17c478bd9Sstevel@tonic-gate /* 27c478bd9Sstevel@tonic-gate * CDDL HEADER START 37c478bd9Sstevel@tonic-gate * 47c478bd9Sstevel@tonic-gate * The contents of this file are subject to the terms of the 5c892ebf1Skrishna * Common Development and Distribution License (the "License"). 6c892ebf1Skrishna * You may not use this file except in compliance with the License. 77c478bd9Sstevel@tonic-gate * 87c478bd9Sstevel@tonic-gate * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 97c478bd9Sstevel@tonic-gate * or http://www.opensolaris.org/os/licensing. 107c478bd9Sstevel@tonic-gate * See the License for the specific language governing permissions 117c478bd9Sstevel@tonic-gate * and limitations under the License. 127c478bd9Sstevel@tonic-gate * 137c478bd9Sstevel@tonic-gate * When distributing Covered Code, include this CDDL HEADER in each 147c478bd9Sstevel@tonic-gate * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 157c478bd9Sstevel@tonic-gate * If applicable, add the following below this CDDL HEADER, with the 167c478bd9Sstevel@tonic-gate * fields enclosed by brackets "[]" replaced with your own identifying 177c478bd9Sstevel@tonic-gate * information: Portions Copyright [yyyy] [name of copyright owner] 187c478bd9Sstevel@tonic-gate * 197c478bd9Sstevel@tonic-gate * CDDL HEADER END 207c478bd9Sstevel@tonic-gate */ 217c478bd9Sstevel@tonic-gate /* 22e8c016efSMark Powers * Copyright 2009 Sun Microsystems, Inc. All rights reserved. 237c478bd9Sstevel@tonic-gate * Use is subject to license terms. 247c478bd9Sstevel@tonic-gate */ 257c478bd9Sstevel@tonic-gate 267c478bd9Sstevel@tonic-gate #ifndef _SYS_CRYPTO_COMMON_H 277c478bd9Sstevel@tonic-gate #define _SYS_CRYPTO_COMMON_H 287c478bd9Sstevel@tonic-gate 297c478bd9Sstevel@tonic-gate /* 307c478bd9Sstevel@tonic-gate * Header file for the common data structures of the cryptographic framework 317c478bd9Sstevel@tonic-gate */ 327c478bd9Sstevel@tonic-gate 337c478bd9Sstevel@tonic-gate #ifdef __cplusplus 347c478bd9Sstevel@tonic-gate extern "C" { 357c478bd9Sstevel@tonic-gate #endif 367c478bd9Sstevel@tonic-gate 377c478bd9Sstevel@tonic-gate #include <sys/types.h> 387c478bd9Sstevel@tonic-gate #include <sys/uio.h> 397c478bd9Sstevel@tonic-gate #include <sys/stream.h> 407c478bd9Sstevel@tonic-gate #include <sys/mutex.h> 417c478bd9Sstevel@tonic-gate #include <sys/condvar.h> 427c478bd9Sstevel@tonic-gate 437c478bd9Sstevel@tonic-gate 447c478bd9Sstevel@tonic-gate /* Cryptographic Mechanisms */ 457c478bd9Sstevel@tonic-gate 467c478bd9Sstevel@tonic-gate #define CRYPTO_MAX_MECH_NAME 32 477c478bd9Sstevel@tonic-gate typedef char crypto_mech_name_t[CRYPTO_MAX_MECH_NAME]; 487c478bd9Sstevel@tonic-gate 497c478bd9Sstevel@tonic-gate typedef uint64_t crypto_mech_type_t; 507c478bd9Sstevel@tonic-gate 517c478bd9Sstevel@tonic-gate typedef struct crypto_mechanism { 527c478bd9Sstevel@tonic-gate crypto_mech_type_t cm_type; /* mechanism type */ 537c478bd9Sstevel@tonic-gate caddr_t cm_param; /* mech. parameter */ 547c478bd9Sstevel@tonic-gate size_t cm_param_len; /* mech. parameter len */ 557c478bd9Sstevel@tonic-gate } crypto_mechanism_t; 567c478bd9Sstevel@tonic-gate 57f317a3a3Skrishna #ifdef _SYSCALL32 58f317a3a3Skrishna 59f317a3a3Skrishna typedef struct crypto_mechanism32 { 60f317a3a3Skrishna crypto_mech_type_t cm_type; /* mechanism type */ 61f317a3a3Skrishna caddr32_t cm_param; /* mech. parameter */ 62f317a3a3Skrishna size32_t cm_param_len; /* mech. parameter len */ 63f317a3a3Skrishna } crypto_mechanism32_t; 64f317a3a3Skrishna 65f317a3a3Skrishna #endif /* _SYSCALL32 */ 66f317a3a3Skrishna 671e9884acSmcpowers #ifdef _KERNEL 68d2b32306Smcpowers /* CK_AES_CTR_PARAMS provides parameters to the CKM_AES_CTR mechanism */ 69d2b32306Smcpowers typedef struct CK_AES_CTR_PARAMS { 70d2b32306Smcpowers ulong_t ulCounterBits; 71d2b32306Smcpowers uint8_t cb[16]; 72d2b32306Smcpowers } CK_AES_CTR_PARAMS; 731e9884acSmcpowers #endif 74d2b32306Smcpowers 75d2b32306Smcpowers /* CK_AES_CCM_PARAMS provides parameters to the CKM_AES_CCM mechanism */ 76d2b32306Smcpowers typedef struct CK_AES_CCM_PARAMS { 77d2b32306Smcpowers ulong_t ulMACSize; 78d2b32306Smcpowers ulong_t ulNonceSize; 79d2b32306Smcpowers ulong_t ulAuthDataSize; 80d2b32306Smcpowers ulong_t ulDataSize; /* used for plaintext or ciphertext */ 81d2b32306Smcpowers uchar_t *nonce; 82d2b32306Smcpowers uchar_t *authData; 83d2b32306Smcpowers } CK_AES_CCM_PARAMS; 84d2b32306Smcpowers 854d703b5cSMark Powers /* CK_AES_GCM_PARAMS provides parameters to the CKM_AES_GCM mechanism */ 864d703b5cSMark Powers typedef struct CK_AES_GCM_PARAMS { 874d703b5cSMark Powers uchar_t *pIv; 884d703b5cSMark Powers ulong_t ulIvLen; 894d703b5cSMark Powers ulong_t ulIvBits; 904d703b5cSMark Powers uchar_t *pAAD; 914d703b5cSMark Powers ulong_t ulAADLen; 924d703b5cSMark Powers ulong_t ulTagBits; 934d703b5cSMark Powers } CK_AES_GCM_PARAMS; 944d703b5cSMark Powers 95983a1033SMark Powers /* CK_AES_GMAC_PARAMS provides parameters to the CKM_AES_GMAC mechanism */ 96983a1033SMark Powers typedef struct CK_AES_GMAC_PARAMS { 97983a1033SMark Powers uchar_t *pIv; 98983a1033SMark Powers uchar_t *pAAD; 99983a1033SMark Powers ulong_t ulAADLen; 100983a1033SMark Powers } CK_AES_GMAC_PARAMS; 101983a1033SMark Powers 1028d4583b0Sfr41279 #ifdef _KERNEL 1038d4583b0Sfr41279 /* 1048d4583b0Sfr41279 * CK_ECDH1_DERIVE_PARAMS provides the parameters to the 1058d4583b0Sfr41279 * CKM_ECDH1_KEY_DERIVE mechanism 1068d4583b0Sfr41279 */ 1078d4583b0Sfr41279 typedef struct CK_ECDH1_DERIVE_PARAMS { 1088d4583b0Sfr41279 ulong_t kdf; 1098d4583b0Sfr41279 ulong_t ulSharedDataLen; 1108d4583b0Sfr41279 uchar_t *pSharedData; 1118d4583b0Sfr41279 ulong_t ulPublicDataLen; 1128d4583b0Sfr41279 uchar_t *pPublicData; 1138d4583b0Sfr41279 } CK_ECDH1_DERIVE_PARAMS; 1148d4583b0Sfr41279 #endif 1158d4583b0Sfr41279 116d2b32306Smcpowers #ifdef _KERNEL 117d2b32306Smcpowers #ifdef _SYSCALL32 118d2b32306Smcpowers 119d2b32306Smcpowers /* needed for 32-bit applications running on 64-bit kernels */ 120d2b32306Smcpowers typedef struct CK_AES_CTR_PARAMS32 { 121d2b32306Smcpowers uint32_t ulCounterBits; 122d2b32306Smcpowers uint8_t cb[16]; 123d2b32306Smcpowers } CK_AES_CTR_PARAMS32; 124d2b32306Smcpowers 125d2b32306Smcpowers /* needed for 32-bit applications running on 64-bit kernels */ 126d2b32306Smcpowers typedef struct CK_AES_CCM_PARAMS32 { 127d2b32306Smcpowers uint32_t ulMACSize; 128d2b32306Smcpowers uint32_t ulNonceSize; 129d2b32306Smcpowers uint32_t ulAuthDataSize; 130d2b32306Smcpowers uint32_t ulDataSize; 131d2b32306Smcpowers caddr32_t nonce; 132d2b32306Smcpowers caddr32_t authData; 133d2b32306Smcpowers } CK_AES_CCM_PARAMS32; 134d2b32306Smcpowers 1354d703b5cSMark Powers /* needed for 32-bit applications running on 64-bit kernels */ 1364d703b5cSMark Powers typedef struct CK_AES_GCM_PARAMS32 { 1374d703b5cSMark Powers caddr32_t pIv; 1384d703b5cSMark Powers uint32_t ulIvLen; 1394d703b5cSMark Powers uint32_t ulIvBits; 1404d703b5cSMark Powers caddr32_t pAAD; 1414d703b5cSMark Powers uint32_t ulAADLen; 1424d703b5cSMark Powers uint32_t ulTagBits; 1434d703b5cSMark Powers } CK_AES_GCM_PARAMS32; 1444d703b5cSMark Powers 145983a1033SMark Powers /* needed for 32-bit applications running on 64-bit kernels */ 146983a1033SMark Powers typedef struct CK_AES_GMAC_PARAMS32 { 147983a1033SMark Powers caddr32_t pIv; 148983a1033SMark Powers caddr32_t pAAD; 149983a1033SMark Powers uint32_t ulAADLen; 150983a1033SMark Powers } CK_AES_GMAC_PARAMS32; 151983a1033SMark Powers 1528d4583b0Sfr41279 typedef struct CK_ECDH1_DERIVE_PARAMS32 { 1538d4583b0Sfr41279 uint32_t kdf; 1548d4583b0Sfr41279 uint32_t ulSharedDataLen; 1558d4583b0Sfr41279 caddr32_t pSharedData; 1568d4583b0Sfr41279 uint32_t ulPublicDataLen; 1578d4583b0Sfr41279 caddr32_t pPublicData; 1588d4583b0Sfr41279 } CK_ECDH1_DERIVE_PARAMS32; 1598d4583b0Sfr41279 160d2b32306Smcpowers #endif /* _SYSCALL32 */ 161d2b32306Smcpowers #endif /* _KERNEL */ 162d2b32306Smcpowers 1637c478bd9Sstevel@tonic-gate /* 1646a1073f8Skrishna * The measurement unit bit flag for a mechanism's minimum or maximum key size. 1657c478bd9Sstevel@tonic-gate * The unit are mechanism dependant. It can be in bits or in bytes. 1667c478bd9Sstevel@tonic-gate */ 1677c478bd9Sstevel@tonic-gate typedef uint32_t crypto_keysize_unit_t; 1687c478bd9Sstevel@tonic-gate 1696a1073f8Skrishna /* 1706a1073f8Skrishna * The following bit flags are valid in cm_mech_flags field in 1716a1073f8Skrishna * the crypto_mech_info_t structure of the SPI. 1726a1073f8Skrishna * 1736a1073f8Skrishna * Only the first two bit flags are valid in mi_keysize_unit 1746a1073f8Skrishna * field in the crypto_mechanism_info_t structure of the API. 1756a1073f8Skrishna */ 1767c478bd9Sstevel@tonic-gate #define CRYPTO_KEYSIZE_UNIT_IN_BITS 0x00000001 1777c478bd9Sstevel@tonic-gate #define CRYPTO_KEYSIZE_UNIT_IN_BYTES 0x00000002 1786a1073f8Skrishna #define CRYPTO_CAN_SHARE_OPSTATE 0x00000004 /* supports sharing */ 1797c478bd9Sstevel@tonic-gate 1807c478bd9Sstevel@tonic-gate 1817c478bd9Sstevel@tonic-gate /* Mechanisms supported out-of-the-box */ 1825151fb12Sdarrenm #define SUN_CKM_MD4 "CKM_MD4" 1837c478bd9Sstevel@tonic-gate #define SUN_CKM_MD5 "CKM_MD5" 1847c478bd9Sstevel@tonic-gate #define SUN_CKM_MD5_HMAC "CKM_MD5_HMAC" 1857c478bd9Sstevel@tonic-gate #define SUN_CKM_MD5_HMAC_GENERAL "CKM_MD5_HMAC_GENERAL" 1867c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA1 "CKM_SHA_1" 1877c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA1_HMAC "CKM_SHA_1_HMAC" 1887c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA1_HMAC_GENERAL "CKM_SHA_1_HMAC_GENERAL" 1897c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA256 "CKM_SHA256" 1907c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA256_HMAC "CKM_SHA256_HMAC" 1917c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA256_HMAC_GENERAL "CKM_SHA256_HMAC_GENERAL" 1927c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA384 "CKM_SHA384" 1937c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA384_HMAC "CKM_SHA384_HMAC" 1947c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA384_HMAC_GENERAL "CKM_SHA384_HMAC_GENERAL" 1957c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA512 "CKM_SHA512" 1967c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA512_HMAC "CKM_SHA512_HMAC" 1977c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA512_HMAC_GENERAL "CKM_SHA512_HMAC_GENERAL" 1987c478bd9Sstevel@tonic-gate #define SUN_CKM_DES_CBC "CKM_DES_CBC" 1997c478bd9Sstevel@tonic-gate #define SUN_CKM_DES3_CBC "CKM_DES3_CBC" 2007c478bd9Sstevel@tonic-gate #define SUN_CKM_DES_ECB "CKM_DES_ECB" 2017c478bd9Sstevel@tonic-gate #define SUN_CKM_DES3_ECB "CKM_DES3_ECB" 202f66d273dSizick #define SUN_CKM_BLOWFISH_CBC "CKM_BLOWFISH_CBC" 203f66d273dSizick #define SUN_CKM_BLOWFISH_ECB "CKM_BLOWFISH_ECB" 2047c478bd9Sstevel@tonic-gate #define SUN_CKM_AES_CBC "CKM_AES_CBC" 2057c478bd9Sstevel@tonic-gate #define SUN_CKM_AES_ECB "CKM_AES_ECB" 206894b2776Smcpowers #define SUN_CKM_AES_CTR "CKM_AES_CTR" 2077fb8ff4bSktung #define SUN_CKM_AES_CCM "CKM_AES_CCM" 2084d703b5cSMark Powers #define SUN_CKM_AES_GCM "CKM_AES_GCM" 209983a1033SMark Powers #define SUN_CKM_AES_GMAC "CKM_AES_GMAC" 210*4df55fdeSJanie Lu #define SUN_CKM_AES_CFB128 "CKM_AES_CFB128" 2117c478bd9Sstevel@tonic-gate #define SUN_CKM_RC4 "CKM_RC4" 2127c478bd9Sstevel@tonic-gate #define SUN_CKM_RSA_PKCS "CKM_RSA_PKCS" 2137c478bd9Sstevel@tonic-gate #define SUN_CKM_RSA_X_509 "CKM_RSA_X_509" 2147c478bd9Sstevel@tonic-gate #define SUN_CKM_MD5_RSA_PKCS "CKM_MD5_RSA_PKCS" 2157c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA1_RSA_PKCS "CKM_SHA1_RSA_PKCS" 216f66d273dSizick #define SUN_CKM_SHA256_RSA_PKCS "CKM_SHA256_RSA_PKCS" 217f66d273dSizick #define SUN_CKM_SHA384_RSA_PKCS "CKM_SHA384_RSA_PKCS" 218f66d273dSizick #define SUN_CKM_SHA512_RSA_PKCS "CKM_SHA512_RSA_PKCS" 219f9fbec18Smcpowers #define SUN_CKM_EC_KEY_PAIR_GEN "CKM_EC_KEY_PAIR_GEN" 220f9fbec18Smcpowers #define SUN_CKM_ECDH1_DERIVE "CKM_ECDH1_DERIVE" 221f9fbec18Smcpowers #define SUN_CKM_ECDSA_SHA1 "CKM_ECDSA_SHA1" 222f9fbec18Smcpowers #define SUN_CKM_ECDSA "CKM_ECDSA" 2237c478bd9Sstevel@tonic-gate 2246a1073f8Skrishna /* Shared operation context format for CKM_RC4 */ 2256a1073f8Skrishna typedef struct { 22655553f71Sda73024 #if defined(__amd64) 22755553f71Sda73024 uint32_t i, j; 22855553f71Sda73024 uint32_t arr[256]; 22992a8e44dSDan OpenSolaris Anderson uint32_t flag; 23055553f71Sda73024 #else 23155553f71Sda73024 uchar_t arr[256]; 23255553f71Sda73024 uchar_t i, j; 23355553f71Sda73024 #endif /* __amd64 */ 2346a1073f8Skrishna uint64_t pad; /* For 64-bit alignment */ 2356a1073f8Skrishna } arcfour_state_t; 2366a1073f8Skrishna 2377c478bd9Sstevel@tonic-gate /* Data arguments of cryptographic operations */ 2387c478bd9Sstevel@tonic-gate 2397c478bd9Sstevel@tonic-gate typedef enum crypto_data_format { 2407c478bd9Sstevel@tonic-gate CRYPTO_DATA_RAW = 1, 2417c478bd9Sstevel@tonic-gate CRYPTO_DATA_UIO, 2427c478bd9Sstevel@tonic-gate CRYPTO_DATA_MBLK 2437c478bd9Sstevel@tonic-gate } crypto_data_format_t; 2447c478bd9Sstevel@tonic-gate 2457c478bd9Sstevel@tonic-gate typedef struct crypto_data { 2467c478bd9Sstevel@tonic-gate crypto_data_format_t cd_format; /* Format identifier */ 2477c478bd9Sstevel@tonic-gate off_t cd_offset; /* Offset from the beginning */ 2487c478bd9Sstevel@tonic-gate size_t cd_length; /* # of bytes in use */ 2497c478bd9Sstevel@tonic-gate caddr_t cd_miscdata; /* ancillary data */ 2507c478bd9Sstevel@tonic-gate union { 2517c478bd9Sstevel@tonic-gate /* Raw format */ 2527c478bd9Sstevel@tonic-gate iovec_t cdu_raw; /* Pointer and length */ 2537c478bd9Sstevel@tonic-gate 2547c478bd9Sstevel@tonic-gate /* uio scatter-gather format */ 2557c478bd9Sstevel@tonic-gate uio_t *cdu_uio; 2567c478bd9Sstevel@tonic-gate 2577c478bd9Sstevel@tonic-gate /* mblk scatter-gather format */ 2587c478bd9Sstevel@tonic-gate mblk_t *cdu_mp; /* The mblk chain */ 2597c478bd9Sstevel@tonic-gate 2607c478bd9Sstevel@tonic-gate } cdu; /* Crypto Data Union */ 2617c478bd9Sstevel@tonic-gate } crypto_data_t; 2627c478bd9Sstevel@tonic-gate 2637c478bd9Sstevel@tonic-gate #define cd_raw cdu.cdu_raw 2647c478bd9Sstevel@tonic-gate #define cd_uio cdu.cdu_uio 2657c478bd9Sstevel@tonic-gate #define cd_mp cdu.cdu_mp 2667c478bd9Sstevel@tonic-gate 2677c478bd9Sstevel@tonic-gate typedef struct crypto_dual_data { 2687c478bd9Sstevel@tonic-gate crypto_data_t dd_data; /* The data */ 2697c478bd9Sstevel@tonic-gate off_t dd_offset2; /* Used by dual operation */ 2707c478bd9Sstevel@tonic-gate size_t dd_len2; /* # of bytes to take */ 2717c478bd9Sstevel@tonic-gate } crypto_dual_data_t; 2727c478bd9Sstevel@tonic-gate 2737c478bd9Sstevel@tonic-gate #define dd_format dd_data.cd_format 2747c478bd9Sstevel@tonic-gate #define dd_offset1 dd_data.cd_offset 2757c478bd9Sstevel@tonic-gate #define dd_len1 dd_data.cd_length 2767c478bd9Sstevel@tonic-gate #define dd_miscdata dd_data.cd_miscdata 2777c478bd9Sstevel@tonic-gate #define dd_raw dd_data.cd_raw 2787c478bd9Sstevel@tonic-gate #define dd_uio dd_data.cd_uio 2797c478bd9Sstevel@tonic-gate #define dd_mp dd_data.cd_mp 2807c478bd9Sstevel@tonic-gate 2817c478bd9Sstevel@tonic-gate /* The keys, and their contents */ 2827c478bd9Sstevel@tonic-gate 2837c478bd9Sstevel@tonic-gate typedef enum { 2847c478bd9Sstevel@tonic-gate CRYPTO_KEY_RAW = 1, /* ck_data is a cleartext key */ 2857c478bd9Sstevel@tonic-gate CRYPTO_KEY_REFERENCE, /* ck_obj_id is an opaque reference */ 2867c478bd9Sstevel@tonic-gate CRYPTO_KEY_ATTR_LIST /* ck_attrs is a list of object attributes */ 2877c478bd9Sstevel@tonic-gate } crypto_key_format_t; 2887c478bd9Sstevel@tonic-gate 2897c478bd9Sstevel@tonic-gate typedef uint64_t crypto_attr_type_t; 2907c478bd9Sstevel@tonic-gate 2917c478bd9Sstevel@tonic-gate /* Attribute types to use for passing a RSA public key or a private key. */ 2927c478bd9Sstevel@tonic-gate #define SUN_CKA_MODULUS 0x00000120 2937c478bd9Sstevel@tonic-gate #define SUN_CKA_MODULUS_BITS 0x00000121 2947c478bd9Sstevel@tonic-gate #define SUN_CKA_PUBLIC_EXPONENT 0x00000122 2957c478bd9Sstevel@tonic-gate #define SUN_CKA_PRIVATE_EXPONENT 0x00000123 2967c478bd9Sstevel@tonic-gate #define SUN_CKA_PRIME_1 0x00000124 2977c478bd9Sstevel@tonic-gate #define SUN_CKA_PRIME_2 0x00000125 2987c478bd9Sstevel@tonic-gate #define SUN_CKA_EXPONENT_1 0x00000126 2997c478bd9Sstevel@tonic-gate #define SUN_CKA_EXPONENT_2 0x00000127 3007c478bd9Sstevel@tonic-gate #define SUN_CKA_COEFFICIENT 0x00000128 3017c478bd9Sstevel@tonic-gate #define SUN_CKA_PRIME 0x00000130 3027c478bd9Sstevel@tonic-gate #define SUN_CKA_SUBPRIME 0x00000131 3037c478bd9Sstevel@tonic-gate #define SUN_CKA_BASE 0x00000132 3047c478bd9Sstevel@tonic-gate 305f9fbec18Smcpowers #define CKK_EC 0x00000003 306f9fbec18Smcpowers #define CKK_GENERIC_SECRET 0x00000010 307f9fbec18Smcpowers #define CKK_RC4 0x00000012 308f9fbec18Smcpowers #define CKK_AES 0x0000001F 309f9fbec18Smcpowers #define CKK_DES 0x00000013 310f9fbec18Smcpowers #define CKK_DES2 0x00000014 311f9fbec18Smcpowers #define CKK_DES3 0x00000015 312f9fbec18Smcpowers 313f9fbec18Smcpowers #define CKO_PUBLIC_KEY 0x00000002 314f9fbec18Smcpowers #define CKO_PRIVATE_KEY 0x00000003 315f9fbec18Smcpowers #define CKA_CLASS 0x00000000 316f9fbec18Smcpowers #define CKA_VALUE 0x00000011 317f9fbec18Smcpowers #define CKA_KEY_TYPE 0x00000100 318f9fbec18Smcpowers #define CKA_VALUE_LEN 0x00000161 319f9fbec18Smcpowers #define CKA_EC_PARAMS 0x00000180 320f9fbec18Smcpowers #define CKA_EC_POINT 0x00000181 321f9fbec18Smcpowers 3227c478bd9Sstevel@tonic-gate typedef uint32_t crypto_object_id_t; 3237c478bd9Sstevel@tonic-gate 3247c478bd9Sstevel@tonic-gate typedef struct crypto_object_attribute { 3257c478bd9Sstevel@tonic-gate crypto_attr_type_t oa_type; /* attribute type */ 3267c478bd9Sstevel@tonic-gate caddr_t oa_value; /* attribute value */ 3277c478bd9Sstevel@tonic-gate ssize_t oa_value_len; /* length of attribute value */ 3287c478bd9Sstevel@tonic-gate } crypto_object_attribute_t; 3297c478bd9Sstevel@tonic-gate 3307c478bd9Sstevel@tonic-gate typedef struct crypto_key { 3317c478bd9Sstevel@tonic-gate crypto_key_format_t ck_format; /* format identifier */ 3327c478bd9Sstevel@tonic-gate union { 3337c478bd9Sstevel@tonic-gate /* for CRYPTO_KEY_RAW ck_format */ 3347c478bd9Sstevel@tonic-gate struct { 3357c478bd9Sstevel@tonic-gate uint_t cku_v_length; /* # of bits in ck_data */ 3367c478bd9Sstevel@tonic-gate void *cku_v_data; /* ptr to key value */ 3377c478bd9Sstevel@tonic-gate } cku_key_value; 3387c478bd9Sstevel@tonic-gate 3397c478bd9Sstevel@tonic-gate /* for CRYPTO_KEY_REFERENCE ck_format */ 3407c478bd9Sstevel@tonic-gate crypto_object_id_t cku_key_id; /* reference to object key */ 3417c478bd9Sstevel@tonic-gate 3427c478bd9Sstevel@tonic-gate /* for CRYPTO_KEY_ATTR_LIST ck_format */ 3437c478bd9Sstevel@tonic-gate struct { 3447c478bd9Sstevel@tonic-gate uint_t cku_a_count; /* number of attributes */ 3457c478bd9Sstevel@tonic-gate crypto_object_attribute_t *cku_a_oattr; 3467c478bd9Sstevel@tonic-gate } cku_key_attrs; 3477c478bd9Sstevel@tonic-gate } cku_data; /* Crypto Key union */ 3487c478bd9Sstevel@tonic-gate } crypto_key_t; 3497c478bd9Sstevel@tonic-gate 350f317a3a3Skrishna #ifdef _SYSCALL32 351f317a3a3Skrishna 352f317a3a3Skrishna typedef struct crypto_object_attribute32 { 353f317a3a3Skrishna uint64_t oa_type; /* attribute type */ 354f317a3a3Skrishna caddr32_t oa_value; /* attribute value */ 355f317a3a3Skrishna ssize32_t oa_value_len; /* length of attribute value */ 356f317a3a3Skrishna } crypto_object_attribute32_t; 357f317a3a3Skrishna 358f317a3a3Skrishna typedef struct crypto_key32 { 359f317a3a3Skrishna crypto_key_format_t ck_format; /* format identifier */ 360f317a3a3Skrishna union { 361f317a3a3Skrishna /* for CRYPTO_KEY_RAW ck_format */ 362f317a3a3Skrishna struct { 363f317a3a3Skrishna uint32_t cku_v_length; /* # of bytes in ck_data */ 364f317a3a3Skrishna caddr32_t cku_v_data; /* ptr to key value */ 365f317a3a3Skrishna } cku_key_value; 366f317a3a3Skrishna 367f317a3a3Skrishna /* for CRYPTO_KEY_REFERENCE ck_format */ 368f317a3a3Skrishna crypto_object_id_t cku_key_id; /* reference to object key */ 369f317a3a3Skrishna 370f317a3a3Skrishna /* for CRYPTO_KEY_ATTR_LIST ck_format */ 371f317a3a3Skrishna struct { 372f317a3a3Skrishna uint32_t cku_a_count; /* number of attributes */ 373f317a3a3Skrishna caddr32_t cku_a_oattr; 374f317a3a3Skrishna } cku_key_attrs; 375f317a3a3Skrishna } cku_data; /* Crypto Key union */ 376f317a3a3Skrishna } crypto_key32_t; 377f317a3a3Skrishna 378f317a3a3Skrishna #endif /* _SYSCALL32 */ 379f317a3a3Skrishna 3807c478bd9Sstevel@tonic-gate #define ck_data cku_data.cku_key_value.cku_v_data 3817c478bd9Sstevel@tonic-gate #define ck_length cku_data.cku_key_value.cku_v_length 3827c478bd9Sstevel@tonic-gate #define ck_obj_id cku_data.cku_key_id 3837c478bd9Sstevel@tonic-gate #define ck_count cku_data.cku_key_attrs.cku_a_count 3847c478bd9Sstevel@tonic-gate #define ck_attrs cku_data.cku_key_attrs.cku_a_oattr 3857c478bd9Sstevel@tonic-gate 3867c478bd9Sstevel@tonic-gate /* 3877c478bd9Sstevel@tonic-gate * Raw key lengths are expressed in number of bits. 3887c478bd9Sstevel@tonic-gate * The following macro returns the minimum number of 3897c478bd9Sstevel@tonic-gate * bytes that can contain the specified number of bits. 3907c478bd9Sstevel@tonic-gate */ 3917c478bd9Sstevel@tonic-gate #define CRYPTO_BITS2BYTES(n) (((n) + 7) >> 3) 3927c478bd9Sstevel@tonic-gate 3937c478bd9Sstevel@tonic-gate /* Providers */ 3947c478bd9Sstevel@tonic-gate 3957c478bd9Sstevel@tonic-gate typedef enum { 3967c478bd9Sstevel@tonic-gate CRYPTO_HW_PROVIDER = 0, 3977c478bd9Sstevel@tonic-gate CRYPTO_SW_PROVIDER, 3987c478bd9Sstevel@tonic-gate CRYPTO_LOGICAL_PROVIDER 3997c478bd9Sstevel@tonic-gate } crypto_provider_type_t; 4007c478bd9Sstevel@tonic-gate 4017c478bd9Sstevel@tonic-gate typedef uint32_t crypto_provider_id_t; 4027c478bd9Sstevel@tonic-gate #define KCF_PROVID_INVALID ((uint32_t)-1) 4037c478bd9Sstevel@tonic-gate 4047c478bd9Sstevel@tonic-gate typedef struct crypto_provider_entry { 4057c478bd9Sstevel@tonic-gate crypto_provider_id_t pe_provider_id; 4067c478bd9Sstevel@tonic-gate uint_t pe_mechanism_count; 4077c478bd9Sstevel@tonic-gate } crypto_provider_entry_t; 4087c478bd9Sstevel@tonic-gate 4097c478bd9Sstevel@tonic-gate typedef struct crypto_dev_list_entry { 4107c478bd9Sstevel@tonic-gate char le_dev_name[MAXNAMELEN]; 4117c478bd9Sstevel@tonic-gate uint_t le_dev_instance; 4127c478bd9Sstevel@tonic-gate uint_t le_mechanism_count; 4137c478bd9Sstevel@tonic-gate } crypto_dev_list_entry_t; 4147c478bd9Sstevel@tonic-gate 4157c478bd9Sstevel@tonic-gate /* User type for authentication ioctls and SPI entry points */ 4167c478bd9Sstevel@tonic-gate 4177c478bd9Sstevel@tonic-gate typedef enum crypto_user_type { 4187c478bd9Sstevel@tonic-gate CRYPTO_SO = 0, 4197c478bd9Sstevel@tonic-gate CRYPTO_USER 4207c478bd9Sstevel@tonic-gate } crypto_user_type_t; 4217c478bd9Sstevel@tonic-gate 4227c478bd9Sstevel@tonic-gate /* Version for provider management ioctls and SPI entry points */ 4237c478bd9Sstevel@tonic-gate 4247c478bd9Sstevel@tonic-gate typedef struct crypto_version { 4257c478bd9Sstevel@tonic-gate uchar_t cv_major; 4267c478bd9Sstevel@tonic-gate uchar_t cv_minor; 4277c478bd9Sstevel@tonic-gate } crypto_version_t; 4287c478bd9Sstevel@tonic-gate 4297c478bd9Sstevel@tonic-gate /* session data structure opaque to the consumer */ 4307c478bd9Sstevel@tonic-gate typedef void *crypto_session_t; 4317c478bd9Sstevel@tonic-gate 432c892ebf1Skrishna /* provider data structure opaque to the consumer */ 433894b2776Smcpowers typedef void *crypto_provider_t; 434894b2776Smcpowers 435c892ebf1Skrishna /* Limits used by both consumers and providers */ 436c892ebf1Skrishna #define CRYPTO_EXT_SIZE_LABEL 32 437c892ebf1Skrishna #define CRYPTO_EXT_SIZE_MANUF 32 438c892ebf1Skrishna #define CRYPTO_EXT_SIZE_MODEL 16 439c892ebf1Skrishna #define CRYPTO_EXT_SIZE_SERIAL 16 440c892ebf1Skrishna #define CRYPTO_EXT_SIZE_TIME 16 441c892ebf1Skrishna 442c892ebf1Skrishna typedef struct crypto_provider_ext_info { 443c892ebf1Skrishna uchar_t ei_label[CRYPTO_EXT_SIZE_LABEL]; 444c892ebf1Skrishna uchar_t ei_manufacturerID[CRYPTO_EXT_SIZE_MANUF]; 445c892ebf1Skrishna uchar_t ei_model[CRYPTO_EXT_SIZE_MODEL]; 446c892ebf1Skrishna uchar_t ei_serial_number[CRYPTO_EXT_SIZE_SERIAL]; 447c892ebf1Skrishna ulong_t ei_flags; 448c892ebf1Skrishna ulong_t ei_max_session_count; 449c892ebf1Skrishna ulong_t ei_max_pin_len; 450c892ebf1Skrishna ulong_t ei_min_pin_len; 451c892ebf1Skrishna ulong_t ei_total_public_memory; 452c892ebf1Skrishna ulong_t ei_free_public_memory; 453c892ebf1Skrishna ulong_t ei_total_private_memory; 454c892ebf1Skrishna ulong_t ei_free_private_memory; 455c892ebf1Skrishna crypto_version_t ei_hardware_version; 456c892ebf1Skrishna crypto_version_t ei_firmware_version; 457c892ebf1Skrishna uchar_t ei_time[CRYPTO_EXT_SIZE_TIME]; 458*4df55fdeSJanie Lu int ei_hash_max_input_len; 459*4df55fdeSJanie Lu int ei_hmac_max_input_len; 460c892ebf1Skrishna } crypto_provider_ext_info_t; 461c892ebf1Skrishna 4627c478bd9Sstevel@tonic-gate typedef uint_t crypto_session_id_t; 4637c478bd9Sstevel@tonic-gate 46423c57df7Smcpowers typedef enum cmd_type { 46523c57df7Smcpowers COPY_FROM_DATA, 46623c57df7Smcpowers COPY_TO_DATA, 46723c57df7Smcpowers COMPARE_TO_DATA, 46823c57df7Smcpowers MD5_DIGEST_DATA, 46923c57df7Smcpowers SHA1_DIGEST_DATA, 470e8c016efSMark Powers SHA2_DIGEST_DATA, 471e8c016efSMark Powers GHASH_DATA 47223c57df7Smcpowers } cmd_type_t; 47323c57df7Smcpowers 47423c57df7Smcpowers #define CRYPTO_DO_UPDATE 0x01 47523c57df7Smcpowers #define CRYPTO_DO_FINAL 0x02 47623c57df7Smcpowers #define CRYPTO_DO_MD5 0x04 47723c57df7Smcpowers #define CRYPTO_DO_SHA1 0x08 47823c57df7Smcpowers #define CRYPTO_DO_SIGN 0x10 47923c57df7Smcpowers #define CRYPTO_DO_VERIFY 0x20 48023c57df7Smcpowers #define CRYPTO_DO_SHA2 0x40 48123c57df7Smcpowers 48223c57df7Smcpowers #define PROVIDER_OWNS_KEY_SCHEDULE 0x00000001 48323c57df7Smcpowers 4847c478bd9Sstevel@tonic-gate /* 4857c478bd9Sstevel@tonic-gate * Common cryptographic status and error codes. 4867c478bd9Sstevel@tonic-gate */ 4877c478bd9Sstevel@tonic-gate #define CRYPTO_SUCCESS 0x00000000 4887c478bd9Sstevel@tonic-gate #define CRYPTO_CANCEL 0x00000001 4897c478bd9Sstevel@tonic-gate #define CRYPTO_HOST_MEMORY 0x00000002 4907c478bd9Sstevel@tonic-gate #define CRYPTO_GENERAL_ERROR 0x00000003 4917c478bd9Sstevel@tonic-gate #define CRYPTO_FAILED 0x00000004 4927c478bd9Sstevel@tonic-gate #define CRYPTO_ARGUMENTS_BAD 0x00000005 4937c478bd9Sstevel@tonic-gate #define CRYPTO_ATTRIBUTE_READ_ONLY 0x00000006 4947c478bd9Sstevel@tonic-gate #define CRYPTO_ATTRIBUTE_SENSITIVE 0x00000007 4957c478bd9Sstevel@tonic-gate #define CRYPTO_ATTRIBUTE_TYPE_INVALID 0x00000008 4967c478bd9Sstevel@tonic-gate #define CRYPTO_ATTRIBUTE_VALUE_INVALID 0x00000009 4977c478bd9Sstevel@tonic-gate #define CRYPTO_CANCELED 0x0000000A 4987c478bd9Sstevel@tonic-gate #define CRYPTO_DATA_INVALID 0x0000000B 4997c478bd9Sstevel@tonic-gate #define CRYPTO_DATA_LEN_RANGE 0x0000000C 5007c478bd9Sstevel@tonic-gate #define CRYPTO_DEVICE_ERROR 0x0000000D 5017c478bd9Sstevel@tonic-gate #define CRYPTO_DEVICE_MEMORY 0x0000000E 5027c478bd9Sstevel@tonic-gate #define CRYPTO_DEVICE_REMOVED 0x0000000F 5037c478bd9Sstevel@tonic-gate #define CRYPTO_ENCRYPTED_DATA_INVALID 0x00000010 5047c478bd9Sstevel@tonic-gate #define CRYPTO_ENCRYPTED_DATA_LEN_RANGE 0x00000011 5057c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_HANDLE_INVALID 0x00000012 5067c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_SIZE_RANGE 0x00000013 5077c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_TYPE_INCONSISTENT 0x00000014 5087c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_NOT_NEEDED 0x00000015 5097c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_CHANGED 0x00000016 5107c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_NEEDED 0x00000017 5117c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_INDIGESTIBLE 0x00000018 5127c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_FUNCTION_NOT_PERMITTED 0x00000019 5137c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_NOT_WRAPPABLE 0x0000001A 5147c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_UNEXTRACTABLE 0x0000001B 5157c478bd9Sstevel@tonic-gate #define CRYPTO_MECHANISM_INVALID 0x0000001C 5167c478bd9Sstevel@tonic-gate #define CRYPTO_MECHANISM_PARAM_INVALID 0x0000001D 5177c478bd9Sstevel@tonic-gate #define CRYPTO_OBJECT_HANDLE_INVALID 0x0000001E 5187c478bd9Sstevel@tonic-gate #define CRYPTO_OPERATION_IS_ACTIVE 0x0000001F 5197c478bd9Sstevel@tonic-gate #define CRYPTO_OPERATION_NOT_INITIALIZED 0x00000020 5207c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_INCORRECT 0x00000021 5217c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_INVALID 0x00000022 5227c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_LEN_RANGE 0x00000023 5237c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_EXPIRED 0x00000024 5247c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_LOCKED 0x00000025 5257c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_CLOSED 0x00000026 5267c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_COUNT 0x00000027 5277c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_HANDLE_INVALID 0x00000028 5287c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_READ_ONLY 0x00000029 5297c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_EXISTS 0x0000002A 5307c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_READ_ONLY_EXISTS 0x0000002B 5317c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_READ_WRITE_SO_EXISTS 0x0000002C 5327c478bd9Sstevel@tonic-gate #define CRYPTO_SIGNATURE_INVALID 0x0000002D 5337c478bd9Sstevel@tonic-gate #define CRYPTO_SIGNATURE_LEN_RANGE 0x0000002E 5347c478bd9Sstevel@tonic-gate #define CRYPTO_TEMPLATE_INCOMPLETE 0x0000002F 5357c478bd9Sstevel@tonic-gate #define CRYPTO_TEMPLATE_INCONSISTENT 0x00000030 5367c478bd9Sstevel@tonic-gate #define CRYPTO_UNWRAPPING_KEY_HANDLE_INVALID 0x00000031 5377c478bd9Sstevel@tonic-gate #define CRYPTO_UNWRAPPING_KEY_SIZE_RANGE 0x00000032 5387c478bd9Sstevel@tonic-gate #define CRYPTO_UNWRAPPING_KEY_TYPE_INCONSISTENT 0x00000033 5397c478bd9Sstevel@tonic-gate #define CRYPTO_USER_ALREADY_LOGGED_IN 0x00000034 5407c478bd9Sstevel@tonic-gate #define CRYPTO_USER_NOT_LOGGED_IN 0x00000035 5417c478bd9Sstevel@tonic-gate #define CRYPTO_USER_PIN_NOT_INITIALIZED 0x00000036 5427c478bd9Sstevel@tonic-gate #define CRYPTO_USER_TYPE_INVALID 0x00000037 5437c478bd9Sstevel@tonic-gate #define CRYPTO_USER_ANOTHER_ALREADY_LOGGED_IN 0x00000038 5447c478bd9Sstevel@tonic-gate #define CRYPTO_USER_TOO_MANY_TYPES 0x00000039 5457c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPED_KEY_INVALID 0x0000003A 5467c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPED_KEY_LEN_RANGE 0x0000003B 5477c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPING_KEY_HANDLE_INVALID 0x0000003C 5487c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPING_KEY_SIZE_RANGE 0x0000003D 5497c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPING_KEY_TYPE_INCONSISTENT 0x0000003E 5507c478bd9Sstevel@tonic-gate #define CRYPTO_RANDOM_SEED_NOT_SUPPORTED 0x0000003F 5517c478bd9Sstevel@tonic-gate #define CRYPTO_RANDOM_NO_RNG 0x00000040 5527c478bd9Sstevel@tonic-gate #define CRYPTO_DOMAIN_PARAMS_INVALID 0x00000041 5537c478bd9Sstevel@tonic-gate #define CRYPTO_BUFFER_TOO_SMALL 0x00000042 5547c478bd9Sstevel@tonic-gate #define CRYPTO_INFORMATION_SENSITIVE 0x00000043 5557c478bd9Sstevel@tonic-gate #define CRYPTO_NOT_SUPPORTED 0x00000044 5567c478bd9Sstevel@tonic-gate 5577c478bd9Sstevel@tonic-gate #define CRYPTO_QUEUED 0x00000045 5587c478bd9Sstevel@tonic-gate #define CRYPTO_BUFFER_TOO_BIG 0x00000046 5597c478bd9Sstevel@tonic-gate #define CRYPTO_INVALID_CONTEXT 0x00000047 5607c478bd9Sstevel@tonic-gate #define CRYPTO_INVALID_MAC 0x00000048 5617c478bd9Sstevel@tonic-gate #define CRYPTO_MECH_NOT_SUPPORTED 0x00000049 5627c478bd9Sstevel@tonic-gate #define CRYPTO_INCONSISTENT_ATTRIBUTE 0x0000004A 5637c478bd9Sstevel@tonic-gate #define CRYPTO_NO_PERMISSION 0x0000004B 5647c478bd9Sstevel@tonic-gate #define CRYPTO_INVALID_PROVIDER_ID 0x0000004C 5657c478bd9Sstevel@tonic-gate #define CRYPTO_VERSION_MISMATCH 0x0000004D 5667c478bd9Sstevel@tonic-gate #define CRYPTO_BUSY 0x0000004E 5677c478bd9Sstevel@tonic-gate #define CRYPTO_UNKNOWN_PROVIDER 0x0000004F 5687c478bd9Sstevel@tonic-gate #define CRYPTO_MODVERIFICATION_FAILED 0x00000050 5697c478bd9Sstevel@tonic-gate #define CRYPTO_OLD_CTX_TEMPLATE 0x00000051 5707c478bd9Sstevel@tonic-gate #define CRYPTO_WEAK_KEY 0x00000052 57173556491SAnthony Scarpino #define CRYPTO_FIPS140_ERROR 0x00000053 5727c478bd9Sstevel@tonic-gate 5737c478bd9Sstevel@tonic-gate /* 5747c478bd9Sstevel@tonic-gate * Special values that can be used to indicate that information is unavailable 5757c478bd9Sstevel@tonic-gate * or that there is not practical limit. These values can be used 5767c478bd9Sstevel@tonic-gate * by fields of the SPI crypto_provider_ext_info(9S) structure. 5777c478bd9Sstevel@tonic-gate * The value of CRYPTO_UNAVAILABLE_INFO should be the same as 5787c478bd9Sstevel@tonic-gate * CK_UNAVAILABLE_INFO in the PKCS#11 spec. 5797c478bd9Sstevel@tonic-gate */ 5807c478bd9Sstevel@tonic-gate #define CRYPTO_UNAVAILABLE_INFO ((ulong_t)(-1)) 5817c478bd9Sstevel@tonic-gate #define CRYPTO_EFFECTIVELY_INFINITE 0x0 5827c478bd9Sstevel@tonic-gate 5837c478bd9Sstevel@tonic-gate #ifdef __cplusplus 5847c478bd9Sstevel@tonic-gate } 5857c478bd9Sstevel@tonic-gate #endif 5867c478bd9Sstevel@tonic-gate 5877c478bd9Sstevel@tonic-gate #endif /* _SYS_CRYPTO_COMMON_H */ 588