linux/include/net/sctp/auth.h
<<
>>
Prefs
   1/* SCTP kernel implementation
   2 * (C) Copyright 2007 Hewlett-Packard Development Company, L.P.
   3 *
   4 * This file is part of the SCTP kernel implementation
   5 *
   6 * This SCTP implementation is free software;
   7 * you can redistribute it and/or modify it under the terms of
   8 * the GNU General Public License as published by
   9 * the Free Software Foundation; either version 2, or (at your option)
  10 * any later version.
  11 *
  12 * This SCTP implementation is distributed in the hope that it
  13 * will be useful, but WITHOUT ANY WARRANTY; without even the implied
  14 *                 ************************
  15 * warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
  16 * See the GNU General Public License for more details.
  17 *
  18 * You should have received a copy of the GNU General Public License
  19 * along with GNU CC; see the file COPYING.  If not, see
  20 * <http://www.gnu.org/licenses/>.
  21 *
  22 * Please send any bug reports or fixes you make to the
  23 * email address(es):
  24 *    lksctp developers <linux-sctp@vger.kernel.org>
  25 *
  26 * Written or modified by:
  27 *   Vlad Yasevich     <vladislav.yasevich@hp.com>
  28 */
  29
  30#ifndef __sctp_auth_h__
  31#define __sctp_auth_h__
  32
  33#include <linux/list.h>
  34#include <linux/refcount.h>
  35
  36struct sctp_endpoint;
  37struct sctp_association;
  38struct sctp_authkey;
  39struct sctp_hmacalgo;
  40struct crypto_shash;
  41
  42/*
  43 * Define a generic struct that will hold all the info
  44 * necessary for an HMAC transform
  45 */
  46struct sctp_hmac {
  47        __u16 hmac_id;          /* one of the above ids */
  48        char *hmac_name;        /* name for loading */
  49        __u16 hmac_len;         /* length of the signature */
  50};
  51
  52/* This is generic structure that containst authentication bytes used
  53 * as keying material.  It's a what is referred to as byte-vector all
  54 * over SCTP-AUTH
  55 */
  56struct sctp_auth_bytes {
  57        refcount_t refcnt;
  58        __u32 len;
  59        __u8  data[];
  60};
  61
  62/* Definition for a shared key, weather endpoint or association */
  63struct sctp_shared_key {
  64        struct list_head key_list;
  65        __u16 key_id;
  66        struct sctp_auth_bytes *key;
  67};
  68
  69#define key_for_each(__key, __list_head) \
  70        list_for_each_entry(__key, __list_head, key_list)
  71
  72#define key_for_each_safe(__key, __tmp, __list_head) \
  73        list_for_each_entry_safe(__key, __tmp, __list_head, key_list)
  74
  75static inline void sctp_auth_key_hold(struct sctp_auth_bytes *key)
  76{
  77        if (!key)
  78                return;
  79
  80        refcount_inc(&key->refcnt);
  81}
  82
  83void sctp_auth_key_put(struct sctp_auth_bytes *key);
  84struct sctp_shared_key *sctp_auth_shkey_create(__u16 key_id, gfp_t gfp);
  85void sctp_auth_destroy_keys(struct list_head *keys);
  86int sctp_auth_asoc_init_active_key(struct sctp_association *asoc, gfp_t gfp);
  87struct sctp_shared_key *sctp_auth_get_shkey(
  88                                const struct sctp_association *asoc,
  89                                __u16 key_id);
  90int sctp_auth_asoc_copy_shkeys(const struct sctp_endpoint *ep,
  91                                struct sctp_association *asoc,
  92                                gfp_t gfp);
  93int sctp_auth_init_hmacs(struct sctp_endpoint *ep, gfp_t gfp);
  94void sctp_auth_destroy_hmacs(struct crypto_shash *auth_hmacs[]);
  95struct sctp_hmac *sctp_auth_get_hmac(__u16 hmac_id);
  96struct sctp_hmac *sctp_auth_asoc_get_hmac(const struct sctp_association *asoc);
  97void sctp_auth_asoc_set_default_hmac(struct sctp_association *asoc,
  98                                     struct sctp_hmac_algo_param *hmacs);
  99int sctp_auth_asoc_verify_hmac_id(const struct sctp_association *asoc,
 100                                    __be16 hmac_id);
 101int sctp_auth_send_cid(enum sctp_cid chunk,
 102                       const struct sctp_association *asoc);
 103int sctp_auth_recv_cid(enum sctp_cid chunk,
 104                       const struct sctp_association *asoc);
 105void sctp_auth_calculate_hmac(const struct sctp_association *asoc,
 106                            struct sk_buff *skb,
 107                            struct sctp_auth_chunk *auth, gfp_t gfp);
 108
 109/* API Helpers */
 110int sctp_auth_ep_add_chunkid(struct sctp_endpoint *ep, __u8 chunk_id);
 111int sctp_auth_ep_set_hmacs(struct sctp_endpoint *ep,
 112                            struct sctp_hmacalgo *hmacs);
 113int sctp_auth_set_key(struct sctp_endpoint *ep,
 114                      struct sctp_association *asoc,
 115                      struct sctp_authkey *auth_key);
 116int sctp_auth_set_active_key(struct sctp_endpoint *ep,
 117                      struct sctp_association *asoc,
 118                      __u16 key_id);
 119int sctp_auth_del_key_id(struct sctp_endpoint *ep,
 120                      struct sctp_association *asoc,
 121                      __u16 key_id);
 122
 123#endif
 124