd9Sstevel@tonic-gate uint_t cku_a_count; /* number of attributes */ 3287c478bd9Sstevel@tonic-gate crypto_object_attribute_t *cku_a_oattr; 3297c478bd9Sstevel@tonic-gate } cku_key_attrs; 3307c478bd9Sstevel@tonic-gate } cku_data; /* Crypto Key union */ 3317c478bd9Sstevel@tonic-gate } crypto_key_t; 3327c478bd9Sstevel@tonic-gate 333f317a3a3Skrishna #ifdef _SYSCALL32 334f317a3a3Skrishna 335f317a3a3Skrishna typedef struct crypto_object_attribute32 { 336f317a3a3Skrishna uint64_t oa_type; /* attribute type */ 337f317a3a3Skrishna caddr32_t oa_value; /* attribute value */ 338f317a3a3Skrishna ssize32_t oa_value_len; /* length of attribute value */ 339f317a3a3Skrishna } crypto_object_attribute32_t; 340f317a3a3Skrishna 341f317a3a3Skrishna typedef struct crypto_key32 { 342f317a3a3Skrishna crypto_key_format_t ck_format; /* format identifier */ 343f317a3a3Skrishna union { 344f317a3a3Skrishna /* for CRYPTO_KEY_RAW ck_format */ 345f317a3a3Skrishna struct { 346f317a3a3Skrishna uint32_t cku_v_length; /* # of bytes in ck_data */ 347f317a3a3Skrishna caddr32_t cku_v_data; /* ptr to key value */ 348f317a3a3Skrishna } cku_key_value; 349f317a3a3Skrishna 350f317a3a3Skrishna /* for CRYPTO_KEY_REFERENCE ck_format */ 351f317a3a3Skrishna crypto_object_id_t cku_key_id; /* reference to object key */ 352f317a3a3Skrishna 353f317a3a3Skrishna /* for CRYPTO_KEY_ATTR_LIST ck_format */ 354f317a3a3Skrishna struct { 355f317a3a3Skrishna uint32_t cku_a_count; /* number of attributes */ 356f317a3a3Skrishna caddr32_t cku_a_oattr; 357f317a3a3Skrishna } cku_key_attrs; 358f317a3a3Skrishna } cku_data; /* Crypto Key union */ 359f317a3a3Skrishna } crypto_key32_t; 360f317a3a3Skrishna 361f317a3a3Skrishna #endif /* _SYSCALL32 */ 362f317a3a3Skrishna 3637c478bd9Sstevel@tonic-gate #define ck_data cku_data.cku_key_value.cku_v_data 3647c478bd9Sstevel@tonic-gate #define ck_length cku_data.cku_key_value.cku_v_length 3657c478bd9Sstevel@tonic-gate #define ck_obj_id cku_data.cku_key_id 3667c478bd9Sstevel@tonic-gate #define ck_count cku_data.cku_key_attrs.cku_a_count 3677c478bd9Sstevel@tonic-gate #define ck_attrs cku_data.cku_key_attrs.cku_a_oattr 3687c478bd9Sstevel@tonic-gate 3697c478bd9Sstevel@tonic-gate /* 3707c478bd9Sstevel@tonic-gate * Raw key lengths are expressed in number of bits. 3717c478bd9Sstevel@tonic-gate * The following macro returns the minimum number of 3727c478bd9Sstevel@tonic-gate * bytes that can contain the specified number of bits. 3737c478bd9Sstevel@tonic-gate */ 3747c478bd9Sstevel@tonic-gate #define CRYPTO_BITS2BYTES(n) (((n) + 7) >> 3) 3757c478bd9Sstevel@tonic-gate 3767c478bd9Sstevel@tonic-gate /* Providers */ 3777c478bd9Sstevel@tonic-gate 3787c478bd9Sstevel@tonic-gate typedef enum { 3797c478bd9Sstevel@tonic-gate CRYPTO_HW_PROVIDER = 0, 3807c478bd9Sstevel@tonic-gate CRYPTO_SW_PROVIDER, 3817c478bd9Sstevel@tonic-gate CRYPTO_LOGICAL_PROVIDER 3827c478bd9Sstevel@tonic-gate } crypto_provider_type_t; 3837c478bd9Sstevel@tonic-gate 3847c478bd9Sstevel@tonic-gate typedef uint32_t crypto_provider_id_t; 3857c478bd9Sstevel@tonic-gate #define KCF_PROVID_INVALID ((uint32_t)-1) 3867c478bd9Sstevel@tonic-gate 3877c478bd9Sstevel@tonic-gate typedef struct crypto_provider_entry { 3887c478bd9Sstevel@tonic-gate crypto_provider_id_t pe_provider_id; 3897c478bd9Sstevel@tonic-gate uint_t pe_mechanism_count; 3907c478bd9Sstevel@tonic-gate } crypto_provider_entry_t; 3917c478bd9Sstevel@tonic-gate 3927c478bd9Sstevel@tonic-gate typedef struct crypto_dev_list_entry { 3937c478bd9Sstevel@tonic-gate char le_dev_name[MAXNAMELEN]; 3947c478bd9Sstevel@tonic-gate uint_t le_dev_instance; 3957c478bd9Sstevel@tonic-gate uint_t le_mechanism_count; 3967c478bd9Sstevel@tonic-gate } crypto_dev_list_entry_t; 3977c478bd9Sstevel@tonic-gate 3987c478bd9Sstevel@tonic-gate /* User type for authentication ioctls and SPI entry points */ 3997c478bd9Sstevel@tonic-gate 4007c478bd9Sstevel@tonic-gate typedef enum crypto_user_type { 4017c478bd9Sstevel@tonic-gate CRYPTO_SO = 0, 4027c478bd9Sstevel@tonic-gate CRYPTO_USER 4037c478bd9Sstevel@tonic-gate } crypto_user_type_t; 4047c478bd9Sstevel@tonic-gate 4057c478bd9Sstevel@tonic-gate /* Version for provider management ioctls and SPI entry points */ 4067c478bd9Sstevel@tonic-gate 4077c478bd9Sstevel@tonic-gate typedef struct crypto_version { 4087c478bd9Sstevel@tonic-gate uchar_t cv_major; 4097c478bd9Sstevel@tonic-gate uchar_t cv_minor; 4107c478bd9Sstevel@tonic-gate } crypto_version_t; 4117c478bd9Sstevel@tonic-gate 4127c478bd9Sstevel@tonic-gate /* session data structure opaque to the consumer */ 4137c478bd9Sstevel@tonic-gate typedef void *crypto_session_t; 4147c478bd9Sstevel@tonic-gate 415c892ebf1Skrishna /* provider data structure opaque to the consumer */ 416894b2776Smcpowers typedef void *crypto_provider_t; 417894b2776Smcpowers 418c892ebf1Skrishna /* Limits used by both consumers and providers */ 419c892ebf1Skrishna #define CRYPTO_EXT_SIZE_LABEL 32 420c892ebf1Skrishna #define CRYPTO_EXT_SIZE_MANUF 32 421c892ebf1Skrishna #define CRYPTO_EXT_SIZE_MODEL 16 422c892ebf1Skrishna #define CRYPTO_EXT_SIZE_SERIAL 16 423c892ebf1Skrishna #define CRYPTO_EXT_SIZE_TIME 16 424c892ebf1Skrishna 425c892ebf1Skrishna typedef struct crypto_provider_ext_info { 426c892ebf1Skrishna uchar_t ei_label[CRYPTO_EXT_SIZE_LABEL]; 427c892ebf1Skrishna uchar_t ei_manufacturerID[CRYPTO_EXT_SIZE_MANUF]; 428c892ebf1Skrishna uchar_t ei_model[CRYPTO_EXT_SIZE_MODEL]; 429c892ebf1Skrishna uchar_t ei_serial_number[CRYPTO_EXT_SIZE_SERIAL]; 430c892ebf1Skrishna ulong_t ei_flags; 431c892ebf1Skrishna ulong_t ei_max_session_count; 432c892ebf1Skrishna ulong_t ei_max_pin_len; 433c892ebf1Skrishna ulong_t ei_min_pin_len; 434c892ebf1Skrishna ulong_t ei_total_public_memory; 435c892ebf1Skrishna ulong_t ei_free_public_memory; 436c892ebf1Skrishna ulong_t ei_total_private_memory; 437c892ebf1Skrishna ulong_t ei_free_private_memory; 438c892ebf1Skrishna crypto_version_t ei_hardware_version; 439c892ebf1Skrishna crypto_version_t ei_firmware_version; 440c892ebf1Skrishna uchar_t ei_time[CRYPTO_EXT_SIZE_TIME]; 441c892ebf1Skrishna } crypto_provider_ext_info_t; 442c892ebf1Skrishna 4437c478bd9Sstevel@tonic-gate typedef uint_t crypto_session_id_t; 4447c478bd9Sstevel@tonic-gate 44523c57df7Smcpowers typedef enum cmd_type { 44623c57df7Smcpowers COPY_FROM_DATA, 44723c57df7Smcpowers COPY_TO_DATA, 44823c57df7Smcpowers COMPARE_TO_DATA, 44923c57df7Smcpowers MD5_DIGEST_DATA, 45023c57df7Smcpowers SHA1_DIGEST_DATA, 45123c57df7Smcpowers SHA2_DIGEST_DATA 45223c57df7Smcpowers } cmd_type_t; 45323c57df7Smcpowers 45423c57df7Smcpowers #define CRYPTO_DO_UPDATE 0x01 45523c57df7Smcpowers #define CRYPTO_DO_FINAL 0x02 45623c57df7Smcpowers #define CRYPTO_DO_MD5 0x04 45723c57df7Smcpowers #define CRYPTO_DO_SHA1 0x08 45823c57df7Smcpowers #define CRYPTO_DO_SIGN 0x10 45923c57df7Smcpowers #define CRYPTO_DO_VERIFY 0x20 46023c57df7Smcpowers #define CRYPTO_DO_SHA2 0x40 46123c57df7Smcpowers 46223c57df7Smcpowers #define PROVIDER_OWNS_KEY_SCHEDULE 0x00000001 46323c57df7Smcpowers 4647c478bd9Sstevel@tonic-gate /* 4657c478bd9Sstevel@tonic-gate * Common cryptographic status and error codes. 4667c478bd9Sstevel@tonic-gate */ 4677c478bd9Sstevel@tonic-gate #define CRYPTO_SUCCESS 0x00000000 4687c478bd9Sstevel@tonic-gate #define CRYPTO_CANCEL 0x00000001 4697c478bd9Sstevel@tonic-gate #define CRYPTO_HOST_MEMORY 0x00000002 4707c478bd9Sstevel@tonic-gate #define CRYPTO_GENERAL_ERROR 0x00000003 4717c478bd9Sstevel@tonic-gate #define CRYPTO_FAILED 0x00000004 4727c478bd9Sstevel@tonic-gate #define CRYPTO_ARGUMENTS_BAD 0x00000005 4737c478bd9Sstevel@tonic-gate #define CRYPTO_ATTRIBUTE_READ_ONLY 0x00000006 4747c478bd9Sstevel@tonic-gate #define CRYPTO_ATTRIBUTE_SENSITIVE 0x00000007 4757c478bd9Sstevel@tonic-gate #define CRYPTO_ATTRIBUTE_TYPE_INVALID 0x00000008 4767c478bd9Sstevel@tonic-gate #define CRYPTO_ATTRIBUTE_VALUE_INVALID 0x00000009 4777c478bd9Sstevel@tonic-gate #define CRYPTO_CANCELED 0x0000000A 4787c478bd9Sstevel@tonic-gate #define CRYPTO_DATA_INVALID 0x0000000B 4797c478bd9Sstevel@tonic-gate #define CRYPTO_DATA_LEN_RANGE 0x0000000C 4807c478bd9Sstevel@tonic-gate #define CRYPTO_DEVICE_ERROR 0x0000000D 4817c478bd9Sstevel@tonic-gate #define CRYPTO_DEVICE_MEMORY 0x0000000E 4827c478bd9Sstevel@tonic-gate #define CRYPTO_DEVICE_REMOVED 0x0000000F 4837c478bd9Sstevel@tonic-gate #define CRYPTO_ENCRYPTED_DATA_INVALID 0x00000010 4847c478bd9Sstevel@tonic-gate #define CRYPTO_ENCRYPTED_DATA_LEN_RANGE 0x00000011 4857c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_HANDLE_INVALID 0x00000012 4867c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_SIZE_RANGE 0x00000013 4877c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_TYPE_INCONSISTENT 0x00000014 4887c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_NOT_NEEDED 0x00000015 4897c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_CHANGED 0x00000016 4907c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_NEEDED 0x00000017 4917c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_INDIGESTIBLE 0x00000018 4927c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_FUNCTION_NOT_PERMITTED 0x00000019 4937c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_NOT_WRAPPABLE 0x0000001A 4947c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_UNEXTRACTABLE 0x0000001B 4957c478bd9Sstevel@tonic-gate #define CRYPTO_MECHANISM_INVALID 0x0000001C 4967c478bd9Sstevel@tonic-gate #define CRYPTO_MECHANISM_PARAM_INVALID 0x0000001D 4977c478bd9Sstevel@tonic-gate #define CRYPTO_OBJECT_HANDLE_INVALID 0x0000001E 4987c478bd9Sstevel@tonic-gate #define CRYPTO_OPERATION_IS_ACTIVE 0x0000001F 4997c478bd9Sstevel@tonic-gate #define CRYPTO_OPERATION_NOT_INITIALIZED 0x00000020 5007c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_INCORRECT 0x00000021 5017c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_INVALID 0x00000022 5027c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_LEN_RANGE 0x00000023 5037c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_EXPIRED 0x00000024 5047c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_LOCKED 0x00000025 5057c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_CLOSED 0x00000026 5067c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_COUNT 0x00000027 5077c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_HANDLE_INVALID 0x00000028 5087c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_READ_ONLY 0x00000029 5097c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_EXISTS 0x0000002A 5107c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_READ_ONLY_EXISTS 0x0000002B 5117c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_READ_WRITE_SO_EXISTS 0x0000002C 5127c478bd9Sstevel@tonic-gate #define CRYPTO_SIGNATURE_INVALID 0x0000002D 5137c478bd9Sstevel@tonic-gate #define CRYPTO_SIGNATURE_LEN_RANGE 0x0000002E 5147c478bd9Sstevel@tonic-gate #define CRYPTO_TEMPLATE_INCOMPLETE 0x0000002F 5157c478bd9Sstevel@tonic-gate #define CRYPTO_TEMPLATE_INCONSISTENT 0x00000030 5167c478bd9Sstevel@tonic-gate #define CRYPTO_UNWRAPPING_KEY_HANDLE_INVALID 0x00000031 5177c478bd9Sstevel@tonic-gate #define CRYPTO_UNWRAPPING_KEY_SIZE_RANGE 0x00000032 5187c478bd9Sstevel@tonic-gate #define CRYPTO_UNWRAPPING_KEY_TYPE_INCONSISTENT 0x00000033 5197c478bd9Sstevel@tonic-gate #define CRYPTO_USER_ALREADY_LOGGED_IN 0x00000034 5207c478bd9Sstevel@tonic-gate #define CRYPTO_USER_NOT_LOGGED_IN 0x00000035 5217c478bd9Sstevel@tonic-gate #define CRYPTO_USER_PIN_NOT_INITIALIZED 0x00000036 5227c478bd9Sstevel@tonic-gate #define CRYPTO_USER_TYPE_INVALID 0x00000037 5237c478bd9Sstevel@tonic-gate #define CRYPTO_USER_ANOTHER_ALREADY_LOGGED_IN 0x00000038 5247c478bd9Sstevel@tonic-gate #define CRYPTO_USER_TOO_MANY_TYPES 0x00000039 5257c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPED_KEY_INVALID 0x0000003A 5267c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPED_KEY_LEN_RANGE 0x0000003B 5277c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPING_KEY_HANDLE_INVALID 0x0000003C 5287c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPING_KEY_SIZE_RANGE 0x0000003D 5297c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPING_KEY_TYPE_INCONSISTENT 0x0000003E 5307c478bd9Sstevel@tonic-gate #define CRYPTO_RANDOM_SEED_NOT_SUPPORTED 0x0000003F 5317c478bd9Sstevel@tonic-gate #define CRYPTO_RANDOM_NO_RNG 0x00000040 5327c478bd9Sstevel@tonic-gate #define CRYPTO_DOMAIN_PARAMS_INVALID 0x00000041 5337c478bd9Sstevel@tonic-gate #define CRYPTO_BUFFER_TOO_SMALL 0x00000042 5347c478bd9Sstevel@tonic-gate #define CRYPTO_INFORMATION_SENSITIVE 0x00000043 5357c478bd9Sstevel@tonic-gate #define CRYPTO_NOT_SUPPORTED 0x00000044 5367c478bd9Sstevel@tonic-gate 5377c478bd9Sstevel@tonic-gate #define CRYPTO_QUEUED 0x00000045 5387c478bd9Sstevel@tonic-gate #define CRYPTO_BUFFER_TOO_BIG 0x00000046 5397c478bd9Sstevel@tonic-gate #define CRYPTO_INVALID_CONTEXT 0x00000047 5407c478bd9Sstevel@tonic-gate #define CRYPTO_INVALID_MAC 0x00000048 5417c478bd9Sstevel@tonic-gate #define CRYPTO_MECH_NOT_SUPPORTED 0x00000049 5427c478bd9Sstevel@tonic-gate #define CRYPTO_INCONSISTENT_ATTRIBUTE 0x0000004A 5437c478bd9Sstevel@tonic-gate #define CRYPTO_NO_PERMISSION 0x0000004B 5447c478bd9Sstevel@tonic-gate #define CRYPTO_INVALID_PROVIDER_ID 0x0000004C 5457c478bd9Sstevel@tonic-gate #define CRYPTO_VERSION_MISMATCH 0x0000004D 5467c478bd9Sstevel@tonic-gate #define CRYPTO_BUSY 0x0000004E 5477c478bd9Sstevel@tonic-gate #define CRYPTO_UNKNOWN_PROVIDER 0x0000004F 5487c478bd9Sstevel@tonic-gate #define CRYPTO_MODVERIFICATION_FAILED 0x00000050 5497c478bd9Sstevel@tonic-gate #define CRYPTO_OLD_CTX_TEMPLATE 0x00000051 5507c478bd9Sstevel@tonic-gate #define CRYPTO_WEAK_KEY 0x00000052 5517c478bd9Sstevel@tonic-gate 5527c478bd9Sstevel@tonic-gate /* 5537c478bd9Sstevel@tonic-gate * Special values that can be used to indicate that information is unavailable 5547c478bd9Sstevel@tonic-gate * or that there is not practical limit. These values can be used 5557c478bd9Sstevel@tonic-gate * by fields of the SPI crypto_provider_ext_info(9S) structure. 5567c478bd9Sstevel@tonic-gate * The value of CRYPTO_UNAVAILABLE_INFO should be the same as 5577c478bd9Sstevel@tonic-gate * CK_UNAVAILABLE_INFO in the PKCS#11 spec. 5587c478bd9Sstevel@tonic-gate */ 5597c478bd9Sstevel@tonic-gate #define CRYPTO_UNAVAILABLE_INFO ((ulong_t)(-1)) 5607c478bd9Sstevel@tonic-gate #define CRYPTO_EFFECTIVELY_INFINITE 0x0 5617c478bd9Sstevel@tonic-gate 5627c478bd9Sstevel@tonic-gate #ifdef __cplusplus 5637c478bd9Sstevel@tonic-gate } 5647c478bd9Sstevel@tonic-gate #endif 5657c478bd9Sstevel@tonic-gate 5667c478bd9Sstevel@tonic-gate #endif /* _SYS_CRYPTO_COMMON_H */ 567