XRootD
Loading...
Searching...
No Matches
XrdSecProtocolgsi.hh
Go to the documentation of this file.
1/******************************************************************************/
2/* */
3/* X r d S e c P r o t o c o l g s i . h h */
4/* */
5/* (c) 2005 G. Ganis / CERN */
6/* */
7/* This file is part of the XRootD software suite. */
8/* */
9/* XRootD is free software: you can redistribute it and/or modify it under */
10/* the terms of the GNU Lesser General Public License as published by the */
11/* Free Software Foundation, either version 3 of the License, or (at your */
12/* option) any later version. */
13/* */
14/* XRootD is distributed in the hope that it will be useful, but WITHOUT */
15/* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or */
16/* FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public */
17/* License for more details. */
18/* */
19/* You should have received a copy of the GNU Lesser General Public License */
20/* along with XRootD in a file called COPYING.LESSER (LGPL license) and file */
21/* COPYING (GPL license). If not, see <http://www.gnu.org/licenses/>. */
22/* */
23/* The copyright holder's institutional names and contributor's names may not */
24/* be used to endorse or promote products derived from this software without */
25/* specific prior written permission of the institution or contributor. */
26/* */
27/******************************************************************************/
28#include <ctime>
29#include <memory>
30
32
34#include "XrdOuc/XrdOucGMap.hh"
35#include "XrdOuc/XrdOucHash.hh"
38
40
43
44#include "XrdSut/XrdSutCache.hh"
45
47#include "XrdSut/XrdSutPFile.hh"
49#include "XrdSut/XrdSutRndm.hh"
50
55
57
59
60/******************************************************************************/
61/* D e f i n e s */
62/******************************************************************************/
63
66
67#define XrdSecPROTOIDENT "gsi"
68#define XrdSecPROTOIDLEN sizeof(XrdSecPROTOIDENT)
69#define XrdSecgsiVERSION 10700
70#define XrdSecNOIPCHK 0x0001
71#define XrdSecDEBUG 0x1000
72#define XrdCryptoMax 10
73
74#define kMAXBUFLEN 1024
75
76
77#define XrdSecgsiVersDHsigned 10400 // Version at which started signing
78 // of server DH parameters
79#define XrdSecgsiVersCertKey 10600 // Version at which started supporting
80 // authentication with cert/key only
81#define XrdSecgsiVersRtagHash 10700 // Version at which started signing the
82 // context bound digest of the random
83 // tag instead of the tag itself
84
85//
86// Message codes either returned by server or included in buffers
88 kgST_error = -1, // error occurred
89 kgST_ok = 0, // ok
90 kgST_more = 1 // need more info
91};
92
93// Client steps
96 kXGC_certreq = 1000, // 1000: request server certificate
97 kXGC_cert, // 1001: packet with (proxy) certificate
98 kXGC_sigpxy, // 1002: packet with signed proxy certificate
100};
101
102// Server steps
105 kXGS_init = 2000, // 2000: fake code used the first time
106 kXGS_cert, // 2001: packet with certificate
107 kXGS_pxyreq, // 2002: packet with proxy req to be signed
109};
110
111// Handshake options
113 kOptsDlgPxy = 1, // 0x0001: Ask for a delegated proxy
114 kOptsFwdPxy = 2, // 0x0002: Forward local proxy
115 kOptsSigReq = 4, // 0x0004: Accept to sign delegated proxy
116 kOptsSrvReq = 8, // 0x0008: Server request for delegated proxy
117 kOptsPxFile = 16, // 0x0010: Save delegated proxies in file
118 kOptsDelChn = 32, // 0x0020: Delete chain
119 kOptsPxCred = 64, // 0x0040: Save delegated proxies as credentials
120 kOptsCreatePxy = 128, // 0x0080: Request a client proxy
121 kOptsDelPxy = 256 // 0x0100: Delete the proxy PxyChain
122};
123
124// Error codes
154
155#define REL1(x) { if (x) delete x; }
156#define REL2(x,y) { if (x) delete x; if (y) delete y; }
157#define REL3(x,y,z) { if (x) delete x; if (y) delete y; if (z) delete z; }
158
159#define SafeDelete(x) { if (x) {delete x ; x = 0;} }
160#define SafeDelArray(x) { if (x) {delete [] x ; x = 0;} }
161#define SafeFree(x) { if (x) {free(x) ; x = 0;} }
162
163// External functions for generic mapping
164typedef char *(*XrdSecgsiGMAP_t)(const char *, int);
166typedef int (*XrdSecgsiAuthzInit_t)(const char *);
167typedef int (*XrdSecgsiAuthzKey_t)(XrdSecEntity &, char **);
168// VOMS extraction
171//
172// This a small class to set the relevant options in one go
173//
174class XrdOucGMap;
175class XrdOucTrace;
177public:
178 short debug; // [cs] debug flag
179 char mode; // [cs] 'c' or 's'
180 char *clist; // [s] list of crypto modules ["ssl" ]
181 char *certdir;// [cs] dir with CA info [/etc/grid-security/certificates]
182 char *crldir; // [cs] dir with CRL info [/etc/grid-security/certificates]
183 char *crlext; // [cs] extension of CRL files [.r0]
184 char *cert; // [s] server certificate [/etc/grid-security/root/rootcert.pem]
185 // [c] user certificate [$HOME/.globus/usercert.pem]
186 char *key; // [s] server private key [/etc/grid-security/root/rootkey.pem]
187 // [c] user private key [$HOME/.globus/userkey.pem]
188 char *cipher; // [s] list of ciphers [aes-128-cbc:bf-cbc:des-ede3-cbc]
189 char *md; // [s] list of MDs [sha256:md5]
190 int crl; // [cs] check level of CRL's [1]
191 int ca; // [cs] verification level of CA's [1]
192 int crlrefresh; // [cs] CRL refresh or expiration period in secs [1 day]
193 char *proxy; // [c] user proxy [/tmp/x509up_u<uid>]
194 char *valid; // [c] proxy validity [12:00]
195 int deplen; // [c] depth of signature path for proxies [0]
196 int bits; // [c] bits in PKI for proxies [default: XrdCryptoDefRSABits]
197 char *gridmap;// [s] gridmap file [/etc/grid-security/gridmap]
198 int gmapto; // [s] validity in secs of grid-map cache entries [600 s]
199 char *gmapfun;// [s] file with the function to map DN to usernames [0]
200 char *gmapfunparms;// [s] parameters for the function to map DN to usernames [0]
201 char *authzfun;// [s] file with the function to fill entities [0]
202 char *authzfunparms;// [s] parameters for the function to fill entities [0]
203 int authzcall; // [s] when to call authz function [1 -> always]
204 int authzto; // [s] validity in secs of authz cache entries [-1 => unlimited]
205 int ogmap; // [s] gridmap file checking option
206 int dlgpxy; // [c] explicitely ask the creation of a delegated proxy; default 0
207 // [s] ask client for proxies; default: do not accept delegated proxies
208 int sigpxy; // [c] accept delegated proxy requests
209 int createpxy; // [c] force client proxy authentications
210 char *srvnames;// [c] '|' separated list of allowed server names
211 char *exppxy; // [s] template for the exported file with proxies
212 int authzpxy; // [s] if 1 make proxy available in exported form in the 'endorsement'
213 // field of the XrdSecEntity object for use in XrdAcc
214 int vomsat; // [s] 0 do not look for; 1 extract if any
215 char *vomsfun;// [s] file with the function to fill VOMS [0]
216 char *vomsfunparms;// [s] parameters for the function to fill VOMS [0]
217 int moninfo; // [s] 0 do not look for; 1 use DN as default
218 int hashcomp; // [cs] 1 send hash names with both algorithms; 0 send only the default [1]
219
220 bool trustdns; // [cs] 'true' if DNS is trusted [true]
221 bool showDN; // [cs] 'true' display the dn
222
223 gsiOptions() { debug = -1; mode = 's'; clist = 0;
224 certdir = 0; crldir = 0; crlext = 0; cert = 0; key = 0;
225 cipher = 0; md = 0; ca = 1 ; crl = 1; crlrefresh = 86400;
226 proxy = 0; valid = 0; deplen = 0; bits = XrdCryptoDefRSABits;
227 gridmap = 0; gmapto = 600;
228 gmapfun = 0; gmapfunparms = 0; authzfun = 0; authzfunparms = 0;
229 authzto = -1; authzcall = 1;
230 ogmap = 1; dlgpxy = 0; sigpxy = 1; srvnames = 0;
231 exppxy = 0; authzpxy = 0;
232 vomsat = 1; vomsfun = 0; vomsfunparms = 0; moninfo = 0;
233 hashcomp = 1; trustdns = true; showDN = false; createpxy = 1;}
234 virtual ~gsiOptions() { } // Cleanup inside XrdSecProtocolgsiInit
235 void Print(XrdOucTrace *t); // Print summary of gsi option status
236};
237
239class gsiHSVars;
240
241// From a proxy query
247
248// To query proxies
249typedef struct {
250 const char *cert;
251 const char *key;
252 const char *certdir;
253 const char *out;
254 const char *valid;
256 int bits;
258} ProxyIn_t;
259
260template<class T>
261class GSIStack {
262public:
263 void Add(T *t) {
264 char k[40]; snprintf(k, 40, "%p", static_cast<void*>(t));
265 mtx.Lock();
266 if (!stack.Find(k)) stack.Add(k, t, 0, Hash_count); // We need an additional count
267 stack.Add(k, t, 0, Hash_count);
268 mtx.UnLock();
269 }
270 void Del(T *t) {
271 char k[40]; snprintf(k, 40, "%p", static_cast<void*>(t));
272 mtx.Lock();
273 if (stack.Find(k)) stack.Del(k, Hash_count);
274 mtx.UnLock();
275 }
276private:
277 XrdSysMutex mtx;
278 XrdOucHash<T> stack;
279};
280
281/******************************************************************************/
282/* X r d S e c P r o t o c o l g s i C l a s s */
283/******************************************************************************/
284
286{
287friend class gsiOptions;
288friend class gsiHSVars;
289public:
291 XrdSecParameters **parms,
292 XrdOucErrInfo *einfo=0);
293
295 XrdOucErrInfo *einfo=0);
296
297 XrdSecProtocolgsi(int opts, const char *hname, XrdNetAddrInfo &endPoint,
298 const char *parms = 0);
299 virtual ~XrdSecProtocolgsi() {} // Delete() does it all
300
301 // Initialization methods
302 static char *Init(gsiOptions o, XrdOucErrInfo *erp);
303
304 void Delete();
305
306 // Encrypt / Decrypt methods
307 int Encrypt(const char *inbuf, int inlen,
308 XrdSecBuffer **outbuf);
309 int Decrypt(const char *inbuf, int inlen,
310 XrdSecBuffer **outbuf);
311 // Sign / Verify methods
312 int Sign(const char *inbuf, int inlen,
313 XrdSecBuffer **outbuf);
314 int Verify(const char *inbuf, int inlen,
315 const char *sigbuf, int siglen);
316
317 // Export session key
318 int getKey(char *kbuf=0, int klen=0);
319 // Import a key
320 int setKey(char *kbuf, int klen);
321
322 // Enable tracing
323 static XrdOucTrace *EnableTracing();
324
325private:
326 XrdNetAddrInfo epAddr;
327
328 // Static members initialized at startup
329 static XrdSysMutex gsiContext;
330 static String CAdir;
331 static String CRLdir;
332 static String DefCRLext;
333 static String SrvCert;
334 static String SrvKey;
335 static String UsrProxy;
336 static String UsrCert;
337 static String UsrKey;
338 static String PxyValid;
339 static int DepLength;
340 static int DefBits;
341 static int CACheck;
342 static int CRLCheck;
343 static int CRLDownload;
344 static int CRLRefresh;
345 static String DefCrypto;
346 static String DefCipher;
347 static String DefMD;
348 static String DefError;
349 static String GMAPFile;
350 static int GMAPOpt;
351 static bool GMAPuseDNname;
352 static int GMAPCacheTimeOut;
353 static XrdSecgsiGMAP_t GMAPFun;
354 static XrdSecgsiAuthz_t AuthzFun;
355 static XrdSecgsiAuthzKey_t AuthzKey;
356 static int AuthzCertFmt;
357 static int AuthzCacheTimeOut;
358 static int PxyReqOpts;
359 static int AuthzPxyWhat;
360 static int AuthzPxyWhere;
361 static int AuthzAlways;
362 static String SrvAllowedNames;
363 static int VOMSAttrOpt;
364 static XrdSecgsiVOMS_t VOMSFun;
365 static int VOMSCertFmt;
366 static int MonInfoOpt;
367 static bool HashCompatibility;
368 static bool TrustDNS;
369 static bool ShowDN;
370 //
371 // Crypto related info
372 static int ncrypt; // Number of factories
373 static XrdCryptoFactory *cryptF[XrdCryptoMax]; // their hooks
374 static int cryptID[XrdCryptoMax]; // their IDs
375 static String cryptName[XrdCryptoMax]; // their names
376 static XrdCryptoCipher *refcip[XrdCryptoMax]; // ref for session ciphers
377 //
378 // Caches
379 static XrdSutCache cacheCA; // Info about trusted CA's
380 static XrdSutCache cacheCert; // Server certificates info cache
381 static XrdSutCache cachePxy; // Client proxies cache;
382 static XrdSutCache cacheGMAPFun; // Cache for entries mapped by GMAPFun
383 static XrdSutCache cacheAuthzFun; // Cache for entities filled by AuthzFun
384 //
385 // Services
386 static XrdOucGMap *servGMap; // Grid mapping service
387 //
388 // CA and CRL stacks
389 static GSIStack<XrdCryptoX509Chain> stackCA; // Stack of CA in use
390 static std::unique_ptr<GSIStack<XrdCryptoX509Crl>> stackCRL; // Stack of CRL in use
391 //
392 // GMAP control vars
393 static time_t lastGMAPCheck; // time of last check on GMAP
394 static XrdSysMutex mutexGMAP; // mutex to control GMAP reloads
395 //
396 // Running options / settings
397 static int Debug; // [CS] Debug level
398 static bool Server; // [CS] If server mode
399 static int TimeSkew; // [CS] Allowed skew in secs for time stamps
400 //
401 // for error logging and tracing
402 static XrdSysLogger Logger;
403 static XrdSysError eDest;
404 static XrdOucTrace *GSITrace;
405
406 // Information local to this instance
407 int options;
408 XrdCryptoFactory *sessionCF; // Chosen crypto factory
409 XrdCryptoCipher *sessionKey; // Session Key (result of the handshake)
410 XrdSutBucket *bucketKey; // Bucket with the key in export form
411 XrdCryptoMsgDigest *sessionMD; // Message Digest instance
412 XrdCryptoRSA *sessionKsig; // RSA key to sign
413 XrdCryptoRSA *sessionKver; // RSA key to verify
414 X509Chain *proxyChain; // Chain with the delegated proxy on servers
415 bool srvMode; // TRUE if server mode
416 char *expectedHost; // Expected hostname if TrustDNS is enabled.
417 bool useIV; // Use a non-zeroed unique IV in cipher enc/dec operations
418 String urlUsrProxy; // Proxy file location if given to client in url
419 String urlUsrCert; // Proxy cert location if given to client in url
420 String urlUsrKey; // Proxy key location if given to client in url
421
422 // Temporary Handshake local info
423 gsiHSVars *hs;
424
425 // Parsing received buffers: client
426 int ParseClientInput(XrdSutBuffer *br, XrdSutBuffer **bm,
427 String &emsg);
428 int ClientDoInit(XrdSutBuffer *br, XrdSutBuffer **bm,
429 String &cmsg);
430 int ClientDoCert(XrdSutBuffer *br, XrdSutBuffer **bm,
431 String &cmsg);
432 int ClientDoPxyreq(XrdSutBuffer *br, XrdSutBuffer **bm,
433 String &cmsg);
434
435 // Parsing received buffers: server
436 int ParseServerInput(XrdSutBuffer *br, XrdSutBuffer **bm,
437 String &cmsg);
438 int ServerDoCertreq(XrdSutBuffer *br, XrdSutBuffer **bm,
439 String &cmsg);
440 int ServerDoCert(XrdSutBuffer *br, XrdSutBuffer **bm,
441 String &cmsg);
442 int ServerDoSigpxy(XrdSutBuffer *br, XrdSutBuffer **bm,
443 String &cmsg);
444
445 // Auxilliary functions
446 int ParseCrypto(String cryptlist);
447 int ParseCAlist(String calist);
448
449 // Load CA certificates
450 static int GetCA(const char *cahash,
451 XrdCryptoFactory *cryptof, gsiHSVars *hs = 0);
452 static String GetCApath(const char *cahash);
453 static bool VerifyCA(int opt, X509Chain *cca, XrdCryptoFactory *cf);
454 static int VerifyCRL(XrdCryptoX509Crl *crl, XrdCryptoX509 *xca, XrdOucString crldir,
455 XrdCryptoFactory *CF, int hashalg);
456 bool ServerCertNameOK(const char *subject, const char *hname, String &e);
457 static XrdSutCacheEntry *GetSrvCertEnt(XrdSutCERef &gcref,
459 time_t timestamp, String &cal);
460
461 // Load CRLs
462 static XrdCryptoX509Crl *LoadCRL(XrdCryptoX509 *xca, const char *sjhash,
463 XrdCryptoFactory *CF, int dwld, int &err);
464
465 // Updating proxies
466 static int QueryProxy(bool checkcache, XrdSutCache *cache, const char *tag,
467 XrdCryptoFactory *cf, time_t timestamp,
468 ProxyIn_t *pi, ProxyOut_t *po);
469 static int InitProxy(ProxyIn_t *pi, XrdCryptoFactory *cf,
470 X509Chain *ch = 0, XrdCryptoRSA **key = 0);
471
472 // Error functions
473 static void ErrF(XrdOucErrInfo *einfo, kXR_int32 ecode,
474 const char *msg1, const char *msg2 = 0,
475 const char *msg3 = 0);
478 kXR_int32 ecode, const char *msg1 = 0,
479 const char *msg2 = 0, const char *msg3 = 0);
480 int ErrS(String ID, XrdOucErrInfo *einfo, XrdSutBuffer *b1,
481 XrdSutBuffer *b2, XrdSutBuffer *b3,
482 kXR_int32 ecode, const char *msg1 = 0,
483 const char *msg2 = 0, const char *msg3 = 0);
484
485 // Check Time stamp
486 bool CheckTimeStamp(XrdSutBuffer *b, int skew, String &emsg);
487
488 // Check random challenge
489 bool CheckRtag(XrdSutBuffer *bm, String &emsg);
490
491 // Auxilliary methods
492 int AddSerialized(char opt, kXR_int32 step, String ID,
493 XrdSutBuffer *bls, XrdSutBuffer *buf,
494 kXR_int32 type, XrdCryptoCipher *cip);
495 // Grid map cache handling
496 static XrdSecgsiGMAP_t // Load alternative function for mapping
497 LoadGMAPFun(const char *plugin, const char *parms);
498 static XrdSecgsiAuthz_t // Load alternative function to fill XrdSecEntity
499 LoadAuthzFun(const char *plugin, const char *parms, int &fmt);
500 static XrdSecgsiVOMS_t // Load alternative function to extract VOMS
501 LoadVOMSFun(const char *plugin, const char *parms, int &fmt);
502 static void QueryGMAP(XrdCryptoX509Chain* chain, int now, String &name); //Lookup info for DN
503
504 // Entity handling
505 void CopyEntity(XrdSecEntity *in, XrdSecEntity *out, int *lout = 0);
506 void FreeEntity(XrdSecEntity *in);
507};
508
510public:
511 int Iter; // Iteration number
512 time_t TimeStamp; // Time of last call
513 String CryptoMod; // Crypto module in use
514 int RemVers; // Version run by remote counterpart
515 XrdCryptoCipher *Rcip; // Reference cipher
516 bool HasPad; // Whether padding is supported
517 XrdSutBucket *Cbck; // Bucket with the certificate in export form
518 String ID; // Handshake ID (dummy for clients)
519 XrdSutPFEntry *Cref; // Cache reference
520 XrdSutPFEntry *Pent; // Pointer to relevant file entry
521 X509Chain *Chain; // Chain to be eventually verified
522 XrdCryptoX509Crl *Crl; // Pointer to CRL, if required
523 X509Chain *PxyChain; // Proxy Chain on clients
524 bool RtagOK; // Rndm tag checked / not checked
525 bool Tty; // Terminal attached / not attached
526 int LastStep; // Step required at previous iteration
527 int Options; // Handshake options;
528 int HashAlg; // Hash algorithm of peer hash name;
529 XrdSutBuffer *Parms; // Buffer with server parms on first iteration
530
531 gsiHSVars() { Iter = 0; TimeStamp = -1; CryptoMod = "";
532 RemVers = -1; Rcip = 0; HasPad = 0;
533 Cbck = 0;
534 ID = ""; Cref = 0; Pent = 0; Chain = 0; Crl = 0; PxyChain = 0;
535 RtagOK = 0; Tty = 0; LastStep = 0; Options = 0; HashAlg = 0; Parms = 0;}
536
538 if (Options & kOptsDelChn) {
539 // Do not delete the CA certificate in the cached reference
540 if (Chain) Chain->Cleanup(1);
542 }
543 // Make sure XrdSecProtocolgsi::stackCRL exists, it could happen
544 // that it has been deallocated due to static deinitialization
545 // order fiasco
546 if (Crl && bool( XrdSecProtocolgsi::stackCRL ) ) {
547 // This decreases the counter and actually deletes the object only
548 // when no instance is using it
549 XrdSecProtocolgsi::stackCRL->Del(Crl);
550 Crl = 0;
551 }
552 if (Options & kOptsDelPxy) {
553 if (PxyChain) PxyChain->Cleanup();
555 } else {
556 // The proxy chain is owned by the proxy cache; invalid proxies
557 // are detected (and eventually removed) by QueryProxy
558 PxyChain = 0;
559 }
560 SafeDelete(Parms); }
561 void Dump(XrdSecProtocolgsi *p = 0);
562};
int kXR_int32
Definition XPtypes.hh:89
static XrdSysLogger Logger
static XrdSysError eDest(0,"crypto_")
#define XrdCryptoDefRSABits
@ Hash_count
Definition XrdOucHash.hh:54
XrdSecBuffer XrdSecParameters
XrdSecBuffer XrdSecCredentials
kgsiHandshakeOpts
@ kOptsDelChn
@ kOptsDelPxy
@ kOptsSigReq
@ kOptsFwdPxy
@ kOptsPxCred
@ kOptsSrvReq
@ kOptsDlgPxy
@ kOptsCreatePxy
@ kOptsPxFile
#define SafeDelete(x)
const char * valid
int(* XrdSecgsiAuthz_t)(XrdSecEntity &)
XrdSutBucket * cbck
const char * out
XrdCryptoRSA * ksig
XrdCryptogsiX509Chain X509Chain
const char * key
kgsiServerSteps
@ kXGS_cert
@ kXGS_none
@ kXGS_pxyreq
@ kXGS_init
@ kXGS_reserved
XrdSecgsiAuthz_t XrdSecgsiVOMS_t
int(* XrdSecgsiAuthzKey_t)(XrdSecEntity &, char **)
XrdOucString String
@ kgST_ok
@ kgST_error
@ kgST_more
int(* XrdSecgsiAuthzInit_t)(const char *)
const char * certdir
const char * cert
#define XrdCryptoMax
kgsiClientSteps
@ kXGC_sigpxy
@ kXGC_cert
@ kXGC_reserved
@ kXGC_none
@ kXGC_certreq
XrdSecgsiAuthzInit_t XrdSecgsiVOMSInit_t
@ kGSErrExportPuK
@ kGSErrBadRndmTag
@ kGSErrCreateBuffer
@ kGSErrNoCipher
@ kGSErrInit
@ kGSErrFinCipher
@ kGSErrParseBuffer
@ kGSErrGenCipher
@ kGSErrBadCreds
@ kGSErrUnmarshal
@ kGSErrRefCipher
@ kGSErrBadProtocol
@ kGSErrMarshal
@ kGSErrNoPublic
@ kGSErrSaveCreds
@ kGSErrSerialBuffer
@ kGSErrNoCreds
@ kGSErrDecodeBuffer
@ kGSErrLoadCrypto
@ kGSErrEncRndmTag
@ kGSErrDuplicateBucket
@ kGSErrBadOpt
@ kGSErrNoRndmTag
@ kGSErrAddBucket
@ kGSErrError
@ kGSErrCreateBucket
@ kGSErrNoBuffer
char *(* XrdSecgsiGMAP_t)(const char *, int)
X509Chain * chain
XrdOucString CAdir
XrdOucString CRLdir
bool Debug
int ncrypt
XrdOucString DefCrypto
XrdCryptoFactory ** CF
void ParseCrypto()
struct myOpts opts
int emsg(int rc, char *msg)
#define ID
void Add(T *t)
void Del(T *t)
XrdSecProtocol(const char *pName)
Constructor.
static XrdOucTrace * EnableTracing()
int Authenticate(XrdSecCredentials *cred, XrdSecParameters **parms, XrdOucErrInfo *einfo=0)
int Verify(const char *inbuf, int inlen, const char *sigbuf, int siglen)
XrdSecProtocolgsi(int opts, const char *hname, XrdNetAddrInfo &endPoint, const char *parms=0)
int Decrypt(const char *inbuf, int inlen, XrdSecBuffer **outbuf)
int Encrypt(const char *inbuf, int inlen, XrdSecBuffer **outbuf)
void Delete()
Delete the protocol object. DO NOT use C++ delete() on this object.
static char * Init(gsiOptions o, XrdOucErrInfo *erp)
XrdSecCredentials * getCredentials(XrdSecParameters *parm=0, XrdOucErrInfo *einfo=0)
int getKey(char *kbuf=0, int klen=0)
int Sign(const char *inbuf, int inlen, XrdSecBuffer **outbuf)
int setKey(char *kbuf, int klen)
XrdSutPFEntry * Cref
X509Chain * PxyChain
XrdCryptoX509Crl * Crl
XrdSutBuffer * Parms
XrdSutBucket * Cbck
void Dump(XrdSecProtocolgsi *p=0)
X509Chain * Chain
XrdSutPFEntry * Pent
XrdCryptoCipher * Rcip
virtual ~gsiOptions()
void Print(XrdOucTrace *t)
Generic structure to pass security information back and forth.