2003-06-05 07:14:21 +00:00
|
|
|
/* keydb.h - Key database
|
2006-04-19 11:26:11 +00:00
|
|
|
* Copyright (C) 1998, 1999, 2000, 2001, 2002, 2003, 2004, 2005,
|
2010-02-02 14:06:19 +00:00
|
|
|
* 2006, 2010 Free Software Foundation, Inc.
|
2016-02-19 14:48:56 +01:00
|
|
|
* Copyright (C) 2015, 2016 g10 Code GmbH
|
2003-06-05 07:14:21 +00:00
|
|
|
*
|
|
|
|
* This file is part of GnuPG.
|
|
|
|
*
|
|
|
|
* GnuPG is free software; you can redistribute it and/or modify
|
|
|
|
* it under the terms of the GNU General Public License as published by
|
2007-07-04 19:49:40 +00:00
|
|
|
* the Free Software Foundation; either version 3 of the License, or
|
2003-06-05 07:14:21 +00:00
|
|
|
* (at your option) any later version.
|
|
|
|
*
|
|
|
|
* GnuPG is distributed in the hope that it will be useful,
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
* GNU General Public License for more details.
|
|
|
|
*
|
|
|
|
* You should have received a copy of the GNU General Public License
|
2016-11-05 12:02:19 +01:00
|
|
|
* along with this program; if not, see <https://www.gnu.org/licenses/>.
|
2003-06-05 07:14:21 +00:00
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef G10_KEYDB_H
|
|
|
|
#define G10_KEYDB_H
|
|
|
|
|
2017-03-07 20:21:23 +09:00
|
|
|
#include "../common/types.h"
|
|
|
|
#include "../common/util.h"
|
2003-06-05 07:14:21 +00:00
|
|
|
#include "packet.h"
|
|
|
|
|
2018-04-06 11:01:46 +02:00
|
|
|
/* What qualifies as a certification (key-signature in contrast to a
|
|
|
|
* data signature)? Note that a back signature is special and can be
|
|
|
|
* made by key and data signatures capable subkeys.) */
|
2003-06-05 07:14:21 +00:00
|
|
|
#define IS_CERT(s) (IS_KEY_SIG(s) || IS_UID_SIG(s) || IS_SUBKEY_SIG(s) \
|
|
|
|
|| IS_KEY_REV(s) || IS_UID_REV(s) || IS_SUBKEY_REV(s))
|
|
|
|
#define IS_SIG(s) (!IS_CERT(s))
|
|
|
|
#define IS_KEY_SIG(s) ((s)->sig_class == 0x1f)
|
|
|
|
#define IS_UID_SIG(s) (((s)->sig_class & ~3) == 0x10)
|
|
|
|
#define IS_SUBKEY_SIG(s) ((s)->sig_class == 0x18)
|
2018-04-06 10:18:53 +02:00
|
|
|
#define IS_BACK_SIG(s) ((s)->sig_class == 0x19)
|
2003-06-05 07:14:21 +00:00
|
|
|
#define IS_KEY_REV(s) ((s)->sig_class == 0x20)
|
|
|
|
#define IS_UID_REV(s) ((s)->sig_class == 0x30)
|
|
|
|
#define IS_SUBKEY_REV(s) ((s)->sig_class == 0x28)
|
|
|
|
|
|
|
|
struct getkey_ctx_s;
|
|
|
|
typedef struct getkey_ctx_s *GETKEY_CTX;
|
2010-02-02 14:06:19 +00:00
|
|
|
typedef struct getkey_ctx_s *getkey_ctx_t;
|
2003-06-05 07:14:21 +00:00
|
|
|
|
|
|
|
/****************
|
|
|
|
* A Keyblock is all packets which form an entire certificate;
|
|
|
|
* i.e. the public key, certificate, trust packets, user ids,
|
|
|
|
* signatures, and subkey.
|
|
|
|
*
|
|
|
|
* This structure is also used to bind arbitrary packets together.
|
|
|
|
*/
|
|
|
|
|
|
|
|
struct kbnode_struct {
|
|
|
|
KBNODE next;
|
|
|
|
PACKET *pkt;
|
|
|
|
int flag;
|
|
|
|
int private_flag;
|
|
|
|
ulong recno; /* used while updating the trustdb */
|
|
|
|
};
|
|
|
|
|
|
|
|
#define is_deleted_kbnode(a) ((a)->private_flag & 1)
|
|
|
|
#define is_cloned_kbnode(a) ((a)->private_flag & 2)
|
|
|
|
|
|
|
|
|
2015-12-04 08:56:02 +01:00
|
|
|
/* Bit flags used with build_pk_list. */
|
2015-12-17 10:36:27 +01:00
|
|
|
enum
|
|
|
|
{
|
2016-07-06 14:03:50 +02:00
|
|
|
PK_LIST_ENCRYPT_TO = 1, /* This is an encrypt-to recipient. */
|
|
|
|
PK_LIST_HIDDEN = 2, /* This is a hidden recipient. */
|
|
|
|
PK_LIST_CONFIG = 4, /* Specified via config file. */
|
|
|
|
PK_LIST_FROM_FILE = 8 /* Take key from file with that name. */
|
2015-12-17 10:36:27 +01:00
|
|
|
};
|
2017-01-17 12:43:13 +01:00
|
|
|
|
2016-07-06 14:03:50 +02:00
|
|
|
/* To store private data in the flags the private data must be left
|
2017-01-17 12:43:13 +01:00
|
|
|
* shifted by this value. */
|
2015-12-17 10:36:27 +01:00
|
|
|
enum
|
|
|
|
{
|
2016-07-06 14:03:50 +02:00
|
|
|
PK_LIST_SHIFT = 4
|
2015-12-17 10:36:27 +01:00
|
|
|
};
|
2015-12-04 08:56:02 +01:00
|
|
|
|
2003-06-05 07:14:21 +00:00
|
|
|
|
2009-09-30 15:28:38 +00:00
|
|
|
/* Structure to hold a couple of public key certificates. */
|
|
|
|
typedef struct pk_list *PK_LIST; /* Deprecated. */
|
|
|
|
typedef struct pk_list *pk_list_t;
|
2011-02-04 12:57:53 +01:00
|
|
|
struct pk_list
|
2009-09-30 15:28:38 +00:00
|
|
|
{
|
|
|
|
PK_LIST next;
|
|
|
|
PKT_public_key *pk;
|
2016-07-06 14:03:50 +02:00
|
|
|
int flags; /* See PK_LIST_ constants. */
|
2003-06-05 07:14:21 +00:00
|
|
|
};
|
|
|
|
|
2010-02-02 14:06:19 +00:00
|
|
|
/* Structure to hold a list of secret key certificates. */
|
2003-06-05 07:14:21 +00:00
|
|
|
typedef struct sk_list *SK_LIST;
|
2011-02-04 12:57:53 +01:00
|
|
|
struct sk_list
|
2010-02-02 14:06:19 +00:00
|
|
|
{
|
|
|
|
SK_LIST next;
|
|
|
|
PKT_public_key *pk;
|
|
|
|
int mark; /* not used */
|
2003-06-05 07:14:21 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
/* structure to collect all information which can be used to
|
|
|
|
* identify a public key */
|
|
|
|
typedef struct pubkey_find_info *PUBKEY_FIND_INFO;
|
|
|
|
struct pubkey_find_info {
|
|
|
|
u32 keyid[2];
|
|
|
|
unsigned nbits;
|
|
|
|
byte pubkey_algo;
|
|
|
|
byte fingerprint[MAX_FINGERPRINT_LEN];
|
|
|
|
char userid[1];
|
|
|
|
};
|
|
|
|
|
|
|
|
|
2017-04-28 10:06:33 +09:00
|
|
|
/* Helper type for preference functions. */
|
2006-07-27 14:18:55 +00:00
|
|
|
union pref_hint
|
|
|
|
{
|
|
|
|
int digest_length;
|
|
|
|
};
|
|
|
|
|
|
|
|
|
gpg: Revamp reading and writing of ring trust packets.
* g10/parse-packet.c (parse_trust): Rename to ...
(parse_ring_trust): this. Change args and implement new ring trust
packet format.
(parse): Add special ring trust packet handling.
* g10/packet.h (PKT_user_id): New fields KEYUPDATE, UPDATEURL, and
KEYSRC.
(PKT_public_key): Ditto.
(RING_TRUST_SIG, RING_TRUST_KEY, RING_TRUST_UID): New consts.
(PKT_ring_trust): New.
(struct packet_struct): Remove member RING_TRUST.
(strcu parse_packet_ctx_s): Add field SKIP_META.
(init_parse_packet): Init SKIPT_META.
* g10/free-packet.c (release_public_key_parts): Free UDPATEURL.
(free_user_id): Ditto.
* g10/mainproc.c (list_node): Remove printing of non-documented "rtv"
lines.
* g10/build-packet.c (build_packet_and_meta): New.
(do_ring_trust): New.
* g10/export.c (write_keyblock_to_output): Use build_packet_and_meta
in backup mode.
(do_export_one_keyblock): Ditto.
* g10/import.c (read_block): Add arg WITH_META. Skip ring trust
packets if that ism not set.
(import): Call read_block WITH_META in restore mode.
* g10/keydb.h (KEYSRC_UNKNOWN, KEYSRC_FILE, KEYSRC_KS, KEYSRC_PREF_KS)
(KEYSRC_WKD, KEYSRC_WKD_SD, KEYSRC_DANE): New constants. They are not
yet used, though.
* g10/keydb.c (parse_keyblock_image): Allow ring trust packets.
(build_keyblock_image): Ditto. Use build_packet_and_meta.
* g10/keyring.c (keyring_get_keyblock): Remove specila treatment of
ring trust packets.
(write_keyblock): Use build_packet_and_meta. Remove special treatment
of ring trust packets and initialization of the signature caches.
--
This patch introduced the framework to store meta data for keys and
user ids in the keyrings/keyboxes. Ring trust packets are
implementation defined and have always been used in gpg to cache the
signature verification status.
Ring trust packets are only exported with the export option "backup"
and only imported with the import option "restore".
The new code uses a cleaner way to handle the ring trust packets: When
the parser reads a ring trust packet and the previously read packet
matches the type of that ring trust packet, the information is stored
in that previously read packet (signature, user id, or primary key)
and the next packet is read immediately. Thus only the parser sees
the ring trust packets. Ring trust packets are written by using the
new function build_packet_and_meta instead of build_packet. That
function writes a ring trust packet when the needed information is
available.
As a side-effect of this patch the signature status cache works again
and "gpg --check-sigs" is thus much faster.
Signed-off-by: Werner Koch <wk@gnupg.org>
2017-03-30 09:07:02 +02:00
|
|
|
/* Constants to describe from where a key was fetched or updated. */
|
|
|
|
enum
|
|
|
|
{
|
2017-07-13 17:28:32 +02:00
|
|
|
KEYORG_UNKNOWN = 0,
|
|
|
|
KEYORG_KS = 1, /* Public keyserver. */
|
|
|
|
KEYORG_KS_PREF = 2, /* Preferred keysrver. */
|
|
|
|
KEYORG_DANE = 3, /* OpenPGP DANE. */
|
|
|
|
KEYORG_WKD = 4, /* Web Key Directory. */
|
|
|
|
KEYORG_URL = 5, /* Trusted URL. */
|
|
|
|
KEYORG_FILE = 6, /* Trusted file. */
|
2017-07-20 14:49:07 +02:00
|
|
|
KEYORG_SELF = 7 /* We generated it. */
|
gpg: Revamp reading and writing of ring trust packets.
* g10/parse-packet.c (parse_trust): Rename to ...
(parse_ring_trust): this. Change args and implement new ring trust
packet format.
(parse): Add special ring trust packet handling.
* g10/packet.h (PKT_user_id): New fields KEYUPDATE, UPDATEURL, and
KEYSRC.
(PKT_public_key): Ditto.
(RING_TRUST_SIG, RING_TRUST_KEY, RING_TRUST_UID): New consts.
(PKT_ring_trust): New.
(struct packet_struct): Remove member RING_TRUST.
(strcu parse_packet_ctx_s): Add field SKIP_META.
(init_parse_packet): Init SKIPT_META.
* g10/free-packet.c (release_public_key_parts): Free UDPATEURL.
(free_user_id): Ditto.
* g10/mainproc.c (list_node): Remove printing of non-documented "rtv"
lines.
* g10/build-packet.c (build_packet_and_meta): New.
(do_ring_trust): New.
* g10/export.c (write_keyblock_to_output): Use build_packet_and_meta
in backup mode.
(do_export_one_keyblock): Ditto.
* g10/import.c (read_block): Add arg WITH_META. Skip ring trust
packets if that ism not set.
(import): Call read_block WITH_META in restore mode.
* g10/keydb.h (KEYSRC_UNKNOWN, KEYSRC_FILE, KEYSRC_KS, KEYSRC_PREF_KS)
(KEYSRC_WKD, KEYSRC_WKD_SD, KEYSRC_DANE): New constants. They are not
yet used, though.
* g10/keydb.c (parse_keyblock_image): Allow ring trust packets.
(build_keyblock_image): Ditto. Use build_packet_and_meta.
* g10/keyring.c (keyring_get_keyblock): Remove specila treatment of
ring trust packets.
(write_keyblock): Use build_packet_and_meta. Remove special treatment
of ring trust packets and initialization of the signature caches.
--
This patch introduced the framework to store meta data for keys and
user ids in the keyrings/keyboxes. Ring trust packets are
implementation defined and have always been used in gpg to cache the
signature verification status.
Ring trust packets are only exported with the export option "backup"
and only imported with the import option "restore".
The new code uses a cleaner way to handle the ring trust packets: When
the parser reads a ring trust packet and the previously read packet
matches the type of that ring trust packet, the information is stored
in that previously read packet (signature, user id, or primary key)
and the next packet is read immediately. Thus only the parser sees
the ring trust packets. Ring trust packets are written by using the
new function build_packet_and_meta instead of build_packet. That
function writes a ring trust packet when the needed information is
available.
As a side-effect of this patch the signature status cache works again
and "gpg --check-sigs" is thus much faster.
Signed-off-by: Werner Koch <wk@gnupg.org>
2017-03-30 09:07:02 +02:00
|
|
|
};
|
|
|
|
|
|
|
|
|
2003-06-05 07:14:21 +00:00
|
|
|
/*-- keydb.c --*/
|
|
|
|
|
2012-12-27 15:04:29 +01:00
|
|
|
#define KEYDB_RESOURCE_FLAG_PRIMARY 2 /* The primary resource. */
|
|
|
|
#define KEYDB_RESOURCE_FLAG_DEFAULT 4 /* The default one. */
|
|
|
|
#define KEYDB_RESOURCE_FLAG_READONLY 8 /* Open in read only mode. */
|
2015-08-07 15:53:56 +02:00
|
|
|
#define KEYDB_RESOURCE_FLAG_GPGVDEF 16 /* Default file for gpgv. */
|
2012-12-27 15:04:29 +01:00
|
|
|
|
2015-11-17 11:36:38 +01:00
|
|
|
/* Format a search term for debugging output. The caller must free
|
|
|
|
the result. */
|
|
|
|
char *keydb_search_desc_dump (struct keydb_search_desc *desc);
|
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Register a resource (keyring or keybox). */
|
2012-12-27 15:04:29 +01:00
|
|
|
gpg_error_t keydb_add_resource (const char *url, unsigned int flags);
|
|
|
|
|
2015-08-31 11:14:21 +02:00
|
|
|
/* Dump some statistics to the log. */
|
|
|
|
void keydb_dump_stats (void);
|
|
|
|
|
2015-12-03 12:18:32 +01:00
|
|
|
/* Create a new database handle. Returns NULL on error, sets ERRNO,
|
|
|
|
and prints an error diagnostic. */
|
2010-04-21 16:26:17 +00:00
|
|
|
KEYDB_HANDLE keydb_new (void);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
|
|
|
/* Free all resources owned by the database handle. */
|
2003-06-05 07:14:21 +00:00
|
|
|
void keydb_release (KEYDB_HANDLE hd);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
2017-10-18 18:28:52 +02:00
|
|
|
/* Take a lock on the files immediately and not only during insert or
|
|
|
|
* update. This lock is released with keydb_release. */
|
|
|
|
gpg_error_t keydb_lock (KEYDB_HANDLE hd);
|
|
|
|
|
2015-08-31 11:14:21 +02:00
|
|
|
/* Set a flag on the handle to suppress use of cached results. This
|
|
|
|
is required for updating a keyring and for key listings. Fixme:
|
|
|
|
Using a new parameter for keydb_new might be a better solution. */
|
2014-10-13 14:01:29 +02:00
|
|
|
void keydb_disable_caching (KEYDB_HANDLE hd);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Save the last found state and invalidate the current selection. */
|
2015-05-08 15:51:11 +02:00
|
|
|
void keydb_push_found_state (KEYDB_HANDLE hd);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Restore the previous save state. */
|
2015-05-08 15:51:11 +02:00
|
|
|
void keydb_pop_found_state (KEYDB_HANDLE hd);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Return the file name of the resource. */
|
2003-06-05 07:14:21 +00:00
|
|
|
const char *keydb_get_resource_name (KEYDB_HANDLE hd);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Return the keyblock last found by keydb_search. */
|
2011-04-29 15:07:11 +02:00
|
|
|
gpg_error_t keydb_get_keyblock (KEYDB_HANDLE hd, KBNODE *ret_kb);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Update the keyblock KB. */
|
g10: Cache the effective policy. Recompute it when required.
* g10/tofu.c (initdb): Add column effective_policy to the bindings
table.
(record_binding): New parameters effective_policy and set_conflict.
Save the effective policy. If SET_CONFLICT is set, then set conflict
according to CONFLICT. Otherwise, preserve the current value of
conflict. Update callers.
(get_trust): Don't compute the effective policy here...
(get_policy): ... do it here, if it was not cached. Take new
parameters, PK, the public key, and NOW, the time that the operation
started. Update callers.
(show_statistics): New parameter PK. Pass it to get_policy. Update
callers.
(tofu_notice_key_changed): New function.
* g10/gpgv.c (tofu_notice_key_changed): New stub.
* g10/import.c (import_revoke_cert): Take additional argument CTRL.
Pass it to keydb_update_keyblock.
* g10/keydb.c (keydb_update_keyblock): Take additional argument CTRL.
Update callers.
[USE_TOFU]: Call tofu_notice_key_changed.
* g10/test-stubs.c (tofu_notice_key_changed): New stub.
* tests/openpgp/tofu.scm: Assume that manually setting a binding's
policy to auto does not cause the tofu engine to forget about any
conflict.
--
Signed-off-by: Neal H. Walfield <neal@g10code.com>
We now store the computed policy in the tofu DB (in the
effective_policy column of the bindings table) to avoid computing it
every time, which is expensive. Further, policy is never overridden
in case of a conflict. Instead, we detect a conflict if CONFLICT is
not empty.
This change is backwards compatible to existing DBs. The only minor
incompatibility is that unresolved conflicts won't be automatically
resolved in case we import a direct signature, or cross signatures.
2016-11-21 22:47:30 +01:00
|
|
|
gpg_error_t keydb_update_keyblock (ctrl_t ctrl, KEYDB_HANDLE hd, kbnode_t kb);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Insert a keyblock into one of the underlying keyrings or keyboxes. */
|
2011-04-29 15:07:11 +02:00
|
|
|
gpg_error_t keydb_insert_keyblock (KEYDB_HANDLE hd, kbnode_t kb);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Delete the currently selected keyblock. */
|
2011-04-29 15:07:11 +02:00
|
|
|
gpg_error_t keydb_delete_keyblock (KEYDB_HANDLE hd);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Find the first writable resource. */
|
2015-08-28 16:22:59 +02:00
|
|
|
gpg_error_t keydb_locate_writable (KEYDB_HANDLE hd);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
|
|
|
/* Rebuild the on-disk caches of all key resources. */
|
2017-03-31 20:03:52 +02:00
|
|
|
void keydb_rebuild_caches (ctrl_t ctrl, int noisy);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
|
|
|
/* Return the number of skipped blocks (because they were to large to
|
|
|
|
read from a keybox) since the last search reset. */
|
2014-10-09 21:01:49 +02:00
|
|
|
unsigned long keydb_get_skipped_counter (KEYDB_HANDLE hd);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Clears the current search result and resets the handle's position. */
|
2011-04-29 15:07:11 +02:00
|
|
|
gpg_error_t keydb_search_reset (KEYDB_HANDLE hd);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Search the database for keys matching the search description. */
|
2013-01-08 09:43:21 +01:00
|
|
|
gpg_error_t keydb_search (KEYDB_HANDLE hd, KEYDB_SEARCH_DESC *desc,
|
|
|
|
size_t ndesc, size_t *descindex);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Return the first non-legacy key in the database. */
|
2011-04-29 15:07:11 +02:00
|
|
|
gpg_error_t keydb_search_first (KEYDB_HANDLE hd);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Return the next key (not the next matching key!). */
|
2011-04-29 15:07:11 +02:00
|
|
|
gpg_error_t keydb_search_next (KEYDB_HANDLE hd);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
|
|
|
/* This is a convenience function for searching for keys with a long
|
2016-01-11 11:41:49 +01:00
|
|
|
key id. */
|
2011-04-29 15:07:11 +02:00
|
|
|
gpg_error_t keydb_search_kid (KEYDB_HANDLE hd, u32 *kid);
|
2015-08-31 11:14:21 +02:00
|
|
|
|
|
|
|
/* This is a convenience function for searching for keys with a long
|
2016-01-11 11:41:49 +01:00
|
|
|
(20 byte) fingerprint. */
|
2011-04-29 15:07:11 +02:00
|
|
|
gpg_error_t keydb_search_fpr (KEYDB_HANDLE hd, const byte *fpr);
|
2003-06-05 07:14:21 +00:00
|
|
|
|
2015-06-20 15:03:32 +02:00
|
|
|
|
2003-06-05 07:14:21 +00:00
|
|
|
/*-- pkclist.c --*/
|
2017-03-31 20:03:52 +02:00
|
|
|
void show_revocation_reason (ctrl_t ctrl, PKT_public_key *pk, int mode );
|
2016-05-21 11:41:49 +02:00
|
|
|
int check_signatures_trust (ctrl_t ctrl, PKT_signature *sig);
|
2009-09-30 15:28:38 +00:00
|
|
|
|
|
|
|
void release_pk_list (PK_LIST pk_list);
|
2015-12-18 13:26:40 +01:00
|
|
|
int build_pk_list (ctrl_t ctrl, strlist_t rcpts, PK_LIST *ret_pk_list);
|
2010-10-01 20:33:53 +00:00
|
|
|
gpg_error_t find_and_check_key (ctrl_t ctrl,
|
2011-02-04 12:57:53 +01:00
|
|
|
const char *name, unsigned int use,
|
2016-07-06 14:03:50 +02:00
|
|
|
int mark_hidden, int from_file,
|
|
|
|
pk_list_t *pk_list_addr);
|
2009-09-30 15:28:38 +00:00
|
|
|
|
2006-07-27 14:18:55 +00:00
|
|
|
int algo_available( preftype_t preftype, int algo,
|
|
|
|
const union pref_hint *hint );
|
2003-06-05 07:14:21 +00:00
|
|
|
int select_algo_from_prefs( PK_LIST pk_list, int preftype,
|
2006-07-27 14:18:55 +00:00
|
|
|
int request, const union pref_hint *hint);
|
2003-06-05 07:14:21 +00:00
|
|
|
int select_mdc_from_pklist (PK_LIST pk_list);
|
2006-11-05 15:08:58 +00:00
|
|
|
void warn_missing_mdc_from_pklist (PK_LIST pk_list);
|
|
|
|
void warn_missing_aes_from_pklist (PK_LIST pk_list);
|
2003-06-05 07:14:21 +00:00
|
|
|
|
|
|
|
/*-- skclist.c --*/
|
2006-08-21 20:20:23 +00:00
|
|
|
int random_is_faked (void);
|
2003-06-05 07:14:21 +00:00
|
|
|
void release_sk_list( SK_LIST sk_list );
|
2015-11-03 23:15:27 +01:00
|
|
|
gpg_error_t build_sk_list (ctrl_t ctrl, strlist_t locusr,
|
|
|
|
SK_LIST *ret_sk_list, unsigned use);
|
2003-06-05 07:14:21 +00:00
|
|
|
|
|
|
|
/*-- passphrase.h --*/
|
2010-01-08 19:18:49 +00:00
|
|
|
unsigned char encode_s2k_iterations (int iterations);
|
2003-06-05 07:14:21 +00:00
|
|
|
int have_static_passphrase(void);
|
2013-02-07 20:37:58 +01:00
|
|
|
const char *get_static_passphrase (void);
|
2006-04-19 11:26:11 +00:00
|
|
|
void set_passphrase_from_string(const char *pass);
|
2003-06-05 07:14:21 +00:00
|
|
|
void read_passphrase_from_fd( int fd );
|
2016-08-08 18:45:29 +02:00
|
|
|
void passphrase_clear_cache (const char *cacheid);
|
2009-05-15 19:26:46 +00:00
|
|
|
DEK *passphrase_to_dek_ext(u32 *keyid, int pubkey_algo,
|
|
|
|
int cipher_algo, STRING2KEY *s2k, int mode,
|
|
|
|
const char *tryagain_text,
|
|
|
|
const char *custdesc, const char *custprompt,
|
|
|
|
int *canceled);
|
2016-08-08 18:45:29 +02:00
|
|
|
DEK *passphrase_to_dek (int cipher_algo, STRING2KEY *s2k,
|
|
|
|
int create, int nocache,
|
2003-06-05 07:14:21 +00:00
|
|
|
const char *tryagain_text, int *canceled);
|
|
|
|
void set_next_passphrase( const char *s );
|
|
|
|
char *get_last_passphrase(void);
|
2006-04-19 11:26:11 +00:00
|
|
|
void next_to_last_passphrase(void);
|
2003-06-05 07:14:21 +00:00
|
|
|
|
2017-03-31 20:03:52 +02:00
|
|
|
void emit_status_need_passphrase (ctrl_t ctrl, u32 *keyid,
|
|
|
|
u32 *mainkeyid, int pubkey_algo);
|
2013-02-07 20:37:58 +01:00
|
|
|
|
2014-04-14 14:40:18 +02:00
|
|
|
#define FORMAT_KEYDESC_NORMAL 0
|
|
|
|
#define FORMAT_KEYDESC_IMPORT 1
|
|
|
|
#define FORMAT_KEYDESC_EXPORT 2
|
2014-04-15 16:40:48 +02:00
|
|
|
#define FORMAT_KEYDESC_DELKEY 3
|
2017-03-31 20:03:52 +02:00
|
|
|
char *gpg_format_keydesc (ctrl_t ctrl,
|
|
|
|
PKT_public_key *pk, int mode, int escaped);
|
2010-04-27 14:11:41 +00:00
|
|
|
|
|
|
|
|
2003-06-05 07:14:21 +00:00
|
|
|
/*-- getkey.c --*/
|
2015-09-16 14:01:48 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Cache a copy of a public key in the public key cache. */
|
2003-06-05 07:14:21 +00:00
|
|
|
void cache_public_key( PKT_public_key *pk );
|
2015-09-16 14:01:48 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Disable and drop the public key cache. */
|
2003-06-05 07:14:21 +00:00
|
|
|
void getkey_disable_caches(void);
|
2015-09-16 14:01:48 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Return the public key with the key id KEYID and store it at PK. */
|
2017-03-31 20:03:52 +02:00
|
|
|
int get_pubkey (ctrl_t ctrl, PKT_public_key *pk, u32 *keyid);
|
2015-09-16 14:01:48 +02:00
|
|
|
|
|
|
|
/* Similar to get_pubkey, but it does not take PK->REQ_USAGE into
|
|
|
|
account nor does it merge in the self-signed data. This function
|
2016-01-11 11:41:49 +01:00
|
|
|
also only considers primary keys. */
|
|
|
|
int get_pubkey_fast (PKT_public_key *pk, u32 *keyid);
|
2015-09-16 14:01:48 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Return the key block for the key with KEYID. */
|
2017-03-31 20:03:52 +02:00
|
|
|
kbnode_t get_pubkeyblock (ctrl_t ctrl, u32 *keyid);
|
2015-09-16 14:01:48 +02:00
|
|
|
|
2015-12-22 14:57:53 +01:00
|
|
|
/* A list used by get_pubkeys to gather all of the matches. */
|
2015-12-23 15:45:20 +01:00
|
|
|
struct pubkey_s
|
2015-12-22 14:57:53 +01:00
|
|
|
{
|
2015-12-23 15:45:20 +01:00
|
|
|
struct pubkey_s *next;
|
2015-12-22 14:57:53 +01:00
|
|
|
/* The key to use (either the public key or the subkey). */
|
|
|
|
PKT_public_key *pk;
|
|
|
|
kbnode_t keyblock;
|
|
|
|
};
|
2015-12-23 15:45:20 +01:00
|
|
|
typedef struct pubkey_s *pubkey_t;
|
2015-12-22 14:57:53 +01:00
|
|
|
|
|
|
|
/* Free a single key. This does not remove key from any list! */
|
2015-12-23 15:45:20 +01:00
|
|
|
void pubkey_free (pubkey_t key);
|
2015-12-22 14:57:53 +01:00
|
|
|
|
|
|
|
/* Free a list of public keys. */
|
2015-12-23 15:45:20 +01:00
|
|
|
void pubkeys_free (pubkey_t keys);
|
2015-12-22 14:57:53 +01:00
|
|
|
|
2017-04-28 10:06:33 +09:00
|
|
|
/* Returns all keys that match the search specification SEARCH_TERMS.
|
2015-12-22 14:57:53 +01:00
|
|
|
The returned keys should be freed using pubkeys_free. */
|
|
|
|
gpg_error_t
|
|
|
|
get_pubkeys (ctrl_t ctrl,
|
|
|
|
char *search_terms, int use, int include_unusable, char *source,
|
|
|
|
int warn_possibly_ambiguous,
|
2015-12-23 15:45:20 +01:00
|
|
|
pubkey_t *r_keys);
|
2015-12-22 14:57:53 +01:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Find a public key identified by NAME. */
|
2010-10-01 20:33:53 +00:00
|
|
|
int get_pubkey_byname (ctrl_t ctrl,
|
2015-09-16 14:01:48 +02:00
|
|
|
GETKEY_CTX *retctx, PKT_public_key *pk,
|
|
|
|
const char *name,
|
2003-06-05 07:14:21 +00:00
|
|
|
KBNODE *ret_keyblock, KEYDB_HANDLE *ret_kdbhd,
|
2008-04-08 11:04:16 +00:00
|
|
|
int include_unusable, int no_akl );
|
2015-09-16 14:01:48 +02:00
|
|
|
|
2016-10-27 18:48:51 +02:00
|
|
|
/* Likewise, but only return the best match if NAME resembles a mail
|
|
|
|
* address. */
|
2017-07-28 11:08:32 +02:00
|
|
|
gpg_error_t get_best_pubkey_byname (ctrl_t ctrl,
|
|
|
|
GETKEY_CTX *retctx, PKT_public_key *pk,
|
|
|
|
const char *name, KBNODE *ret_keyblock,
|
|
|
|
int include_unusable, int no_akl);
|
2016-10-27 18:48:51 +02:00
|
|
|
|
2016-07-06 14:03:50 +02:00
|
|
|
/* Get a public key directly from file FNAME. */
|
|
|
|
gpg_error_t get_pubkey_fromfile (ctrl_t ctrl,
|
|
|
|
PKT_public_key *pk, const char *fname);
|
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Return the public key with the key id KEYID iff the secret key is
|
|
|
|
* available and store it at PK. */
|
2017-03-31 20:03:52 +02:00
|
|
|
gpg_error_t get_seckey (ctrl_t ctrl, PKT_public_key *pk, u32 *keyid);
|
2015-09-16 14:01:48 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Lookup a key with the specified fingerprint. */
|
2017-03-31 20:03:52 +02:00
|
|
|
int get_pubkey_byfprint (ctrl_t ctrl, PKT_public_key *pk, kbnode_t *r_keyblock,
|
2015-05-07 12:01:12 +02:00
|
|
|
const byte *fprint, size_t fprint_len);
|
2015-09-16 14:01:48 +02:00
|
|
|
|
|
|
|
/* This function is similar to get_pubkey_byfprint, but it doesn't
|
|
|
|
merge the self-signed data into the public key and subkeys or into
|
2016-01-11 11:41:49 +01:00
|
|
|
the user ids. */
|
2017-10-18 17:52:41 +02:00
|
|
|
gpg_error_t get_pubkey_byfprint_fast (PKT_public_key *pk,
|
|
|
|
const byte *fprint, size_t fprint_len);
|
|
|
|
|
|
|
|
/* This function is similar to get_pubkey_byfprint, but it doesn't
|
|
|
|
merge the self-signed data into the public key and subkeys or into
|
|
|
|
the user ids. */
|
|
|
|
gpg_error_t get_keyblock_byfprint_fast (kbnode_t *r_keyblock,
|
|
|
|
KEYDB_HANDLE *r_hd,
|
|
|
|
const byte *fprint, size_t fprint_len,
|
|
|
|
int lock);
|
|
|
|
|
2006-04-19 11:26:11 +00:00
|
|
|
|
2015-12-03 12:18:32 +01:00
|
|
|
/* Returns true if a secret key is available for the public key with
|
|
|
|
key id KEYID. */
|
2010-04-21 16:26:17 +00:00
|
|
|
int have_secret_key_with_kid (u32 *keyid);
|
|
|
|
|
2015-11-03 23:39:46 +01:00
|
|
|
/* Parse the --default-key parameter. Returns the last key (in terms
|
|
|
|
of when the option is given) that is available. */
|
|
|
|
const char *parse_def_secret_key (ctrl_t ctrl);
|
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Look up a secret key. */
|
2015-11-03 23:15:27 +01:00
|
|
|
gpg_error_t get_seckey_default (ctrl_t ctrl, PKT_public_key *pk);
|
2017-05-22 09:27:36 +09:00
|
|
|
gpg_error_t get_seckey_default_or_card (ctrl_t ctrl, PKT_public_key *pk,
|
|
|
|
const byte *fpr, size_t fpr_len);
|
2010-04-21 16:26:17 +00:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Search for keys matching some criteria. */
|
2017-03-31 20:03:52 +02:00
|
|
|
gpg_error_t getkey_bynames (ctrl_t ctrl,
|
|
|
|
getkey_ctx_t *retctx, PKT_public_key *pk,
|
2010-02-02 14:06:19 +00:00
|
|
|
strlist_t names, int want_secret,
|
|
|
|
kbnode_t *ret_keyblock);
|
2015-09-16 14:01:48 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Search for one key matching some criteria. */
|
2015-11-03 23:15:27 +01:00
|
|
|
gpg_error_t getkey_byname (ctrl_t ctrl,
|
|
|
|
getkey_ctx_t *retctx, PKT_public_key *pk,
|
2010-02-02 14:06:19 +00:00
|
|
|
const char *name, int want_secret,
|
|
|
|
kbnode_t *ret_keyblock);
|
2015-09-16 14:01:48 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Return the next search result. */
|
2017-03-31 20:03:52 +02:00
|
|
|
gpg_error_t getkey_next (ctrl_t ctrl, getkey_ctx_t ctx,
|
|
|
|
PKT_public_key *pk, kbnode_t *ret_keyblock);
|
2015-09-16 14:01:48 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Release any resources used by a key listing context. */
|
2017-03-31 20:35:28 +02:00
|
|
|
void getkey_end (ctrl_t ctrl, getkey_ctx_t ctx);
|
2010-02-02 14:06:19 +00:00
|
|
|
|
2015-09-16 14:01:48 +02:00
|
|
|
/* Return the database handle used by this context. The context still
|
|
|
|
owns the handle. */
|
|
|
|
KEYDB_HANDLE get_ctx_handle(GETKEY_CTX ctx);
|
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Enumerate some secret keys. */
|
2015-11-03 23:15:27 +01:00
|
|
|
gpg_error_t enum_secret_keys (ctrl_t ctrl, void **context, PKT_public_key *pk);
|
2010-02-02 14:06:19 +00:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* Set the mainkey_id fields for all keys in KEYBLOCK. */
|
2014-04-15 16:40:48 +02:00
|
|
|
void setup_main_keyids (kbnode_t keyblock);
|
2015-09-16 14:01:48 +02:00
|
|
|
|
2016-01-11 11:41:49 +01:00
|
|
|
/* This function merges information from the self-signed data into the
|
|
|
|
data structures. */
|
2017-03-31 20:03:52 +02:00
|
|
|
void merge_keys_and_selfsig (ctrl_t ctrl, kbnode_t keyblock);
|
2015-09-16 14:01:48 +02:00
|
|
|
|
2018-04-12 17:53:17 +02:00
|
|
|
char *get_user_id_string_native (ctrl_t ctrl, u32 *keyid);
|
|
|
|
char *get_long_user_id_string (ctrl_t ctrl, u32 *keyid);
|
|
|
|
char *get_user_id (ctrl_t ctrl, u32 *keyid, size_t *rn, int *r_nouid);
|
|
|
|
char *get_user_id_native (ctrl_t ctrl, u32 *keyid);
|
2017-03-31 20:03:52 +02:00
|
|
|
char *get_user_id_byfpr (ctrl_t ctrl, const byte *fpr, size_t *rn);
|
|
|
|
char *get_user_id_byfpr_native (ctrl_t ctrl, const byte *fpr);
|
2015-09-16 14:01:48 +02:00
|
|
|
|
2006-04-19 11:26:11 +00:00
|
|
|
void release_akl(void);
|
2017-08-04 21:58:46 +02:00
|
|
|
int parse_auto_key_locate(const char *options);
|
2017-07-13 17:28:32 +02:00
|
|
|
int parse_key_origin (char *string);
|
2017-07-20 17:27:48 +02:00
|
|
|
const char *key_origin_string (int origin);
|
2003-06-05 07:14:21 +00:00
|
|
|
|
|
|
|
/*-- keyid.c --*/
|
|
|
|
int pubkey_letter( int algo );
|
2014-02-05 10:37:59 +01:00
|
|
|
char *pubkey_string (PKT_public_key *pk, char *buffer, size_t bufsize);
|
|
|
|
#define PUBKEY_STRING_SIZE 32
|
2006-05-23 16:19:43 +00:00
|
|
|
u32 v3_keyid (gcry_mpi_t a, u32 *ki);
|
2006-04-19 11:26:11 +00:00
|
|
|
void hash_public_key( gcry_md_hd_t md, PKT_public_key *pk );
|
2016-02-08 00:31:35 +01:00
|
|
|
char *format_keyid (u32 *keyid, int format, char *buffer, int len);
|
2016-02-19 14:48:56 +01:00
|
|
|
|
|
|
|
/* Return PK's keyid. The memory is owned by PK. */
|
|
|
|
u32 *pk_keyid (PKT_public_key *pk);
|
|
|
|
|
|
|
|
/* Return the keyid of the primary key associated with PK. The memory
|
|
|
|
is owned by PK. */
|
|
|
|
u32 *pk_main_keyid (PKT_public_key *pk);
|
|
|
|
|
|
|
|
/* Order A and B. If A < B then return -1, if A == B then return 0,
|
|
|
|
and if A > B then return 1. */
|
|
|
|
static int GPGRT_ATTR_UNUSED
|
|
|
|
keyid_cmp (const u32 *a, const u32 *b)
|
|
|
|
{
|
|
|
|
if (a[0] < b[0])
|
|
|
|
return -1;
|
|
|
|
if (a[0] > b[0])
|
|
|
|
return 1;
|
|
|
|
if (a[1] < b[1])
|
|
|
|
return -1;
|
|
|
|
if (a[1] > b[1])
|
|
|
|
return 1;
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2016-11-21 16:19:32 +01:00
|
|
|
/* Return whether PK is a primary key. */
|
|
|
|
static int GPGRT_ATTR_UNUSED
|
|
|
|
pk_is_primary (PKT_public_key *pk)
|
|
|
|
{
|
|
|
|
return keyid_cmp (pk_keyid (pk), pk_main_keyid (pk)) == 0;
|
|
|
|
}
|
|
|
|
|
2016-02-19 14:48:56 +01:00
|
|
|
/* Copy the keyid in SRC to DEST and return DEST. */
|
|
|
|
u32 *keyid_copy (u32 *dest, const u32 *src);
|
|
|
|
|
2006-04-19 11:26:11 +00:00
|
|
|
size_t keystrlen(void);
|
|
|
|
const char *keystr(u32 *keyid);
|
2010-08-31 15:58:39 +00:00
|
|
|
const char *keystr_with_sub (u32 *main_kid, u32 *sub_kid);
|
2006-04-19 11:26:11 +00:00
|
|
|
const char *keystr_from_pk(PKT_public_key *pk);
|
2010-08-31 15:58:39 +00:00
|
|
|
const char *keystr_from_pk_with_sub (PKT_public_key *main_pk,
|
|
|
|
PKT_public_key *sub_pk);
|
2016-02-19 14:48:56 +01:00
|
|
|
|
|
|
|
/* Return PK's key id as a string using the default format. PK owns
|
|
|
|
the storage. */
|
|
|
|
const char *pk_keyid_str (PKT_public_key *pk);
|
|
|
|
|
2006-04-19 11:26:11 +00:00
|
|
|
const char *keystr_from_desc(KEYDB_SEARCH_DESC *desc);
|
2003-06-05 07:14:21 +00:00
|
|
|
u32 keyid_from_pk( PKT_public_key *pk, u32 *keyid );
|
2017-03-31 20:03:52 +02:00
|
|
|
u32 keyid_from_sig (PKT_signature *sig, u32 *keyid );
|
|
|
|
u32 keyid_from_fingerprint (ctrl_t ctrl, const byte *fprint, size_t fprint_len,
|
|
|
|
u32 *keyid);
|
2003-06-05 07:14:21 +00:00
|
|
|
byte *namehash_from_uid(PKT_user_id *uid);
|
|
|
|
unsigned nbits_from_pk( PKT_public_key *pk );
|
2017-07-20 13:36:44 +02:00
|
|
|
|
|
|
|
/* Convert an UTC TIMESTAMP into an UTC yyyy-mm-dd string. Return
|
|
|
|
* that string. The caller should pass a buffer with at least a size
|
|
|
|
* of MK_DATESTR_SIZE. */
|
|
|
|
char *mk_datestr (char *buffer, size_t bufsize, u32 timestamp);
|
|
|
|
#define MK_DATESTR_SIZE 11
|
|
|
|
|
2003-06-05 07:14:21 +00:00
|
|
|
const char *datestr_from_pk( PKT_public_key *pk );
|
|
|
|
const char *datestr_from_sig( PKT_signature *sig );
|
|
|
|
const char *expirestr_from_pk( PKT_public_key *pk );
|
|
|
|
const char *expirestr_from_sig( PKT_signature *sig );
|
2006-04-19 11:26:11 +00:00
|
|
|
const char *revokestr_from_pk( PKT_public_key *pk );
|
2014-08-12 10:36:30 +02:00
|
|
|
const char *usagestr_from_pk (PKT_public_key *pk, int fill);
|
2003-06-05 07:14:21 +00:00
|
|
|
const char *colon_strtime (u32 t);
|
|
|
|
const char *colon_datestr_from_pk (PKT_public_key *pk);
|
|
|
|
const char *colon_datestr_from_sig (PKT_signature *sig);
|
|
|
|
const char *colon_expirestr_from_sig (PKT_signature *sig);
|
|
|
|
byte *fingerprint_from_pk( PKT_public_key *pk, byte *buf, size_t *ret_len );
|
2015-11-14 09:13:02 +01:00
|
|
|
char *hexfingerprint (PKT_public_key *pk, char *buffer, size_t buflen);
|
|
|
|
char *format_hexfingerprint (const char *fingerprint,
|
|
|
|
char *buffer, size_t buflen);
|
2010-04-20 17:57:50 +00:00
|
|
|
gpg_error_t keygrip_from_pk (PKT_public_key *pk, unsigned char *array);
|
|
|
|
gpg_error_t hexkeygrip_from_pk (PKT_public_key *pk, char **r_grip);
|
|
|
|
|
2003-06-05 07:14:21 +00:00
|
|
|
|
|
|
|
/*-- kbnode.c --*/
|
|
|
|
KBNODE new_kbnode( PACKET *pkt );
|
|
|
|
KBNODE clone_kbnode( KBNODE node );
|
|
|
|
void release_kbnode( KBNODE n );
|
|
|
|
void delete_kbnode( KBNODE node );
|
|
|
|
void add_kbnode( KBNODE root, KBNODE node );
|
|
|
|
void insert_kbnode( KBNODE root, KBNODE node, int pkttype );
|
|
|
|
void move_kbnode( KBNODE *root, KBNODE node, KBNODE where );
|
|
|
|
void remove_kbnode( KBNODE *root, KBNODE node );
|
|
|
|
KBNODE find_prev_kbnode( KBNODE root, KBNODE node, int pkttype );
|
|
|
|
KBNODE find_next_kbnode( KBNODE node, int pkttype );
|
|
|
|
KBNODE find_kbnode( KBNODE node, int pkttype );
|
|
|
|
KBNODE walk_kbnode( KBNODE root, KBNODE *context, int all );
|
|
|
|
void clear_kbnode_flags( KBNODE n );
|
|
|
|
int commit_kbnode( KBNODE *root );
|
|
|
|
void dump_kbnode( KBNODE node );
|
|
|
|
|
|
|
|
#endif /*G10_KEYDB_H*/
|