XRootD
XrdSecProtocolgsi.hh
Go to the documentation of this file.
1 /******************************************************************************/
2 /* */
3 /* X r d S e c P r o t o c o l g s i . h h */
4 /* */
5 /* (c) 2005 G. Ganis / CERN */
6 /* */
7 /* This file is part of the XRootD software suite. */
8 /* */
9 /* XRootD is free software: you can redistribute it and/or modify it under */
10 /* the terms of the GNU Lesser General Public License as published by the */
11 /* Free Software Foundation, either version 3 of the License, or (at your */
12 /* option) any later version. */
13 /* */
14 /* XRootD is distributed in the hope that it will be useful, but WITHOUT */
15 /* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or */
16 /* FITNESS FOR A PARTICULAR PURPOSE. See the GNU Lesser General Public */
17 /* License for more details. */
18 /* */
19 /* You should have received a copy of the GNU Lesser General Public License */
20 /* along with XRootD in a file called COPYING.LESSER (LGPL license) and file */
21 /* COPYING (GPL license). If not, see <http://www.gnu.org/licenses/>. */
22 /* */
23 /* The copyright holder's institutional names and contributor's names may not */
24 /* be used to endorse or promote products derived from this software without */
25 /* specific prior written permission of the institution or contributor. */
26 /* */
27 /******************************************************************************/
28 #include <ctime>
29 #include <memory>
30 
31 #include "XrdNet/XrdNetAddrInfo.hh"
32 
33 #include "XrdOuc/XrdOucErrInfo.hh"
34 #include "XrdOuc/XrdOucGMap.hh"
35 #include "XrdOuc/XrdOucHash.hh"
36 #include "XrdOuc/XrdOucString.hh"
38 
39 #include "XrdSys/XrdSysPthread.hh"
40 
43 
44 #include "XrdSut/XrdSutCache.hh"
45 
46 #include "XrdSut/XrdSutPFEntry.hh"
47 #include "XrdSut/XrdSutPFile.hh"
48 #include "XrdSut/XrdSutBuffer.hh"
49 #include "XrdSut/XrdSutRndm.hh"
50 
55 
57 
59 
60 /******************************************************************************/
61 /* D e f i n e s */
62 /******************************************************************************/
63 
66 
67 #define XrdSecPROTOIDENT "gsi"
68 #define XrdSecPROTOIDLEN sizeof(XrdSecPROTOIDENT)
69 #define XrdSecgsiVERSION 10700
70 #define XrdSecNOIPCHK 0x0001
71 #define XrdSecDEBUG 0x1000
72 #define XrdCryptoMax 10
73 
74 #define kMAXBUFLEN 1024
75 
76 
77 #define XrdSecgsiVersDHsigned 10400 // Version at which started signing
78  // of server DH parameters
79 #define XrdSecgsiVersCertKey 10600 // Version at which started supporting
80  // authentication with cert/key only
81 #define XrdSecgsiVersRtagHash 10700 // Version at which started signing the
82  // context bound digest of the random
83  // tag instead of the tag itself
84 
85 //
86 // Message codes either returned by server or included in buffers
87 enum kgsiStatus {
88  kgST_error = -1, // error occurred
89  kgST_ok = 0, // ok
90  kgST_more = 1 // need more info
91 };
92 
93 // Client steps
95  kXGC_none = 0,
96  kXGC_certreq = 1000, // 1000: request server certificate
97  kXGC_cert, // 1001: packet with (proxy) certificate
98  kXGC_sigpxy, // 1002: packet with signed proxy certificate
99  kXGC_reserved //
100 };
101 
102 // Server steps
105  kXGS_init = 2000, // 2000: fake code used the first time
106  kXGS_cert, // 2001: packet with certificate
107  kXGS_pxyreq, // 2002: packet with proxy req to be signed
108  kXGS_reserved //
109 };
110 
111 // Handshake options
113  kOptsDlgPxy = 1, // 0x0001: Ask for a delegated proxy
114  kOptsFwdPxy = 2, // 0x0002: Forward local proxy
115  kOptsSigReq = 4, // 0x0004: Accept to sign delegated proxy
116  kOptsSrvReq = 8, // 0x0008: Server request for delegated proxy
117  kOptsPxFile = 16, // 0x0010: Save delegated proxies in file
118  kOptsDelChn = 32, // 0x0020: Delete chain
119  kOptsPxCred = 64, // 0x0040: Save delegated proxies as credentials
120  kOptsCreatePxy = 128, // 0x0080: Request a client proxy
121  kOptsDelPxy = 256 // 0x0100: Delete the proxy PxyChain
122 };
123 
124 // Error codes
126  kGSErrParseBuffer = 10000, // 10000
134  kGSErrGenCipher, // 10008
135  kGSErrExportPuK, // 10009
138  kGSErrNoRndmTag, // 10012
139  kGSErrNoCipher, // 10013
140  kGSErrNoCreds, // 10014
141  kGSErrBadOpt, // 10015
142  kGSErrMarshal, // 10016
143  kGSErrUnmarshal, // 10017
144  kGSErrSaveCreds, // 10018
145  kGSErrNoBuffer, // 10019
146  kGSErrRefCipher, // 10020
147  kGSErrNoPublic, // 10021
148  kGSErrAddBucket, // 10022
149  kGSErrFinCipher, // 10023
150  kGSErrInit, // 10024
151  kGSErrBadCreds, // 10025
152  kGSErrError // 10026
153 };
154 
155 #define REL1(x) { if (x) delete x; }
156 #define REL2(x,y) { if (x) delete x; if (y) delete y; }
157 #define REL3(x,y,z) { if (x) delete x; if (y) delete y; if (z) delete z; }
158 
159 #define SafeDelete(x) { if (x) {delete x ; x = 0;} }
160 #define SafeDelArray(x) { if (x) {delete [] x ; x = 0;} }
161 #define SafeFree(x) { if (x) {free(x) ; x = 0;} }
162 
163 // External functions for generic mapping
164 typedef char *(*XrdSecgsiGMAP_t)(const char *, int);
165 typedef int (*XrdSecgsiAuthz_t)(XrdSecEntity &);
166 typedef int (*XrdSecgsiAuthzInit_t)(const char *);
167 typedef int (*XrdSecgsiAuthzKey_t)(XrdSecEntity &, char **);
168 // VOMS extraction
171 //
172 // This a small class to set the relevant options in one go
173 //
174 class XrdOucGMap;
175 class XrdOucTrace;
176 class gsiOptions {
177 public:
178  short debug; // [cs] debug flag
179  char mode; // [cs] 'c' or 's'
180  char *clist; // [s] list of crypto modules ["ssl" ]
181  char *certdir;// [cs] dir with CA info [/etc/grid-security/certificates]
182  char *crldir; // [cs] dir with CRL info [/etc/grid-security/certificates]
183  char *crlext; // [cs] extension of CRL files [.r0]
184  char *cert; // [s] server certificate [/etc/grid-security/root/rootcert.pem]
185  // [c] user certificate [$HOME/.globus/usercert.pem]
186  char *key; // [s] server private key [/etc/grid-security/root/rootkey.pem]
187  // [c] user private key [$HOME/.globus/userkey.pem]
188  char *cipher; // [s] list of ciphers [aes-128-cbc:bf-cbc:des-ede3-cbc]
189  char *md; // [s] list of MDs [sha256:md5]
190  int crl; // [cs] check level of CRL's [1]
191  int ca; // [cs] verification level of CA's [1]
192  int crlrefresh; // [cs] CRL refresh or expiration period in secs [1 day]
193  char *proxy; // [c] user proxy [/tmp/x509up_u<uid>]
194  char *valid; // [c] proxy validity [12:00]
195  int deplen; // [c] depth of signature path for proxies [0]
196  int bits; // [c] bits in PKI for proxies [default: XrdCryptoDefRSABits]
197  char *gridmap;// [s] gridmap file [/etc/grid-security/gridmap]
198  int gmapto; // [s] validity in secs of grid-map cache entries [600 s]
199  char *gmapfun;// [s] file with the function to map DN to usernames [0]
200  char *gmapfunparms;// [s] parameters for the function to map DN to usernames [0]
201  char *authzfun;// [s] file with the function to fill entities [0]
202  char *authzfunparms;// [s] parameters for the function to fill entities [0]
203  int authzcall; // [s] when to call authz function [1 -> always]
204  int authzto; // [s] validity in secs of authz cache entries [-1 => unlimited]
205  int ogmap; // [s] gridmap file checking option
206  int dlgpxy; // [c] explicitely ask the creation of a delegated proxy; default 0
207  // [s] ask client for proxies; default: do not accept delegated proxies
208  int sigpxy; // [c] accept delegated proxy requests
209  int createpxy; // [c] force client proxy authentications
210  char *srvnames;// [c] '|' separated list of allowed server names
211  char *exppxy; // [s] template for the exported file with proxies
212  int authzpxy; // [s] if 1 make proxy available in exported form in the 'endorsement'
213  // field of the XrdSecEntity object for use in XrdAcc
214  int vomsat; // [s] 0 do not look for; 1 extract if any
215  char *vomsfun;// [s] file with the function to fill VOMS [0]
216  char *vomsfunparms;// [s] parameters for the function to fill VOMS [0]
217  int moninfo; // [s] 0 do not look for; 1 use DN as default
218  int hashcomp; // [cs] 1 send hash names with both algorithms; 0 send only the default [1]
219 
220  bool trustdns; // [cs] 'true' if DNS is trusted [true]
221  bool showDN; // [cs] 'true' display the dn
222 
223  gsiOptions() { debug = -1; mode = 's'; clist = 0;
224  certdir = 0; crldir = 0; crlext = 0; cert = 0; key = 0;
225  cipher = 0; md = 0; ca = 1 ; crl = 1; crlrefresh = 86400;
226  proxy = 0; valid = 0; deplen = 0; bits = XrdCryptoDefRSABits;
227  gridmap = 0; gmapto = 600;
228  gmapfun = 0; gmapfunparms = 0; authzfun = 0; authzfunparms = 0;
229  authzto = -1; authzcall = 1;
230  ogmap = 1; dlgpxy = 0; sigpxy = 1; srvnames = 0;
231  exppxy = 0; authzpxy = 0;
232  vomsat = 1; vomsfun = 0; vomsfunparms = 0; moninfo = 0;
233  hashcomp = 1; trustdns = true; showDN = false; createpxy = 1;}
234  virtual ~gsiOptions() { } // Cleanup inside XrdSecProtocolgsiInit
235  void Print(XrdOucTrace *t); // Print summary of gsi option status
236 };
237 
238 class XrdSecProtocolgsi;
239 class gsiHSVars;
240 
241 // From a proxy query
242 typedef struct {
246 } ProxyOut_t;
247 
248 // To query proxies
249 typedef struct {
250  const char *cert;
251  const char *key;
252  const char *certdir;
253  const char *out;
254  const char *valid;
255  int deplen;
256  int bits;
257  bool createpxy;
258 } ProxyIn_t;
259 
260 template<class T>
261 class GSIStack {
262 public:
263  void Add(T *t) {
264  char k[40]; snprintf(k, 40, "%p", static_cast<void*>(t));
265  mtx.Lock();
266  if (!stack.Find(k)) stack.Add(k, t, 0, Hash_count); // We need an additional count
267  stack.Add(k, t, 0, Hash_count);
268  mtx.UnLock();
269  }
270  void Del(T *t) {
271  char k[40]; snprintf(k, 40, "%p", static_cast<void*>(t));
272  mtx.Lock();
273  if (stack.Find(k)) stack.Del(k, Hash_count);
274  mtx.UnLock();
275  }
276 private:
277  XrdSysMutex mtx;
278  XrdOucHash<T> stack;
279 };
280 
281 /******************************************************************************/
282 /* X r d S e c P r o t o c o l g s i C l a s s */
283 /******************************************************************************/
284 
286 {
287 friend class gsiOptions;
288 friend class gsiHSVars;
289 public:
290  int Authenticate (XrdSecCredentials *cred,
291  XrdSecParameters **parms,
292  XrdOucErrInfo *einfo=0);
293 
295  XrdOucErrInfo *einfo=0);
296 
297  XrdSecProtocolgsi(int opts, const char *hname, XrdNetAddrInfo &endPoint,
298  const char *parms = 0);
299  virtual ~XrdSecProtocolgsi() {} // Delete() does it all
300 
301  // Initialization methods
302  static char *Init(gsiOptions o, XrdOucErrInfo *erp);
303 
304  void Delete();
305 
306  // Encrypt / Decrypt methods
307  int Encrypt(const char *inbuf, int inlen,
308  XrdSecBuffer **outbuf);
309  int Decrypt(const char *inbuf, int inlen,
310  XrdSecBuffer **outbuf);
311  // Sign / Verify methods
312  int Sign(const char *inbuf, int inlen,
313  XrdSecBuffer **outbuf);
314  int Verify(const char *inbuf, int inlen,
315  const char *sigbuf, int siglen);
316 
317  // Export session key
318  int getKey(char *kbuf=0, int klen=0);
319  // Import a key
320  int setKey(char *kbuf, int klen);
321 
322  // Enable tracing
323  static XrdOucTrace *EnableTracing();
324 
325 private:
326  XrdNetAddrInfo epAddr;
327 
328  // Static members initialized at startup
329  static XrdSysMutex gsiContext;
330  static String CAdir;
331  static String CRLdir;
332  static String DefCRLext;
333  static String SrvCert;
334  static String SrvKey;
335  static String UsrProxy;
336  static String UsrCert;
337  static String UsrKey;
338  static String PxyValid;
339  static int DepLength;
340  static int DefBits;
341  static int CACheck;
342  static int CRLCheck;
343  static int CRLDownload;
344  static int CRLRefresh;
345  static String DefCrypto;
346  static String DefCipher;
347  static String DefMD;
348  static String DefError;
349  static String GMAPFile;
350  static int GMAPOpt;
351  static bool GMAPuseDNname;
352  static int GMAPCacheTimeOut;
353  static XrdSecgsiGMAP_t GMAPFun;
354  static XrdSecgsiAuthz_t AuthzFun;
355  static XrdSecgsiAuthzKey_t AuthzKey;
356  static int AuthzCertFmt;
357  static int AuthzCacheTimeOut;
358  static int PxyReqOpts;
359  static int AuthzPxyWhat;
360  static int AuthzPxyWhere;
361  static int AuthzAlways;
362  static String SrvAllowedNames;
363  static int VOMSAttrOpt;
364  static XrdSecgsiVOMS_t VOMSFun;
365  static int VOMSCertFmt;
366  static int MonInfoOpt;
367  static bool HashCompatibility;
368  static bool TrustDNS;
369  static bool ShowDN;
370  //
371  // Crypto related info
372  static int ncrypt; // Number of factories
373  static XrdCryptoFactory *cryptF[XrdCryptoMax]; // their hooks
374  static int cryptID[XrdCryptoMax]; // their IDs
375  static String cryptName[XrdCryptoMax]; // their names
376  static XrdCryptoCipher *refcip[XrdCryptoMax]; // ref for session ciphers
377  //
378  // Caches
379  static XrdSutCache cacheCA; // Info about trusted CA's
380  static XrdSutCache cacheCert; // Server certificates info cache
381  static XrdSutCache cachePxy; // Client proxies cache;
382  static XrdSutCache cacheGMAPFun; // Cache for entries mapped by GMAPFun
383  static XrdSutCache cacheAuthzFun; // Cache for entities filled by AuthzFun
384  //
385  // Services
386  static XrdOucGMap *servGMap; // Grid mapping service
387  //
388  // CA and CRL stacks
389  static GSIStack<XrdCryptoX509Chain> stackCA; // Stack of CA in use
390  static std::unique_ptr<GSIStack<XrdCryptoX509Crl>> stackCRL; // Stack of CRL in use
391  //
392  // GMAP control vars
393  static time_t lastGMAPCheck; // time of last check on GMAP
394  static XrdSysMutex mutexGMAP; // mutex to control GMAP reloads
395  //
396  // Running options / settings
397  static int Debug; // [CS] Debug level
398  static bool Server; // [CS] If server mode
399  static int TimeSkew; // [CS] Allowed skew in secs for time stamps
400  //
401  // for error logging and tracing
402  static XrdSysLogger Logger;
403  static XrdSysError eDest;
404  static XrdOucTrace *GSITrace;
405 
406  // Information local to this instance
407  int options;
408  XrdCryptoFactory *sessionCF; // Chosen crypto factory
409  XrdCryptoCipher *sessionKey; // Session Key (result of the handshake)
410  XrdSutBucket *bucketKey; // Bucket with the key in export form
411  XrdCryptoMsgDigest *sessionMD; // Message Digest instance
412  XrdCryptoRSA *sessionKsig; // RSA key to sign
413  XrdCryptoRSA *sessionKver; // RSA key to verify
414  X509Chain *proxyChain; // Chain with the delegated proxy on servers
415  bool srvMode; // TRUE if server mode
416  char *expectedHost; // Expected hostname if TrustDNS is enabled.
417  bool useIV; // Use a non-zeroed unique IV in cipher enc/dec operations
418  String urlUsrProxy; // Proxy file location if given to client in url
419  String urlUsrCert; // Proxy cert location if given to client in url
420  String urlUsrKey; // Proxy key location if given to client in url
421 
422  // Temporary Handshake local info
423  gsiHSVars *hs;
424 
425  // Parsing received buffers: client
426  int ParseClientInput(XrdSutBuffer *br, XrdSutBuffer **bm,
427  String &emsg);
428  int ClientDoInit(XrdSutBuffer *br, XrdSutBuffer **bm,
429  String &cmsg);
430  int ClientDoCert(XrdSutBuffer *br, XrdSutBuffer **bm,
431  String &cmsg);
432  int ClientDoPxyreq(XrdSutBuffer *br, XrdSutBuffer **bm,
433  String &cmsg);
434 
435  // Parsing received buffers: server
436  int ParseServerInput(XrdSutBuffer *br, XrdSutBuffer **bm,
437  String &cmsg);
438  int ServerDoCertreq(XrdSutBuffer *br, XrdSutBuffer **bm,
439  String &cmsg);
440  int ServerDoCert(XrdSutBuffer *br, XrdSutBuffer **bm,
441  String &cmsg);
442  int ServerDoSigpxy(XrdSutBuffer *br, XrdSutBuffer **bm,
443  String &cmsg);
444 
445  // Auxilliary functions
446  int ParseCrypto(String cryptlist);
447  int ParseCAlist(String calist);
448 
449  // Load CA certificates
450  static int GetCA(const char *cahash,
451  XrdCryptoFactory *cryptof, gsiHSVars *hs = 0);
452  static String GetCApath(const char *cahash);
453  static bool VerifyCA(int opt, X509Chain *cca, XrdCryptoFactory *cf);
454  static int VerifyCRL(XrdCryptoX509Crl *crl, XrdCryptoX509 *xca, XrdOucString crldir,
455  XrdCryptoFactory *CF, int hashalg);
456  bool ServerCertNameOK(const char *subject, const char *hname, String &e);
457  static XrdSutCacheEntry *GetSrvCertEnt(XrdSutCERef &gcref,
458  XrdCryptoFactory *cf,
459  time_t timestamp, String &cal);
460 
461  // Load CRLs
462  static XrdCryptoX509Crl *LoadCRL(XrdCryptoX509 *xca, const char *sjhash,
463  XrdCryptoFactory *CF, int dwld, int &err);
464 
465  // Updating proxies
466  static int QueryProxy(bool checkcache, XrdSutCache *cache, const char *tag,
467  XrdCryptoFactory *cf, time_t timestamp,
468  ProxyIn_t *pi, ProxyOut_t *po);
469  static int InitProxy(ProxyIn_t *pi, XrdCryptoFactory *cf,
470  X509Chain *ch = 0, XrdCryptoRSA **key = 0);
471 
472  // Error functions
473  static void ErrF(XrdOucErrInfo *einfo, kXR_int32 ecode,
474  const char *msg1, const char *msg2 = 0,
475  const char *msg3 = 0);
476  XrdSecCredentials *ErrC(XrdOucErrInfo *einfo, XrdSutBuffer *b1,
477  XrdSutBuffer *b2,XrdSutBuffer *b3,
478  kXR_int32 ecode, const char *msg1 = 0,
479  const char *msg2 = 0, const char *msg3 = 0);
480  int ErrS(String ID, XrdOucErrInfo *einfo, XrdSutBuffer *b1,
481  XrdSutBuffer *b2, XrdSutBuffer *b3,
482  kXR_int32 ecode, const char *msg1 = 0,
483  const char *msg2 = 0, const char *msg3 = 0);
484 
485  // Check Time stamp
486  bool CheckTimeStamp(XrdSutBuffer *b, int skew, String &emsg);
487 
488  // Check random challenge
489  bool CheckRtag(XrdSutBuffer *bm, String &emsg);
490 
491  // Auxilliary methods
492  int AddSerialized(char opt, kXR_int32 step, String ID,
493  XrdSutBuffer *bls, XrdSutBuffer *buf,
494  kXR_int32 type, XrdCryptoCipher *cip);
495  // Grid map cache handling
496  static XrdSecgsiGMAP_t // Load alternative function for mapping
497  LoadGMAPFun(const char *plugin, const char *parms);
498  static XrdSecgsiAuthz_t // Load alternative function to fill XrdSecEntity
499  LoadAuthzFun(const char *plugin, const char *parms, int &fmt);
500  static XrdSecgsiVOMS_t // Load alternative function to extract VOMS
501  LoadVOMSFun(const char *plugin, const char *parms, int &fmt);
502  static void QueryGMAP(XrdCryptoX509Chain* chain, int now, String &name); //Lookup info for DN
503 
504  // Entity handling
505  void CopyEntity(XrdSecEntity *in, XrdSecEntity *out, int *lout = 0);
506  void FreeEntity(XrdSecEntity *in);
507 };
508 
509 class gsiHSVars {
510 public:
511  int Iter; // Iteration number
512  time_t TimeStamp; // Time of last call
513  String CryptoMod; // Crypto module in use
514  int RemVers; // Version run by remote counterpart
515  XrdCryptoCipher *Rcip; // Reference cipher
516  bool HasPad; // Whether padding is supported
517  XrdSutBucket *Cbck; // Bucket with the certificate in export form
518  String ID; // Handshake ID (dummy for clients)
519  XrdSutPFEntry *Cref; // Cache reference
520  XrdSutPFEntry *Pent; // Pointer to relevant file entry
521  X509Chain *Chain; // Chain to be eventually verified
522  XrdCryptoX509Crl *Crl; // Pointer to CRL, if required
523  X509Chain *PxyChain; // Proxy Chain on clients
524  bool RtagOK; // Rndm tag checked / not checked
525  bool Tty; // Terminal attached / not attached
526  int LastStep; // Step required at previous iteration
527  int Options; // Handshake options;
528  int HashAlg; // Hash algorithm of peer hash name;
529  XrdSutBuffer *Parms; // Buffer with server parms on first iteration
530 
531  gsiHSVars() { Iter = 0; TimeStamp = -1; CryptoMod = "";
532  RemVers = -1; Rcip = 0; HasPad = 0;
533  Cbck = 0;
534  ID = ""; Cref = 0; Pent = 0; Chain = 0; Crl = 0; PxyChain = 0;
535  RtagOK = 0; Tty = 0; LastStep = 0; Options = 0; HashAlg = 0; Parms = 0;}
536 
538  if (Options & kOptsDelChn) {
539  // Do not delete the CA certificate in the cached reference
540  if (Chain) Chain->Cleanup(1);
541  SafeDelete(Chain);
542  }
543  // Make sure XrdSecProtocolgsi::stackCRL exists, it could happen
544  // that it has been deallocated due to static deinitialization
545  // order fiasco
546  if (Crl && bool( XrdSecProtocolgsi::stackCRL ) ) {
547  // This decreases the counter and actually deletes the object only
548  // when no instance is using it
549  XrdSecProtocolgsi::stackCRL->Del(Crl);
550  Crl = 0;
551  }
552  if (Options & kOptsDelPxy) {
553  if (PxyChain) PxyChain->Cleanup();
555  } else {
556  // The proxy chain is owned by the proxy cache; invalid proxies
557  // are detected (and eventually removed) by QueryProxy
558  PxyChain = 0;
559  }
560  SafeDelete(Parms); }
561  void Dump(XrdSecProtocolgsi *p = 0);
562 };
int kXR_int32
Definition: XPtypes.hh:89
static XrdSysError eDest(0,"crypto_")
#define XrdCryptoDefRSABits
Definition: XrdCryptoAux.hh:53
@ Hash_count
Definition: XrdOucHash.hh:54
kgsiHandshakeOpts
@ kOptsDelChn
@ kOptsDelPxy
@ kOptsSigReq
@ kOptsFwdPxy
@ kOptsPxCred
@ kOptsSrvReq
@ kOptsDlgPxy
@ kOptsCreatePxy
@ kOptsPxFile
#define SafeDelete(x)
const char * valid
int(* XrdSecgsiAuthz_t)(XrdSecEntity &)
XrdSutBucket * cbck
const char * out
XrdCryptoRSA * ksig
XrdCryptogsiX509Chain X509Chain
const char * key
kgsiServerSteps
@ kXGS_cert
@ kXGS_none
@ kXGS_pxyreq
@ kXGS_init
@ kXGS_reserved
XrdSecgsiAuthz_t XrdSecgsiVOMS_t
int(* XrdSecgsiAuthzKey_t)(XrdSecEntity &, char **)
XrdOucString String
kgsiStatus
@ kgST_ok
@ kgST_error
@ kgST_more
int(* XrdSecgsiAuthzInit_t)(const char *)
const char * certdir
char *(* XrdSecgsiGMAP_t)(const char *, int)
const char * cert
#define XrdCryptoMax
kgsiClientSteps
@ kXGC_sigpxy
@ kXGC_cert
@ kXGC_reserved
@ kXGC_none
@ kXGC_certreq
XrdSecgsiAuthzInit_t XrdSecgsiVOMSInit_t
@ kGSErrExportPuK
@ kGSErrBadRndmTag
@ kGSErrCreateBuffer
@ kGSErrNoCipher
@ kGSErrInit
@ kGSErrFinCipher
@ kGSErrParseBuffer
@ kGSErrGenCipher
@ kGSErrBadCreds
@ kGSErrUnmarshal
@ kGSErrRefCipher
@ kGSErrBadProtocol
@ kGSErrMarshal
@ kGSErrNoPublic
@ kGSErrSaveCreds
@ kGSErrSerialBuffer
@ kGSErrNoCreds
@ kGSErrDecodeBuffer
@ kGSErrLoadCrypto
@ kGSErrEncRndmTag
@ kGSErrDuplicateBucket
@ kGSErrBadOpt
@ kGSErrNoRndmTag
@ kGSErrAddBucket
@ kGSErrError
@ kGSErrCreateBucket
@ kGSErrNoBuffer
X509Chain * chain
XrdOucString CAdir
XrdOucString CRLdir
bool Debug
int ncrypt
XrdOucString DefCrypto
XrdCryptoFactory ** CF
void ParseCrypto()
struct myOpts opts
int emsg(int rc, char *msg)
#define ID
void Add(T *t)
void Del(T *t)
void Cleanup(bool keepCA=0)
static XrdOucTrace * EnableTracing()
int Authenticate(XrdSecCredentials *cred, XrdSecParameters **parms, XrdOucErrInfo *einfo=0)
int Verify(const char *inbuf, int inlen, const char *sigbuf, int siglen)
XrdSecProtocolgsi(int opts, const char *hname, XrdNetAddrInfo &endPoint, const char *parms=0)
int Decrypt(const char *inbuf, int inlen, XrdSecBuffer **outbuf)
int Encrypt(const char *inbuf, int inlen, XrdSecBuffer **outbuf)
void Delete()
Delete the protocol object. DO NOT use C++ delete() on this object.
static char * Init(gsiOptions o, XrdOucErrInfo *erp)
XrdSecCredentials * getCredentials(XrdSecParameters *parm=0, XrdOucErrInfo *einfo=0)
int getKey(char *kbuf=0, int klen=0)
int Sign(const char *inbuf, int inlen, XrdSecBuffer **outbuf)
int setKey(char *kbuf, int klen)
XrdSutPFEntry * Cref
X509Chain * PxyChain
XrdCryptoX509Crl * Crl
XrdSutBuffer * Parms
XrdSutBucket * Cbck
void Dump(XrdSecProtocolgsi *p=0)
X509Chain * Chain
XrdSutPFEntry * Pent
XrdCryptoCipher * Rcip
virtual ~gsiOptions()
void Print(XrdOucTrace *t)
XrdSysLogger Logger
Definition: XrdGlobals.cc:47
Generic structure to pass security information back and forth.