17c478bd9Sstevel@tonic-gate /* 27c478bd9Sstevel@tonic-gate * CDDL HEADER START 37c478bd9Sstevel@tonic-gate * 47c478bd9Sstevel@tonic-gate * The contents of this file are subject to the terms of the 5c892ebf1Skrishna * Common Development and Distribution License (the "License"). 6c892ebf1Skrishna * You may not use this file except in compliance with the License. 77c478bd9Sstevel@tonic-gate * 87c478bd9Sstevel@tonic-gate * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 97c478bd9Sstevel@tonic-gate * or http://www.opensolaris.org/os/licensing. 107c478bd9Sstevel@tonic-gate * See the License for the specific language governing permissions 117c478bd9Sstevel@tonic-gate * and limitations under the License. 127c478bd9Sstevel@tonic-gate * 137c478bd9Sstevel@tonic-gate * When distributing Covered Code, include this CDDL HEADER in each 147c478bd9Sstevel@tonic-gate * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 157c478bd9Sstevel@tonic-gate * If applicable, add the following below this CDDL HEADER, with the 167c478bd9Sstevel@tonic-gate * fields enclosed by brackets "[]" replaced with your own identifying 177c478bd9Sstevel@tonic-gate * information: Portions Copyright [yyyy] [name of copyright owner] 187c478bd9Sstevel@tonic-gate * 197c478bd9Sstevel@tonic-gate * CDDL HEADER END 207c478bd9Sstevel@tonic-gate */ 217c478bd9Sstevel@tonic-gate /* 22*e8ab7b17SZdenek Kotala * Copyright (c) 2003, 2010, Oracle and/or its affiliates. All rights reserved. 237c478bd9Sstevel@tonic-gate */ 247c478bd9Sstevel@tonic-gate 257c478bd9Sstevel@tonic-gate #ifndef _SYS_CRYPTO_COMMON_H 267c478bd9Sstevel@tonic-gate #define _SYS_CRYPTO_COMMON_H 277c478bd9Sstevel@tonic-gate 287c478bd9Sstevel@tonic-gate /* 297c478bd9Sstevel@tonic-gate * Header file for the common data structures of the cryptographic framework 307c478bd9Sstevel@tonic-gate */ 317c478bd9Sstevel@tonic-gate 327c478bd9Sstevel@tonic-gate #ifdef __cplusplus 337c478bd9Sstevel@tonic-gate extern "C" { 347c478bd9Sstevel@tonic-gate #endif 357c478bd9Sstevel@tonic-gate 367c478bd9Sstevel@tonic-gate #include <sys/types.h> 377c478bd9Sstevel@tonic-gate #include <sys/uio.h> 387c478bd9Sstevel@tonic-gate #include <sys/stream.h> 397c478bd9Sstevel@tonic-gate #include <sys/mutex.h> 407c478bd9Sstevel@tonic-gate #include <sys/condvar.h> 417c478bd9Sstevel@tonic-gate 427c478bd9Sstevel@tonic-gate 437c478bd9Sstevel@tonic-gate /* Cryptographic Mechanisms */ 447c478bd9Sstevel@tonic-gate 457c478bd9Sstevel@tonic-gate #define CRYPTO_MAX_MECH_NAME 32 467c478bd9Sstevel@tonic-gate typedef char crypto_mech_name_t[CRYPTO_MAX_MECH_NAME]; 477c478bd9Sstevel@tonic-gate 487c478bd9Sstevel@tonic-gate typedef uint64_t crypto_mech_type_t; 497c478bd9Sstevel@tonic-gate 507c478bd9Sstevel@tonic-gate typedef struct crypto_mechanism { 517c478bd9Sstevel@tonic-gate crypto_mech_type_t cm_type; /* mechanism type */ 527c478bd9Sstevel@tonic-gate caddr_t cm_param; /* mech. parameter */ 537c478bd9Sstevel@tonic-gate size_t cm_param_len; /* mech. parameter len */ 547c478bd9Sstevel@tonic-gate } crypto_mechanism_t; 557c478bd9Sstevel@tonic-gate 56f317a3a3Skrishna #ifdef _SYSCALL32 57f317a3a3Skrishna 58f317a3a3Skrishna typedef struct crypto_mechanism32 { 59f317a3a3Skrishna crypto_mech_type_t cm_type; /* mechanism type */ 60f317a3a3Skrishna caddr32_t cm_param; /* mech. parameter */ 61f317a3a3Skrishna size32_t cm_param_len; /* mech. parameter len */ 62f317a3a3Skrishna } crypto_mechanism32_t; 63f317a3a3Skrishna 64f317a3a3Skrishna #endif /* _SYSCALL32 */ 65f317a3a3Skrishna 661e9884acSmcpowers #ifdef _KERNEL 67d2b32306Smcpowers /* CK_AES_CTR_PARAMS provides parameters to the CKM_AES_CTR mechanism */ 68d2b32306Smcpowers typedef struct CK_AES_CTR_PARAMS { 69d2b32306Smcpowers ulong_t ulCounterBits; 70d2b32306Smcpowers uint8_t cb[16]; 71d2b32306Smcpowers } CK_AES_CTR_PARAMS; 721e9884acSmcpowers #endif 73d2b32306Smcpowers 74d2b32306Smcpowers /* CK_AES_CCM_PARAMS provides parameters to the CKM_AES_CCM mechanism */ 75d2b32306Smcpowers typedef struct CK_AES_CCM_PARAMS { 76d2b32306Smcpowers ulong_t ulMACSize; 77d2b32306Smcpowers ulong_t ulNonceSize; 78d2b32306Smcpowers ulong_t ulAuthDataSize; 79d2b32306Smcpowers ulong_t ulDataSize; /* used for plaintext or ciphertext */ 80d2b32306Smcpowers uchar_t *nonce; 81d2b32306Smcpowers uchar_t *authData; 82d2b32306Smcpowers } CK_AES_CCM_PARAMS; 83d2b32306Smcpowers 844d703b5cSMark Powers /* CK_AES_GCM_PARAMS provides parameters to the CKM_AES_GCM mechanism */ 854d703b5cSMark Powers typedef struct CK_AES_GCM_PARAMS { 864d703b5cSMark Powers uchar_t *pIv; 874d703b5cSMark Powers ulong_t ulIvLen; 884d703b5cSMark Powers ulong_t ulIvBits; 894d703b5cSMark Powers uchar_t *pAAD; 904d703b5cSMark Powers ulong_t ulAADLen; 914d703b5cSMark Powers ulong_t ulTagBits; 924d703b5cSMark Powers } CK_AES_GCM_PARAMS; 934d703b5cSMark Powers 94983a1033SMark Powers /* CK_AES_GMAC_PARAMS provides parameters to the CKM_AES_GMAC mechanism */ 95983a1033SMark Powers typedef struct CK_AES_GMAC_PARAMS { 96983a1033SMark Powers uchar_t *pIv; 97983a1033SMark Powers uchar_t *pAAD; 98983a1033SMark Powers ulong_t ulAADLen; 99983a1033SMark Powers } CK_AES_GMAC_PARAMS; 100983a1033SMark Powers 1018d4583b0Sfr41279 #ifdef _KERNEL 1028d4583b0Sfr41279 /* 1038d4583b0Sfr41279 * CK_ECDH1_DERIVE_PARAMS provides the parameters to the 1048d4583b0Sfr41279 * CKM_ECDH1_KEY_DERIVE mechanism 1058d4583b0Sfr41279 */ 1068d4583b0Sfr41279 typedef struct CK_ECDH1_DERIVE_PARAMS { 1078d4583b0Sfr41279 ulong_t kdf; 1088d4583b0Sfr41279 ulong_t ulSharedDataLen; 1098d4583b0Sfr41279 uchar_t *pSharedData; 1108d4583b0Sfr41279 ulong_t ulPublicDataLen; 1118d4583b0Sfr41279 uchar_t *pPublicData; 1128d4583b0Sfr41279 } CK_ECDH1_DERIVE_PARAMS; 1138d4583b0Sfr41279 #endif 1148d4583b0Sfr41279 115d2b32306Smcpowers #ifdef _KERNEL 116d2b32306Smcpowers #ifdef _SYSCALL32 117d2b32306Smcpowers 118d2b32306Smcpowers /* needed for 32-bit applications running on 64-bit kernels */ 119d2b32306Smcpowers typedef struct CK_AES_CTR_PARAMS32 { 120d2b32306Smcpowers uint32_t ulCounterBits; 121d2b32306Smcpowers uint8_t cb[16]; 122d2b32306Smcpowers } CK_AES_CTR_PARAMS32; 123d2b32306Smcpowers 124d2b32306Smcpowers /* needed for 32-bit applications running on 64-bit kernels */ 125d2b32306Smcpowers typedef struct CK_AES_CCM_PARAMS32 { 126d2b32306Smcpowers uint32_t ulMACSize; 127d2b32306Smcpowers uint32_t ulNonceSize; 128d2b32306Smcpowers uint32_t ulAuthDataSize; 129d2b32306Smcpowers uint32_t ulDataSize; 130d2b32306Smcpowers caddr32_t nonce; 131d2b32306Smcpowers caddr32_t authData; 132d2b32306Smcpowers } CK_AES_CCM_PARAMS32; 133d2b32306Smcpowers 1344d703b5cSMark Powers /* needed for 32-bit applications running on 64-bit kernels */ 1354d703b5cSMark Powers typedef struct CK_AES_GCM_PARAMS32 { 1364d703b5cSMark Powers caddr32_t pIv; 1374d703b5cSMark Powers uint32_t ulIvLen; 1384d703b5cSMark Powers uint32_t ulIvBits; 1394d703b5cSMark Powers caddr32_t pAAD; 1404d703b5cSMark Powers uint32_t ulAADLen; 1414d703b5cSMark Powers uint32_t ulTagBits; 1424d703b5cSMark Powers } CK_AES_GCM_PARAMS32; 1434d703b5cSMark Powers 144983a1033SMark Powers /* needed for 32-bit applications running on 64-bit kernels */ 145983a1033SMark Powers typedef struct CK_AES_GMAC_PARAMS32 { 146983a1033SMark Powers caddr32_t pIv; 147983a1033SMark Powers caddr32_t pAAD; 148983a1033SMark Powers uint32_t ulAADLen; 149983a1033SMark Powers } CK_AES_GMAC_PARAMS32; 150983a1033SMark Powers 1518d4583b0Sfr41279 typedef struct CK_ECDH1_DERIVE_PARAMS32 { 1528d4583b0Sfr41279 uint32_t kdf; 1538d4583b0Sfr41279 uint32_t ulSharedDataLen; 1548d4583b0Sfr41279 caddr32_t pSharedData; 1558d4583b0Sfr41279 uint32_t ulPublicDataLen; 1568d4583b0Sfr41279 caddr32_t pPublicData; 1578d4583b0Sfr41279 } CK_ECDH1_DERIVE_PARAMS32; 1588d4583b0Sfr41279 159d2b32306Smcpowers #endif /* _SYSCALL32 */ 160d2b32306Smcpowers #endif /* _KERNEL */ 161d2b32306Smcpowers 1627c478bd9Sstevel@tonic-gate /* 1636a1073f8Skrishna * The measurement unit bit flag for a mechanism's minimum or maximum key size. 16495014fbbSDan OpenSolaris Anderson * The unit are mechanism dependent. It can be in bits or in bytes. 1657c478bd9Sstevel@tonic-gate */ 1667c478bd9Sstevel@tonic-gate typedef uint32_t crypto_keysize_unit_t; 1677c478bd9Sstevel@tonic-gate 1686a1073f8Skrishna /* 1696a1073f8Skrishna * The following bit flags are valid in cm_mech_flags field in 1706a1073f8Skrishna * the crypto_mech_info_t structure of the SPI. 1716a1073f8Skrishna * 1726a1073f8Skrishna * Only the first two bit flags are valid in mi_keysize_unit 1736a1073f8Skrishna * field in the crypto_mechanism_info_t structure of the API. 1746a1073f8Skrishna */ 1757c478bd9Sstevel@tonic-gate #define CRYPTO_KEYSIZE_UNIT_IN_BITS 0x00000001 1767c478bd9Sstevel@tonic-gate #define CRYPTO_KEYSIZE_UNIT_IN_BYTES 0x00000002 1776a1073f8Skrishna #define CRYPTO_CAN_SHARE_OPSTATE 0x00000004 /* supports sharing */ 1787c478bd9Sstevel@tonic-gate 1797c478bd9Sstevel@tonic-gate 1807c478bd9Sstevel@tonic-gate /* Mechanisms supported out-of-the-box */ 1815151fb12Sdarrenm #define SUN_CKM_MD4 "CKM_MD4" 1827c478bd9Sstevel@tonic-gate #define SUN_CKM_MD5 "CKM_MD5" 1837c478bd9Sstevel@tonic-gate #define SUN_CKM_MD5_HMAC "CKM_MD5_HMAC" 1847c478bd9Sstevel@tonic-gate #define SUN_CKM_MD5_HMAC_GENERAL "CKM_MD5_HMAC_GENERAL" 1857c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA1 "CKM_SHA_1" 1867c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA1_HMAC "CKM_SHA_1_HMAC" 1877c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA1_HMAC_GENERAL "CKM_SHA_1_HMAC_GENERAL" 1887c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA256 "CKM_SHA256" 1897c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA256_HMAC "CKM_SHA256_HMAC" 1907c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA256_HMAC_GENERAL "CKM_SHA256_HMAC_GENERAL" 1917c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA384 "CKM_SHA384" 1927c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA384_HMAC "CKM_SHA384_HMAC" 1937c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA384_HMAC_GENERAL "CKM_SHA384_HMAC_GENERAL" 1947c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA512 "CKM_SHA512" 1957c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA512_HMAC "CKM_SHA512_HMAC" 1967c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA512_HMAC_GENERAL "CKM_SHA512_HMAC_GENERAL" 1977c478bd9Sstevel@tonic-gate #define SUN_CKM_DES_CBC "CKM_DES_CBC" 1987c478bd9Sstevel@tonic-gate #define SUN_CKM_DES3_CBC "CKM_DES3_CBC" 1997c478bd9Sstevel@tonic-gate #define SUN_CKM_DES_ECB "CKM_DES_ECB" 2007c478bd9Sstevel@tonic-gate #define SUN_CKM_DES3_ECB "CKM_DES3_ECB" 201f66d273dSizick #define SUN_CKM_BLOWFISH_CBC "CKM_BLOWFISH_CBC" 202f66d273dSizick #define SUN_CKM_BLOWFISH_ECB "CKM_BLOWFISH_ECB" 2037c478bd9Sstevel@tonic-gate #define SUN_CKM_AES_CBC "CKM_AES_CBC" 2047c478bd9Sstevel@tonic-gate #define SUN_CKM_AES_ECB "CKM_AES_ECB" 205894b2776Smcpowers #define SUN_CKM_AES_CTR "CKM_AES_CTR" 2067fb8ff4bSktung #define SUN_CKM_AES_CCM "CKM_AES_CCM" 2074d703b5cSMark Powers #define SUN_CKM_AES_GCM "CKM_AES_GCM" 208983a1033SMark Powers #define SUN_CKM_AES_GMAC "CKM_AES_GMAC" 2094df55fdeSJanie Lu #define SUN_CKM_AES_CFB128 "CKM_AES_CFB128" 2107c478bd9Sstevel@tonic-gate #define SUN_CKM_RC4 "CKM_RC4" 2117c478bd9Sstevel@tonic-gate #define SUN_CKM_RSA_PKCS "CKM_RSA_PKCS" 2127c478bd9Sstevel@tonic-gate #define SUN_CKM_RSA_X_509 "CKM_RSA_X_509" 2137c478bd9Sstevel@tonic-gate #define SUN_CKM_MD5_RSA_PKCS "CKM_MD5_RSA_PKCS" 2147c478bd9Sstevel@tonic-gate #define SUN_CKM_SHA1_RSA_PKCS "CKM_SHA1_RSA_PKCS" 215f66d273dSizick #define SUN_CKM_SHA256_RSA_PKCS "CKM_SHA256_RSA_PKCS" 216f66d273dSizick #define SUN_CKM_SHA384_RSA_PKCS "CKM_SHA384_RSA_PKCS" 217f66d273dSizick #define SUN_CKM_SHA512_RSA_PKCS "CKM_SHA512_RSA_PKCS" 218f9fbec18Smcpowers #define SUN_CKM_EC_KEY_PAIR_GEN "CKM_EC_KEY_PAIR_GEN" 219f9fbec18Smcpowers #define SUN_CKM_ECDH1_DERIVE "CKM_ECDH1_DERIVE" 220f9fbec18Smcpowers #define SUN_CKM_ECDSA_SHA1 "CKM_ECDSA_SHA1" 221f9fbec18Smcpowers #define SUN_CKM_ECDSA "CKM_ECDSA" 2227c478bd9Sstevel@tonic-gate 2236a1073f8Skrishna /* Shared operation context format for CKM_RC4 */ 2246a1073f8Skrishna typedef struct { 22555553f71Sda73024 #if defined(__amd64) 22655553f71Sda73024 uint32_t i, j; 22755553f71Sda73024 uint32_t arr[256]; 22892a8e44dSDan OpenSolaris Anderson uint32_t flag; 22955553f71Sda73024 #else 23055553f71Sda73024 uchar_t arr[256]; 23155553f71Sda73024 uchar_t i, j; 23255553f71Sda73024 #endif /* __amd64 */ 2336a1073f8Skrishna uint64_t pad; /* For 64-bit alignment */ 2346a1073f8Skrishna } arcfour_state_t; 2356a1073f8Skrishna 2367c478bd9Sstevel@tonic-gate /* Data arguments of cryptographic operations */ 2377c478bd9Sstevel@tonic-gate 2387c478bd9Sstevel@tonic-gate typedef enum crypto_data_format { 2397c478bd9Sstevel@tonic-gate CRYPTO_DATA_RAW = 1, 2407c478bd9Sstevel@tonic-gate CRYPTO_DATA_UIO, 2417c478bd9Sstevel@tonic-gate CRYPTO_DATA_MBLK 2427c478bd9Sstevel@tonic-gate } crypto_data_format_t; 2437c478bd9Sstevel@tonic-gate 2447c478bd9Sstevel@tonic-gate typedef struct crypto_data { 2457c478bd9Sstevel@tonic-gate crypto_data_format_t cd_format; /* Format identifier */ 2467c478bd9Sstevel@tonic-gate off_t cd_offset; /* Offset from the beginning */ 2477c478bd9Sstevel@tonic-gate size_t cd_length; /* # of bytes in use */ 2487c478bd9Sstevel@tonic-gate caddr_t cd_miscdata; /* ancillary data */ 2497c478bd9Sstevel@tonic-gate union { 2507c478bd9Sstevel@tonic-gate /* Raw format */ 2517c478bd9Sstevel@tonic-gate iovec_t cdu_raw; /* Pointer and length */ 2527c478bd9Sstevel@tonic-gate 2537c478bd9Sstevel@tonic-gate /* uio scatter-gather format */ 2547c478bd9Sstevel@tonic-gate uio_t *cdu_uio; 2557c478bd9Sstevel@tonic-gate 2567c478bd9Sstevel@tonic-gate /* mblk scatter-gather format */ 2577c478bd9Sstevel@tonic-gate mblk_t *cdu_mp; /* The mblk chain */ 2587c478bd9Sstevel@tonic-gate 2597c478bd9Sstevel@tonic-gate } cdu; /* Crypto Data Union */ 2607c478bd9Sstevel@tonic-gate } crypto_data_t; 2617c478bd9Sstevel@tonic-gate 2627c478bd9Sstevel@tonic-gate #define cd_raw cdu.cdu_raw 2637c478bd9Sstevel@tonic-gate #define cd_uio cdu.cdu_uio 2647c478bd9Sstevel@tonic-gate #define cd_mp cdu.cdu_mp 2657c478bd9Sstevel@tonic-gate 2667c478bd9Sstevel@tonic-gate typedef struct crypto_dual_data { 2677c478bd9Sstevel@tonic-gate crypto_data_t dd_data; /* The data */ 2687c478bd9Sstevel@tonic-gate off_t dd_offset2; /* Used by dual operation */ 2697c478bd9Sstevel@tonic-gate size_t dd_len2; /* # of bytes to take */ 2707c478bd9Sstevel@tonic-gate } crypto_dual_data_t; 2717c478bd9Sstevel@tonic-gate 2727c478bd9Sstevel@tonic-gate #define dd_format dd_data.cd_format 2737c478bd9Sstevel@tonic-gate #define dd_offset1 dd_data.cd_offset 2747c478bd9Sstevel@tonic-gate #define dd_len1 dd_data.cd_length 2757c478bd9Sstevel@tonic-gate #define dd_miscdata dd_data.cd_miscdata 2767c478bd9Sstevel@tonic-gate #define dd_raw dd_data.cd_raw 2777c478bd9Sstevel@tonic-gate #define dd_uio dd_data.cd_uio 2787c478bd9Sstevel@tonic-gate #define dd_mp dd_data.cd_mp 2797c478bd9Sstevel@tonic-gate 2807c478bd9Sstevel@tonic-gate /* The keys, and their contents */ 2817c478bd9Sstevel@tonic-gate 2827c478bd9Sstevel@tonic-gate typedef enum { 2837c478bd9Sstevel@tonic-gate CRYPTO_KEY_RAW = 1, /* ck_data is a cleartext key */ 2847c478bd9Sstevel@tonic-gate CRYPTO_KEY_REFERENCE, /* ck_obj_id is an opaque reference */ 2857c478bd9Sstevel@tonic-gate CRYPTO_KEY_ATTR_LIST /* ck_attrs is a list of object attributes */ 2867c478bd9Sstevel@tonic-gate } crypto_key_format_t; 2877c478bd9Sstevel@tonic-gate 2887c478bd9Sstevel@tonic-gate typedef uint64_t crypto_attr_type_t; 2897c478bd9Sstevel@tonic-gate 2907c478bd9Sstevel@tonic-gate /* Attribute types to use for passing a RSA public key or a private key. */ 2917c478bd9Sstevel@tonic-gate #define SUN_CKA_MODULUS 0x00000120 2927c478bd9Sstevel@tonic-gate #define SUN_CKA_MODULUS_BITS 0x00000121 2937c478bd9Sstevel@tonic-gate #define SUN_CKA_PUBLIC_EXPONENT 0x00000122 2947c478bd9Sstevel@tonic-gate #define SUN_CKA_PRIVATE_EXPONENT 0x00000123 2957c478bd9Sstevel@tonic-gate #define SUN_CKA_PRIME_1 0x00000124 2967c478bd9Sstevel@tonic-gate #define SUN_CKA_PRIME_2 0x00000125 2977c478bd9Sstevel@tonic-gate #define SUN_CKA_EXPONENT_1 0x00000126 2987c478bd9Sstevel@tonic-gate #define SUN_CKA_EXPONENT_2 0x00000127 2997c478bd9Sstevel@tonic-gate #define SUN_CKA_COEFFICIENT 0x00000128 3007c478bd9Sstevel@tonic-gate #define SUN_CKA_PRIME 0x00000130 3017c478bd9Sstevel@tonic-gate #define SUN_CKA_SUBPRIME 0x00000131 3027c478bd9Sstevel@tonic-gate #define SUN_CKA_BASE 0x00000132 3037c478bd9Sstevel@tonic-gate 304f9fbec18Smcpowers #define CKK_EC 0x00000003 305f9fbec18Smcpowers #define CKK_GENERIC_SECRET 0x00000010 306f9fbec18Smcpowers #define CKK_RC4 0x00000012 307f9fbec18Smcpowers #define CKK_AES 0x0000001F 308f9fbec18Smcpowers #define CKK_DES 0x00000013 309f9fbec18Smcpowers #define CKK_DES2 0x00000014 310f9fbec18Smcpowers #define CKK_DES3 0x00000015 311f9fbec18Smcpowers 312f9fbec18Smcpowers #define CKO_PUBLIC_KEY 0x00000002 313f9fbec18Smcpowers #define CKO_PRIVATE_KEY 0x00000003 314f9fbec18Smcpowers #define CKA_CLASS 0x00000000 315f9fbec18Smcpowers #define CKA_VALUE 0x00000011 316f9fbec18Smcpowers #define CKA_KEY_TYPE 0x00000100 317f9fbec18Smcpowers #define CKA_VALUE_LEN 0x00000161 318f9fbec18Smcpowers #define CKA_EC_PARAMS 0x00000180 319f9fbec18Smcpowers #define CKA_EC_POINT 0x00000181 320f9fbec18Smcpowers 3217c478bd9Sstevel@tonic-gate typedef uint32_t crypto_object_id_t; 3227c478bd9Sstevel@tonic-gate 3237c478bd9Sstevel@tonic-gate typedef struct crypto_object_attribute { 3247c478bd9Sstevel@tonic-gate crypto_attr_type_t oa_type; /* attribute type */ 3257c478bd9Sstevel@tonic-gate caddr_t oa_value; /* attribute value */ 3267c478bd9Sstevel@tonic-gate ssize_t oa_value_len; /* length of attribute value */ 3277c478bd9Sstevel@tonic-gate } crypto_object_attribute_t; 3287c478bd9Sstevel@tonic-gate 3297c478bd9Sstevel@tonic-gate typedef struct crypto_key { 3307c478bd9Sstevel@tonic-gate crypto_key_format_t ck_format; /* format identifier */ 3317c478bd9Sstevel@tonic-gate union { 3327c478bd9Sstevel@tonic-gate /* for CRYPTO_KEY_RAW ck_format */ 3337c478bd9Sstevel@tonic-gate struct { 3347c478bd9Sstevel@tonic-gate uint_t cku_v_length; /* # of bits in ck_data */ 3357c478bd9Sstevel@tonic-gate void *cku_v_data; /* ptr to key value */ 3367c478bd9Sstevel@tonic-gate } cku_key_value; 3377c478bd9Sstevel@tonic-gate 3387c478bd9Sstevel@tonic-gate /* for CRYPTO_KEY_REFERENCE ck_format */ 3397c478bd9Sstevel@tonic-gate crypto_object_id_t cku_key_id; /* reference to object key */ 3407c478bd9Sstevel@tonic-gate 3417c478bd9Sstevel@tonic-gate /* for CRYPTO_KEY_ATTR_LIST ck_format */ 3427c478bd9Sstevel@tonic-gate struct { 3437c478bd9Sstevel@tonic-gate uint_t cku_a_count; /* number of attributes */ 3447c478bd9Sstevel@tonic-gate crypto_object_attribute_t *cku_a_oattr; 3457c478bd9Sstevel@tonic-gate } cku_key_attrs; 3467c478bd9Sstevel@tonic-gate } cku_data; /* Crypto Key union */ 3477c478bd9Sstevel@tonic-gate } crypto_key_t; 3487c478bd9Sstevel@tonic-gate 349f317a3a3Skrishna #ifdef _SYSCALL32 350f317a3a3Skrishna 351f317a3a3Skrishna typedef struct crypto_object_attribute32 { 352f317a3a3Skrishna uint64_t oa_type; /* attribute type */ 353f317a3a3Skrishna caddr32_t oa_value; /* attribute value */ 354f317a3a3Skrishna ssize32_t oa_value_len; /* length of attribute value */ 355f317a3a3Skrishna } crypto_object_attribute32_t; 356f317a3a3Skrishna 357f317a3a3Skrishna typedef struct crypto_key32 { 358f317a3a3Skrishna crypto_key_format_t ck_format; /* format identifier */ 359f317a3a3Skrishna union { 360f317a3a3Skrishna /* for CRYPTO_KEY_RAW ck_format */ 361f317a3a3Skrishna struct { 362f317a3a3Skrishna uint32_t cku_v_length; /* # of bytes in ck_data */ 363f317a3a3Skrishna caddr32_t cku_v_data; /* ptr to key value */ 364f317a3a3Skrishna } cku_key_value; 365f317a3a3Skrishna 366f317a3a3Skrishna /* for CRYPTO_KEY_REFERENCE ck_format */ 367f317a3a3Skrishna crypto_object_id_t cku_key_id; /* reference to object key */ 368f317a3a3Skrishna 369f317a3a3Skrishna /* for CRYPTO_KEY_ATTR_LIST ck_format */ 370f317a3a3Skrishna struct { 371f317a3a3Skrishna uint32_t cku_a_count; /* number of attributes */ 372f317a3a3Skrishna caddr32_t cku_a_oattr; 373f317a3a3Skrishna } cku_key_attrs; 374f317a3a3Skrishna } cku_data; /* Crypto Key union */ 375f317a3a3Skrishna } crypto_key32_t; 376f317a3a3Skrishna 377f317a3a3Skrishna #endif /* _SYSCALL32 */ 378f317a3a3Skrishna 3797c478bd9Sstevel@tonic-gate #define ck_data cku_data.cku_key_value.cku_v_data 3807c478bd9Sstevel@tonic-gate #define ck_length cku_data.cku_key_value.cku_v_length 3817c478bd9Sstevel@tonic-gate #define ck_obj_id cku_data.cku_key_id 3827c478bd9Sstevel@tonic-gate #define ck_count cku_data.cku_key_attrs.cku_a_count 3837c478bd9Sstevel@tonic-gate #define ck_attrs cku_data.cku_key_attrs.cku_a_oattr 3847c478bd9Sstevel@tonic-gate 3857c478bd9Sstevel@tonic-gate /* 3867c478bd9Sstevel@tonic-gate * Raw key lengths are expressed in number of bits. 3877c478bd9Sstevel@tonic-gate * The following macro returns the minimum number of 3887c478bd9Sstevel@tonic-gate * bytes that can contain the specified number of bits. 38995014fbbSDan OpenSolaris Anderson * Round up without overflowing the integer type. 3907c478bd9Sstevel@tonic-gate */ 39195014fbbSDan OpenSolaris Anderson #define CRYPTO_BITS2BYTES(n) ((n) == 0 ? 0 : (((n) - 1) >> 3) + 1) 39295014fbbSDan OpenSolaris Anderson #define CRYPTO_BYTES2BITS(n) ((n) << 3) 3937c478bd9Sstevel@tonic-gate 3947c478bd9Sstevel@tonic-gate /* Providers */ 3957c478bd9Sstevel@tonic-gate 3967c478bd9Sstevel@tonic-gate typedef enum { 3977c478bd9Sstevel@tonic-gate CRYPTO_HW_PROVIDER = 0, 3987c478bd9Sstevel@tonic-gate CRYPTO_SW_PROVIDER, 3997c478bd9Sstevel@tonic-gate CRYPTO_LOGICAL_PROVIDER 4007c478bd9Sstevel@tonic-gate } crypto_provider_type_t; 4017c478bd9Sstevel@tonic-gate 4027c478bd9Sstevel@tonic-gate typedef uint32_t crypto_provider_id_t; 4037c478bd9Sstevel@tonic-gate #define KCF_PROVID_INVALID ((uint32_t)-1) 4047c478bd9Sstevel@tonic-gate 4057c478bd9Sstevel@tonic-gate typedef struct crypto_provider_entry { 4067c478bd9Sstevel@tonic-gate crypto_provider_id_t pe_provider_id; 4077c478bd9Sstevel@tonic-gate uint_t pe_mechanism_count; 4087c478bd9Sstevel@tonic-gate } crypto_provider_entry_t; 4097c478bd9Sstevel@tonic-gate 4107c478bd9Sstevel@tonic-gate typedef struct crypto_dev_list_entry { 4117c478bd9Sstevel@tonic-gate char le_dev_name[MAXNAMELEN]; 4127c478bd9Sstevel@tonic-gate uint_t le_dev_instance; 4137c478bd9Sstevel@tonic-gate uint_t le_mechanism_count; 4147c478bd9Sstevel@tonic-gate } crypto_dev_list_entry_t; 4157c478bd9Sstevel@tonic-gate 4167c478bd9Sstevel@tonic-gate /* User type for authentication ioctls and SPI entry points */ 4177c478bd9Sstevel@tonic-gate 4187c478bd9Sstevel@tonic-gate typedef enum crypto_user_type { 4197c478bd9Sstevel@tonic-gate CRYPTO_SO = 0, 4207c478bd9Sstevel@tonic-gate CRYPTO_USER 4217c478bd9Sstevel@tonic-gate } crypto_user_type_t; 4227c478bd9Sstevel@tonic-gate 4237c478bd9Sstevel@tonic-gate /* Version for provider management ioctls and SPI entry points */ 4247c478bd9Sstevel@tonic-gate 4257c478bd9Sstevel@tonic-gate typedef struct crypto_version { 4267c478bd9Sstevel@tonic-gate uchar_t cv_major; 4277c478bd9Sstevel@tonic-gate uchar_t cv_minor; 4287c478bd9Sstevel@tonic-gate } crypto_version_t; 4297c478bd9Sstevel@tonic-gate 4307c478bd9Sstevel@tonic-gate /* session data structure opaque to the consumer */ 4317c478bd9Sstevel@tonic-gate typedef void *crypto_session_t; 4327c478bd9Sstevel@tonic-gate 433c892ebf1Skrishna /* provider data structure opaque to the consumer */ 434894b2776Smcpowers typedef void *crypto_provider_t; 435894b2776Smcpowers 436c892ebf1Skrishna /* Limits used by both consumers and providers */ 437c892ebf1Skrishna #define CRYPTO_EXT_SIZE_LABEL 32 438c892ebf1Skrishna #define CRYPTO_EXT_SIZE_MANUF 32 439c892ebf1Skrishna #define CRYPTO_EXT_SIZE_MODEL 16 440c892ebf1Skrishna #define CRYPTO_EXT_SIZE_SERIAL 16 441c892ebf1Skrishna #define CRYPTO_EXT_SIZE_TIME 16 442c892ebf1Skrishna 443c892ebf1Skrishna typedef struct crypto_provider_ext_info { 444c892ebf1Skrishna uchar_t ei_label[CRYPTO_EXT_SIZE_LABEL]; 445c892ebf1Skrishna uchar_t ei_manufacturerID[CRYPTO_EXT_SIZE_MANUF]; 446c892ebf1Skrishna uchar_t ei_model[CRYPTO_EXT_SIZE_MODEL]; 447c892ebf1Skrishna uchar_t ei_serial_number[CRYPTO_EXT_SIZE_SERIAL]; 448c892ebf1Skrishna ulong_t ei_flags; 449c892ebf1Skrishna ulong_t ei_max_session_count; 450c892ebf1Skrishna ulong_t ei_max_pin_len; 451c892ebf1Skrishna ulong_t ei_min_pin_len; 452c892ebf1Skrishna ulong_t ei_total_public_memory; 453c892ebf1Skrishna ulong_t ei_free_public_memory; 454c892ebf1Skrishna ulong_t ei_total_private_memory; 455c892ebf1Skrishna ulong_t ei_free_private_memory; 456c892ebf1Skrishna crypto_version_t ei_hardware_version; 457c892ebf1Skrishna crypto_version_t ei_firmware_version; 458c892ebf1Skrishna uchar_t ei_time[CRYPTO_EXT_SIZE_TIME]; 4594df55fdeSJanie Lu int ei_hash_max_input_len; 4604df55fdeSJanie Lu int ei_hmac_max_input_len; 461c892ebf1Skrishna } crypto_provider_ext_info_t; 462c892ebf1Skrishna 4637c478bd9Sstevel@tonic-gate typedef uint_t crypto_session_id_t; 4647c478bd9Sstevel@tonic-gate 46523c57df7Smcpowers typedef enum cmd_type { 46623c57df7Smcpowers COPY_FROM_DATA, 46723c57df7Smcpowers COPY_TO_DATA, 46823c57df7Smcpowers COMPARE_TO_DATA, 46923c57df7Smcpowers MD5_DIGEST_DATA, 47023c57df7Smcpowers SHA1_DIGEST_DATA, 471e8c016efSMark Powers SHA2_DIGEST_DATA, 472e8c016efSMark Powers GHASH_DATA 47323c57df7Smcpowers } cmd_type_t; 47423c57df7Smcpowers 47523c57df7Smcpowers #define CRYPTO_DO_UPDATE 0x01 47623c57df7Smcpowers #define CRYPTO_DO_FINAL 0x02 47723c57df7Smcpowers #define CRYPTO_DO_MD5 0x04 47823c57df7Smcpowers #define CRYPTO_DO_SHA1 0x08 47923c57df7Smcpowers #define CRYPTO_DO_SIGN 0x10 48023c57df7Smcpowers #define CRYPTO_DO_VERIFY 0x20 48123c57df7Smcpowers #define CRYPTO_DO_SHA2 0x40 48223c57df7Smcpowers 48323c57df7Smcpowers #define PROVIDER_OWNS_KEY_SCHEDULE 0x00000001 48423c57df7Smcpowers 4857c478bd9Sstevel@tonic-gate /* 4867c478bd9Sstevel@tonic-gate * Common cryptographic status and error codes. 4877c478bd9Sstevel@tonic-gate */ 4887c478bd9Sstevel@tonic-gate #define CRYPTO_SUCCESS 0x00000000 4897c478bd9Sstevel@tonic-gate #define CRYPTO_CANCEL 0x00000001 4907c478bd9Sstevel@tonic-gate #define CRYPTO_HOST_MEMORY 0x00000002 4917c478bd9Sstevel@tonic-gate #define CRYPTO_GENERAL_ERROR 0x00000003 4927c478bd9Sstevel@tonic-gate #define CRYPTO_FAILED 0x00000004 4937c478bd9Sstevel@tonic-gate #define CRYPTO_ARGUMENTS_BAD 0x00000005 4947c478bd9Sstevel@tonic-gate #define CRYPTO_ATTRIBUTE_READ_ONLY 0x00000006 4957c478bd9Sstevel@tonic-gate #define CRYPTO_ATTRIBUTE_SENSITIVE 0x00000007 4967c478bd9Sstevel@tonic-gate #define CRYPTO_ATTRIBUTE_TYPE_INVALID 0x00000008 4977c478bd9Sstevel@tonic-gate #define CRYPTO_ATTRIBUTE_VALUE_INVALID 0x00000009 4987c478bd9Sstevel@tonic-gate #define CRYPTO_CANCELED 0x0000000A 4997c478bd9Sstevel@tonic-gate #define CRYPTO_DATA_INVALID 0x0000000B 5007c478bd9Sstevel@tonic-gate #define CRYPTO_DATA_LEN_RANGE 0x0000000C 5017c478bd9Sstevel@tonic-gate #define CRYPTO_DEVICE_ERROR 0x0000000D 5027c478bd9Sstevel@tonic-gate #define CRYPTO_DEVICE_MEMORY 0x0000000E 5037c478bd9Sstevel@tonic-gate #define CRYPTO_DEVICE_REMOVED 0x0000000F 5047c478bd9Sstevel@tonic-gate #define CRYPTO_ENCRYPTED_DATA_INVALID 0x00000010 5057c478bd9Sstevel@tonic-gate #define CRYPTO_ENCRYPTED_DATA_LEN_RANGE 0x00000011 5067c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_HANDLE_INVALID 0x00000012 5077c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_SIZE_RANGE 0x00000013 5087c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_TYPE_INCONSISTENT 0x00000014 5097c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_NOT_NEEDED 0x00000015 5107c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_CHANGED 0x00000016 5117c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_NEEDED 0x00000017 5127c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_INDIGESTIBLE 0x00000018 5137c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_FUNCTION_NOT_PERMITTED 0x00000019 5147c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_NOT_WRAPPABLE 0x0000001A 5157c478bd9Sstevel@tonic-gate #define CRYPTO_KEY_UNEXTRACTABLE 0x0000001B 5167c478bd9Sstevel@tonic-gate #define CRYPTO_MECHANISM_INVALID 0x0000001C 5177c478bd9Sstevel@tonic-gate #define CRYPTO_MECHANISM_PARAM_INVALID 0x0000001D 5187c478bd9Sstevel@tonic-gate #define CRYPTO_OBJECT_HANDLE_INVALID 0x0000001E 5197c478bd9Sstevel@tonic-gate #define CRYPTO_OPERATION_IS_ACTIVE 0x0000001F 5207c478bd9Sstevel@tonic-gate #define CRYPTO_OPERATION_NOT_INITIALIZED 0x00000020 5217c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_INCORRECT 0x00000021 5227c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_INVALID 0x00000022 5237c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_LEN_RANGE 0x00000023 5247c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_EXPIRED 0x00000024 5257c478bd9Sstevel@tonic-gate #define CRYPTO_PIN_LOCKED 0x00000025 5267c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_CLOSED 0x00000026 5277c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_COUNT 0x00000027 5287c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_HANDLE_INVALID 0x00000028 5297c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_READ_ONLY 0x00000029 5307c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_EXISTS 0x0000002A 5317c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_READ_ONLY_EXISTS 0x0000002B 5327c478bd9Sstevel@tonic-gate #define CRYPTO_SESSION_READ_WRITE_SO_EXISTS 0x0000002C 5337c478bd9Sstevel@tonic-gate #define CRYPTO_SIGNATURE_INVALID 0x0000002D 5347c478bd9Sstevel@tonic-gate #define CRYPTO_SIGNATURE_LEN_RANGE 0x0000002E 5357c478bd9Sstevel@tonic-gate #define CRYPTO_TEMPLATE_INCOMPLETE 0x0000002F 5367c478bd9Sstevel@tonic-gate #define CRYPTO_TEMPLATE_INCONSISTENT 0x00000030 5377c478bd9Sstevel@tonic-gate #define CRYPTO_UNWRAPPING_KEY_HANDLE_INVALID 0x00000031 5387c478bd9Sstevel@tonic-gate #define CRYPTO_UNWRAPPING_KEY_SIZE_RANGE 0x00000032 5397c478bd9Sstevel@tonic-gate #define CRYPTO_UNWRAPPING_KEY_TYPE_INCONSISTENT 0x00000033 5407c478bd9Sstevel@tonic-gate #define CRYPTO_USER_ALREADY_LOGGED_IN 0x00000034 5417c478bd9Sstevel@tonic-gate #define CRYPTO_USER_NOT_LOGGED_IN 0x00000035 5427c478bd9Sstevel@tonic-gate #define CRYPTO_USER_PIN_NOT_INITIALIZED 0x00000036 5437c478bd9Sstevel@tonic-gate #define CRYPTO_USER_TYPE_INVALID 0x00000037 5447c478bd9Sstevel@tonic-gate #define CRYPTO_USER_ANOTHER_ALREADY_LOGGED_IN 0x00000038 5457c478bd9Sstevel@tonic-gate #define CRYPTO_USER_TOO_MANY_TYPES 0x00000039 5467c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPED_KEY_INVALID 0x0000003A 5477c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPED_KEY_LEN_RANGE 0x0000003B 5487c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPING_KEY_HANDLE_INVALID 0x0000003C 5497c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPING_KEY_SIZE_RANGE 0x0000003D 5507c478bd9Sstevel@tonic-gate #define CRYPTO_WRAPPING_KEY_TYPE_INCONSISTENT 0x0000003E 5517c478bd9Sstevel@tonic-gate #define CRYPTO_RANDOM_SEED_NOT_SUPPORTED 0x0000003F 5527c478bd9Sstevel@tonic-gate #define CRYPTO_RANDOM_NO_RNG 0x00000040 5537c478bd9Sstevel@tonic-gate #define CRYPTO_DOMAIN_PARAMS_INVALID 0x00000041 5547c478bd9Sstevel@tonic-gate #define CRYPTO_BUFFER_TOO_SMALL 0x00000042 5557c478bd9Sstevel@tonic-gate #define CRYPTO_INFORMATION_SENSITIVE 0x00000043 5567c478bd9Sstevel@tonic-gate #define CRYPTO_NOT_SUPPORTED 0x00000044 5577c478bd9Sstevel@tonic-gate 5587c478bd9Sstevel@tonic-gate #define CRYPTO_QUEUED 0x00000045 5597c478bd9Sstevel@tonic-gate #define CRYPTO_BUFFER_TOO_BIG 0x00000046 5607c478bd9Sstevel@tonic-gate #define CRYPTO_INVALID_CONTEXT 0x00000047 5617c478bd9Sstevel@tonic-gate #define CRYPTO_INVALID_MAC 0x00000048 5627c478bd9Sstevel@tonic-gate #define CRYPTO_MECH_NOT_SUPPORTED 0x00000049 5637c478bd9Sstevel@tonic-gate #define CRYPTO_INCONSISTENT_ATTRIBUTE 0x0000004A 5647c478bd9Sstevel@tonic-gate #define CRYPTO_NO_PERMISSION 0x0000004B 5657c478bd9Sstevel@tonic-gate #define CRYPTO_INVALID_PROVIDER_ID 0x0000004C 5667c478bd9Sstevel@tonic-gate #define CRYPTO_VERSION_MISMATCH 0x0000004D 5677c478bd9Sstevel@tonic-gate #define CRYPTO_BUSY 0x0000004E 5687c478bd9Sstevel@tonic-gate #define CRYPTO_UNKNOWN_PROVIDER 0x0000004F 5697c478bd9Sstevel@tonic-gate #define CRYPTO_MODVERIFICATION_FAILED 0x00000050 5707c478bd9Sstevel@tonic-gate #define CRYPTO_OLD_CTX_TEMPLATE 0x00000051 5717c478bd9Sstevel@tonic-gate #define CRYPTO_WEAK_KEY 0x00000052 57273556491SAnthony Scarpino #define CRYPTO_FIPS140_ERROR 0x00000053 573*e8ab7b17SZdenek Kotala /* 574*e8ab7b17SZdenek Kotala * Don't forget to update CRYPTO_LAST_ERROR and the error_number_table[] 575*e8ab7b17SZdenek Kotala * in kernelUtil.c when new error code is added. 576*e8ab7b17SZdenek Kotala */ 577*e8ab7b17SZdenek Kotala #define CRYPTO_LAST_ERROR 0x00000053 5787c478bd9Sstevel@tonic-gate 5797c478bd9Sstevel@tonic-gate /* 5807c478bd9Sstevel@tonic-gate * Special values that can be used to indicate that information is unavailable 5817c478bd9Sstevel@tonic-gate * or that there is not practical limit. These values can be used 5827c478bd9Sstevel@tonic-gate * by fields of the SPI crypto_provider_ext_info(9S) structure. 5837c478bd9Sstevel@tonic-gate * The value of CRYPTO_UNAVAILABLE_INFO should be the same as 5847c478bd9Sstevel@tonic-gate * CK_UNAVAILABLE_INFO in the PKCS#11 spec. 5857c478bd9Sstevel@tonic-gate */ 5867c478bd9Sstevel@tonic-gate #define CRYPTO_UNAVAILABLE_INFO ((ulong_t)(-1)) 5877c478bd9Sstevel@tonic-gate #define CRYPTO_EFFECTIVELY_INFINITE 0x0 5887c478bd9Sstevel@tonic-gate 5897c478bd9Sstevel@tonic-gate #ifdef __cplusplus 5907c478bd9Sstevel@tonic-gate } 5917c478bd9Sstevel@tonic-gate #endif 5927c478bd9Sstevel@tonic-gate 5937c478bd9Sstevel@tonic-gate #endif /* _SYS_CRYPTO_COMMON_H */ 594