67#define XrdSecPROTOIDENT "gsi"
68#define XrdSecPROTOIDLEN sizeof(XrdSecPROTOIDENT)
69#define XrdSecgsiVERSION 10700
70#define XrdSecNOIPCHK 0x0001
71#define XrdSecDEBUG 0x1000
72#define XrdCryptoMax 10
74#define kMAXBUFLEN 1024
77#define XrdSecgsiVersDHsigned 10400
79#define XrdSecgsiVersCertKey 10600
81#define XrdSecgsiVersRtagHash 10700
155#define REL1(x) { if (x) delete x; }
156#define REL2(x,y) { if (x) delete x; if (y) delete y; }
157#define REL3(x,y,z) { if (x) delete x; if (y) delete y; if (z) delete z; }
159#define SafeDelete(x) { if (x) {delete x ; x = 0;} }
160#define SafeDelArray(x) { if (x) {delete [] x ; x = 0;} }
161#define SafeFree(x) { if (x) {free(x) ; x = 0;} }
164typedef char *(*XrdSecgsiGMAP_t)(
const char *, int);
264 char k[40]; snprintf(k, 40,
"%p",
static_cast<void*
>(t));
266 if (!stack.Find(k)) stack.Add(k, t, 0,
Hash_count);
271 char k[40]; snprintf(k, 40,
"%p",
static_cast<void*
>(t));
298 const char *parms = 0);
307 int Encrypt(
const char *inbuf,
int inlen,
309 int Decrypt(
const char *inbuf,
int inlen,
312 int Sign(
const char *inbuf,
int inlen,
314 int Verify(
const char *inbuf,
int inlen,
315 const char *sigbuf,
int siglen);
318 int getKey(
char *kbuf=0,
int klen=0);
320 int setKey(
char *kbuf,
int klen);
339 static int DepLength;
343 static int CRLDownload;
344 static int CRLRefresh;
351 static bool GMAPuseDNname;
352 static int GMAPCacheTimeOut;
356 static int AuthzCertFmt;
357 static int AuthzCacheTimeOut;
358 static int PxyReqOpts;
359 static int AuthzPxyWhat;
360 static int AuthzPxyWhere;
361 static int AuthzAlways;
362 static String SrvAllowedNames;
363 static int VOMSAttrOpt;
365 static int VOMSCertFmt;
366 static int MonInfoOpt;
367 static bool HashCompatibility;
368 static bool TrustDNS;
390 static std::unique_ptr<GSIStack<XrdCryptoX509Crl>> stackCRL;
393 static time_t lastGMAPCheck;
447 int ParseCAlist(
String calist);
450 static int GetCA(
const char *cahash,
452 static String GetCApath(
const char *cahash);
456 bool ServerCertNameOK(
const char *subject,
const char *hname,
String &e);
459 time_t timestamp,
String &cal);
466 static int QueryProxy(
bool checkcache,
XrdSutCache *cache,
const char *tag,
474 const char *msg1,
const char *msg2 = 0,
475 const char *msg3 = 0);
479 const char *msg2 = 0,
const char *msg3 = 0);
483 const char *msg2 = 0,
const char *msg3 = 0);
497 LoadGMAPFun(
const char *plugin,
const char *parms);
499 LoadAuthzFun(
const char *plugin,
const char *parms,
int &fmt);
501 LoadVOMSFun(
const char *plugin,
const char *parms,
int &fmt);
546 if (
Crl &&
bool( XrdSecProtocolgsi::stackCRL ) ) {
549 XrdSecProtocolgsi::stackCRL->Del(
Crl);
static XrdSysLogger Logger
static XrdSysError eDest(0,"crypto_")
#define XrdCryptoDefRSABits
XrdSecBuffer XrdSecParameters
XrdSecBuffer XrdSecCredentials
int(* XrdSecgsiAuthz_t)(XrdSecEntity &)
XrdCryptogsiX509Chain X509Chain
XrdSecgsiAuthz_t XrdSecgsiVOMS_t
int(* XrdSecgsiAuthzKey_t)(XrdSecEntity &, char **)
int(* XrdSecgsiAuthzInit_t)(const char *)
XrdSecgsiAuthzInit_t XrdSecgsiVOMSInit_t
char *(* XrdSecgsiGMAP_t)(const char *, int)
int emsg(int rc, char *msg)
XrdSecProtocol(const char *pName)
Constructor.
static XrdOucTrace * EnableTracing()
int Authenticate(XrdSecCredentials *cred, XrdSecParameters **parms, XrdOucErrInfo *einfo=0)
int Verify(const char *inbuf, int inlen, const char *sigbuf, int siglen)
virtual ~XrdSecProtocolgsi()
XrdSecProtocolgsi(int opts, const char *hname, XrdNetAddrInfo &endPoint, const char *parms=0)
int Decrypt(const char *inbuf, int inlen, XrdSecBuffer **outbuf)
int Encrypt(const char *inbuf, int inlen, XrdSecBuffer **outbuf)
void Delete()
Delete the protocol object. DO NOT use C++ delete() on this object.
static char * Init(gsiOptions o, XrdOucErrInfo *erp)
XrdSecCredentials * getCredentials(XrdSecParameters *parm=0, XrdOucErrInfo *einfo=0)
int getKey(char *kbuf=0, int klen=0)
int Sign(const char *inbuf, int inlen, XrdSecBuffer **outbuf)
int setKey(char *kbuf, int klen)
void Dump(XrdSecProtocolgsi *p=0)
void Print(XrdOucTrace *t)
Generic structure to pass security information back and forth.