Add support for PKCS#11 Version 3.0 and 3.1

This commit is contained in:
Tobias Frauenschläger
2026-01-23 16:15:57 +01:00
parent a6316114bd
commit ee16b9506f
4 changed files with 510 additions and 27 deletions
+2
View File
@@ -281,6 +281,8 @@ HAVE_INTEL_SPEEDUP
HAVE_MDK_RTX
HAVE_NETX_BSD
HAVE_PKCS7_RSA_RAW_SIGN_CALLBACK
HAVE_PKCS11_STATIC
HAVE_PKCS11_V3_STATIC
HAVE_POCO_LIB
HAVE_RTP_SYS
HAVE_SECURE_GETENV
+224 -25
View File
@@ -432,7 +432,7 @@ static void pkcs11_val(const char* op, CK_ULONG val)
*/
int wc_Pkcs11_Initialize(Pkcs11Dev* dev, const char* library, void* heap)
{
return wc_Pkcs11_Initialize_ex(dev, library, heap, NULL);
return wc_Pkcs11_Initialize_v3(dev, library, heap, NULL, NULL, NULL);
}
/**
@@ -451,52 +451,249 @@ int wc_Pkcs11_Initialize(Pkcs11Dev* dev, const char* library, void* heap)
*/
int wc_Pkcs11_Initialize_ex(Pkcs11Dev* dev, const char* library, void* heap,
CK_RV* rvp)
{
return wc_Pkcs11_Initialize_v3(dev, library, heap, NULL, NULL, rvp);
}
/**
* Load library, get function list and initialize PKCS#11.
*
* @param [in] dev Device object.
* @param [in] library Library name including path.
* @param [in] heap Heap hint.
* @param [in,out] version On in, desired version of interface.
* On out, actual obtained version of interface.
* @param [in] interfaceName Name of the interface to use.
* @param [out] rvp PKCS#11 return value. Last return value seen.
* May be NULL.
* @return BAD_FUNC_ARG when dev or library are NULL pointers.
* @return BAD_PATH_ERROR when dynamic library cannot be opened.
* @return WC_INIT_E when the initialization PKCS#11 fails.
* @return WC_HW_E when unable to get PKCS#11 function list.
* @return 0 on success.
*/
int wc_Pkcs11_Initialize_v3(Pkcs11Dev* dev, const char* library,
void* heap, int* version, const char* interfaceName, CK_RV* rvp)
{
int ret = 0;
CK_RV rv = CKR_OK;
#ifndef HAVE_PKCS11_STATIC
#if !defined(HAVE_PKCS11_STATIC) && !defined(HAVE_PKCS11_V3_STATIC)
void* func;
#endif
CK_C_INITIALIZE_ARGS args;
CK_VERSION_PTR version_ptr = NULL;
if (dev == NULL || library == NULL)
ret = BAD_FUNC_ARG;
if (ret == 0) {
dev->heap = heap;
#ifndef HAVE_PKCS11_STATIC
#if defined(HAVE_PKCS11_V3_STATIC)
CK_INTERFACE_PTR interface = NULL;
CK_VERSION pkcs11_version = {0, 0};
if (version != NULL) {
if (*version == WC_PCKS11VERSION_2_20) {
pkcs11_version.major = 2;
pkcs11_version.minor = 20;
}
else if (*version == WC_PCKS11VERSION_2_20) {
pkcs11_version.major = 2;
pkcs11_version.minor = 40;
}
else if (*version == WC_PCKS11VERSION_3_0) {
pkcs11_version.major = 3;
pkcs11_version.minor = 0;
}
else if (*version == WC_PCKS11VERSION_3_1) {
pkcs11_version.major = 3;
pkcs11_version.minor = 1;
}
version_ptr = &pkcs11_version;
}
else {
version_ptr = NULL;
}
rv = C_GetInterface((CK_UTF8CHAR_PTR) interfaceName, version_ptr,
&interface, 0);
if (rv == CKR_OK) {
dev->func = interface->pFunctionList;
version_ptr = (CK_VERSION_PTR) interface->pFunctionList;
if (version_ptr->major == 2 && version_ptr->minor == 20) {
dev->version = WC_PCKS11VERSION_2_20;
}
else if (version_ptr->major == 2 &&
version_ptr->minor == 40) {
dev->version = WC_PCKS11VERSION_2_40;
}
else if (version_ptr->major == 3 &&
version_ptr->minor == 0) {
dev->version = WC_PCKS11VERSION_3_0;
}
else if (version_ptr->major == 3 &&
version_ptr->minor == 1) {
dev->version = WC_PCKS11VERSION_3_1;
}
else {
WOLFSSL_MSG_EX("Unsupported PKCS#11 version: %d.%d",
version_ptr->major, version_ptr->minor);
ret = WC_HW_E;
}
}
else {
PKCS11_RV("CK_C_GetInterface", rv);
ret = WC_HW_E;
}
#elif defined(HAVE_PKCS11_STATIC)
rv = C_GetFunctionList(&dev->func);
if (rv == CKR_OK) {
version_ptr = (CK_VERSION_PTR) dev->func;
if (version_ptr->major == 2 &&
version_ptr->minor == 20) {
dev->version = WC_PCKS11VERSION_2_20;
}
else if (version_ptr->major == 2 &&
version_ptr->minor == 40) {
dev->version = WC_PCKS11VERSION_2_40;
}
else {
WOLFSSL_MSG_EX("Unsupported PKCS#11 version: %d.%d",
version_ptr->major,
version_ptr->minor);
ret = WC_HW_E;
}
}
else {
PKCS11_RV("CK_C_GetFunctionList", rv);
ret = WC_HW_E;
}
#else
/* Load dynamic library */
dev->dlHandle = dlopen(library, RTLD_NOW | RTLD_LOCAL);
if (dev->dlHandle == NULL) {
WOLFSSL_MSG(dlerror());
ret = BAD_PATH_ERROR;
}
if (ret == 0) {
/* Check if the library supports PKCS#11 version 3.0 (or above) by
* looking for the C_GetInterface method (only present for >= V3.0).
*/
func = dlsym(dev->dlHandle, "C_GetInterface");
if (func != NULL) {
/* Function is present, use it */
CK_INTERFACE_PTR interface = NULL;
CK_VERSION pkcs11_version = {0, 0};
if (version != NULL) {
if (*version == WC_PCKS11VERSION_2_20) {
pkcs11_version.major = 2;
pkcs11_version.minor = 20;
}
else if (*version == WC_PCKS11VERSION_2_40) {
pkcs11_version.major = 2;
pkcs11_version.minor = 40;
}
else if (*version == WC_PCKS11VERSION_3_0) {
pkcs11_version.major = 3;
pkcs11_version.minor = 0;
}
else if (*version == WC_PCKS11VERSION_3_1) {
pkcs11_version.major = 3;
pkcs11_version.minor = 1;
}
version_ptr = &pkcs11_version;
}
else {
version_ptr = NULL;
}
rv = ((CK_C_GetInterface)func)((CK_UTF8CHAR_PTR) interfaceName,
version_ptr, &interface, 0);
if (rv == CKR_OK) {
dev->func = interface->pFunctionList;
version_ptr = (CK_VERSION_PTR) interface->pFunctionList;
if (version_ptr->major == 2 && version_ptr->minor == 20) {
dev->version = WC_PCKS11VERSION_2_20;
}
else if (version_ptr->major == 2 &&
version_ptr->minor == 40) {
dev->version = WC_PCKS11VERSION_2_40;
}
else if (version_ptr->major == 3 &&
version_ptr->minor == 0) {
dev->version = WC_PCKS11VERSION_3_0;
}
else if (version_ptr->major == 3 &&
version_ptr->minor == 1) {
dev->version = WC_PCKS11VERSION_3_1;
}
else {
WOLFSSL_MSG_EX("Unsupported PKCS#11 version: %d.%d",
version_ptr->major, version_ptr->minor);
ret = WC_HW_E;
}
}
else {
PKCS11_RV("CK_C_GetInterface", rv);
ret = WC_HW_E;
}
}
else {
/* Function not present, try a 2.x library by looking for
* C_GetFunctionList. */
func = dlsym(dev->dlHandle, "C_GetFunctionList");
if (func == NULL) {
#if defined(_WIN32)
WOLFSSL_MSG_EX("GetProcAddress(): %d", GetLastError());
#else
WOLFSSL_MSG(dlerror());
#endif
ret = WC_HW_E;
}
if (ret == 0) {
rv = ((CK_C_GetFunctionList)func)(&dev->func);
if (rv == CKR_OK) {
version_ptr = (CK_VERSION_PTR) dev->func;
if (version_ptr->major == 2 &&
version_ptr->minor == 20) {
dev->version = WC_PCKS11VERSION_2_20;
}
else if (version_ptr->major == 2 &&
version_ptr->minor == 40) {
dev->version = WC_PCKS11VERSION_2_40;
}
else {
WOLFSSL_MSG_EX("Unsupported PKCS#11 version: %d.%d",
version_ptr->major,
version_ptr->minor);
ret = WC_HW_E;
}
}
else {
PKCS11_RV("CK_C_GetFunctionList", rv);
ret = WC_HW_E;
}
}
}
}
#endif
}
if (ret == 0) {
dev->func = NULL;
func = dlsym(dev->dlHandle, "C_GetFunctionList");
if (func == NULL) {
WOLFSSL_MSG(dlerror());
ret = WC_HW_E;
}
}
if (ret == 0) {
rv = ((CK_C_GetFunctionList)func)(&dev->func);
#else
rv = C_GetFunctionList(&dev->func);
#endif
if (rv != CKR_OK) {
PKCS11_RV("CK_C_GetFunctionList", ret);
ret = WC_HW_E;
}
}
if (ret == 0 && version != NULL)
*version = dev->version;
if (ret == 0) {
XMEMSET(&args, 0x00, sizeof(args));
args.flags = CKF_OS_LOCKING_OK;
rv = dev->func->C_Initialize(&args);
if (rv != CKR_OK) {
PKCS11_RV("C_Initialize", ret);
if (rv == CKR_CRYPTOKI_ALREADY_INITIALIZED) {
WOLFSSL_MSG("PKCS#11 already initialized");
rv = CKR_OK;
}
else if (rv != CKR_OK) {
PKCS11_RV("C_Initialize", rv);
ret = WC_INIT_E;
}
}
@@ -520,7 +717,7 @@ int wc_Pkcs11_Initialize_ex(Pkcs11Dev* dev, const char* library, void* heap,
void wc_Pkcs11_Finalize(Pkcs11Dev* dev)
{
if (dev != NULL
#ifndef HAVE_PKCS11_STATIC
#if !defined(HAVE_PKCS11_STATIC) && !defined(HAVE_PKCS11_V3_STATIC)
&& dev->dlHandle != NULL
#endif
) {
@@ -528,7 +725,7 @@ void wc_Pkcs11_Finalize(Pkcs11Dev* dev)
dev->func->C_Finalize(NULL);
dev->func = NULL;
}
#ifndef HAVE_PKCS11_STATIC
#if !defined(HAVE_PKCS11_STATIC) && !defined(HAVE_PKCS11_V3_STATIC)
dlclose(dev->dlHandle);
dev->dlHandle = NULL;
#endif
@@ -633,6 +830,7 @@ static int Pkcs11Token_Init(Pkcs11Token* token, Pkcs11Dev* dev, int slotId,
token->userPin = NULL_PTR;
token->userPinSz = 0;
token->userPinLogin = 0;
token->version = dev->version;
}
XFREE(slot, dev->heap, DYNAMIC_TYPE_TMP_BUFFER);
@@ -809,6 +1007,7 @@ static int Pkcs11OpenSession(Pkcs11Token* token, Pkcs11Session* session,
if (ret == 0) {
session->func = token->func;
session->slotId = token->slotId;
session->version = token->version;
}
return ret;
+272 -1
View File
@@ -184,6 +184,7 @@ extern "C" {
#define CKR_OK 0x00000000UL
#define CKR_MECHANISM_INVALID 0x00000070UL
#define CKR_SIGNATURE_INVALID 0x000000C0UL
#define CKR_CRYPTOKI_ALREADY_INITIALIZED 0x00000191UL
#define CKD_NULL 0x00000001UL
#define CKZ_DATA_SPECIFIED 0x00000001UL
@@ -386,13 +387,33 @@ typedef CK_RSA_PKCS_OAEP_PARAMS *CK_RSA_PKCS_OAEP_PARAMS_PTR;
/* Function list types. */
typedef struct CK_FUNCTION_LIST CK_FUNCTION_LIST;
typedef struct CK_FUNCTION_LIST_3_0 CK_FUNCTION_LIST_3_0;
typedef CK_FUNCTION_LIST* CK_FUNCTION_LIST_PTR;
typedef CK_FUNCTION_LIST_3_0* CK_FUNCTION_LIST_3_0_PTR;
typedef CK_FUNCTION_LIST_PTR* CK_FUNCTION_LIST_PTR_PTR;
typedef CK_FUNCTION_LIST_3_0_PTR* CK_FUNCTION_LIST_3_0_PTR_PTR;
typedef CK_RV (*CK_C_GetFunctionList)(CK_FUNCTION_LIST_PTR_PTR ppFunctionList);
#ifdef HAVE_PKCS11_STATIC
typedef struct CK_INTERFACE {
CK_UTF8CHAR_PTR pInterfaceName;
CK_VOID_PTR pFunctionList;
CK_FLAGS flags;
} CK_INTERFACE;
typedef CK_INTERFACE* CK_INTERFACE_PTR;
typedef CK_INTERFACE_PTR* CK_INTERFACE_PTR_PTR;
typedef CK_RV (*CK_C_GetInterface)(CK_UTF8CHAR_PTR pInterfaceName,
CK_VERSION_PTR pVersion, CK_INTERFACE_PTR_PTR ppInterface, CK_FLAGS flags);
#if defined(HAVE_PKCS11_STATIC)
CK_RV C_GetFunctionList(CK_FUNCTION_LIST_PTR_PTR ppFunctionList);
#elif defined(HAVE_PKCS11_V3_STATIC)
CK_RV C_GetInterface(CK_UTF8CHAR_PTR pInterfaceName, CK_VERSION_PTR pVersion,
CK_INTERFACE_PTR_PTR ppInterface, CK_FLAGS flags);
#endif
struct CK_FUNCTION_LIST {
@@ -578,6 +599,256 @@ struct CK_FUNCTION_LIST {
};
struct CK_FUNCTION_LIST_3_0 {
CK_VERSION version;
CK_RV (*C_Initialize)(CK_VOID_PTR pInitArgs);
CK_RV (*C_Finalize)(CK_VOID_PTR pReserved);
CK_RV (*C_GetInfo)(CK_INFO_PTR pInfo);
CK_RV (*C_GetFunctionList)(CK_FUNCTION_LIST_PTR_PTR ppFunctionList);
CK_RV (*C_GetSlotList)(CK_BBOOL tokenPresent, CK_SLOT_ID_PTR pSlotList,
CK_ULONG_PTR pulCount);
CK_RV (*C_GetSlotInfo)(CK_SLOT_ID slotID, CK_SLOT_INFO_PTR pInfo);
CK_RV (*C_GetTokenInfo)(CK_SLOT_ID slotID, CK_TOKEN_INFO_PTR pInfo);
CK_RV (*C_GetMechanismList)(CK_SLOT_ID slotID,
CK_MECHANISM_TYPE_PTR pMechanismList,
CK_ULONG_PTR pulCount);
CK_RV (*C_GetMechanismInfo)(CK_SLOT_ID slotID, CK_MECHANISM_TYPE type,
CK_MECHANISM_INFO_PTR pInfo);
CK_RV (*C_InitToken)(CK_SLOT_ID slotID, CK_UTF8CHAR_PTR pPin,
CK_ULONG ulPinLen, CK_UTF8CHAR_PTR pLabel);
CK_RV (*C_InitPIN)(CK_SESSION_HANDLE hSession, CK_UTF8CHAR_PTR pPin,
CK_ULONG ulPinLen);
CK_RV (*C_SetPIN)(CK_SESSION_HANDLE hSession, CK_UTF8CHAR_PTR pOldPin,
CK_ULONG ulOldLen, CK_UTF8CHAR_PTR pNewPin,
CK_ULONG ulNewLen);
CK_RV (*C_OpenSession)(CK_SLOT_ID slotID, CK_FLAGS flags,
CK_VOID_PTR pApplication, CK_NOTIFY Notify,
CK_SESSION_HANDLE_PTR phSession);
CK_RV (*C_CloseSession)(CK_SESSION_HANDLE hSession);
CK_RV (*C_CloseAllSessions)(CK_SLOT_ID slotID);
CK_RV (*C_GetSessionInfo)(CK_SESSION_HANDLE hSession,
CK_SESSION_INFO_PTR pInfo);
CK_RV (*C_GetOperationState)(CK_SESSION_HANDLE hSession,
CK_BYTE_PTR pOperationState,
CK_ULONG_PTR pulOperationStateLen);
CK_RV (*C_SetOperationState)(CK_SESSION_HANDLE hSession,
CK_BYTE_PTR pOperationState,
CK_ULONG ulOperationStateLen,
CK_OBJECT_HANDLE hEncryptionKey,
CK_OBJECT_HANDLE hAuthenticationKey);
CK_RV (*C_Login)(CK_SESSION_HANDLE hSession, CK_USER_TYPE userType,
CK_UTF8CHAR_PTR pPin, CK_ULONG ulPinLen);
CK_RV (*C_Logout)(CK_SESSION_HANDLE hSession);
CK_RV (*C_CreateObject)(CK_SESSION_HANDLE hSession,
CK_ATTRIBUTE_PTR pTemplate, CK_ULONG ulCount,
CK_OBJECT_HANDLE_PTR phObject);
CK_RV (*C_CopyObject)(CK_SESSION_HANDLE hSession, CK_OBJECT_HANDLE hObject,
CK_ATTRIBUTE_PTR pTemplate, CK_ULONG ulCount,
CK_OBJECT_HANDLE_PTR phNewObject);
CK_RV (*C_DestroyObject)(CK_SESSION_HANDLE hSession,
CK_OBJECT_HANDLE hObject);
CK_RV (*C_GetObjectSize)(CK_SESSION_HANDLE hSession,
CK_OBJECT_HANDLE hObject, CK_ULONG_PTR pulSize);
CK_RV (*C_GetAttributeValue)(CK_SESSION_HANDLE hSession,
CK_OBJECT_HANDLE hObject,
CK_ATTRIBUTE_PTR pTemplate, CK_ULONG ulCount);
CK_RV (*C_SetAttributeValue)(CK_SESSION_HANDLE hSession,
CK_OBJECT_HANDLE hObject,
CK_ATTRIBUTE_PTR pTemplate, CK_ULONG ulCount);
CK_RV (*C_FindObjectsInit)(CK_SESSION_HANDLE hSession,
CK_ATTRIBUTE_PTR pTemplate, CK_ULONG ulCount);
CK_RV (*C_FindObjects)(CK_SESSION_HANDLE hSession,
CK_OBJECT_HANDLE_PTR phObject,
CK_ULONG ulMaxObjectCount,
CK_ULONG_PTR pulObjectCount);
CK_RV (*C_FindObjectsFinal)(CK_SESSION_HANDLE hSession);
CK_RV (*C_EncryptInit)(CK_SESSION_HANDLE hSession,
CK_MECHANISM_PTR pMechanism, CK_OBJECT_HANDLE hKey);
CK_RV (*C_Encrypt)(CK_SESSION_HANDLE hSession, CK_BYTE_PTR pData,
CK_ULONG ulDataLen, CK_BYTE_PTR pEncryptedData,
CK_ULONG_PTR pulEncryptedDataLen);
CK_RV (*C_EncryptUpdate)(CK_SESSION_HANDLE hSession, CK_BYTE_PTR pPart,
CK_ULONG ulPartLen, CK_BYTE_PTR pEncryptedPart,
CK_ULONG_PTR pulEncryptedPartLen);
CK_RV (*C_EncryptFinal)(CK_SESSION_HANDLE hSession,
CK_BYTE_PTR pLastEncryptedPart,
CK_ULONG_PTR pulLastEncryptedPartLen);
CK_RV (*C_DecryptInit)(CK_SESSION_HANDLE hSession,
CK_MECHANISM_PTR pMechanism, CK_OBJECT_HANDLE hKey);
CK_RV (*C_Decrypt)(CK_SESSION_HANDLE hSession, CK_BYTE_PTR pEncryptedData,
CK_ULONG ulEncryptedDataLen, CK_BYTE_PTR pData,
CK_ULONG_PTR pulDataLen);
CK_RV (*C_DecryptUpdate)(CK_SESSION_HANDLE hSession,
CK_BYTE_PTR pEncryptedPart,
CK_ULONG ulEncryptedPartLen, CK_BYTE_PTR pPart,
CK_ULONG_PTR pulPartLen);
CK_RV (*C_DecryptFinal)(CK_SESSION_HANDLE hSession, CK_BYTE_PTR pLastPart,
CK_ULONG_PTR pulLastPartLen);
CK_RV (*C_DigestInit)(CK_SESSION_HANDLE hSession,
CK_MECHANISM_PTR pMechanism);
CK_RV (*C_Digest)(CK_SESSION_HANDLE hSession, CK_BYTE_PTR pData,
CK_ULONG ulDataLen, CK_BYTE_PTR pDigest,
CK_ULONG_PTR pulDigestLen);
CK_RV (*C_DigestUpdate)(CK_SESSION_HANDLE hSession, CK_BYTE_PTR pPart,
CK_ULONG ulPartLen);
CK_RV (*C_DigestKey)(CK_SESSION_HANDLE hSession, CK_OBJECT_HANDLE hKey);
CK_RV (*C_DigestFinal)(CK_SESSION_HANDLE hSession, CK_BYTE_PTR pDigest,
CK_ULONG_PTR pulDigestLen);
CK_RV (*C_SignInit)(CK_SESSION_HANDLE hSession, CK_MECHANISM_PTR pMechanism,
CK_OBJECT_HANDLE hKey);
CK_RV (*C_Sign)(CK_SESSION_HANDLE hSession, CK_BYTE_PTR pData,
CK_ULONG ulDataLen, CK_BYTE_PTR pSignature,
CK_ULONG_PTR pulSignatureLen);
CK_RV (*C_SignUpdate)(CK_SESSION_HANDLE hSession, CK_BYTE_PTR pPart,
CK_ULONG ulPartLen);
CK_RV (*C_SignFinal)(CK_SESSION_HANDLE hSession, CK_BYTE_PTR pSignature,
CK_ULONG_PTR pulSignatureLen);
CK_RV (*C_SignRecoverInit)(CK_SESSION_HANDLE hSession,
CK_MECHANISM_PTR pMechanism,
CK_OBJECT_HANDLE hKey);
CK_RV (*C_SignRecover)(CK_SESSION_HANDLE hSession, CK_BYTE_PTR pData,
CK_ULONG ulDataLen, CK_BYTE_PTR pSignature,
CK_ULONG_PTR pulSignatureLen);
CK_RV (*C_VerifyInit)(CK_SESSION_HANDLE hSession,
CK_MECHANISM_PTR pMechanism, CK_OBJECT_HANDLE hKey);
CK_RV (*C_Verify)(CK_SESSION_HANDLE hSession, CK_BYTE_PTR pData,
CK_ULONG ulDataLen, CK_BYTE_PTR pSignature,
CK_ULONG ulSignatureLen);
CK_RV (*C_VerifyUpdate)(CK_SESSION_HANDLE hSession, CK_BYTE_PTR pPart,
CK_ULONG ulPartLen);
CK_RV (*C_VerifyFinal)(CK_SESSION_HANDLE hSession,
CK_BYTE_PTR pSignature, CK_ULONG ulSignatureLen);
CK_RV (*C_VerifyRecoverInit)(CK_SESSION_HANDLE hSession,
CK_MECHANISM_PTR pMechanism,
CK_OBJECT_HANDLE hKey);
CK_RV (*C_VerifyRecover)(CK_SESSION_HANDLE hSession,
CK_BYTE_PTR pSignature, CK_ULONG ulSignatureLen,
CK_BYTE_PTR pData, CK_ULONG_PTR pulDataLen);
CK_RV (*C_DigestEncryptUpdate)(CK_SESSION_HANDLE hSession,
CK_BYTE_PTR pPart, CK_ULONG ulPartLen,
CK_BYTE_PTR pEncryptedPart,
CK_ULONG_PTR pulEncryptedPartLen);
CK_RV (*C_DecryptDigestUpdate)(CK_SESSION_HANDLE hSession,
CK_BYTE_PTR pEncryptedPart,
CK_ULONG ulEncryptedPartLen,
CK_BYTE_PTR pPart, CK_ULONG_PTR pulPartLen);
CK_RV (*C_SignEncryptUpdate)(CK_SESSION_HANDLE hSession,
CK_BYTE_PTR pPart, CK_ULONG ulPartLen,
CK_BYTE_PTR pEncryptedPart,
CK_ULONG_PTR pulEncryptedPartLen);
CK_RV (*C_DecryptVerifyUpdate)(CK_SESSION_HANDLE hSession,
CK_BYTE_PTR pEncryptedPart,
CK_ULONG ulEncryptedPartLen,
CK_BYTE_PTR pPart, CK_ULONG_PTR pulPartLen);
CK_RV (*C_GenerateKey)(CK_SESSION_HANDLE hSession,
CK_MECHANISM_PTR pMechanism,
CK_ATTRIBUTE_PTR pTemplate, CK_ULONG ulCount,
CK_OBJECT_HANDLE_PTR phKey);
CK_RV (*C_GenerateKeyPair)(CK_SESSION_HANDLE hSession,
CK_MECHANISM_PTR pMechanism,
CK_ATTRIBUTE_PTR pPublicKeyTemplate,
CK_ULONG ulPublicKeyAttributeCount,
CK_ATTRIBUTE_PTR pPrivateKeyTemplate,
CK_ULONG ulPrivateKeyAttributeCount,
CK_OBJECT_HANDLE_PTR phPublicKey,
CK_OBJECT_HANDLE_PTR phPrivateKey);
CK_RV (*C_WrapKey)(CK_SESSION_HANDLE hSession,
CK_MECHANISM_PTR pMechanism,
CK_OBJECT_HANDLE hWrappingKey, CK_OBJECT_HANDLE hKey,
CK_BYTE_PTR pWrappedKey,
CK_ULONG_PTR pulWrappedKeyLen);
CK_RV (*C_UnwrapKey)(CK_SESSION_HANDLE hSession,
CK_MECHANISM_PTR pMechanism,
CK_OBJECT_HANDLE hUnwrappingKey,
CK_BYTE_PTR pWrappedKey, CK_ULONG ulWrappedKeyLen,
CK_ATTRIBUTE_PTR pTemplate,
CK_ULONG ulAttributeCount,
CK_OBJECT_HANDLE_PTR phKey);
CK_RV (*C_DeriveKey)(CK_SESSION_HANDLE hSession,
CK_MECHANISM_PTR pMechanism,
CK_OBJECT_HANDLE hBaseKey,
CK_ATTRIBUTE_PTR pTemplate,
CK_ULONG ulAttributeCount,
CK_OBJECT_HANDLE_PTR phKey);
CK_RV (*C_SeedRandom)(CK_SESSION_HANDLE hSession, CK_BYTE_PTR pSeed,
CK_ULONG ulSeedLen);
CK_RV (*C_GenerateRandom)(CK_SESSION_HANDLE hSession,
CK_BYTE_PTR pRandomData, CK_ULONG ulRandomLen);
CK_RV (*C_GetFunctionStatus)(CK_SESSION_HANDLE hSession);
CK_RV (*C_CancelFunction)(CK_SESSION_HANDLE hSession);
CK_RV (*C_WaitForSlotEvent)(CK_FLAGS flags, CK_SLOT_ID_PTR pSlot,
CK_VOID_PTR pReserved);
/* PKCS#11 V 3.0 functions */
CK_RV (*C_GetInterfaceList)(CK_INTERFACE_PTR pInterfacesList,
CK_ULONG_PTR pulCount);
CK_RV (*C_GetInterface)(CK_UTF8CHAR_PTR pInterfaceName,
CK_VERSION_PTR pVersion,
CK_INTERFACE_PTR_PTR ppInterface,
CK_FLAGS flags);
CK_RV (*C_LoginUser)(CK_SESSION_HANDLE hSession, CK_USER_TYPE userType,
CK_UTF8CHAR_PTR pPin, CK_ULONG ulPinLen,
CK_UTF8CHAR_PTR pUsername, CK_ULONG ulUsernameLen);
CK_RV (*C_SessionCancel)(CK_SESSION_HANDLE hSession, CK_FLAGS flags);
CK_RV (*C_MessageEncryptInit)(CK_SESSION_HANDLE hSession,
CK_MECHANISM_PTR pMechanism,
CK_OBJECT_HANDLE hKey);
CK_RV (*C_EncryptMessage)(CK_SESSION_HANDLE hSession, CK_VOID_PTR pParameter,
CK_ULONG ulParameterLen, CK_BYTE_PTR pAssociatedData,
CK_ULONG ulAssociatedDataLen, CK_BYTE_PTR pPlaintext,
CK_ULONG ulPlaintextLen, CK_BYTE_PTR pCiphertext,
CK_ULONG_PTR pulCiphertextLen);
CK_RV (*C_EncryptMessageBegin)(CK_SESSION_HANDLE hSession, CK_VOID_PTR pParameter,
CK_ULONG ulParameterLen, CK_BYTE_PTR pAssociatedData,
CK_ULONG ulAssociatedDataLen);
CK_RV (*C_EncryptMessageNext)(CK_SESSION_HANDLE hSession, CK_VOID_PTR pParameter,
CK_ULONG ulParameterLen, CK_BYTE_PTR pPlaintextPart,
CK_ULONG ulPlaintextPartLen, CK_BYTE_PTR pCiphertextPart,
CK_ULONG_PTR pulCiphertextPartLen, CK_FLAGS flags);
CK_RV (*C_MessageEncryptFinal)(CK_SESSION_HANDLE hSession);
CK_RV (*C_MessageDecryptInit)(CK_SESSION_HANDLE hSession, CK_MECHANISM_PTR pMechanism,
CK_OBJECT_HANDLE hKey);
CK_RV (*C_DecryptMessage)(CK_SESSION_HANDLE hSession, CK_VOID_PTR pParameter,
CK_ULONG ulParameterLen, CK_BYTE_PTR pAssociatedData,
CK_ULONG ulAssociatedDataLen, CK_BYTE_PTR pCiphertext,
CK_ULONG ulCiphertextLen, CK_BYTE_PTR pPlaintext,
CK_ULONG_PTR pulPlaintextLen);
CK_RV (*C_DecryptMessageBegin)(CK_SESSION_HANDLE hSession, CK_VOID_PTR pParameter,
CK_ULONG ulParameterLen, CK_BYTE_PTR pAssociatedData,
CK_ULONG ulAssociatedDataLen);
CK_RV (*C_DecryptMessageNext)(CK_SESSION_HANDLE hSession, CK_VOID_PTR pParameter,
CK_ULONG ulParameterLen, CK_BYTE_PTR pCiphertextPart,
CK_ULONG ulCiphertextPartLen, CK_BYTE_PTR pPlaintextPart,
CK_ULONG_PTR pulPlaintextPartLen, CK_FLAGS flags);
CK_RV (*C_MessageDecryptFinal)(CK_SESSION_HANDLE hSession);
CK_RV (*C_MessageSignInit)(CK_SESSION_HANDLE hSession, CK_MECHANISM_PTR pMechanism,
CK_OBJECT_HANDLE hKey);
CK_RV (*C_SignMessage)(CK_SESSION_HANDLE hSession, CK_VOID_PTR pParameter,
CK_ULONG ulParameterLen, CK_BYTE_PTR pData,
CK_ULONG ulDataLen, CK_BYTE_PTR pSignature,
CK_ULONG_PTR pulSignatureLen);
CK_RV (*C_SignMessageBegin)(CK_SESSION_HANDLE hSession, CK_VOID_PTR pParameter,
CK_ULONG ulParameterLen);
CK_RV (*C_SignMessageNext)(CK_SESSION_HANDLE hSession, CK_VOID_PTR pParameter,
CK_ULONG ulParameterLen, CK_BYTE_PTR pData,
CK_ULONG ulDataLen, CK_BYTE_PTR pSignature,
CK_ULONG_PTR pulSignatureLen);
CK_RV (*C_MessageSignFinal)(CK_SESSION_HANDLE hSession);
CK_RV (*C_MessageVerifyInit)(CK_SESSION_HANDLE hSession, CK_MECHANISM_PTR pMechanism,
CK_OBJECT_HANDLE hKey);
CK_RV (*C_VerifyMessage)(CK_SESSION_HANDLE hSession, CK_VOID_PTR pParameter,
CK_ULONG ulParameterLen, CK_BYTE_PTR pData,
CK_ULONG ulDataLen, CK_BYTE_PTR pSignature,
CK_ULONG ulSignatureLen);
CK_RV (*C_VerifyMessageBegin)(CK_SESSION_HANDLE hSession, CK_VOID_PTR pParameter,
CK_ULONG ulParameterLen);
CK_RV (*C_VerifyMessageNext)(CK_SESSION_HANDLE hSession, CK_VOID_PTR pParameter,
CK_ULONG ulParameterLen, CK_BYTE_PTR pData,
CK_ULONG ulDataLen, CK_BYTE_PTR pSignature,
CK_ULONG ulSignatureLen);
CK_RV (*C_MessageVerifyFinal)(CK_SESSION_HANDLE hSession);
};
#ifdef __cplusplus
}
#endif
+12 -1
View File
@@ -37,13 +37,20 @@
extern "C" {
#endif
enum Pkcs11InterfaceVersionType {
WC_PCKS11VERSION_2_20,
WC_PCKS11VERSION_2_40,
WC_PCKS11VERSION_3_0,
WC_PCKS11VERSION_3_1,
};
typedef struct Pkcs11Dev {
#ifndef HAVE_PKCS11_STATIC
#if !defined(HAVE_PKCS11_STATIC) && !defined(HAVE_PKCS11_V3_STATIC)
void* dlHandle; /* Handle to library */
#endif
CK_FUNCTION_LIST* func; /* Array of functions */
void* heap;
int version; /* Pkcs11InterfaceVersionType */
} Pkcs11Dev;
typedef struct Pkcs11Token {
@@ -53,12 +60,14 @@ typedef struct Pkcs11Token {
CK_UTF8CHAR_PTR userPin; /* User's PIN to login with */
CK_ULONG userPinSz; /* Size of user's PIN in bytes */
byte userPinLogin:1; /* Login with User's PIN */
int version; /* Pkcs11InterfaceVersionType */
} Pkcs11Token;
typedef struct Pkcs11Session {
CK_FUNCTION_LIST* func; /* Table of PKCS#11 function from lib */
CK_SLOT_ID slotId; /* Id of slot to use */
CK_SESSION_HANDLE handle; /* Handle to active session */
int version; /* Pkcs11InterfaceVersionType */
} Pkcs11Session;
/* Types of keys that can be stored. */
@@ -74,6 +83,8 @@ WOLFSSL_API int wc_Pkcs11_Initialize(Pkcs11Dev* dev, const char* library,
void* heap);
WOLFSSL_API int wc_Pkcs11_Initialize_ex(Pkcs11Dev* dev, const char* library,
void* heap, CK_RV* rvp);
WOLFSSL_API int wc_Pkcs11_Initialize_v3(Pkcs11Dev* dev, const char* library,
void* heap, int* version, const char* interfaceName, CK_RV* rvp);
WOLFSSL_API void wc_Pkcs11_Finalize(Pkcs11Dev* dev);
WOLFSSL_API int wc_Pkcs11Token_Init(Pkcs11Token* token, Pkcs11Dev* dev,