VOMS CC API 1.5.0
Loading...
Searching...
No Matches
voms_api.h
Go to the documentation of this file.
1/*********************************************************************
2 *
3 * Authors: Vincenzo Ciaschini - Vincenzo.Ciaschini@cnaf.infn.it
4 *
5 * Copyright (c) Members of the EGEE Collaboration. 2004-2010.
6 * See http://www.eu-egee.org/partners/ for details on the copyright holders.
7 *
8 * Licensed under the Apache License, Version 2.0 (the "License");
9 * you may not use this file except in compliance with the License.
10 * You may obtain a copy of the License at
11 *
12 * http://www.apache.org/licenses/LICENSE-2.0
13 *
14 * Unless required by applicable law or agreed to in writing, software
15 * distributed under the License is distributed on an "AS IS" BASIS,
16 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
17 * See the License for the specific language governing permissions and
18 * limitations under the License.
19 *
20 * Parts of this code may be based upon or even include verbatim pieces,
21 * originally written by other people, in which case the original header
22 * follows.
23 *
24 *********************************************************************/
25
26#ifndef VOMS_API_H
27#define VOMS_API_H
28
29#include <fstream>
30#include <string>
31#include <vector>
32
33extern "C" {
34#ifndef GSSAPI_H_
35/*
36 * Also check against _GSSAPI_H_ as that is what the Kerberos 5 code defines and
37 * what header files on some systems look for.
38 */
39
40#ifndef _GSSAPI_H_
41typedef void * gss_cred_id_t;
42typedef void * gss_ctx_id_t;
43#endif
44#endif
45
46#include <openssl/x509.h>
47#include <openssl/bio.h>
48#include <sys/types.h>
49#include "newformat.h"
50}
51
54struct data {
55 std::string group;
56 std::string role;
57 std::string cap;
58};
59
62struct attribute {
63 std::string name;
64 std::string qualifier;
65 std::string value;
66};
67
69 std::string grantor;
70 std::vector<attribute> attributes;
71};
72
73
81
82struct contactdata {
86 std::string nick;
87 std::string host;
88 std::string contact;
89 std::string vo;
90 int port;
91
92 int version;
93};
94
95class vomspriv;
96
97struct voms {
98 friend class vomsdata;
99 int version;
100 int siglen;
101 std::string signature;
102 std::string user;
103 std::string userca;
104 std::string server;
105 std::string serverca;
106 std::string voname;
107 std::string uri;
108 std::string date1;
109 std::string date2;
111 std::vector<data> std;
112 std::string custom;
113 /* Data below this line only makes sense if version >= 1 */
114 std::vector<std::string> fqan;
115 std::string serial;
116 /* Data below this line is private. */
117
118private:
119 void *realdata;
120 X509 *holder;
121public:
122 voms(const voms &);
124 voms &operator=(const voms &);
126
127private:
128 struct vomsr *translate();
129 friend int TranslateVOMS(struct vomsdatar *vd, std::vector<voms>&v, int *error);
130
131public:
132 AC *GetAC();
133
134public:
135 std::vector<attributelist>& GetAttributes();
136 std::vector<std::string> GetTargets();
137
138private:
139 vomspriv *vp;
140};
141
147
149 VERIFY_FULL = 0xffffffff,
150 VERIFY_NONE = 0x00000000,
151 VERIFY_DATE = 0x00000001,
152 VERIFY_TARGET = 0x00000002,
153 VERIFY_KEY = 0x00000004,
154 VERIFY_SIGN = 0x00000008,
155 VERIFY_ORDER = 0x00000010,
156 VERIFY_ID = 0x00000020,
157 VERIFY_CERTLIST = 0x00000040
158};
159
188
189typedef bool (*check_sig)(X509 *, void *, verror_type &);
190
191class vomsdatapriv;
192
193struct vomsdata {
194 private:
195 class Initializer {
196 public:
197 Initializer();
198 private:
199 Initializer(Initializer &);
200 };
201
202 private:
203 static Initializer init;
204 std::string ca_cert_dir;
205 std::string voms_cert_dir;
206 int duration;
207 std::string ordering;
208 std::vector<contactdata> servers;
209 std::vector<std::string> targets;
210
211 public:
213
215
216 vomsdata(std::string voms_dir = "",
217 std::string cert_dir = "");
227
228 bool LoadSystemContacts(std::string dir = "");
235 bool LoadUserContacts(std::string dir = "");
244
245 std::vector<contactdata> FindByAlias(std::string alias);
251
252
253 std::vector<contactdata> FindByVO(std::string vo);
259
260
261 void Order(std::string att);
267
268 void ResetOrder(void);
269
270 void AddTarget(std::string target);
274
275 std::vector<std::string> ListTargets(void);
276
277 void ResetTargets(void);
278 std::string ServerErrors(void);
279
280 bool Retrieve(X509 *cert, STACK_OF(X509) *chain,
290 bool Contact(std::string hostname, int port,
291 std::string servsubject,
292 std::string command);
302 bool Contact(std::string hostname, int port,
303 std::string servsubject,
304 std::string command,
305 int timeout);
316
317 bool ContactRaw(std::string hostname, int port,
318 std::string servsubject,
319 std::string command,
320 std::string &raw,
321 int& version);
330 bool ContactRaw(std::string hostname, int port,
331 std::string servsubject,
332 std::string command,
333 std::string &raw,
334 int& version,
335 int timeout);
345
349
350 void SetLifetime(int lifetime);
353
354 bool Import(std::string buffer);
361 bool Export(std::string &data);
370
371 std::vector<voms> data;
374 std::string workvo;
375 std::string extra_data;
384private:
385 bool loadfile(std::string, uid_t uid, gid_t gid);
386 bool loadfile0(std::string, uid_t uid, gid_t gid);
387 bool verifydata(std::string &message, std::string subject, std::string ca,
388 X509 *holder, voms &v);
389 bool check_cert(X509 *cert);
390 bool retrieve(X509 *cert, STACK_OF(X509) *chain, recurse_type how,
391 AC_SEQ **listnew, std::string &subject, std::string &ca,
392 X509 **holder);
393 verify_type ver_type;
394
395 std::string serverrors;
396 std::string errmessage;
397
398 void seterror(verror_type, std::string);
399
400 bool check_sig_ac(X509 *, void *);
401 X509 *check(void *);
402 bool contact(const std::string&, int, const std::string&,
403 const std::string&, std::string&, std::string&,
404 std::string&, int timeout);
405 bool verifydata(AC *ac, const std::string& subject, const std::string& ca,
406 X509 *holder, voms &v);
407 bool evaluate(AC_SEQ *, const std::string&, const std::string&, X509*);
408
409public:
410
411 std::string ErrorMessage(void);
413
418
423
424 bool Retrieve(X509_EXTENSION *ext);
427
431
432 bool Retrieve(FILE *file, recurse_type how);
438
439 bool Retrieve(AC *ac);
442
444private:
445 // X509 *check_file(void *);
446 bool check_cert(STACK_OF(X509) *);
447 X509 *check_from_certs(AC *ac, const std::string& voname);
448 X509 *check_from_file(AC *, std::ifstream&, const std::string &vo, const std::string &filename);
449
450public:
452
453private:
454 int retry_count;
455
456public:
457 void SetRetryCount(int retryCount);
458
459public:
461
462private:
463 time_t verificationtime;
464 bool verifyac(X509 *, X509 *, AC*, time_t, voms&);
465
466public:
467 bool LoadCredentials(X509*, EVP_PKEY *, STACK_OF(X509) *);
468 bool ContactRESTRaw(const std::string&, int, const std::string&, std::string&, int, int);
469
470private:
471 bool InterpretOutput(const std::string&, std::string&);
472
473private:
474 vomsdatapriv *vdp;
475};
476
477
478extern "C" {
482}
483
484#endif
std::string value
Definition voms_api.h:65
std::string qualifier
Definition voms_api.h:64
std::string name
Definition voms_api.h:63
std::string grantor
Definition voms_api.h:69
std::vector< attribute > attributes
Definition voms_api.h:70
std::string host
Definition voms_api.h:87
std::string contact
Definition voms_api.h:88
std::string nick
Definition voms_api.h:86
std::string vo
Definition voms_api.h:89
int version
Definition voms_api.h:92
User's characteristics: can be repeated.Generic name-value attribute : can be repeated.
Definition voms_api.h:54
std::string group
Definition voms_api.h:55
std::string cap
Definition voms_api.h:57
std::string role
Definition voms_api.h:56
std::string date2
Definition voms_api.h:109
std::vector< std::string > fqan
Definition voms_api.h:114
friend class vomsdata
Definition voms_api.h:98
int version
Definition voms_api.h:99
std::string user
Definition voms_api.h:102
std::string voname
Definition voms_api.h:106
AC * GetAC()
int siglen
Definition voms_api.h:100
std::string signature
Definition voms_api.h:101
std::vector< attributelist > & GetAttributes()
std::string uri
Definition voms_api.h:107
std::string serial
Definition voms_api.h:115
std::string userca
Definition voms_api.h:103
std::string custom
Definition voms_api.h:112
friend int TranslateVOMS(struct vomsdatar *vd, std::vector< voms > &v, int *error)
voms(const voms &)
data_type type
Definition voms_api.h:110
std::string serverca
Definition voms_api.h:105
std::string date1
Definition voms_api.h:108
std::vector< std::string > GetTargets()
std::vector< data > std
Definition voms_api.h:111
voms & operator=(const voms &)
std::string server
Definition voms_api.h:104
bool Export(std::string &data)
std::vector< contactdata > FindByVO(std::string vo)
std::vector< contactdata > FindByAlias(std::string alias)
void ResetOrder(void)
void AddTarget(std::string target)
bool RetrieveFromCred(gss_cred_id_t credential, recurse_type how)
bool Import(std::string buffer)
bool Retrieve(FILE *file, recurse_type how)
void SetVerificationTime(time_t)
std::string ServerErrors(void)
void ResetTargets(void)
void SetVerificationType(verify_type how)
bool LoadUserContacts(std::string dir="")
bool Retrieve(X509_EXTENSION *ext)
bool ContactRaw(std::string hostname, int port, std::string servsubject, std::string command, std::string &raw, int &version, int timeout)
bool RetrieveFromCtx(gss_ctx_id_t context, recurse_type how)
bool LoadSystemContacts(std::string dir="")
bool Contact(std::string hostname, int port, std::string servsubject, std::string command, int timeout)
std::string ErrorMessage(void)
bool RetrieveFromProxy(recurse_type how)
bool ContactRESTRaw(const std::string &, int, const std::string &, std::string &, int, int)
vomsdata(std::string voms_dir="", std::string cert_dir="")
verror_type error
Definition voms_api.h:212
std::string workvo
Definition voms_api.h:374
std::vector< voms > data
Definition voms_api.h:371
bool ContactRaw(std::string hostname, int port, std::string servsubject, std::string command, std::string &raw, int &version)
bool Retrieve(AC *ac)
void SetLifetime(int lifetime)
std::string extra_data
Definition voms_api.h:375
static void SkipSslInitialization()
bool DefaultData(voms &)
bool LoadCredentials(X509 *, EVP_PKEY *, STACK_OF(X509) *)
void SetRetryCount(int retryCount)
bool Retrieve(X509 *cert, STACK_OF(X509) *chain, recurse_type how=RECURSE_CHAIN)
bool Contact(std::string hostname, int port, std::string servsubject, std::string command)
std::vector< std::string > ListTargets(void)
void Order(std::string att)
vomsdata(const vomsdata &)
recurse_type
Definition voms_api.h:142
@ RECURSE_NONE
Definition voms_api.h:144
@ RECURSE_DEEP
Definition voms_api.h:145
@ RECURSE_CHAIN
Definition voms_api.h:143
int getVOMSMinorVersionNumber(void)
int getVOMSPatchVersionNumber(void)
void * gss_cred_id_t
Definition voms_api.h:41
bool(* check_sig)(X509 *, void *, verror_type &)
Definition voms_api.h:189
void * gss_ctx_id_t
Definition voms_api.h:42
data_type
The type of data returned.
Definition voms_api.h:76
@ TYPE_CUSTOM
Definition voms_api.h:79
@ TYPE_NODATA
Definition voms_api.h:77
@ TYPE_STD
Definition voms_api.h:78
verify_type
Definition voms_api.h:148
@ VERIFY_SIGN
Definition voms_api.h:154
@ VERIFY_NONE
Definition voms_api.h:150
@ VERIFY_ORDER
Definition voms_api.h:155
@ VERIFY_KEY
Definition voms_api.h:153
@ VERIFY_FULL
Definition voms_api.h:149
@ VERIFY_CERTLIST
Definition voms_api.h:157
@ VERIFY_TARGET
Definition voms_api.h:152
@ VERIFY_ID
Definition voms_api.h:156
@ VERIFY_DATE
Definition voms_api.h:151
verror_type
Error codes.
Definition voms_api.h:162
@ VERR_PARAM
Definition voms_api.h:167
@ VERR_FILE
Definition voms_api.h:186
@ VERR_EXTRAINFO
Definition voms_api.h:172
@ VERR_NOINIT
Definition voms_api.h:169
@ VERR_NONE
Definition voms_api.h:163
@ VERR_NOSOCKET
Definition voms_api.h:164
@ VERR_FORMAT
Definition voms_api.h:173
@ VERR_NOEXT
Definition voms_api.h:168
@ VERR_IDCHECK
Definition voms_api.h:171
@ VERR_TIME
Definition voms_api.h:170
@ VERR_VERIFY
Definition voms_api.h:180
@ VERR_PARSE
Definition voms_api.h:175
@ VERR_ORDER
Definition voms_api.h:183
@ VERR_COMM
Definition voms_api.h:166
@ VERR_SERVERCODE
Definition voms_api.h:184
@ VERR_TYPE
Definition voms_api.h:182
@ VERR_NODATA
Definition voms_api.h:174
@ VERR_SIGN
Definition voms_api.h:177
@ VERR_MEM
Definition voms_api.h:179
@ VERR_NOTAVAIL
Definition voms_api.h:185
@ VERR_NOIDENT
Definition voms_api.h:165
@ VERR_DIR
Definition voms_api.h:176
@ VERR_SERVER
Definition voms_api.h:178
int getVOMSMajorVersionNumber(void)