blob: 170fd4470b0fa6e40025ec9114b67e8f08d7d6ad [file] [log] [blame]
djm@openbsd.org59d01f12020-01-25 23:13:09 +00001/* $OpenBSD: sk-api.h,v 1.8 2020/01/25 23:13:09 djm Exp $ */
djm@openbsd.orged3467c2019-10-31 21:16:20 +00002/*
3 * Copyright (c) 2019 Google LLC
4 *
5 * Permission to use, copy, modify, and distribute this software for any
6 * purpose with or without fee is hereby granted, provided that the above
7 * copyright notice and this permission notice appear in all copies.
8 *
9 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
10 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
11 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
12 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
13 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
14 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
16 */
17
18#ifndef _SK_API_H
19#define _SK_API_H 1
20
21#include <stddef.h>
Darren Tucker03ffc092019-11-02 23:25:01 +110022#ifdef HAVE_STDINT_H
djm@openbsd.orged3467c2019-10-31 21:16:20 +000023#include <stdint.h>
Darren Tucker03ffc092019-11-02 23:25:01 +110024#endif
djm@openbsd.orged3467c2019-10-31 21:16:20 +000025
26/* Flags */
27#define SSH_SK_USER_PRESENCE_REQD 0x01
djm@openbsd.org4532bd02019-12-30 09:19:52 +000028#define SSH_SK_USER_VERIFICATION_REQD 0x04
29#define SSH_SK_RESIDENT_KEY 0x20
djm@openbsd.orged3467c2019-10-31 21:16:20 +000030
markus@openbsd.orgfd1a3b52019-11-12 19:32:30 +000031/* Algs */
32#define SSH_SK_ECDSA 0x00
33#define SSH_SK_ED25519 0x01
34
djm@openbsd.org43ce9642019-12-30 09:24:45 +000035/* Error codes */
36#define SSH_SK_ERR_GENERAL -1
37#define SSH_SK_ERR_UNSUPPORTED -2
38#define SSH_SK_ERR_PIN_REQUIRED -3
djm@openbsd.org59d01f12020-01-25 23:13:09 +000039#define SSH_SK_ERR_DEVICE_NOT_FOUND -4
djm@openbsd.org43ce9642019-12-30 09:24:45 +000040
djm@openbsd.orged3467c2019-10-31 21:16:20 +000041struct sk_enroll_response {
42 uint8_t *public_key;
43 size_t public_key_len;
44 uint8_t *key_handle;
45 size_t key_handle_len;
46 uint8_t *signature;
47 size_t signature_len;
48 uint8_t *attestation_cert;
49 size_t attestation_cert_len;
50};
51
52struct sk_sign_response {
53 uint8_t flags;
54 uint32_t counter;
55 uint8_t *sig_r;
56 size_t sig_r_len;
57 uint8_t *sig_s;
58 size_t sig_s_len;
59};
60
djm@openbsd.org14cea362019-12-30 09:21:16 +000061struct sk_resident_key {
djm@openbsd.orgc312ca02020-01-06 02:00:46 +000062 uint32_t alg;
djm@openbsd.org14cea362019-12-30 09:21:16 +000063 size_t slot;
64 char *application;
65 struct sk_enroll_response key;
66};
67
djm@openbsd.orgc312ca02020-01-06 02:00:46 +000068struct sk_option {
69 char *name;
70 char *value;
71 uint8_t required;
72};
73
74#define SSH_SK_VERSION_MAJOR 0x00040000 /* current API version */
djm@openbsd.orged3467c2019-10-31 21:16:20 +000075#define SSH_SK_VERSION_MAJOR_MASK 0xffff0000
76
77/* Return the version of the middleware API */
78uint32_t sk_api_version(void);
79
80/* Enroll a U2F key (private key generation) */
djm@openbsd.orgc312ca02020-01-06 02:00:46 +000081int sk_enroll(uint32_t alg, const uint8_t *challenge, size_t challenge_len,
djm@openbsd.orgc54cd182019-12-30 09:23:28 +000082 const char *application, uint8_t flags, const char *pin,
djm@openbsd.orgc312ca02020-01-06 02:00:46 +000083 struct sk_option **options, struct sk_enroll_response **enroll_response);
djm@openbsd.orged3467c2019-10-31 21:16:20 +000084
85/* Sign a challenge */
djm@openbsd.orgc312ca02020-01-06 02:00:46 +000086int sk_sign(uint32_t alg, const uint8_t *message, size_t message_len,
djm@openbsd.orged3467c2019-10-31 21:16:20 +000087 const char *application, const uint8_t *key_handle, size_t key_handle_len,
djm@openbsd.orgc312ca02020-01-06 02:00:46 +000088 uint8_t flags, const char *pin, struct sk_option **options,
89 struct sk_sign_response **sign_response);
djm@openbsd.orged3467c2019-10-31 21:16:20 +000090
djm@openbsd.org14cea362019-12-30 09:21:16 +000091/* Enumerate all resident keys */
djm@openbsd.orgc312ca02020-01-06 02:00:46 +000092int sk_load_resident_keys(const char *pin, struct sk_option **options,
djm@openbsd.org14cea362019-12-30 09:21:16 +000093 struct sk_resident_key ***rks, size_t *nrks);
94
djm@openbsd.orged3467c2019-10-31 21:16:20 +000095#endif /* _SK_API_H */