blob: 5a8fa07003286ad5e92cfd4ce019376b11c441d4 [file] [log] [blame]
Brian Carlstromb9a07c12011-04-11 09:03:51 -07001/*
2 * Copyright (C) 2011 The Android Open Source Project
3 *
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
7 *
8 * http://www.apache.org/licenses/LICENSE-2.0
9 *
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License.
15 */
16package android.security;
17
Robin Leeabaa0692017-02-20 20:54:22 +000018import android.content.pm.StringParceledListSlice;
Eran Messeria1730642017-12-11 17:48:47 +000019import android.security.keymaster.KeymasterCertificateChain;
Eran Messeri852c8f12017-11-15 05:55:52 +000020import android.security.keystore.ParcelableKeyGenParameterSpec;
Zoltan Szatmary-Banf0ae1352014-08-18 10:48:33 +010021
Brian Carlstromb9a07c12011-04-11 09:03:51 -070022/**
23 * Caller is required to ensure that {@link KeyStore#unlock
24 * KeyStore.unlock} was successful.
25 *
26 * @hide
27 */
28interface IKeyChainService {
Brian Carlstrom2627d532011-05-13 12:54:24 -070029 // APIs used by KeyChain
Kenny Root5423e682011-11-14 08:43:13 -080030 String requestPrivateKey(String alias);
Fred Quintanaab8b84a2011-07-13 14:55:39 -070031 byte[] getCertificate(String alias);
Rubin Xub4365912016-03-23 12:13:22 +000032 byte[] getCaCertificates(String alias);
Eran Messeri7039f412017-11-08 01:03:30 +000033 boolean isUserSelectable(String alias);
34 void setUserSelectable(String alias, boolean isUserSelectable);
Brian Carlstrom2627d532011-05-13 12:54:24 -070035
Eran Messeri852c8f12017-11-15 05:55:52 +000036 boolean generateKeyPair(in String algorithm, in ParcelableKeyGenParameterSpec spec);
Eran Messeri94d56762017-12-21 20:50:54 +000037 boolean attestKey(in String alias, in byte[] challenge, in int[] idAttestationFlags,
38 out KeymasterCertificateChain chain);
Eran Messeriecf0f222017-12-11 12:32:13 +000039 boolean setKeyPairCertificate(String alias, in byte[] userCert, in byte[] certChain);
Eran Messeri852c8f12017-11-15 05:55:52 +000040
Bartosz Fabianowski05dc9f72017-02-22 23:41:14 +010041 // APIs used by CertInstaller and DevicePolicyManager
42 String installCaCertificate(in byte[] caCertificate);
Brian Carlstrom2627d532011-05-13 12:54:24 -070043
Bernhard Bauer26408cc2014-09-08 14:07:31 +010044 // APIs used by DevicePolicyManager
Rubin Xub4365912016-03-23 12:13:22 +000045 boolean installKeyPair(in byte[] privateKey, in byte[] userCert, in byte[] certChain, String alias);
Robin Leefbc65642015-08-03 16:21:22 +010046 boolean removeKeyPair(String alias);
Bernhard Bauer26408cc2014-09-08 14:07:31 +010047
Brian Carlstrom2627d532011-05-13 12:54:24 -070048 // APIs used by Settings
Brian Carlstrom6da00332011-06-26 21:08:03 -070049 boolean deleteCaCertificate(String alias);
Brian Carlstrom2627d532011-05-13 12:54:24 -070050 boolean reset();
Robin Leeabaa0692017-02-20 20:54:22 +000051 StringParceledListSlice getUserCaAliases();
52 StringParceledListSlice getSystemCaAliases();
Zoltan Szatmary-Banf0ae1352014-08-18 10:48:33 +010053 boolean containsCaAlias(String alias);
54 byte[] getEncodedCaCertificate(String alias, boolean includeDeletedSystem);
55 List<String> getCaCertificateChainAliases(String rootAlias, boolean includeDeletedSystem);
Fred Quintanaab8b84a2011-07-13 14:55:39 -070056
57 // APIs used by KeyChainActivity
58 void setGrant(int uid, String alias, boolean value);
59 boolean hasGrant(int uid, String alias);
Brian Carlstromb9a07c12011-04-11 09:03:51 -070060}