17c478bd9Sstevel@tonic-gate /* 27c478bd9Sstevel@tonic-gate * CDDL HEADER START 37c478bd9Sstevel@tonic-gate * 47c478bd9Sstevel@tonic-gate * The contents of this file are subject to the terms of the 5c892ebf1Skrishna * Common Development and Distribution License (the "License"). 6c892ebf1Skrishna * You may not use this file except in compliance with the License. 77c478bd9Sstevel@tonic-gate * 87c478bd9Sstevel@tonic-gate * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 97c478bd9Sstevel@tonic-gate * or http://www.opensolaris.org/os/licensing. 107c478bd9Sstevel@tonic-gate * See the License for the specific language governing permissions 117c478bd9Sstevel@tonic-gate * and limitations under the License. 127c478bd9Sstevel@tonic-gate * 137c478bd9Sstevel@tonic-gate * When distributing Covered Code, include this CDDL HEADER in each 147c478bd9Sstevel@tonic-gate * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 157c478bd9Sstevel@tonic-gate * If applicable, add the following below this CDDL HEADER, with the 167c478bd9Sstevel@tonic-gate * fields enclosed by brackets "[]" replaced with your own identifying 177c478bd9Sstevel@tonic-gate * information: Portions Copyright [yyyy] [name of copyright owner] 187c478bd9Sstevel@tonic-gate * 197c478bd9Sstevel@tonic-gate * CDDL HEADER END 207c478bd9Sstevel@tonic-gate */ 217c478bd9Sstevel@tonic-gate /* 226a1073f8Skrishna * Copyright 2007 Sun Microsystems, Inc. All rights reserved. 237c478bd9Sstevel@tonic-gate * Use is subject to license terms. 247c478bd9Sstevel@tonic-gate */ 257c478bd9Sstevel@tonic-gate 267c478bd9Sstevel@tonic-gate #ifndef _SYS_CRYPTO_COMMON_H 277c478bd9Sstevel@tonic-gate #define _SYS_CRYPTO_COMMON_H 287c478bd9Sstevel@tonic-gate 297c478bd9Sstevel@tonic-gate #pragma ident "%Z%%M% %I% %E% SMI" 307c478bd9Sstevel@tonic-gate 317c478bd9Sstevel@tonic-gate /* 327c478bd9Sstevel@tonic-gate * Header file for the common data structures of the cryptographic framework 337c478bd9Sstevel@tonic-gate */ 347c478bd9Sstevel@tonic-gate 357c478bd9Sstevel@tonic-gate #ifdef __cplusplus 367c478bd9Sstevel@tonic-gate extern "C" { 377c478bd9Sstevel@tonic-gate #endif 387c478bd9Sstevel@tonic-gate 397c478bd9Sstevel@tonic-gate #include <sys/types.h> 407c478bd9Sstevel@tonic-gate #include <sys/uio.h> 417c478bd9Sstevel@tonic-gate #include <sys/stream.h> 427c478bd9Sstevel@tonic-gate #include <sys/mutex.h> 437c478bd9Sstevel@tonic-gate #include <sys/condvar.h> 447c478bd9Sstevel@tonic-gate 457c478bd9Sstevel@tonic-gate 467c478bd9Sstevel@tonic-gate /* Cryptographic Mechanisms */ 477c478bd9Sstevel@tonic-gate 487c478bd9Sstevel@tonic-gate #define CRYPTO_MAX_MECH_NAME 32 497c478bd9Sstevel@tonic-gate typedef char crypto_mech_name_t[CRYPTO_MAX_MECH_NAME]; 507c478bd9Sstevel@tonic-gate 517c478bd9Sstevel@tonic-gate typedef uint64_t crypto_mech_type_t; 527c478bd9Sstevel@tonic-gate 537c478bd9Sstevel@tonic-gate typedef struct crypto_mechanism { 547c478bd9Sstevel@tonic-gate crypto_mech_type_t cm_type; /* mechanism type */ 557c478bd9Sstevel@tonic-gate caddr_t cm_param; /* mech. parameter */ 567c478bd9Sstevel@tonic-gate size_t cm_param_len; /* mech. parameter len */ 577c478bd9Sstevel@tonic-gate } crypto_mechanism_t; 587c478bd9Sstevel@tonic-gate 59f317a3a3Skrishna #ifdef _SYSCALL32 60f317a3a3Skrishna 61f317a3a3Skrishna typedef struct crypto_mechanism32 { 62f317a3a3Skrishna crypto_mech_type_t cm_type; /* mechanism type */ 63f317a3a3Skrishna caddr32_t cm_param; /* mech. parameter */ 64f317a3a3Skrishna size32_t cm_param_len; /* mech. parameter len */ 65f317a3a3Skrishna } crypto_mechanism32_t; 66f317a3a3Skrishna 67f317a3a3Skrishna #endif /* _SYSCALL32 */ 68f317a3a3Skrishna 69d2b32306Smcpowers /* CK_AES_CTR_PARAMS provides parameters to the CKM_AES_CTR mechanism */ 70d2b32306Smcpowers typedef struct CK_AES_CTR_PARAMS { 71d2b32306Smcpowers ulong_t ulCounterBits; 72d2b32306Smcpowers uint8_t cb[16]; 73d2b32306Smcpowers } CK_AES_CTR_PARAMS; 74d2b32306Smcpowers 75d2b32306Smcpowers /* CK_AES_CCM_PARAMS provides parameters to the CKM_AES_CCM mechanism */ 76d2b32306Smcpowers typedef struct CK_AES_CCM_PARAMS { 77d2b32306Smcpowers ulong_t ulMACSize; 78d2b32306Smcpowers ulong_t ulNonceSize; 79d2b32306Smcpowers ulong_t ulAuthDataSize; 80d2b32306Smcpowers ulong_t ulDataSize; /* used for plaintext or ciphertext */ 81d2b32306Smcpowers uchar_t *nonce; 82d2b32306Smcpowers uchar_t *authData; 83d2b32306Smcpowers } CK_AES_CCM_PARAMS; 84d2b32306Smcpowers 858d4583b0Sfr41279 #ifdef _KERNEL 868d4583b0Sfr41279 /* 878d4583b0Sfr41279 * CK_ECDH1_DERIVE_PARAMS provides the parameters to the 888d4583b0Sfr41279 * CKM_ECDH1_KEY_DERIVE mechanism 898d4583b0Sfr41279 */ 908d4583b0Sfr41279 typedef struct CK_ECDH1_DERIVE_PARAMS { 918d4583b0Sfr41279 ulong_t kdf; 928d4583b0Sfr41279 ulong_t ulSharedDataLen; 938d4583b0Sfr41279 uchar_t *pSharedData; 948d4583b0Sfr41279 ulong_t ulPublicDataLen; 958d4583b0Sfr41279 uchar_t *pPublicData; 968d4583b0Sfr41279 } CK_ECDH1_DERIVE_PARAMS; 978d4583b0Sfr41279 #endif 988d4583b0Sfr41279 99d2b32306Smcpowers #ifdef _KERNEL 100d2b32306Smcpowers #ifdef _SYSCALL32 101d2b32306Smcpowers 102d2b32306Smcpowers /* needed for 32-bit applications running on 64-bit kernels */ 103d2b32306Smcpowers typedef struct CK_AES_CTR_PARAMS32 { 104d2b32306Smcpowers uint32_t ulCounterBits; 105d2b32306Smcpowers uint8_t cb[16]; 106d2b32306Smcpowers } CK_AES_CTR_PARAMS32; 107d2b32306Smcpowers 108d2b32306Smcpowers /* needed for 32-bit applications running on 64-bit kernels */ 109d2b32306Smcpowers typedef struct CK_AES_CCM_PARAMS32 { 110d2b32306Smcpowers uint32_t ulMACSize; 111d2b32306Smcpowers uint32_t ulNonceSize; 112d2b32306Smcpowers uint32_t ulAuthDataSize; 113d2b32306Smcpowers uint32_t ulDataSize; 114d2b32306Smcpowers caddr32_t nonce; 115d2b32306Smcpowers caddr32_t authData; 116d2b32306Smcpowers } CK_AES_CCM_PARAMS32; 117d2b32306Smcpowers 1188d4583b0Sfr41279 typedef struct CK_ECDH1_DERIVE_PARAMS32 { 1198d4583b0Sfr41279 uint32_t kdf; 1208d4583b0Sfr41279 uint32_t ulSharedDataLen; 1218d4583b0Sfr41279 caddr32_t pSharedData; 1228d4583b0Sfr41279 uint32_t ulPublicDataLen; 1238d4583b0Sfr41279 caddr32_t pPublicData; 1248d4583b0Sfr41279 } CK_ECDH1_DERIVE_PARAMS32; 1258d4583b0Sfr41279 126d2b32306Smcpowers #endif /* _SYSCALL32 */ 127d2b32306Smcpowers #endif /* _KERNEL */ 128d2b32306Smcpowers 1297c478bd9Sstevel@tonic-gate /* 1306a1073f8Skrishna * The measurement unit bit flag for a mechanism's minimum or maximum key size. 1317c478bd9Sstevel@tonic-gate * The unit are mechanism dependant. It can be in bits or in bytes. 1327c478bd9Sstevel@tonic-gate */ 1337c478bd9Sstevel@tonic-gate typedef uint32_t crypto_keysize_unit_t; 1347c478bd9Sstevel@tonic-gate 1356a1073f8Skrishna /* 1366a1073f8Skrishna * The following bit flags are valid in cm_mech_flags field in 1376a1073f8Skrishna * the crypto_mech_info_t structure of the SPI. 1386a1073f8Skrishna * 1396a1073f8Skrishna * Only the first two bit flags are valid in mi_keysize_unit 1406a1073f8Skrishna * field in the crypto_mechanism_info_t structure of the API. 1416a1073f8Skrishna */ 1427c478bd9Sstevel@tonic-gate #define CRYPTO_KEYSIZE_UNIT_IN_BITS 0x00000001 1437c478bd9Sstevel@tonic-gate #define CRYPTO_KEYSIZE_UNIT_IN_BYTES 0x00000002 1446a1073f8Skrishna #define CRYPTO_CAN_SHARE_OPSTATE 0x00000004 /* supports sharing */ 1457c478bd9Sstevel@tonic-gate 1467c478bd9Sstevel@tonic-gate 1477c478bd9Sstevel@tonic-gate /* Mechanisms supported out-of-the-box */ 1485151fb12Sdarrenm #define SUN_CKM_MD4 "CKM_MD4" 1497c478bd9Sstevel@tonic-gate #define SUN_CKM_MD5 "CKM_MD5" 1507c478bd9Sstevel@tonic-gate #define SUN_CKM_MD5_HMAC "CKM_MD5_HMAC" 1517c478bd9Sstevel@tonic-gate #define SUN_CKM_MD5_HMAC_GENERAL "CKM_MD5_HMAC_GENERAL" 1527c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA1 "CKM_SHA_1" 1537c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA1_HMAC "CKM_SHA_1_HMAC" 1547c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA1_HMAC_GENERAL "CKM_SHA_1_HMAC_GENERAL" 1557c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA256 "CKM_SHA256" 1567c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA256_HMAC "CKM_SHA256_HMAC" 1577c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA256_HMAC_GENERAL "CKM_SHA256_HMAC_GENERAL" 1587c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA384 "CKM_SHA384" 1597c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA384_HMAC "CKM_SHA384_HMAC" 1607c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA384_HMAC_GENERAL "CKM_SHA384_HMAC_GENERAL" 1617c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA512 "CKM_SHA512" 1627c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA512_HMAC "CKM_SHA512_HMAC" 1637c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA512_HMAC_GENERAL "CKM_SHA512_HMAC_GENERAL" 1647c478bd9Sstevel@tonic-gate #define SUN_CKM_DES_CBC "CKM_DES_CBC" 1657c478bd9Sstevel@tonic-gate #define SUN_CKM_DES3_CBC "CKM_DES3_CBC" 1667c478bd9Sstevel@tonic-gate #define SUN_CKM_DES_ECB "CKM_DES_ECB" 1677c478bd9Sstevel@tonic-gate #define SUN_CKM_DES3_ECB "CKM_DES3_ECB" 168f66d273dSizick #define SUN_CKM_BLOWFISH_CBC "CKM_BLOWFISH_CBC" 169f66d273dSizick #define SUN_CKM_BLOWFISH_ECB "CKM_BLOWFISH_ECB" 1707c478bd9Sstevel@tonic-gate #define SUN_CKM_AES_CBC "CKM_AES_CBC" 1717c478bd9Sstevel@tonic-gate #define SUN_CKM_AES_ECB "CKM_AES_ECB" 172894b2776Smcpowers #define SUN_CKM_AES_CTR "CKM_AES_CTR" 1737fb8ff4bSktung #define SUN_CKM_AES_CCM "CKM_AES_CCM" 1747c478bd9Sstevel@tonic-gate #define SUN_CKM_RC4 "CKM_RC4" 1757c478bd9Sstevel@tonic-gate #define SUN_CKM_RSA_PKCS "CKM_RSA_PKCS" 1767c478bd9Sstevel@tonic-gate #define SUN_CKM_RSA_X_509 "CKM_RSA_X_509" 1777c478bd9Sstevel@tonic-gate #define SUN_CKM_MD5_RSA_PKCS "CKM_MD5_RSA_PKCS" 1787c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA1_RSA_PKCS "CKM_SHA1_RSA_PKCS" 179f66d273dSizick #define SUN_CKM_SHA256_RSA_PKCS "CKM_SHA256_RSA_PKCS" 180f66d273dSizick #define SUN_CKM_SHA384_RSA_PKCS "CKM_SHA384_RSA_PKCS" 181f66d273dSizick #define SUN_CKM_SHA512_RSA_PKCS "CKM_SHA512_RSA_PKCS" 182*f9fbec18Smcpowers #define SUN_CKM_EC_KEY_PAIR_GEN "CKM_EC_KEY_PAIR_GEN" 183*f9fbec18Smcpowers #define SUN_CKM_ECDH1_DERIVE "CKM_ECDH1_DERIVE" 184*f9fbec18Smcpowers #define SUN_CKM_ECDSA_SHA1 "CKM_ECDSA_SHA1" 185*f9fbec18Smcpowers #define SUN_CKM_ECDSA "CKM_ECDSA" 1867c478bd9Sstevel@tonic-gate 1876a1073f8Skrishna /* Shared operation context format for CKM_RC4 */ 1886a1073f8Skrishna typedef struct { 1896a1073f8Skrishna uchar_t arr[256]; 1906a1073f8Skrishna uchar_t i, j; 1916a1073f8Skrishna uint64_t pad; /* For 64-bit alignment */ 1926a1073f8Skrishna } arcfour_state_t; 1936a1073f8Skrishna 1947c478bd9Sstevel@tonic-gate 1957c478bd9Sstevel@tonic-gate /* Data arguments of cryptographic operations */ 1967c478bd9Sstevel@tonic-gate 1977c478bd9Sstevel@tonic-gate typedef enum crypto_data_format { 1987c478bd9Sstevel@tonic-gate CRYPTO_DATA_RAW = 1, 1997c478bd9Sstevel@tonic-gate CRYPTO_DATA_UIO, 2007c478bd9Sstevel@tonic-gate CRYPTO_DATA_MBLK 2017c478bd9Sstevel@tonic-gate } crypto_data_format_t; 2027c478bd9Sstevel@tonic-gate 2037c478bd9Sstevel@tonic-gate typedef struct crypto_data { 2047c478bd9Sstevel@tonic-gate crypto_data_format_t cd_format; /* Format identifier */ 2057c478bd9Sstevel@tonic-gate off_t cd_offset; /* Offset from the beginning */ 2067c478bd9Sstevel@tonic-gate size_t cd_length; /* # of bytes in use */ 2077c478bd9Sstevel@tonic-gate caddr_t cd_miscdata; /* ancillary data */ 2087c478bd9Sstevel@tonic-gate union { 2097c478bd9Sstevel@tonic-gate /* Raw format */ 2107c478bd9Sstevel@tonic-gate iovec_t cdu_raw; /* Pointer and length */ 2117c478bd9Sstevel@tonic-gate 2127c478bd9Sstevel@tonic-gate /* uio scatter-gather format */ 2137c478bd9Sstevel@tonic-gate uio_t *cdu_uio; 2147c478bd9Sstevel@tonic-gate 2157c478bd9Sstevel@tonic-gate /* mblk scatter-gather format */ 2167c478bd9Sstevel@tonic-gate mblk_t *cdu_mp; /* The mblk chain */ 2177c478bd9Sstevel@tonic-gate 2187c478bd9Sstevel@tonic-gate } cdu; /* Crypto Data Union */ 2197c478bd9Sstevel@tonic-gate } crypto_data_t; 2207c478bd9Sstevel@tonic-gate 2217c478bd9Sstevel@tonic-gate #define cd_raw cdu.cdu_raw 2227c478bd9Sstevel@tonic-gate #define cd_uio cdu.cdu_uio 2237c478bd9Sstevel@tonic-gate #define cd_mp cdu.cdu_mp 2247c478bd9Sstevel@tonic-gate 2257c478bd9Sstevel@tonic-gate typedef struct crypto_dual_data { 2267c478bd9Sstevel@tonic-gate crypto_data_t dd_data; /* The data */ 2277c478bd9Sstevel@tonic-gate off_t dd_offset2; /* Used by dual operation */ 2287c478bd9Sstevel@tonic-gate size_t dd_len2; /* # of bytes to take */ 2297c478bd9Sstevel@tonic-gate } crypto_dual_data_t; 2307c478bd9Sstevel@tonic-gate 2317c478bd9Sstevel@tonic-gate #define dd_format dd_data.cd_format 2327c478bd9Sstevel@tonic-gate #define dd_offset1 dd_data.cd_offset 2337c478bd9Sstevel@tonic-gate #define dd_len1 dd_data.cd_length 2347c478bd9Sstevel@tonic-gate #define dd_miscdata dd_data.cd_miscdata 2357c478bd9Sstevel@tonic-gate #define dd_raw dd_data.cd_raw 2367c478bd9Sstevel@tonic-gate #define dd_uio dd_data.cd_uio 2377c478bd9Sstevel@tonic-gate #define dd_mp dd_data.cd_mp 2387c478bd9Sstevel@tonic-gate 2397c478bd9Sstevel@tonic-gate /* The keys, and their contents */ 2407c478bd9Sstevel@tonic-gate 2417c478bd9Sstevel@tonic-gate typedef enum { 2427c478bd9Sstevel@tonic-gate CRYPTO_KEY_RAW = 1, /* ck_data is a cleartext key */ 2437c478bd9Sstevel@tonic-gate CRYPTO_KEY_REFERENCE, /* ck_obj_id is an opaque reference */ 2447c478bd9Sstevel@tonic-gate CRYPTO_KEY_ATTR_LIST /* ck_attrs is a list of object attributes */ 2457c478bd9Sstevel@tonic-gate } crypto_key_format_t; 2467c478bd9Sstevel@tonic-gate 2477c478bd9Sstevel@tonic-gate typedef uint64_t crypto_attr_type_t; 2487c478bd9Sstevel@tonic-gate 2497c478bd9Sstevel@tonic-gate /* Attribute types to use for passing a RSA public key or a private key. */ 2507c478bd9Sstevel@tonic-gate #define SUN_CKA_MODULUS 0x00000120 2517c478bd9Sstevel@tonic-gate #define SUN_CKA_MODULUS_BITS 0x00000121 2527c478bd9Sstevel@tonic-gate #define SUN_CKA_PUBLIC_EXPONENT 0x00000122 2537c478bd9Sstevel@tonic-gate #define SUN_CKA_PRIVATE_EXPONENT 0x00000123 2547c478bd9Sstevel@tonic-gate #define SUN_CKA_PRIME_1 0x00000124 2557c478bd9Sstevel@tonic-gate #define SUN_CKA_PRIME_2 0x00000125 2567c478bd9Sstevel@tonic-gate #define SUN_CKA_EXPONENT_1 0x00000126 2577c478bd9Sstevel@tonic-gate #define SUN_CKA_EXPONENT_2 0x00000127 2587c478bd9Sstevel@tonic-gate #define SUN_CKA_COEFFICIENT 0x00000128 2597c478bd9Sstevel@tonic-gate #define SUN_CKA_PRIME 0x00000130 2607c478bd9Sstevel@tonic-gate #define SUN_CKA_SUBPRIME 0x00000131 2617c478bd9Sstevel@tonic-gate #define SUN_CKA_BASE 0x00000132 2627c478bd9Sstevel@tonic-gate 263*f9fbec18Smcpowers #define CKK_EC 0x00000003 264*f9fbec18Smcpowers #define CKK_GENERIC_SECRET 0x00000010 265*f9fbec18Smcpowers #define CKK_RC4 0x00000012 266*f9fbec18Smcpowers #define CKK_AES 0x0000001F 267*f9fbec18Smcpowers #define CKK_DES 0x00000013 268*f9fbec18Smcpowers #define CKK_DES2 0x00000014 269*f9fbec18Smcpowers #define CKK_DES3 0x00000015 270*f9fbec18Smcpowers 271*f9fbec18Smcpowers #define CKO_PUBLIC_KEY 0x00000002 272*f9fbec18Smcpowers #define CKO_PRIVATE_KEY 0x00000003 273*f9fbec18Smcpowers #define CKA_CLASS 0x00000000 274*f9fbec18Smcpowers #define CKA_VALUE 0x00000011 275*f9fbec18Smcpowers #define CKA_KEY_TYPE 0x00000100 276*f9fbec18Smcpowers #define CKA_VALUE_LEN 0x00000161 277*f9fbec18Smcpowers #define CKA_EC_PARAMS 0x00000180 278*f9fbec18Smcpowers #define CKA_EC_POINT 0x00000181 279*f9fbec18Smcpowers 2807c478bd9Sstevel@tonic-gate typedef uint32_t crypto_object_id_t; 2817c478bd9Sstevel@tonic-gate 2827c478bd9Sstevel@tonic-gate typedef struct crypto_object_attribute { 2837c478bd9Sstevel@tonic-gate crypto_attr_type_t oa_type; /* attribute type */ 2847c478bd9Sstevel@tonic-gate caddr_t oa_value; /* attribute value */ 2857c478bd9Sstevel@tonic-gate ssize_t oa_value_len; /* length of attribute value */ 2867c478bd9Sstevel@tonic-gate } crypto_object_attribute_t; 2877c478bd9Sstevel@tonic-gate 2887c478bd9Sstevel@tonic-gate typedef struct crypto_key { 2897c478bd9Sstevel@tonic-gate crypto_key_format_t ck_format; /* format identifier */ 2907c478bd9Sstevel@tonic-gate union { 2917c478bd9Sstevel@tonic-gate /* for CRYPTO_KEY_RAW ck_format */ 2927c478bd9Sstevel@tonic-gate struct { 2937c478bd9Sstevel@tonic-gate uint_t cku_v_length; /* # of bits in ck_data */ 2947c478bd9Sstevel@tonic-gate void *cku_v_data; /* ptr to key value */ 2957c478bd9Sstevel@tonic-gate } cku_key_value; 2967c478bd9Sstevel@tonic-gate 2977c478bd9Sstevel@tonic-gate /* for CRYPTO_KEY_REFERENCE ck_format */ 2987c478bd9Sstevel@tonic-gate crypto_object_id_t cku_key_id; /* reference to object key */ 2997c478bd9Sstevel@tonic-gate 3007c478bd9Sstevel@tonic-gate /* for CRYPTO_KEY_ATTR_LIST ck_format */ 3017c478bd9Sstevel@tonic-gate struct { 3027c478bd9Sstevel@tonic-gate uint_t cku_a_count; /* number of attributes */ 3037c478bd9Sstevel@tonic-gate crypto_object_attribute_t *cku_a_oattr; 3047c478bd9Sstevel@tonic-gate } cku_key_attrs; 3057c478bd9Sstevel@tonic-gate } cku_data; /* Crypto Key union */ 3067c478bd9Sstevel@tonic-gate } crypto_key_t; 3077c478bd9Sstevel@tonic-gate 308f317a3a3Skrishna #ifdef _SYSCALL32 309f317a3a3Skrishna 310f317a3a3Skrishna typedef struct crypto_object_attribute32 { 311f317a3a3Skrishna uint64_t oa_type; /* attribute type */ 312f317a3a3Skrishna caddr32_t oa_value; /* attribute value */ 313f317a3a3Skrishna ssize32_t oa_value_len; /* length of attribute value */ 314f317a3a3Skrishna } crypto_object_attribute32_t; 315f317a3a3Skrishna 316f317a3a3Skrishna typedef struct crypto_key32 { 317f317a3a3Skrishna crypto_key_format_t ck_format; /* format identifier */ 318f317a3a3Skrishna union { 319f317a3a3Skrishna /* for CRYPTO_KEY_RAW ck_format */ 320f317a3a3Skrishna struct { 321f317a3a3Skrishna uint32_t cku_v_length; /* # of bytes in ck_data */ 322f317a3a3Skrishna caddr32_t cku_v_data; /* ptr to key value */ 323f317a3a3Skrishna } cku_key_value; 324f317a3a3Skrishna 325f317a3a3Skrishna /* for CRYPTO_KEY_REFERENCE ck_format */ 326f317a3a3Skrishna crypto_object_id_t cku_key_id; /* reference to object key */ 327f317a3a3Skrishna 328f317a3a3Skrishna /* for CRYPTO_KEY_ATTR_LIST ck_format */ 329f317a3a3Skrishna struct { 330f317a3a3Skrishna uint32_t cku_a_count; /* number of attributes */ 331f317a3a3Skrishna caddr32_t cku_a_oattr; 332f317a3a3Skrishna } cku_key_attrs; 333f317a3a3Skrishna } cku_data; /* Crypto Key union */ 334f317a3a3Skrishna } crypto_key32_t; 335f317a3a3Skrishna 336f317a3a3Skrishna #endif /* _SYSCALL32 */ 337f317a3a3Skrishna 3387c478bd9Sstevel@tonic-gate #define ck_data cku_data.cku_key_value.cku_v_data 3397c478bd9Sstevel@tonic-gate #define ck_length cku_data.cku_key_value.cku_v_length 3407c478bd9Sstevel@tonic-gate #define ck_obj_id cku_data.cku_key_id 3417c478bd9Sstevel@tonic-gate #define ck_count cku_data.cku_key_attrs.cku_a_count 3427c478bd9Sstevel@tonic-gate #define ck_attrs cku_data.cku_key_attrs.cku_a_oattr 3437c478bd9Sstevel@tonic-gate 3447c478bd9Sstevel@tonic-gate /* 3457c478bd9Sstevel@tonic-gate * Raw key lengths are expressed in number of bits. 3467c478bd9Sstevel@tonic-gate * The following macro returns the minimum number of 3477c478bd9Sstevel@tonic-gate * bytes that can contain the specified number of bits. 3487c478bd9Sstevel@tonic-gate */ 3497c478bd9Sstevel@tonic-gate #define CRYPTO_BITS2BYTES(n) (((n) + 7) >> 3) 3507c478bd9Sstevel@tonic-gate 3517c478bd9Sstevel@tonic-gate /* Providers */ 3527c478bd9Sstevel@tonic-gate 3537c478bd9Sstevel@tonic-gate typedef enum { 3547c478bd9Sstevel@tonic-gate CRYPTO_HW_PROVIDER = 0, 3557c478bd9Sstevel@tonic-gate CRYPTO_SW_PROVIDER, 3567c478bd9Sstevel@tonic-gate CRYPTO_LOGICAL_PROVIDER 3577c478bd9Sstevel@tonic-gate } crypto_provider_type_t; 3587c478bd9Sstevel@tonic-gate 3597c478bd9Sstevel@tonic-gate typedef uint32_t crypto_provider_id_t; 3607c478bd9Sstevel@tonic-gate #define KCF_PROVID_INVALID ((uint32_t)-1) 3617c478bd9Sstevel@tonic-gate 3627c478bd9Sstevel@tonic-gate typedef struct crypto_provider_entry { 3637c478bd9Sstevel@tonic-gate crypto_provider_id_t pe_provider_id; 3647c478bd9Sstevel@tonic-gate uint_t pe_mechanism_count; 3657c478bd9Sstevel@tonic-gate } crypto_provider_entry_t; 3667c478bd9Sstevel@tonic-gate 3677c478bd9Sstevel@tonic-gate typedef struct crypto_dev_list_entry { 3687c478bd9Sstevel@tonic-gate char le_dev_name[MAXNAMELEN]; 3697c478bd9Sstevel@tonic-gate uint_t le_dev_instance; 3707c478bd9Sstevel@tonic-gate uint_t le_mechanism_count; 3717c478bd9Sstevel@tonic-gate } crypto_dev_list_entry_t; 3727c478bd9Sstevel@tonic-gate 3737c478bd9Sstevel@tonic-gate /* User type for authentication ioctls and SPI entry points */ 3747c478bd9Sstevel@tonic-gate 3757c478bd9Sstevel@tonic-gate typedef enum crypto_user_type { 3767c478bd9Sstevel@tonic-gate CRYPTO_SO = 0, 3777c478bd9Sstevel@tonic-gate CRYPTO_USER 3787c478bd9Sstevel@tonic-gate } crypto_user_type_t; 3797c478bd9Sstevel@tonic-gate 3807c478bd9Sstevel@tonic-gate /* Version for provider management ioctls and SPI entry points */ 3817c478bd9Sstevel@tonic-gate 3827c478bd9Sstevel@tonic-gate typedef struct crypto_version { 3837c478bd9Sstevel@tonic-gate uchar_t cv_major; 3847c478bd9Sstevel@tonic-gate uchar_t cv_minor; 3857c478bd9Sstevel@tonic-gate } crypto_version_t; 3867c478bd9Sstevel@tonic-gate 3877c478bd9Sstevel@tonic-gate /* session data structure opaque to the consumer */ 3887c478bd9Sstevel@tonic-gate typedef void *crypto_session_t; 3897c478bd9Sstevel@tonic-gate 390c892ebf1Skrishna /* provider data structure opaque to the consumer */ 391894b2776Smcpowers typedef void *crypto_provider_t; 392894b2776Smcpowers 393c892ebf1Skrishna /* Limits used by both consumers and providers */ 394c892ebf1Skrishna #define CRYPTO_EXT_SIZE_LABEL 32 395c892ebf1Skrishna #define CRYPTO_EXT_SIZE_MANUF 32 396c892ebf1Skrishna #define CRYPTO_EXT_SIZE_MODEL 16 397c892ebf1Skrishna #define CRYPTO_EXT_SIZE_SERIAL 16 398c892ebf1Skrishna #define CRYPTO_EXT_SIZE_TIME 16 399c892ebf1Skrishna 400c892ebf1Skrishna typedef struct crypto_provider_ext_info { 401c892ebf1Skrishna uchar_t ei_label[CRYPTO_EXT_SIZE_LABEL]; 402c892ebf1Skrishna uchar_t ei_manufacturerID[CRYPTO_EXT_SIZE_MANUF]; 403c892ebf1Skrishna uchar_t ei_model[CRYPTO_EXT_SIZE_MODEL]; 404c892ebf1Skrishna uchar_t ei_serial_number[CRYPTO_EXT_SIZE_SERIAL]; 405c892ebf1Skrishna ulong_t ei_flags; 406c892ebf1Skrishna ulong_t ei_max_session_count; 407c892ebf1Skrishna ulong_t ei_max_pin_len; 408c892ebf1Skrishna ulong_t ei_min_pin_len; 409c892ebf1Skrishna ulong_t ei_total_public_memory; 410c892ebf1Skrishna ulong_t ei_free_public_memory; 411c892ebf1Skrishna ulong_t ei_total_private_memory; 412c892ebf1Skrishna ulong_t ei_free_private_memory; 413c892ebf1Skrishna crypto_version_t ei_hardware_version; 414c892ebf1Skrishna crypto_version_t ei_firmware_version; 415c892ebf1Skrishna uchar_t ei_time[CRYPTO_EXT_SIZE_TIME]; 416c892ebf1Skrishna } crypto_provider_ext_info_t; 417c892ebf1Skrishna 4187c478bd9Sstevel@tonic-gate typedef uint_t crypto_session_id_t; 4197c478bd9Sstevel@tonic-gate 4207c478bd9Sstevel@tonic-gate /* 4217c478bd9Sstevel@tonic-gate * Common cryptographic status and error codes. 4227c478bd9Sstevel@tonic-gate */ 4237c478bd9Sstevel@tonic-gate #define CRYPTO_SUCCESS 0x00000000 4247c478bd9Sstevel@tonic-gate #define CRYPTO_CANCEL 0x00000001 4257c478bd9Sstevel@tonic-gate #define CRYPTO_HOST_MEMORY 0x00000002 4267c478bd9Sstevel@tonic-gate #define CRYPTO_GENERAL_ERROR 0x00000003 4277c478bd9Sstevel@tonic-gate #define CRYPTO_FAILED 0x00000004 4287c478bd9Sstevel@tonic-gate #define CRYPTO_ARGUMENTS_BAD 0x00000005 4297c478bd9Sstevel@tonic-gate #define CRYPTO_ATTRIBUTE_READ_ONLY 0x00000006 4307c478bd9Sstevel@tonic-gate #define CRYPTO_ATTRIBUTE_SENSITIVE 0x00000007 4317c478bd9Sstevel@tonic-gate #define CRYPTO_ATTRIBUTE_TYPE_INVALID 0x00000008 4327c478bd9Sstevel@tonic-gate #define CRYPTO_ATTRIBUTE_VALUE_INVALID 0x00000009 4337c478bd9Sstevel@tonic-gate #define CRYPTO_CANCELED 0x0000000A 4347c478bd9Sstevel@tonic-gate #define CRYPTO_DATA_INVALID 0x0000000B 4357c478bd9Sstevel@tonic-gate #define CRYPTO_DATA_LEN_RANGE 0x0000000C 4367c478bd9Sstevel@tonic-gate #define CRYPTO_DEVICE_ERROR 0x0000000D 4377c478bd9Sstevel@tonic-gate #define CRYPTO_DEVICE_MEMORY 0x0000000E 4387c478bd9Sstevel@tonic-gate #define CRYPTO_DEVICE_REMOVED 0x0000000F 4397c478bd9Sstevel@tonic-gate #define CRYPTO_ENCRYPTED_DATA_INVALID 0x00000010 4407c478bd9Sstevel@tonic-gate #define CRYPTO_ENCRYPTED_DATA_LEN_RANGE 0x00000011 4417c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_HANDLE_INVALID 0x00000012 4427c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_SIZE_RANGE 0x00000013 4437c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_TYPE_INCONSISTENT 0x00000014 4447c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_NOT_NEEDED 0x00000015 4457c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_CHANGED 0x00000016 4467c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_NEEDED 0x00000017 4477c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_INDIGESTIBLE 0x00000018 4487c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_FUNCTION_NOT_PERMITTED 0x00000019 4497c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_NOT_WRAPPABLE 0x0000001A 4507c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_UNEXTRACTABLE 0x0000001B 4517c478bd9Sstevel@tonic-gate #define CRYPTO_MECHANISM_INVALID 0x0000001C 4527c478bd9Sstevel@tonic-gate #define CRYPTO_MECHANISM_PARAM_INVALID 0x0000001D 4537c478bd9Sstevel@tonic-gate #define CRYPTO_OBJECT_HANDLE_INVALID 0x0000001E 4547c478bd9Sstevel@tonic-gate #define CRYPTO_OPERATION_IS_ACTIVE 0x0000001F 4557c478bd9Sstevel@tonic-gate #define CRYPTO_OPERATION_NOT_INITIALIZED 0x00000020 4567c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_INCORRECT 0x00000021 4577c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_INVALID 0x00000022 4587c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_LEN_RANGE 0x00000023 4597c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_EXPIRED 0x00000024 4607c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_LOCKED 0x00000025 4617c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_CLOSED 0x00000026 4627c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_COUNT 0x00000027 4637c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_HANDLE_INVALID 0x00000028 4647c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_READ_ONLY 0x00000029 4657c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_EXISTS 0x0000002A 4667c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_READ_ONLY_EXISTS 0x0000002B 4677c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_READ_WRITE_SO_EXISTS 0x0000002C 4687c478bd9Sstevel@tonic-gate #define CRYPTO_SIGNATURE_INVALID 0x0000002D 4697c478bd9Sstevel@tonic-gate #define CRYPTO_SIGNATURE_LEN_RANGE 0x0000002E 4707c478bd9Sstevel@tonic-gate #define CRYPTO_TEMPLATE_INCOMPLETE 0x0000002F 4717c478bd9Sstevel@tonic-gate #define CRYPTO_TEMPLATE_INCONSISTENT 0x00000030 4727c478bd9Sstevel@tonic-gate #define CRYPTO_UNWRAPPING_KEY_HANDLE_INVALID 0x00000031 4737c478bd9Sstevel@tonic-gate #define CRYPTO_UNWRAPPING_KEY_SIZE_RANGE 0x00000032 4747c478bd9Sstevel@tonic-gate #define CRYPTO_UNWRAPPING_KEY_TYPE_INCONSISTENT 0x00000033 4757c478bd9Sstevel@tonic-gate #define CRYPTO_USER_ALREADY_LOGGED_IN 0x00000034 4767c478bd9Sstevel@tonic-gate #define CRYPTO_USER_NOT_LOGGED_IN 0x00000035 4777c478bd9Sstevel@tonic-gate #define CRYPTO_USER_PIN_NOT_INITIALIZED 0x00000036 4787c478bd9Sstevel@tonic-gate #define CRYPTO_USER_TYPE_INVALID 0x00000037 4797c478bd9Sstevel@tonic-gate #define CRYPTO_USER_ANOTHER_ALREADY_LOGGED_IN 0x00000038 4807c478bd9Sstevel@tonic-gate #define CRYPTO_USER_TOO_MANY_TYPES 0x00000039 4817c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPED_KEY_INVALID 0x0000003A 4827c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPED_KEY_LEN_RANGE 0x0000003B 4837c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPING_KEY_HANDLE_INVALID 0x0000003C 4847c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPING_KEY_SIZE_RANGE 0x0000003D 4857c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPING_KEY_TYPE_INCONSISTENT 0x0000003E 4867c478bd9Sstevel@tonic-gate #define CRYPTO_RANDOM_SEED_NOT_SUPPORTED 0x0000003F 4877c478bd9Sstevel@tonic-gate #define CRYPTO_RANDOM_NO_RNG 0x00000040 4887c478bd9Sstevel@tonic-gate #define CRYPTO_DOMAIN_PARAMS_INVALID 0x00000041 4897c478bd9Sstevel@tonic-gate #define CRYPTO_BUFFER_TOO_SMALL 0x00000042 4907c478bd9Sstevel@tonic-gate #define CRYPTO_INFORMATION_SENSITIVE 0x00000043 4917c478bd9Sstevel@tonic-gate #define CRYPTO_NOT_SUPPORTED 0x00000044 4927c478bd9Sstevel@tonic-gate 4937c478bd9Sstevel@tonic-gate #define CRYPTO_QUEUED 0x00000045 4947c478bd9Sstevel@tonic-gate #define CRYPTO_BUFFER_TOO_BIG 0x00000046 4957c478bd9Sstevel@tonic-gate #define CRYPTO_INVALID_CONTEXT 0x00000047 4967c478bd9Sstevel@tonic-gate #define CRYPTO_INVALID_MAC 0x00000048 4977c478bd9Sstevel@tonic-gate #define CRYPTO_MECH_NOT_SUPPORTED 0x00000049 4987c478bd9Sstevel@tonic-gate #define CRYPTO_INCONSISTENT_ATTRIBUTE 0x0000004A 4997c478bd9Sstevel@tonic-gate #define CRYPTO_NO_PERMISSION 0x0000004B 5007c478bd9Sstevel@tonic-gate #define CRYPTO_INVALID_PROVIDER_ID 0x0000004C 5017c478bd9Sstevel@tonic-gate #define CRYPTO_VERSION_MISMATCH 0x0000004D 5027c478bd9Sstevel@tonic-gate #define CRYPTO_BUSY 0x0000004E 5037c478bd9Sstevel@tonic-gate #define CRYPTO_UNKNOWN_PROVIDER 0x0000004F 5047c478bd9Sstevel@tonic-gate #define CRYPTO_MODVERIFICATION_FAILED 0x00000050 5057c478bd9Sstevel@tonic-gate #define CRYPTO_OLD_CTX_TEMPLATE 0x00000051 5067c478bd9Sstevel@tonic-gate #define CRYPTO_WEAK_KEY 0x00000052 5077c478bd9Sstevel@tonic-gate 5087c478bd9Sstevel@tonic-gate /* 5097c478bd9Sstevel@tonic-gate * Special values that can be used to indicate that information is unavailable 5107c478bd9Sstevel@tonic-gate * or that there is not practical limit. These values can be used 5117c478bd9Sstevel@tonic-gate * by fields of the SPI crypto_provider_ext_info(9S) structure. 5127c478bd9Sstevel@tonic-gate * The value of CRYPTO_UNAVAILABLE_INFO should be the same as 5137c478bd9Sstevel@tonic-gate * CK_UNAVAILABLE_INFO in the PKCS#11 spec. 5147c478bd9Sstevel@tonic-gate */ 5157c478bd9Sstevel@tonic-gate #define CRYPTO_UNAVAILABLE_INFO ((ulong_t)(-1)) 5167c478bd9Sstevel@tonic-gate #define CRYPTO_EFFECTIVELY_INFINITE 0x0 5177c478bd9Sstevel@tonic-gate 5187c478bd9Sstevel@tonic-gate #ifdef __cplusplus 5197c478bd9Sstevel@tonic-gate } 5207c478bd9Sstevel@tonic-gate #endif 5217c478bd9Sstevel@tonic-gate 5227c478bd9Sstevel@tonic-gate #endif /* _SYS_CRYPTO_COMMON_H */ 523