Annotation of sbbs/include/cryptlib/cryptlib.h, revision 1.1.1.1

1.1       root        1: /****************************************************************************
                      2: *                                                                                                                                                      *
                      3: *                                                              cryptlib Interface                                                      *
                      4: *                                              Copyright Peter Gutmann 1992-2006                                       *
                      5: *                                                                                                                                                      *
                      6: ****************************************************************************/
                      7: 
                      8: #ifndef _CRYPTLIB_DEFINED
                      9: 
                     10: #define _CRYPTLIB_DEFINED
                     11: 
                     12: /* The current cryptlib version: 3.3.0.0 */
                     13: 
                     14: #define CRYPTLIB_VERSION       3300
                     15: 
                     16: /* Fixup for Windows support.  We need to include windows.h for various types
                     17:    and prototypes needed for DLL's.  In addition wincrypt.h defines some
                     18:    values with the same names as cryptlib ones, so we need to check for this
                     19:    and issue a warning not to mix cryptlib with CryptoAPI (that's like taking
                     20:    a bank vault and making one side out of papier mache).
                     21: 
                     22:    A second, less likely condition can occur when wincrypt.h is included
                     23:    after cryptlib.h, which shouldn't happen if developers follow the
                     24:    convention of including local headers after system headers, but can occur
                     25:    if they ignore this convention.  The NOCRYPT doesn't fix this since
                     26:    wincrypt.h can be pulled in indirectly and unconditionally, for example
                     27:    via winldap.h -> schnlsp.h -> schannel.h -> wincrypt.h.  To fix this, we
                     28:    create a redundant define for CRYPT_MODE_ECB which produces a compile
                     29:    error if wincrypt.h is included after cryptlib.h.  Since thie will
                     30:    conflict with the enum, we have to place it after the CRYPT_MODE_xxx
                     31:    enums */
                     32: 
                     33: #if ( defined( _WINDOWS ) || defined( WIN32 ) || defined( _WIN32 ) || \
                     34:          defined( __WIN32__ ) || defined( _WIN32_WCE ) ) && \
                     35:          !defined( _SCCTK ) && !defined( _CVI_ )
                     36:   #define WIN32_LEAN_AND_MEAN  /* Skip RPC, OLE, Multimedia, etc */
                     37:   #define NOCRYPT                              /* Disable include of wincrypt.h */
                     38:   #include <windows.h>
                     39: 
                     40:   /* Catch use of CryptoAPI and cryptlib at the same time */
                     41:   #if defined( CRYPT_MODE_ECB )
                     42:        #error "cryptlib.h and wincrypt.h can't both be used at the same time due to conflicting type names"
                     43:   #endif /* Clash with wincrypt.h defines */
                     44: #endif /* Windows other than a cross-development environment */
                     45: 
                     46: /* Machine-dependant types to allow use in special library types such as
                     47:    DLL's.  Under Win32 and BeOS we need to use the dllimport and dllexport
                     48:    directives for the DLL/shared-lib version so we define the type used for
                     49:    functions depending on whether we're being included via the cryptlib-
                     50:    internal crypt.h or not */
                     51: 
                     52: #if ( defined( WIN32 ) || defined( _WIN32 ) || defined( __WIN32__ ) || \
                     53:          defined( _WIN32_WCE ) ) && !( defined( STATIC_LIB ) || defined( _SCCTK ) )
                     54:   #define C_PTR        *                                       /* General pointer */
                     55:   #if defined( _WIN32_WCE )
                     56:        /* Rather than relying on _UNICODE being defined (which would cause
                     57:           problems if cryptlib is built with char * but the calling app is built
                     58:           with wchar_t *), we always use the default native char type, which is
                     59:           ASCII (or at least 8-bit) under Win32 and Unicode under WinCE */
                     60:        #define C_CHR wchar_t
                     61:   #else
                     62:        #define C_CHR char
                     63:   #endif /* WinCE vs. Win32 */
                     64:   #define C_STR C_CHR *
                     65:   #if defined( __BORLANDC__ ) && ( __BORLANDC__ < 0x500 )
                     66:        #ifdef _CRYPT_DEFINED
                     67:          #define C_RET int     _export _stdcall                /* BC++ DLL export ret.val.*/
                     68:        #else
                     69:          #define C_RET int     _import _stdcall                /* BC++ DLL import ret.val.*/
                     70:        #endif /* CRYPT_DEFINED */
                     71:   #else
                     72:        #ifdef _CRYPT_DEFINED
                     73:          #define C_RET __declspec( dllexport ) int     __stdcall       /* DLL export ret.val.*/
                     74:        #else
                     75:          #define C_RET __declspec( dllimport ) int     __stdcall       /* DLL import ret.val.*/
                     76:        #endif /* CRYPT_DEFINED */
                     77:   #endif /* BC++ vs.VC++ DLL functions */
                     78: #elif defined( _WINDOWS ) && !defined( STATIC_LIB )
                     79:   #define C_PTR        FAR *                           /* DLL pointer */
                     80:   #define C_CHR char
                     81:   #define C_STR C_CHR FAR *                    /* DLL string pointer */
                     82:   #define C_RET        int FAR PASCAL _export  /* DLL return value */
                     83: #elif defined( __BEOS__ )
                     84: /* #include <BeBuild.h>                                // _EXPORT/_IMPORT defines */
                     85:   #define C_PTR *
                     86:   #define C_CHR char
                     87:   #define C_STR C_CHR *
                     88:   #ifdef _STATIC_LINKING
                     89:        #define C_RET int
                     90:   #else
                     91:        #ifdef _CRYPT_DEFINED
                     92:          #define C_RET __declspec( dllexport ) int     /* Shared lib export ret.val.*/
                     93:        #else
                     94:          #define C_RET __declspec( dllimport ) int     /* Shared lib import ret.val.*/
                     95:        #endif /* CRYPT_DEFINED */
                     96:   #endif /* Static vs. shared lib */
                     97: #elif defined( __SYMBIAN__ )
                     98:   #ifdef _CRYPT_DEFINED
                     99:        #define C_RET   EXPORT_C                                        /* DLL export ret.val.*/
                    100:   #else
                    101:        #define C_RET   IMPORT_C                                        /* DLL import ret.val.*/
                    102:   #endif /* CRYPT_DEFINED */
                    103: #else
                    104:   #define C_PTR        *
                    105:   #define C_CHR char
                    106:   #define C_STR C_CHR *
                    107:   #define C_RET        int
                    108: #endif /* Windows vs.everything else function types */
                    109: 
                    110: /* Symbolic defines to make it clearer how the function parameters behave */
                    111: 
                    112: #define C_IN   const                           /* Input-only */
                    113: #define C_OUT                                          /* Output-only */
                    114: #define C_INOUT                                                /* Modified in-place */
                    115: 
                    116: #ifdef _CRYPTLIB_DEFINED                       /* Disable use in non-C versions of header */
                    117: 
                    118: /* Alongside the externally visible types, cryptlib also has various internal
                    119:    types that are extended forms of the external types that are invisible
                    120:    to the user (e.g. SignedPublicKeyAndChallenge == certRequest).  These can
                    121:    only be used internally and are blocked by the security kernel, so they
                    122:    can never be accessed from outside cryptlib (in fact for good measure
                    123:    they're blocked before they even get to the kernel by preliminary range
                    124:    checks in the API wrapper functions).  The only reason they're defined
                    125:    here is because it's not possible to extend an enum outside the point
                    126:    where it's originally defined */
                    127: 
                    128: #endif /* _CRYPTLIB_DEFINED */
                    129: 
                    130: /****************************************************************************
                    131: *                                                                                                                                                      *
                    132: *                                                      Algorithm and Object Types                                              *
                    133: *                                                                                                                                                      *
                    134: ****************************************************************************/
                    135: 
                    136: /* Algorithm and mode types */
                    137: 
                    138: typedef enum {                                         /* Algorithms */
                    139:        /* No encryption */
                    140:        CRYPT_ALGO_NONE,                                /* No encryption */
                    141: 
                    142:        /* Conventional encryption */
                    143:        CRYPT_ALGO_DES,                                 /* DES */
                    144:        CRYPT_ALGO_3DES,                                /* Triple DES */
                    145:        CRYPT_ALGO_IDEA,                                /* IDEA */
                    146:        CRYPT_ALGO_CAST,                                /* CAST-128 */
                    147:        CRYPT_ALGO_RC2,                                 /* RC2 */
                    148:        CRYPT_ALGO_RC4,                                 /* RC4 */
                    149:        CRYPT_ALGO_RC5,                                 /* RC5 */
                    150:        CRYPT_ALGO_AES,                                 /* AES */
                    151:        CRYPT_ALGO_BLOWFISH,                    /* Blowfish */
                    152:        CRYPT_ALGO_SKIPJACK,                    /* Skipjack */
                    153: 
                    154:        /* Public-key encryption */
                    155:        CRYPT_ALGO_DH = 100,                    /* Diffie-Hellman */
                    156:        CRYPT_ALGO_RSA,                                 /* RSA */
                    157:        CRYPT_ALGO_DSA,                                 /* DSA */
                    158:        CRYPT_ALGO_ELGAMAL,                             /* ElGamal */
                    159:        CRYPT_ALGO_KEA,                                 /* KEA */
                    160: 
                    161:        /* Hash algorithms */
                    162:        CRYPT_ALGO_MD2 = 200,                   /* MD2 */
                    163:        CRYPT_ALGO_MD4,                                 /* MD4 */
                    164:        CRYPT_ALGO_MD5,                                 /* MD5 */
                    165:        CRYPT_ALGO_SHA,                                 /* SHA/SHA1 */
                    166:        CRYPT_ALGO_RIPEMD160,                   /* RIPE-MD 160 */
                    167:        CRYPT_ALGO_SHA2,                                /* SHA2 (SHA-256/384/512)*/
                    168: 
                    169:        /* MAC's */
                    170:        CRYPT_ALGO_HMAC_MD5 = 300,              /* HMAC-MD5 */
                    171:        CRYPT_ALGO_HMAC_SHA1,                   /* HMAC-SHA */
                    172:                CRYPT_ALGO_HMAC_SHA = CRYPT_ALGO_HMAC_SHA1,     /* Older form */
                    173:        CRYPT_ALGO_HMAC_RIPEMD160,              /* HMAC-RIPEMD-160 */
                    174: 
                    175:        /* Vendors may want to use their own algorithms that aren't part of the
                    176:           general cryptlib suite.  The following values are for vendor-defined
                    177:           algorithms, and can be used just like the named algorithm types (it's
                    178:           up to the vendor to keep track of what _VENDOR1 actually corresponds
                    179:           to) */
                    180: #ifdef USE_VENDOR_ALGOS
                    181:        CRYPT_ALGO_VENDOR1 = 10000, CRYPT_ALGO_VENDOR2, CRYPT_ALGO_VENDOR3,
                    182: #endif /* USE_VENDOR_ALGOS */
                    183: 
                    184:        CRYPT_ALGO_LAST,                                /* Last possible crypt algo value */
                    185: 
                    186:        /* In order that we can scan through a range of algorithms with
                    187:           cryptQueryCapability(), we define the following boundary points for
                    188:           each algorithm class */
                    189:        CRYPT_ALGO_FIRST_CONVENTIONAL = CRYPT_ALGO_DES,
                    190:        CRYPT_ALGO_LAST_CONVENTIONAL = CRYPT_ALGO_DH - 1,
                    191:        CRYPT_ALGO_FIRST_PKC = CRYPT_ALGO_DH,
                    192:        CRYPT_ALGO_LAST_PKC = CRYPT_ALGO_MD2 - 1,
                    193:        CRYPT_ALGO_FIRST_HASH = CRYPT_ALGO_MD2,
                    194:        CRYPT_ALGO_LAST_HASH = CRYPT_ALGO_HMAC_MD5 - 1,
                    195:        CRYPT_ALGO_FIRST_MAC = CRYPT_ALGO_HMAC_MD5,
                    196:        CRYPT_ALGO_LAST_MAC = CRYPT_ALGO_HMAC_MD5 + 99  /* End of mac algo.range */
                    197:        } CRYPT_ALGO_TYPE;
                    198: 
                    199: typedef enum {                                         /* Block cipher modes */
                    200:        CRYPT_MODE_NONE,                                /* No encryption mode */
                    201:        CRYPT_MODE_ECB,                                 /* ECB */
                    202:        CRYPT_MODE_CBC,                                 /* CBC */
                    203:        CRYPT_MODE_CFB,                                 /* CFB */
                    204:        CRYPT_MODE_OFB,                                 /* OFB */
                    205:        CRYPT_MODE_LAST                                 /* Last possible crypt mode value */
                    206:        } CRYPT_MODE_TYPE;
                    207: 
                    208: #if ( defined( _WINDOWS ) || defined( WIN32 ) || defined( _WIN32 ) || \
                    209:          defined( __WIN32__ ) ) && !defined( _SCCTK )
                    210:   /* Force an error if wincrypt.h is included after cryptlib.h, see note at
                    211:      the start of the file */
                    212:   #define CRYPT_MODE_ECB       1
                    213: #endif /* Windows other than a cross-development environment */
                    214: 
                    215: /* Keyset subtypes */
                    216: 
                    217: typedef enum {                                         /* Keyset types */
                    218:        CRYPT_KEYSET_NONE,                              /* No keyset type */
                    219:        CRYPT_KEYSET_FILE,                              /* Generic flat file keyset */
                    220:        CRYPT_KEYSET_HTTP,                              /* Web page containing cert/CRL */
                    221:        CRYPT_KEYSET_LDAP,                              /* LDAP directory service */
                    222:        CRYPT_KEYSET_ODBC,                              /* Generic ODBC interface */
                    223:        CRYPT_KEYSET_DATABASE,                  /* Generic RDBMS interface */
                    224:        CRYPT_KEYSET_PLUGIN,                    /* Generic database plugin */
                    225:        CRYPT_KEYSET_ODBC_STORE,                /* ODBC certificate store */
                    226:        CRYPT_KEYSET_DATABASE_STORE,    /* Database certificate store */
                    227:        CRYPT_KEYSET_PLUGIN_STORE,              /* Database plugin certificate store */
                    228:        CRYPT_KEYSET_LAST                               /* Last possible keyset type */
                    229: 
                    230: #ifdef _CRYPT_DEFINED
                    231:        /* Useful defines used internally for range checking */
                    232:        , CRYPT_FIRST_RDBMS = CRYPT_KEYSET_ODBC,
                    233:        CRYPT_LAST_RDBMS = CRYPT_KEYSET_PLUGIN_STORE
                    234: #endif /* _CRYPT_DEFINED */
                    235:        } CRYPT_KEYSET_TYPE;
                    236: 
                    237: /* Device subtypes */
                    238: 
                    239: typedef enum {                                         /* Crypto device types */
                    240:        CRYPT_DEVICE_NONE,                              /* No crypto device */
                    241:        CRYPT_DEVICE_FORTEZZA,                  /* Fortezza card */
                    242:        CRYPT_DEVICE_PKCS11,                    /* PKCS #11 crypto token */
                    243:        CRYPT_DEVICE_CRYPTOAPI,                 /* Microsoft CryptoAPI */
                    244:        CRYPT_DEVICE_LAST                               /* Last possible crypto device type */
                    245:        } CRYPT_DEVICE_TYPE;
                    246: 
                    247: /* Certificate subtypes */
                    248: 
                    249: typedef enum {                                         /* Certificate object types */
                    250:        CRYPT_CERTTYPE_NONE,                    /* No certificate type */
                    251:        CRYPT_CERTTYPE_CERTIFICATE,             /* Certificate */
                    252:        CRYPT_CERTTYPE_ATTRIBUTE_CERT,  /* Attribute certificate */
                    253:        CRYPT_CERTTYPE_CERTCHAIN,               /* PKCS #7 certificate chain */
                    254:        CRYPT_CERTTYPE_CERTREQUEST,             /* PKCS #10 certification request */
                    255:        CRYPT_CERTTYPE_REQUEST_CERT,    /* CRMF certification request */
                    256:        CRYPT_CERTTYPE_REQUEST_REVOCATION,      /* CRMF revocation request */
                    257:        CRYPT_CERTTYPE_CRL,                             /* CRL */
                    258:        CRYPT_CERTTYPE_CMS_ATTRIBUTES,  /* CMS attributes */
                    259:        CRYPT_CERTTYPE_RTCS_REQUEST,    /* RTCS request */
                    260:        CRYPT_CERTTYPE_RTCS_RESPONSE,   /* RTCS response */
                    261:        CRYPT_CERTTYPE_OCSP_REQUEST,    /* OCSP request */
                    262:        CRYPT_CERTTYPE_OCSP_RESPONSE,   /* OCSP response */
                    263:        CRYPT_CERTTYPE_PKIUSER,                 /* PKI user information */
                    264: #ifdef _CRYPT_DEFINED
                    265:        /* Alongside the usual types we can also wind up with various
                    266:           certificate-bagging schemes such as cert chains and sequences that
                    267:           can't be exported in this format and therefore aren't visible to the
                    268:           user, but that need to be distinguished internally.  The following
                    269:           types are only visible internally */
                    270:        CRYPT_ICERTTYPE_CMS_CERTSET,    /* CMS SET OF Certificate = cert chain */
                    271:        CRYPT_ICERTTYPE_SSL_CERTCHAIN,  /* SSL certificate chain = cert chain */
                    272: #endif /* _CRYPT_DEFINED */
                    273:        CRYPT_CERTTYPE_LAST                             /* Last possible cert.type */
                    274: #ifdef _CRYPT_DEFINED
                    275:        , CRYPT_CERTTYPE_LAST_EXTERNAL = CRYPT_CERTTYPE_PKIUSER + 1
                    276: #endif /* _CRYPT_DEFINED */
                    277:        } CRYPT_CERTTYPE_TYPE;
                    278: 
                    279: /* Envelope/data format subtypes */
                    280: 
                    281: typedef enum {
                    282:        CRYPT_FORMAT_NONE,                              /* No format type */
                    283:        CRYPT_FORMAT_AUTO,                              /* Deenv, auto-determine type */
                    284:        CRYPT_FORMAT_CRYPTLIB,                  /* cryptlib native format */
                    285:        CRYPT_FORMAT_CMS,                               /* PKCS #7 / CMS / S/MIME fmt.*/
                    286:                CRYPT_FORMAT_PKCS7 = CRYPT_FORMAT_CMS,
                    287:        CRYPT_FORMAT_SMIME,                             /* As CMS with MSG-style behaviour */
                    288:        CRYPT_FORMAT_PGP,                               /* PGP format */
                    289: #ifdef _CRYPT_DEFINED
                    290:        /* Alongside the usual types we can also wind up with various protocol-
                    291:           specific format types such as SSL and SSH.  The following types are
                    292:           only visible internally */
                    293:        CRYPT_IFORMAT_SSL,                              /* SSL format */
                    294:        CRYPT_IFORMAT_SSH,                              /* SSH format */
                    295: #endif /* _CRYPT_DEFINED */
                    296:        CRYPT_FORMAT_LAST                               /* Last possible format type */
                    297: #ifdef _CRYPT_DEFINED
                    298:        , CRYPT_FORMAT_LAST_EXTERNAL = CRYPT_FORMAT_PGP + 1
                    299: #endif /* _CRYPT_DEFINED */
                    300:        } CRYPT_FORMAT_TYPE;
                    301: 
                    302: /* Session subtypes */
                    303: 
                    304: typedef enum {
                    305:        CRYPT_SESSION_NONE,                             /* No session type */
                    306:        CRYPT_SESSION_SSH,                              /* SSH */
                    307:        CRYPT_SESSION_SSH_SERVER,               /* SSH server */
                    308:        CRYPT_SESSION_SSL,                              /* SSL/TLS */
                    309:        CRYPT_SESSION_SSL_SERVER,               /* SSL/TLS server */
                    310:        CRYPT_SESSION_RTCS,                             /* RTCS */
                    311:        CRYPT_SESSION_RTCS_SERVER,              /* RTCS server */
                    312:        CRYPT_SESSION_OCSP,                             /* OCSP */
                    313:        CRYPT_SESSION_OCSP_SERVER,              /* OCSP server */
                    314:        CRYPT_SESSION_TSP,                              /* TSP */
                    315:        CRYPT_SESSION_TSP_SERVER,               /* TSP server */
                    316:        CRYPT_SESSION_CMP,                              /* CMP */
                    317:        CRYPT_SESSION_CMP_SERVER,               /* CMP server */
                    318:        CRYPT_SESSION_SCEP,                             /* SCEP */
                    319:        CRYPT_SESSION_SCEP_SERVER,              /* SCEP server */
                    320:        CRYPT_SESSION_CERTSTORE_SERVER, /* HTTP cert store interface */
                    321:        CRYPT_SESSION_LAST                              /* Last possible session type */
                    322:        } CRYPT_SESSION_TYPE;
                    323: 
                    324: /* User subtypes */
                    325: 
                    326: typedef enum {
                    327:        CRYPT_USER_NONE,                                /* No user type */
                    328:        CRYPT_USER_NORMAL,                              /* Normal user */
                    329:        CRYPT_USER_SO,                                  /* Security officer */
                    330:        CRYPT_USER_CA,                                  /* CA user */
                    331:        CRYPT_USER_LAST                                 /* Last possible user type */
                    332:        } CRYPT_USER_TYPE;
                    333: 
                    334: /****************************************************************************
                    335: *                                                                                                                                                      *
                    336: *                                                              Attribute Types                                                         *
                    337: *                                                                                                                                                      *
                    338: ****************************************************************************/
                    339: 
                    340: /* Attribute types.  These are arranged in the following order:
                    341: 
                    342:        PROPERTY        - Object property
                    343:        ATTRIBUTE       - Generic attributes
                    344:        OPTION          - Global or object-specific config.option
                    345:        CTXINFO         - Context-specific attribute
                    346:        CERTINFO        - Certificate-specific attribute
                    347:        KEYINFO         - Keyset-specific attribute
                    348:        DEVINFO         - Device-specific attribute
                    349:        ENVINFO         - Envelope-specific attribute
                    350:        SESSINFO        - Session-specific attribute
                    351:        USERINFO        - User-specific attribute */
                    352: 
                    353: typedef enum {
                    354:        CRYPT_ATTRIBUTE_NONE,                   /* Non-value */
                    355: 
                    356:        /* Used internally */
                    357:        CRYPT_PROPERTY_FIRST,
                    358: 
                    359:        /*********************/
                    360:        /* Object attributes */
                    361:        /*********************/
                    362: 
                    363:        /* Object properties */
                    364:        CRYPT_PROPERTY_HIGHSECURITY,    /* Owned+non-forwardcount+locked */
                    365:        CRYPT_PROPERTY_OWNER,                   /* Object owner */
                    366:        CRYPT_PROPERTY_FORWARDCOUNT,    /* No.of times object can be forwarded */
                    367:        CRYPT_PROPERTY_LOCKED,                  /* Whether properties can be chged/read */
                    368:        CRYPT_PROPERTY_USAGECOUNT,              /* Usage count before object expires */
                    369:        CRYPT_PROPERTY_NONEXPORTABLE,   /* Whether key is nonexp.from context */
                    370: 
                    371:        /* Used internally */
                    372:        CRYPT_PROPERTY_LAST, CRYPT_GENERIC_FIRST,
                    373: 
                    374:        /* Extended error information */
                    375:        CRYPT_ATTRIBUTE_ERRORTYPE,              /* Type of last error */
                    376:        CRYPT_ATTRIBUTE_ERRORLOCUS,             /* Locus of last error */
                    377:        CRYPT_ATTRIBUTE_INT_ERRORCODE,  /* Low-level software-specific */
                    378:        CRYPT_ATTRIBUTE_INT_ERRORMESSAGE, /*   error code and message */
                    379: 
                    380:        /* Generic information */
                    381:        CRYPT_ATTRIBUTE_CURRENT_GROUP,  /* Cursor mgt: Group in attribute list */
                    382:        CRYPT_ATTRIBUTE_CURRENT,                /* Cursor mgt: Entry in attribute list */
                    383:        CRYPT_ATTRIBUTE_CURRENT_INSTANCE,       /* Cursor mgt: Instance in attribute list */
                    384:        CRYPT_ATTRIBUTE_BUFFERSIZE,             /* Internal data buffer size */
                    385: 
                    386:        /* User internally */
                    387:        CRYPT_GENERIC_LAST, CRYPT_OPTION_FIRST = 100,
                    388: 
                    389:        /****************************/
                    390:        /* Configuration attributes */
                    391:        /****************************/
                    392: 
                    393:        /* cryptlib information (read-only) */
                    394:        CRYPT_OPTION_INFO_DESCRIPTION,  /* Text description */
                    395:        CRYPT_OPTION_INFO_COPYRIGHT,    /* Copyright notice */
                    396:        CRYPT_OPTION_INFO_MAJORVERSION, /* Major release version */
                    397:        CRYPT_OPTION_INFO_MINORVERSION, /* Minor release version */
                    398:        CRYPT_OPTION_INFO_STEPPING,             /* Release stepping */
                    399: 
                    400:        /* Encryption options */
                    401:        CRYPT_OPTION_ENCR_ALGO,                 /* Encryption algorithm */
                    402:        CRYPT_OPTION_ENCR_HASH,                 /* Hash algorithm */
                    403:        CRYPT_OPTION_ENCR_MAC,                  /* MAC algorithm */
                    404: 
                    405:        /* PKC options */
                    406:        CRYPT_OPTION_PKC_ALGO,                  /* Public-key encryption algorithm */
                    407:        CRYPT_OPTION_PKC_KEYSIZE,               /* Public-key encryption key size */
                    408: 
                    409:        /* Signature options */
                    410:        CRYPT_OPTION_SIG_ALGO,                  /* Signature algorithm */
                    411:        CRYPT_OPTION_SIG_KEYSIZE,               /* Signature keysize */
                    412: 
                    413:        /* Keying options */
                    414:        CRYPT_OPTION_KEYING_ALGO,               /* Key processing algorithm */
                    415:        CRYPT_OPTION_KEYING_ITERATIONS, /* Key processing iterations */
                    416: 
                    417:        /* Certificate options */
                    418:        CRYPT_OPTION_CERT_SIGNUNRECOGNISEDATTRIBUTES,   /* Whether to sign unrecog.attrs */
                    419:        CRYPT_OPTION_CERT_VALIDITY,             /* Certificate validity period */
                    420:        CRYPT_OPTION_CERT_UPDATEINTERVAL,       /* CRL update interval */
                    421:        CRYPT_OPTION_CERT_COMPLIANCELEVEL,      /* PKIX compliance level for cert chks.*/
                    422:        CRYPT_OPTION_CERT_REQUIREPOLICY,        /* Whether explicit policy req'd for certs */
                    423: 
                    424:        /* CMS/SMIME options */
                    425:        CRYPT_OPTION_CMS_DEFAULTATTRIBUTES,     /* Add default CMS attributes */
                    426:                CRYPT_OPTION_SMIME_DEFAULTATTRIBUTES = CRYPT_OPTION_CMS_DEFAULTATTRIBUTES,
                    427: 
                    428:        /* LDAP keyset options */
                    429:        CRYPT_OPTION_KEYS_LDAP_OBJECTCLASS,     /* Object class */
                    430:        CRYPT_OPTION_KEYS_LDAP_OBJECTTYPE,      /* Object type to fetch */
                    431:        CRYPT_OPTION_KEYS_LDAP_FILTER,          /* Query filter */
                    432:        CRYPT_OPTION_KEYS_LDAP_CACERTNAME,      /* CA certificate attribute name */
                    433:        CRYPT_OPTION_KEYS_LDAP_CERTNAME,        /* Certificate attribute name */
                    434:        CRYPT_OPTION_KEYS_LDAP_CRLNAME,         /* CRL attribute name */
                    435:        CRYPT_OPTION_KEYS_LDAP_EMAILNAME,       /* Email attribute name */
                    436: 
                    437:        /* Crypto device options */
                    438:        CRYPT_OPTION_DEVICE_PKCS11_DVR01,       /* Name of first PKCS #11 driver */
                    439:        CRYPT_OPTION_DEVICE_PKCS11_DVR02,       /* Name of second PKCS #11 driver */
                    440:        CRYPT_OPTION_DEVICE_PKCS11_DVR03,       /* Name of third PKCS #11 driver */
                    441:        CRYPT_OPTION_DEVICE_PKCS11_DVR04,       /* Name of fourth PKCS #11 driver */
                    442:        CRYPT_OPTION_DEVICE_PKCS11_DVR05,       /* Name of fifth PKCS #11 driver */
                    443:        CRYPT_OPTION_DEVICE_PKCS11_HARDWAREONLY,/* Use only hardware mechanisms */
                    444: 
                    445:        /* Network access options */
                    446:        CRYPT_OPTION_NET_SOCKS_SERVER,          /* Socks server name */
                    447:        CRYPT_OPTION_NET_SOCKS_USERNAME,        /* Socks user name */
                    448:        CRYPT_OPTION_NET_HTTP_PROXY,            /* Web proxy server */
                    449:        CRYPT_OPTION_NET_CONNECTTIMEOUT,        /* Timeout for network connection setup */
                    450:        CRYPT_OPTION_NET_READTIMEOUT,           /* Timeout for network reads */
                    451:        CRYPT_OPTION_NET_WRITETIMEOUT,          /* Timeout for network writes */
                    452: 
                    453:        /* Miscellaneous options */
                    454:        CRYPT_OPTION_MISC_ASYNCINIT,    /* Whether to init cryptlib async'ly */
                    455:        CRYPT_OPTION_MISC_SIDECHANNELPROTECTION, /* Protect against side-channel attacks */
                    456: 
                    457:        /* cryptlib state information */
                    458:        CRYPT_OPTION_CONFIGCHANGED,             /* Whether in-mem.opts match on-disk ones */
                    459:        CRYPT_OPTION_SELFTESTOK,                /* Whether self-test was completed and OK */
                    460: 
                    461:        /* Used internally */
                    462:        CRYPT_OPTION_LAST, CRYPT_CTXINFO_FIRST = 1000,
                    463: 
                    464:        /**********************/
                    465:        /* Context attributes */
                    466:        /**********************/
                    467: 
                    468:        /* Algorithm and mode information */
                    469:        CRYPT_CTXINFO_ALGO,                             /* Algorithm */
                    470:        CRYPT_CTXINFO_MODE,                             /* Mode */
                    471:        CRYPT_CTXINFO_NAME_ALGO,                /* Algorithm name */
                    472:        CRYPT_CTXINFO_NAME_MODE,                /* Mode name */
                    473:        CRYPT_CTXINFO_KEYSIZE,                  /* Key size in bytes */
                    474:        CRYPT_CTXINFO_BLOCKSIZE,                /* Block size */
                    475:        CRYPT_CTXINFO_IVSIZE,                   /* IV size */
                    476:        CRYPT_CTXINFO_KEYING_ALGO,              /* Key processing algorithm */
                    477:        CRYPT_CTXINFO_KEYING_ITERATIONS,/* Key processing iterations */
                    478:        CRYPT_CTXINFO_KEYING_SALT,              /* Key processing salt */
                    479:        CRYPT_CTXINFO_KEYING_VALUE,             /* Value used to derive key */
                    480: 
                    481:        /* State information */
                    482:        CRYPT_CTXINFO_KEY,                              /* Key */
                    483:        CRYPT_CTXINFO_KEY_COMPONENTS,   /* Public-key components */
                    484:        CRYPT_CTXINFO_IV,                               /* IV */
                    485:        CRYPT_CTXINFO_HASHVALUE,                /* Hash value */
                    486: 
                    487:        /* Misc.information */
                    488:        CRYPT_CTXINFO_LABEL,                    /* Label for private/secret key */
                    489: 
                    490:        /* Used internally */
                    491:        CRYPT_CTXINFO_LAST, CRYPT_CERTINFO_FIRST = 2000,
                    492: 
                    493:        /**************************/
                    494:        /* Certificate attributes */
                    495:        /**************************/
                    496: 
                    497:        /* Because there are so many cert attributes, we break them down into
                    498:           blocks to minimise the number of values that change if a new one is
                    499:           added halfway through */
                    500: 
                    501:        /* Pseudo-information on a cert object or meta-information which is used
                    502:           to control the way that a cert object is processed */
                    503:        CRYPT_CERTINFO_SELFSIGNED,              /* Cert is self-signed */
                    504:        CRYPT_CERTINFO_IMMUTABLE,               /* Cert is signed and immutable */
                    505:        CRYPT_CERTINFO_XYZZY,                   /* Cert is a magic just-works cert */
                    506:        CRYPT_CERTINFO_CERTTYPE,                /* Certificate object type */
                    507:        CRYPT_CERTINFO_FINGERPRINT,             /* Certificate fingerprints */
                    508:                CRYPT_CERTINFO_FINGERPRINT_MD5 = CRYPT_CERTINFO_FINGERPRINT,
                    509:        CRYPT_CERTINFO_FINGERPRINT_SHA,
                    510:        CRYPT_CERTINFO_CURRENT_CERTIFICATE,/* Cursor mgt: Rel.pos in chain/CRL/OCSP */
                    511:        CRYPT_CERTINFO_TRUSTED_USAGE,   /* Usage that cert is trusted for */
                    512:        CRYPT_CERTINFO_TRUSTED_IMPLICIT,/* Whether cert is implicitly trusted */
                    513:        CRYPT_CERTINFO_SIGNATURELEVEL,  /* Amount of detail to include in sigs.*/
                    514: 
                    515:        /* General certificate object information */
                    516:        CRYPT_CERTINFO_VERSION,                 /* Cert.format version */
                    517:        CRYPT_CERTINFO_SERIALNUMBER,    /* Serial number */
                    518:        CRYPT_CERTINFO_SUBJECTPUBLICKEYINFO,    /* Public key */
                    519:        CRYPT_CERTINFO_CERTIFICATE,             /* User certificate */
                    520:                CRYPT_CERTINFO_USERCERTIFICATE = CRYPT_CERTINFO_CERTIFICATE,
                    521:        CRYPT_CERTINFO_CACERTIFICATE,   /* CA certificate */
                    522:        CRYPT_CERTINFO_ISSUERNAME,              /* Issuer DN */
                    523:        CRYPT_CERTINFO_VALIDFROM,               /* Cert valid-from time */
                    524:        CRYPT_CERTINFO_VALIDTO,                 /* Cert valid-to time */
                    525:        CRYPT_CERTINFO_SUBJECTNAME,             /* Subject DN */
                    526:        CRYPT_CERTINFO_ISSUERUNIQUEID,  /* Issuer unique ID */
                    527:        CRYPT_CERTINFO_SUBJECTUNIQUEID, /* Subject unique ID */
                    528:        CRYPT_CERTINFO_CERTREQUEST,             /* Cert.request (DN + public key) */
                    529:        CRYPT_CERTINFO_THISUPDATE,              /* CRL/OCSP current-update time */
                    530:        CRYPT_CERTINFO_NEXTUPDATE,              /* CRL/OCSP next-update time */
                    531:        CRYPT_CERTINFO_REVOCATIONDATE,  /* CRL/OCSP cert-revocation time */
                    532:        CRYPT_CERTINFO_REVOCATIONSTATUS,/* OCSP revocation status */
                    533:        CRYPT_CERTINFO_CERTSTATUS,              /* RTCS certificate status */
                    534:        CRYPT_CERTINFO_DN,                              /* Currently selected DN in string form */
                    535:        CRYPT_CERTINFO_PKIUSER_ID,              /* PKI user ID */
                    536:        CRYPT_CERTINFO_PKIUSER_ISSUEPASSWORD,   /* PKI user issue password */
                    537:        CRYPT_CERTINFO_PKIUSER_REVPASSWORD,             /* PKI user revocation password */
                    538: 
                    539:        /* X.520 Distinguished Name components.  This is a composite field, the
                    540:           DN to be manipulated is selected through the addition of a
                    541:           pseudocomponent, and then one of the following is used to access the
                    542:           DN components directly */
                    543:        CRYPT_CERTINFO_COUNTRYNAME = CRYPT_CERTINFO_FIRST + 100,        /* countryName */
                    544:        CRYPT_CERTINFO_STATEORPROVINCENAME,     /* stateOrProvinceName */
                    545:        CRYPT_CERTINFO_LOCALITYNAME,            /* localityName */
                    546:        CRYPT_CERTINFO_ORGANIZATIONNAME,        /* organizationName */
                    547:                CRYPT_CERTINFO_ORGANISATIONNAME = CRYPT_CERTINFO_ORGANIZATIONNAME,
                    548:        CRYPT_CERTINFO_ORGANIZATIONALUNITNAME,  /* organizationalUnitName */
                    549:                CRYPT_CERTINFO_ORGANISATIONALUNITNAME = CRYPT_CERTINFO_ORGANIZATIONALUNITNAME,
                    550:        CRYPT_CERTINFO_COMMONNAME,              /* commonName */
                    551: 
                    552:        /* X.509 General Name components.  These are handled in the same way as
                    553:           the DN composite field, with the current GeneralName being selected by
                    554:           a pseudo-component after which the individual components can be
                    555:           modified through one of the following */
                    556:        CRYPT_CERTINFO_OTHERNAME_TYPEID,                /* otherName.typeID */
                    557:        CRYPT_CERTINFO_OTHERNAME_VALUE,                 /* otherName.value */
                    558:        CRYPT_CERTINFO_RFC822NAME,                              /* rfc822Name */
                    559:                CRYPT_CERTINFO_EMAIL = CRYPT_CERTINFO_RFC822NAME,
                    560:        CRYPT_CERTINFO_DNSNAME,                                 /* dNSName */
                    561: #if 0  /* Not supported yet, these are never used in practice and have an
                    562:                   insane internal structure */
                    563:        CRYPT_CERTINFO_X400ADDRESS,                             /* x400Address */
                    564: #endif /* 0 */
                    565:        CRYPT_CERTINFO_DIRECTORYNAME,                   /* directoryName */
                    566:        CRYPT_CERTINFO_EDIPARTYNAME_NAMEASSIGNER,       /* ediPartyName.nameAssigner */
                    567:        CRYPT_CERTINFO_EDIPARTYNAME_PARTYNAME,  /* ediPartyName.partyName */
                    568:        CRYPT_CERTINFO_UNIFORMRESOURCEIDENTIFIER,       /* uniformResourceIdentifier */
                    569:        CRYPT_CERTINFO_IPADDRESS,                               /* iPAddress */
                    570:        CRYPT_CERTINFO_REGISTEREDID,                    /* registeredID */
                    571: 
                    572:        /* X.509 certificate extensions.  Although it would be nicer to use names
                    573:           that match the extensions more closely (e.g.
                    574:           CRYPT_CERTINFO_BASICCONSTRAINTS_PATHLENCONSTRAINT), these exceed the
                    575:           32-character ANSI minimum length for unique names, and get really
                    576:           hairy once you get into the weird policy constraints extensions whose
                    577:           names wrap around the screen about three times.
                    578: 
                    579:           The following values are defined in OID order, this isn't absolutely
                    580:           necessary but saves an extra layer of processing when encoding them */
                    581: 
                    582:        /* 1 2 840 113549 1 9 7 challengePassword.  This is here even though it's
                    583:           a CMS attribute because SCEP stuffs it into PKCS #10 requests */
                    584:        CRYPT_CERTINFO_CHALLENGEPASSWORD = CRYPT_CERTINFO_FIRST + 200,
                    585: 
                    586:        /* 1 3 6 1 4 1 3029 3 1 4 cRLExtReason */
                    587:        CRYPT_CERTINFO_CRLEXTREASON,
                    588: 
                    589:        /* 1 3 6 1 4 1 3029 3 1 5 keyFeatures */
                    590:        CRYPT_CERTINFO_KEYFEATURES,
                    591: 
                    592:        /* 1 3 6 1 5 5 7 1 1 authorityInfoAccess */
                    593:        CRYPT_CERTINFO_AUTHORITYINFOACCESS,
                    594:        CRYPT_CERTINFO_AUTHORITYINFO_RTCS,              /* accessDescription.accessLocation */
                    595:        CRYPT_CERTINFO_AUTHORITYINFO_OCSP,              /* accessDescription.accessLocation */
                    596:        CRYPT_CERTINFO_AUTHORITYINFO_CAISSUERS, /* accessDescription.accessLocation */
                    597:        CRYPT_CERTINFO_AUTHORITYINFO_CERTSTORE, /* accessDescription.accessLocation */
                    598:        CRYPT_CERTINFO_AUTHORITYINFO_CRLS,              /* accessDescription.accessLocation */
                    599: 
                    600:        /* 1 3 6 1 5 5 7 1 2 biometricInfo */
                    601:        CRYPT_CERTINFO_BIOMETRICINFO,
                    602:        CRYPT_CERTINFO_BIOMETRICINFO_TYPE,              /* biometricData.typeOfData */
                    603:        CRYPT_CERTINFO_BIOMETRICINFO_HASHALGO,  /* biometricData.hashAlgorithm */
                    604:        CRYPT_CERTINFO_BIOMETRICINFO_HASH,              /* biometricData.dataHash */
                    605:        CRYPT_CERTINFO_BIOMETRICINFO_URL,               /* biometricData.sourceDataUri */
                    606: 
                    607:        /* 1 3 6 1 5 5 7 1 3 qcStatements */
                    608:        CRYPT_CERTINFO_QCSTATEMENT,
                    609:        CRYPT_CERTINFO_QCSTATEMENT_SEMANTICS,
                    610:                                        /* qcStatement.statementInfo.semanticsIdentifier */
                    611:        CRYPT_CERTINFO_QCSTATEMENT_REGISTRATIONAUTHORITY,
                    612:                                        /* qcStatement.statementInfo.nameRegistrationAuthorities */
                    613: 
                    614:        /* 1 3 6 1 5 5 7 48 1 2 ocspNonce */
                    615:        CRYPT_CERTINFO_OCSP_NONCE,                              /* nonce */
                    616: 
                    617:        /* 1 3 6 1 5 5 7 48 1 4 ocspAcceptableResponses */
                    618:        CRYPT_CERTINFO_OCSP_RESPONSE,
                    619:        CRYPT_CERTINFO_OCSP_RESPONSE_OCSP,              /* OCSP standard response */
                    620: 
                    621:        /* 1 3 6 1 5 5 7 48 1 5 ocspNoCheck */
                    622:        CRYPT_CERTINFO_OCSP_NOCHECK,
                    623: 
                    624:        /* 1 3 6 1 5 5 7 48 1 6 ocspArchiveCutoff */
                    625:        CRYPT_CERTINFO_OCSP_ARCHIVECUTOFF,
                    626: 
                    627:        /* 1 3 6 1 5 5 7 48 1 11 subjectInfoAccess */
                    628:        CRYPT_CERTINFO_SUBJECTINFOACCESS,
                    629:        CRYPT_CERTINFO_SUBJECTINFO_CAREPOSITORY,/* accessDescription.accessLocation */
                    630:        CRYPT_CERTINFO_SUBJECTINFO_TIMESTAMPING,/* accessDescription.accessLocation */
                    631: 
                    632:        /* 1 3 36 8 3 1 siggDateOfCertGen */
                    633:        CRYPT_CERTINFO_SIGG_DATEOFCERTGEN,
                    634: 
                    635:        /* 1 3 36 8 3 2 siggProcuration */
                    636:        CRYPT_CERTINFO_SIGG_PROCURATION,
                    637:        CRYPT_CERTINFO_SIGG_PROCURE_COUNTRY,    /* country */
                    638:        CRYPT_CERTINFO_SIGG_PROCURE_TYPEOFSUBSTITUTION, /* typeOfSubstitution */
                    639:        CRYPT_CERTINFO_SIGG_PROCURE_SIGNINGFOR, /* signingFor.thirdPerson */
                    640: 
                    641:        /* 1 3 36 8 3 4 siggMonetaryLimit */
                    642:        CRYPT_CERTINFO_SIGG_MONETARYLIMIT,
                    643:        CRYPT_CERTINFO_SIGG_MONETARY_CURRENCY,  /* currency */
                    644:        CRYPT_CERTINFO_SIGG_MONETARY_AMOUNT,    /* amount */
                    645:        CRYPT_CERTINFO_SIGG_MONETARY_EXPONENT,  /* exponent */
                    646: 
                    647:        /* 1 3 36 8 3 8 siggRestriction */
                    648:        CRYPT_CERTINFO_SIGG_RESTRICTION,
                    649: 
                    650:        /* 1 3 101 1 4 1 strongExtranet */
                    651:        CRYPT_CERTINFO_STRONGEXTRANET,
                    652:        CRYPT_CERTINFO_STRONGEXTRANET_ZONE,             /* sxNetIDList.sxNetID.zone */
                    653:        CRYPT_CERTINFO_STRONGEXTRANET_ID,               /* sxNetIDList.sxNetID.id */
                    654: 
                    655:        /* 2 5 29 9 subjectDirectoryAttributes */
                    656:        CRYPT_CERTINFO_SUBJECTDIRECTORYATTRIBUTES,
                    657:        CRYPT_CERTINFO_SUBJECTDIR_TYPE,                 /* attribute.type */
                    658:        CRYPT_CERTINFO_SUBJECTDIR_VALUES,               /* attribute.values */
                    659: 
                    660:        /* 2 5 29 14 subjectKeyIdentifier */
                    661:        CRYPT_CERTINFO_SUBJECTKEYIDENTIFIER,
                    662: 
                    663:        /* 2 5 29 15 keyUsage */
                    664:        CRYPT_CERTINFO_KEYUSAGE,
                    665: 
                    666:        /* 2 5 29 16 privateKeyUsagePeriod */
                    667:        CRYPT_CERTINFO_PRIVATEKEYUSAGEPERIOD,
                    668:        CRYPT_CERTINFO_PRIVATEKEY_NOTBEFORE,    /* notBefore */
                    669:        CRYPT_CERTINFO_PRIVATEKEY_NOTAFTER,             /* notAfter */
                    670: 
                    671:        /* 2 5 29 17 subjectAltName */
                    672:        CRYPT_CERTINFO_SUBJECTALTNAME,
                    673: 
                    674:        /* 2 5 29 18 issuerAltName */
                    675:        CRYPT_CERTINFO_ISSUERALTNAME,
                    676: 
                    677:        /* 2 5 29 19 basicConstraints */
                    678:        CRYPT_CERTINFO_BASICCONSTRAINTS,
                    679:        CRYPT_CERTINFO_CA,                                              /* cA */
                    680:                CRYPT_CERTINFO_AUTHORITY = CRYPT_CERTINFO_CA,
                    681:        CRYPT_CERTINFO_PATHLENCONSTRAINT,               /* pathLenConstraint */
                    682: 
                    683:        /* 2 5 29 20 cRLNumber */
                    684:        CRYPT_CERTINFO_CRLNUMBER,
                    685: 
                    686:        /* 2 5 29 21 cRLReason */
                    687:        CRYPT_CERTINFO_CRLREASON,
                    688: 
                    689:        /* 2 5 29 23 holdInstructionCode */
                    690:        CRYPT_CERTINFO_HOLDINSTRUCTIONCODE,
                    691: 
                    692:        /* 2 5 29 24 invalidityDate */
                    693:        CRYPT_CERTINFO_INVALIDITYDATE,
                    694: 
                    695:        /* 2 5 29 27 deltaCRLIndicator */
                    696:        CRYPT_CERTINFO_DELTACRLINDICATOR,
                    697: 
                    698:        /* 2 5 29 28 issuingDistributionPoint */
                    699:        CRYPT_CERTINFO_ISSUINGDISTRIBUTIONPOINT,
                    700:        CRYPT_CERTINFO_ISSUINGDIST_FULLNAME,    /* distributionPointName.fullName */
                    701:        CRYPT_CERTINFO_ISSUINGDIST_USERCERTSONLY,       /* onlyContainsUserCerts */
                    702:        CRYPT_CERTINFO_ISSUINGDIST_CACERTSONLY, /* onlyContainsCACerts */
                    703:        CRYPT_CERTINFO_ISSUINGDIST_SOMEREASONSONLY,     /* onlySomeReasons */
                    704:        CRYPT_CERTINFO_ISSUINGDIST_INDIRECTCRL, /* indirectCRL */
                    705: 
                    706:        /* 2 5 29 29 certificateIssuer */
                    707:        CRYPT_CERTINFO_CERTIFICATEISSUER,
                    708: 
                    709:        /* 2 5 29 30 nameConstraints */
                    710:        CRYPT_CERTINFO_NAMECONSTRAINTS,
                    711:        CRYPT_CERTINFO_PERMITTEDSUBTREES,               /* permittedSubtrees */
                    712:        CRYPT_CERTINFO_EXCLUDEDSUBTREES,                /* excludedSubtrees */
                    713: 
                    714:        /* 2 5 29 31 cRLDistributionPoint */
                    715:        CRYPT_CERTINFO_CRLDISTRIBUTIONPOINT,
                    716:        CRYPT_CERTINFO_CRLDIST_FULLNAME,                /* distributionPointName.fullName */
                    717:        CRYPT_CERTINFO_CRLDIST_REASONS,                 /* reasons */
                    718:        CRYPT_CERTINFO_CRLDIST_CRLISSUER,               /* cRLIssuer */
                    719: 
                    720:        /* 2 5 29 32 certificatePolicies */
                    721:        CRYPT_CERTINFO_CERTIFICATEPOLICIES,
                    722:        CRYPT_CERTINFO_CERTPOLICYID,            /* policyInformation.policyIdentifier */
                    723:        CRYPT_CERTINFO_CERTPOLICY_CPSURI,
                    724:                /* policyInformation.policyQualifiers.qualifier.cPSuri */
                    725:        CRYPT_CERTINFO_CERTPOLICY_ORGANIZATION,
                    726:                /* policyInformation.policyQualifiers.qualifier.userNotice.noticeRef.organization */
                    727:        CRYPT_CERTINFO_CERTPOLICY_NOTICENUMBERS,
                    728:                /* policyInformation.policyQualifiers.qualifier.userNotice.noticeRef.noticeNumbers */
                    729:        CRYPT_CERTINFO_CERTPOLICY_EXPLICITTEXT,
                    730:                /* policyInformation.policyQualifiers.qualifier.userNotice.explicitText */
                    731: 
                    732:        /* 2 5 29 33 policyMappings */
                    733:        CRYPT_CERTINFO_POLICYMAPPINGS,
                    734:        CRYPT_CERTINFO_ISSUERDOMAINPOLICY,      /* policyMappings.issuerDomainPolicy */
                    735:        CRYPT_CERTINFO_SUBJECTDOMAINPOLICY,     /* policyMappings.subjectDomainPolicy */
                    736: 
                    737:        /* 2 5 29 35 authorityKeyIdentifier */
                    738:        CRYPT_CERTINFO_AUTHORITYKEYIDENTIFIER,
                    739:        CRYPT_CERTINFO_AUTHORITY_KEYIDENTIFIER, /* keyIdentifier */
                    740:        CRYPT_CERTINFO_AUTHORITY_CERTISSUER,    /* authorityCertIssuer */
                    741:        CRYPT_CERTINFO_AUTHORITY_CERTSERIALNUMBER,      /* authorityCertSerialNumber */
                    742: 
                    743:        /* 2 5 29 36 policyConstraints */
                    744:        CRYPT_CERTINFO_POLICYCONSTRAINTS,
                    745:        CRYPT_CERTINFO_REQUIREEXPLICITPOLICY,   /* policyConstraints.requireExplicitPolicy */
                    746:        CRYPT_CERTINFO_INHIBITPOLICYMAPPING,    /* policyConstraints.inhibitPolicyMapping */
                    747: 
                    748:        /* 2 5 29 37 extKeyUsage */
                    749:        CRYPT_CERTINFO_EXTKEYUSAGE,
                    750:        CRYPT_CERTINFO_EXTKEY_MS_INDIVIDUALCODESIGNING, /* individualCodeSigning */
                    751:        CRYPT_CERTINFO_EXTKEY_MS_COMMERCIALCODESIGNING, /* commercialCodeSigning */
                    752:        CRYPT_CERTINFO_EXTKEY_MS_CERTTRUSTLISTSIGNING,  /* certTrustListSigning */
                    753:        CRYPT_CERTINFO_EXTKEY_MS_TIMESTAMPSIGNING,      /* timeStampSigning */
                    754:        CRYPT_CERTINFO_EXTKEY_MS_SERVERGATEDCRYPTO,     /* serverGatedCrypto */
                    755:        CRYPT_CERTINFO_EXTKEY_MS_ENCRYPTEDFILESYSTEM,   /* encrypedFileSystem */
                    756:        CRYPT_CERTINFO_EXTKEY_SERVERAUTH,               /* serverAuth */
                    757:        CRYPT_CERTINFO_EXTKEY_CLIENTAUTH,               /* clientAuth */
                    758:        CRYPT_CERTINFO_EXTKEY_CODESIGNING,              /* codeSigning */
                    759:        CRYPT_CERTINFO_EXTKEY_EMAILPROTECTION,  /* emailProtection */
                    760:        CRYPT_CERTINFO_EXTKEY_IPSECENDSYSTEM,   /* ipsecEndSystem */
                    761:        CRYPT_CERTINFO_EXTKEY_IPSECTUNNEL,              /* ipsecTunnel */
                    762:        CRYPT_CERTINFO_EXTKEY_IPSECUSER,                /* ipsecUser */
                    763:        CRYPT_CERTINFO_EXTKEY_TIMESTAMPING,             /* timeStamping */
                    764:        CRYPT_CERTINFO_EXTKEY_OCSPSIGNING,              /* ocspSigning */
                    765:        CRYPT_CERTINFO_EXTKEY_DIRECTORYSERVICE, /* directoryService */
                    766:        CRYPT_CERTINFO_EXTKEY_ANYKEYUSAGE,              /* anyExtendedKeyUsage */
                    767:        CRYPT_CERTINFO_EXTKEY_NS_SERVERGATEDCRYPTO,     /* serverGatedCrypto */
                    768:        CRYPT_CERTINFO_EXTKEY_VS_SERVERGATEDCRYPTO_CA,  /* serverGatedCrypto CA */
                    769: 
                    770:        /* 2 5 29 46 freshestCRL */
                    771:        CRYPT_CERTINFO_FRESHESTCRL,
                    772:        CRYPT_CERTINFO_FRESHESTCRL_FULLNAME,    /* distributionPointName.fullName */
                    773:        CRYPT_CERTINFO_FRESHESTCRL_REASONS,             /* reasons */
                    774:        CRYPT_CERTINFO_FRESHESTCRL_CRLISSUER,   /* cRLIssuer */
                    775: 
                    776:        /* 2 5 29 54 inhibitAnyPolicy */
                    777:        CRYPT_CERTINFO_INHIBITANYPOLICY,
                    778: 
                    779:        /* 2 16 840 1 113730 1 x Netscape extensions */
                    780:        CRYPT_CERTINFO_NS_CERTTYPE,                             /* netscape-cert-type */
                    781:        CRYPT_CERTINFO_NS_BASEURL,                              /* netscape-base-url */
                    782:        CRYPT_CERTINFO_NS_REVOCATIONURL,                /* netscape-revocation-url */
                    783:        CRYPT_CERTINFO_NS_CAREVOCATIONURL,              /* netscape-ca-revocation-url */
                    784:        CRYPT_CERTINFO_NS_CERTRENEWALURL,               /* netscape-cert-renewal-url */
                    785:        CRYPT_CERTINFO_NS_CAPOLICYURL,                  /* netscape-ca-policy-url */
                    786:        CRYPT_CERTINFO_NS_SSLSERVERNAME,                /* netscape-ssl-server-name */
                    787:        CRYPT_CERTINFO_NS_COMMENT,                              /* netscape-comment */
                    788: 
                    789:        /* 2 23 42 7 0 SET hashedRootKey */
                    790:        CRYPT_CERTINFO_SET_HASHEDROOTKEY,
                    791:        CRYPT_CERTINFO_SET_ROOTKEYTHUMBPRINT,   /* rootKeyThumbPrint */
                    792: 
                    793:        /* 2 23 42 7 1 SET certificateType */
                    794:        CRYPT_CERTINFO_SET_CERTIFICATETYPE,
                    795: 
                    796:        /* 2 23 42 7 2 SET merchantData */
                    797:        CRYPT_CERTINFO_SET_MERCHANTDATA,
                    798:        CRYPT_CERTINFO_SET_MERID,                               /* merID */
                    799:        CRYPT_CERTINFO_SET_MERACQUIRERBIN,              /* merAcquirerBIN */
                    800:        CRYPT_CERTINFO_SET_MERCHANTLANGUAGE,    /* merNames.language */
                    801:        CRYPT_CERTINFO_SET_MERCHANTNAME,                /* merNames.name */
                    802:        CRYPT_CERTINFO_SET_MERCHANTCITY,                /* merNames.city */
                    803:        CRYPT_CERTINFO_SET_MERCHANTSTATEPROVINCE,/* merNames.stateProvince */
                    804:        CRYPT_CERTINFO_SET_MERCHANTPOSTALCODE,  /* merNames.postalCode */
                    805:        CRYPT_CERTINFO_SET_MERCHANTCOUNTRYNAME, /* merNames.countryName */
                    806:        CRYPT_CERTINFO_SET_MERCOUNTRY,                  /* merCountry */
                    807:        CRYPT_CERTINFO_SET_MERAUTHFLAG,                 /* merAuthFlag */
                    808: 
                    809:        /* 2 23 42 7 3 SET certCardRequired */
                    810:        CRYPT_CERTINFO_SET_CERTCARDREQUIRED,
                    811: 
                    812:        /* 2 23 42 7 4 SET tunneling */
                    813:        CRYPT_CERTINFO_SET_TUNNELING,
                    814:                CRYPT_CERTINFO_SET_TUNNELLING = CRYPT_CERTINFO_SET_TUNNELING,
                    815:        CRYPT_CERTINFO_SET_TUNNELINGFLAG,               /* tunneling */
                    816:                CRYPT_CERTINFO_SET_TUNNELLINGFLAG = CRYPT_CERTINFO_SET_TUNNELINGFLAG,
                    817:        CRYPT_CERTINFO_SET_TUNNELINGALGID,              /* tunnelingAlgID */
                    818:                CRYPT_CERTINFO_SET_TUNNELLINGALGID = CRYPT_CERTINFO_SET_TUNNELINGALGID,
                    819: 
                    820:        /* S/MIME attributes */
                    821: 
                    822:        /* 1 2 840 113549 1 9 3 contentType */
                    823:        CRYPT_CERTINFO_CMS_CONTENTTYPE = CRYPT_CERTINFO_FIRST + 500,
                    824: 
                    825:        /* 1 2 840 113549 1 9 4 messageDigest */
                    826:        CRYPT_CERTINFO_CMS_MESSAGEDIGEST,
                    827: 
                    828:        /* 1 2 840 113549 1 9 5 signingTime */
                    829:        CRYPT_CERTINFO_CMS_SIGNINGTIME,
                    830: 
                    831:        /* 1 2 840 113549 1 9 6 counterSignature */
                    832:        CRYPT_CERTINFO_CMS_COUNTERSIGNATURE,    /* counterSignature */
                    833: 
                    834:        /* 1 2 840 113549 1 9 13 signingDescription */
                    835:        CRYPT_CERTINFO_CMS_SIGNINGDESCRIPTION,
                    836: 
                    837:        /* 1 2 840 113549 1 9 15 sMIMECapabilities */
                    838:        CRYPT_CERTINFO_CMS_SMIMECAPABILITIES,
                    839:        CRYPT_CERTINFO_CMS_SMIMECAP_3DES,               /* 3DES encryption */
                    840:        CRYPT_CERTINFO_CMS_SMIMECAP_AES,                /* AES encryption */
                    841:        CRYPT_CERTINFO_CMS_SMIMECAP_CAST128,    /* CAST-128 encryption */
                    842:        CRYPT_CERTINFO_CMS_SMIMECAP_IDEA,               /* IDEA encryption */
                    843:        CRYPT_CERTINFO_CMS_SMIMECAP_RC2,                /* RC2 encryption (w.128 key) */
                    844:        CRYPT_CERTINFO_CMS_SMIMECAP_RC5,                /* RC5 encryption (w.128 key) */
                    845:        CRYPT_CERTINFO_CMS_SMIMECAP_SKIPJACK,   /* Skipjack encryption */
                    846:        CRYPT_CERTINFO_CMS_SMIMECAP_DES,                /* DES encryption */
                    847:        CRYPT_CERTINFO_CMS_SMIMECAP_PREFERSIGNEDDATA,   /* preferSignedData */
                    848:        CRYPT_CERTINFO_CMS_SMIMECAP_CANNOTDECRYPTANY,   /* canNotDecryptAny */
                    849: 
                    850:        /* 1 2 840 113549 1 9 16 2 1 receiptRequest */
                    851:        CRYPT_CERTINFO_CMS_RECEIPTREQUEST,
                    852:        CRYPT_CERTINFO_CMS_RECEIPT_CONTENTIDENTIFIER, /* contentIdentifier */
                    853:        CRYPT_CERTINFO_CMS_RECEIPT_FROM,                /* receiptsFrom */
                    854:        CRYPT_CERTINFO_CMS_RECEIPT_TO,                  /* receiptsTo */
                    855: 
                    856:        /* 1 2 840 113549 1 9 16 2 2 essSecurityLabel */
                    857:        CRYPT_CERTINFO_CMS_SECURITYLABEL,
                    858:        CRYPT_CERTINFO_CMS_SECLABEL_POLICY,             /* securityPolicyIdentifier */
                    859:        CRYPT_CERTINFO_CMS_SECLABEL_CLASSIFICATION, /* securityClassification */
                    860:        CRYPT_CERTINFO_CMS_SECLABEL_PRIVACYMARK,/* privacyMark */
                    861:        CRYPT_CERTINFO_CMS_SECLABEL_CATTYPE,    /* securityCategories.securityCategory.type */
                    862:        CRYPT_CERTINFO_CMS_SECLABEL_CATVALUE,   /* securityCategories.securityCategory.value */
                    863: 
                    864:        /* 1 2 840 113549 1 9 16 2 3 mlExpansionHistory */
                    865:        CRYPT_CERTINFO_CMS_MLEXPANSIONHISTORY,
                    866:        CRYPT_CERTINFO_CMS_MLEXP_ENTITYIDENTIFIER, /* mlData.mailListIdentifier.issuerAndSerialNumber */
                    867:        CRYPT_CERTINFO_CMS_MLEXP_TIME,                  /* mlData.expansionTime */
                    868:        CRYPT_CERTINFO_CMS_MLEXP_NONE,                  /* mlData.mlReceiptPolicy.none */
                    869:        CRYPT_CERTINFO_CMS_MLEXP_INSTEADOF,             /* mlData.mlReceiptPolicy.insteadOf.generalNames.generalName */
                    870:        CRYPT_CERTINFO_CMS_MLEXP_INADDITIONTO,  /* mlData.mlReceiptPolicy.inAdditionTo.generalNames.generalName */
                    871: 
                    872:        /* 1 2 840 113549 1 9 16 2 4 contentHints */
                    873:        CRYPT_CERTINFO_CMS_CONTENTHINTS,
                    874:        CRYPT_CERTINFO_CMS_CONTENTHINT_DESCRIPTION,     /* contentDescription */
                    875:        CRYPT_CERTINFO_CMS_CONTENTHINT_TYPE,    /* contentType */
                    876: 
                    877:        /* 1 2 840 113549 1 9 16 2 9 equivalentLabels */
                    878:        CRYPT_CERTINFO_CMS_EQUIVALENTLABEL,
                    879:        CRYPT_CERTINFO_CMS_EQVLABEL_POLICY,             /* securityPolicyIdentifier */
                    880:        CRYPT_CERTINFO_CMS_EQVLABEL_CLASSIFICATION, /* securityClassification */
                    881:        CRYPT_CERTINFO_CMS_EQVLABEL_PRIVACYMARK,/* privacyMark */
                    882:        CRYPT_CERTINFO_CMS_EQVLABEL_CATTYPE,    /* securityCategories.securityCategory.type */
                    883:        CRYPT_CERTINFO_CMS_EQVLABEL_CATVALUE,   /* securityCategories.securityCategory.value */
                    884: 
                    885:        /* 1 2 840 113549 1 9 16 2 12 signingCertificate */
                    886:        CRYPT_CERTINFO_CMS_SIGNINGCERTIFICATE,
                    887:        CRYPT_CERTINFO_CMS_SIGNINGCERT_ESSCERTID, /* certs.essCertID */
                    888:        CRYPT_CERTINFO_CMS_SIGNINGCERT_POLICIES,/* policies.policyInformation.policyIdentifier */
                    889: 
                    890:        /* 1 2 840 113549 1 9 16 2 15 signaturePolicyID */
                    891:        CRYPT_CERTINFO_CMS_SIGNATUREPOLICYID,
                    892:        CRYPT_CERTINFO_CMS_SIGPOLICYID,                 /* sigPolicyID */
                    893:        CRYPT_CERTINFO_CMS_SIGPOLICYHASH,               /* sigPolicyHash */
                    894:        CRYPT_CERTINFO_CMS_SIGPOLICY_CPSURI,    /* sigPolicyQualifiers.sigPolicyQualifier.cPSuri */
                    895:        CRYPT_CERTINFO_CMS_SIGPOLICY_ORGANIZATION,
                    896:                /* sigPolicyQualifiers.sigPolicyQualifier.userNotice.noticeRef.organization */
                    897:        CRYPT_CERTINFO_CMS_SIGPOLICY_NOTICENUMBERS,
                    898:                /* sigPolicyQualifiers.sigPolicyQualifier.userNotice.noticeRef.noticeNumbers */
                    899:        CRYPT_CERTINFO_CMS_SIGPOLICY_EXPLICITTEXT,
                    900:                /* sigPolicyQualifiers.sigPolicyQualifier.userNotice.explicitText */
                    901: 
                    902:        /* 1 2 840 113549 1 9 16 9 signatureTypeIdentifier */
                    903:        CRYPT_CERTINFO_CMS_SIGTYPEIDENTIFIER,
                    904:        CRYPT_CERTINFO_CMS_SIGTYPEID_ORIGINATORSIG, /* originatorSig */
                    905:        CRYPT_CERTINFO_CMS_SIGTYPEID_DOMAINSIG, /* domainSig */
                    906:        CRYPT_CERTINFO_CMS_SIGTYPEID_ADDITIONALATTRIBUTES, /* additionalAttributesSig */
                    907:        CRYPT_CERTINFO_CMS_SIGTYPEID_REVIEWSIG, /* reviewSig */
                    908: 
                    909:        /* 1 2 840 113549 1 9 25 3 randomNonce */
                    910:        CRYPT_CERTINFO_CMS_NONCE,                               /* randomNonce */
                    911: 
                    912:        /* SCEP attributes:
                    913:           2 16 840 1 113733 1 9 2 messageType
                    914:           2 16 840 1 113733 1 9 3 pkiStatus
                    915:           2 16 840 1 113733 1 9 4 failInfo
                    916:           2 16 840 1 113733 1 9 5 senderNonce
                    917:           2 16 840 1 113733 1 9 6 recipientNonce
                    918:           2 16 840 1 113733 1 9 7 transID */
                    919:        CRYPT_CERTINFO_SCEP_MESSAGETYPE,                /* messageType */
                    920:        CRYPT_CERTINFO_SCEP_PKISTATUS,                  /* pkiStatus */
                    921:        CRYPT_CERTINFO_SCEP_FAILINFO,                   /* failInfo */
                    922:        CRYPT_CERTINFO_SCEP_SENDERNONCE,                /* senderNonce */
                    923:        CRYPT_CERTINFO_SCEP_RECIPIENTNONCE,             /* recipientNonce */
                    924:        CRYPT_CERTINFO_SCEP_TRANSACTIONID,              /* transID */
                    925: 
                    926:        /* 1 3 6 1 4 1 311 2 1 10 spcAgencyInfo */
                    927:        CRYPT_CERTINFO_CMS_SPCAGENCYINFO,
                    928:        CRYPT_CERTINFO_CMS_SPCAGENCYURL,                /* spcAgencyInfo.url */
                    929: 
                    930:        /* 1 3 6 1 4 1 311 2 1 11 spcStatementType */
                    931:        CRYPT_CERTINFO_CMS_SPCSTATEMENTTYPE,
                    932:        CRYPT_CERTINFO_CMS_SPCSTMT_INDIVIDUALCODESIGNING,       /* individualCodeSigning */
                    933:        CRYPT_CERTINFO_CMS_SPCSTMT_COMMERCIALCODESIGNING,       /* commercialCodeSigning */
                    934: 
                    935:        /* 1 3 6 1 4 1 311 2 1 12 spcOpusInfo */
                    936:        CRYPT_CERTINFO_CMS_SPCOPUSINFO,
                    937:        CRYPT_CERTINFO_CMS_SPCOPUSINFO_NAME,    /* spcOpusInfo.name */
                    938:        CRYPT_CERTINFO_CMS_SPCOPUSINFO_URL,             /* spcOpusInfo.url */
                    939: 
                    940:        /* Used internally */
                    941:        CRYPT_CERTINFO_LAST, CRYPT_KEYINFO_FIRST = 3000,
                    942: 
                    943:        /*********************/
                    944:        /* Keyset attributes */
                    945:        /*********************/
                    946: 
                    947:        CRYPT_KEYINFO_QUERY,                    /* Keyset query */
                    948:        CRYPT_KEYINFO_QUERY_REQUESTS,   /* Query of requests in cert store */
                    949: 
                    950:        /* Used internally */
                    951:        CRYPT_KEYINFO_LAST, CRYPT_DEVINFO_FIRST = 4000,
                    952: 
                    953:        /*********************/
                    954:        /* Device attributes */
                    955:        /*********************/
                    956: 
                    957:        CRYPT_DEVINFO_INITIALISE,       /* Initialise device for use */
                    958:                CRYPT_DEVINFO_INITIALIZE = CRYPT_DEVINFO_INITIALISE,
                    959:        CRYPT_DEVINFO_AUTHENT_USER,     /* Authenticate user to device */
                    960:        CRYPT_DEVINFO_AUTHENT_SUPERVISOR,       /* Authenticate supervisor to dev.*/
                    961:        CRYPT_DEVINFO_SET_AUTHENT_USER, /* Set user authent.value */
                    962:        CRYPT_DEVINFO_SET_AUTHENT_SUPERVISOR,   /* Set supervisor auth.val.*/
                    963:        CRYPT_DEVINFO_ZEROISE,  /* Zeroise device */
                    964:                CRYPT_DEVINFO_ZEROIZE = CRYPT_DEVINFO_ZEROISE,
                    965:        CRYPT_DEVINFO_LOGGEDIN,         /* Whether user is logged in */
                    966:        CRYPT_DEVINFO_LABEL,            /* Device/token label */
                    967: 
                    968:        /* Used internally */
                    969:        CRYPT_DEVINFO_LAST, CRYPT_ENVINFO_FIRST = 5000,
                    970: 
                    971:        /***********************/
                    972:        /* Envelope attributes */
                    973:        /***********************/
                    974: 
                    975:        /* Pseudo-information on an envelope or meta-information which is used to
                    976:           control the way that data in an envelope is processed */
                    977:        CRYPT_ENVINFO_DATASIZE,                 /* Data size information */
                    978:        CRYPT_ENVINFO_COMPRESSION,              /* Compression information */
                    979:        CRYPT_ENVINFO_CONTENTTYPE,              /* Inner CMS content type */
                    980:        CRYPT_ENVINFO_DETACHEDSIGNATURE,/* Generate CMS detached signature */
                    981:        CRYPT_ENVINFO_SIGNATURE_RESULT, /* Signature check result */
                    982:        CRYPT_ENVINFO_MAC,                              /* Use MAC instead of encrypting */
                    983: 
                    984:        /* Resources required for enveloping/deenveloping */
                    985:        CRYPT_ENVINFO_PASSWORD,                 /* User password */
                    986:        CRYPT_ENVINFO_KEY,                              /* Conventional encryption key */
                    987:        CRYPT_ENVINFO_SIGNATURE,                /* Signature/signature check key */
                    988:        CRYPT_ENVINFO_SIGNATURE_EXTRADATA,      /* Extra information added to CMS sigs */
                    989:        CRYPT_ENVINFO_RECIPIENT,                /* Recipient email address */
                    990:        CRYPT_ENVINFO_PUBLICKEY,                /* PKC encryption key */
                    991:        CRYPT_ENVINFO_PRIVATEKEY,               /* PKC decryption key */
                    992:        CRYPT_ENVINFO_PRIVATEKEY_LABEL, /* Label of PKC decryption key */
                    993:        CRYPT_ENVINFO_ORIGINATOR,               /* Originator info/key */
                    994:        CRYPT_ENVINFO_SESSIONKEY,               /* Session key */
                    995:        CRYPT_ENVINFO_HASH,                             /* Hash value */
                    996:        CRYPT_ENVINFO_TIMESTAMP,                /* Timestamp information */
                    997: 
                    998:        /* Keysets used to retrieve keys needed for enveloping/deenveloping */
                    999:        CRYPT_ENVINFO_KEYSET_SIGCHECK,  /* Signature check keyset */
                   1000:        CRYPT_ENVINFO_KEYSET_ENCRYPT,   /* PKC encryption keyset */
                   1001:        CRYPT_ENVINFO_KEYSET_DECRYPT,   /* PKC decryption keyset */
                   1002: 
                   1003:        /* Used internally */
                   1004:        CRYPT_ENVINFO_LAST, CRYPT_SESSINFO_FIRST = 6000,
                   1005: 
                   1006:        /**********************/
                   1007:        /* Session attributes */
                   1008:        /**********************/
                   1009: 
                   1010:        /* Pseudo-information about the session */
                   1011:        CRYPT_SESSINFO_ACTIVE,                  /* Whether session is active */
                   1012:        CRYPT_SESSINFO_CONNECTIONACTIVE,/* Whether network connection is active */
                   1013: 
                   1014:        /* Security-related information */
                   1015:        CRYPT_SESSINFO_USERNAME,                /* User name */
                   1016:        CRYPT_SESSINFO_PASSWORD,                /* Password */
                   1017:        CRYPT_SESSINFO_PRIVATEKEY,              /* Server/client private key */
                   1018:        CRYPT_SESSINFO_KEYSET,                  /* Certificate store */
                   1019:        CRYPT_SESSINFO_AUTHRESPONSE,    /* Session authorisation OK */
                   1020: 
                   1021:        /* Client/server information */
                   1022:        CRYPT_SESSINFO_SERVER_NAME,             /* Server name */
                   1023:        CRYPT_SESSINFO_SERVER_PORT,             /* Server port number */
                   1024:        CRYPT_SESSINFO_SERVER_FINGERPRINT,/* Server key fingerprint */
                   1025:        CRYPT_SESSINFO_CLIENT_NAME,             /* Client name */
                   1026:        CRYPT_SESSINFO_CLIENT_PORT,             /* Client port number */
                   1027:        CRYPT_SESSINFO_SESSION,                 /* Transport mechanism */
                   1028:        CRYPT_SESSINFO_NETWORKSOCKET,   /* User-supplied network socket */
                   1029: 
                   1030:        /* Generic protocol-related information */
                   1031:        CRYPT_SESSINFO_VERSION,                 /* Protocol version */
                   1032:        CRYPT_SESSINFO_REQUEST,                 /* Cert.request object */
                   1033:        CRYPT_SESSINFO_RESPONSE,                /* Cert.response object */
                   1034:        CRYPT_SESSINFO_CACERTIFICATE,   /* Issuing CA certificate */
                   1035: 
                   1036:        /* Protocol-specific information */
                   1037:        CRYPT_SESSINFO_TSP_MSGIMPRINT,  /* TSP message imprint */
                   1038:        CRYPT_SESSINFO_CMP_REQUESTTYPE, /* Request type */
                   1039:        CRYPT_SESSINFO_CMP_PKIBOOT,             /* Enable PKIBoot facility */
                   1040:        CRYPT_SESSINFO_CMP_PRIVKEYSET,  /* Private-key keyset */
                   1041:        CRYPT_SESSINFO_SSH_CHANNEL,             /* SSH current channel */
                   1042:        CRYPT_SESSINFO_SSH_CHANNEL_TYPE,/* SSH channel type */
                   1043:        CRYPT_SESSINFO_SSH_CHANNEL_ARG1,/* SSH channel argument 1 */
                   1044:        CRYPT_SESSINFO_SSH_CHANNEL_ARG2,/* SSH channel argument 2 */
                   1045:        CRYPT_SESSINFO_SSH_CHANNEL_ACTIVE,/* SSH channel active */
                   1046: 
                   1047:        /* Used internally */
                   1048:        CRYPT_SESSINFO_LAST, CRYPT_USERINFO_FIRST = 7000,
                   1049: 
                   1050:        /**********************/
                   1051:        /* User attributes */
                   1052:        /**********************/
                   1053: 
                   1054:        /* Security-related information */
                   1055:        CRYPT_USERINFO_PASSWORD,                /* Password */
                   1056: 
                   1057:        /* User role-related information */
                   1058:        CRYPT_USERINFO_CAKEY_CERTSIGN,  /* CA cert signing key */
                   1059:        CRYPT_USERINFO_CAKEY_CRLSIGN,   /* CA CRL signing key */
                   1060:        CRYPT_USERINFO_CAKEY_RTCSSIGN,  /* CA RTCS signing key */
                   1061:        CRYPT_USERINFO_CAKEY_OCSPSIGN,  /* CA OCSP signing key */
                   1062: 
                   1063:        /* Used internally for range checking */
                   1064:        CRYPT_USERINFO_LAST, CRYPT_ATTRIBUTE_LAST = CRYPT_USERINFO_LAST
                   1065: 
                   1066: #ifdef _CRYPT_DEFINED
                   1067:        /***********************/
                   1068:        /* Internal attributes */
                   1069:        /***********************/
                   1070: 
                   1071:        /* The following attributes are only visible internally and are protected
                   1072:           from any external access by the kernel (and for good measure by checks
                   1073:           in other places as well).  The two attributes CRYPT_IATTRIBUTE_KEY_SPKI
                   1074:           and CRYPT_IATTRIBUTE_SPKI are actually the same thing, the difference
                   1075:           is that the former is write-only for contexts and the latter is read-
                   1076:           only for certificates (the former is used when loading a context from
                   1077:           a key contained in a device, where the actual key components aren't
                   1078:           directly available in the context but may be needed in the future for
                   1079:           things like cert requests).  Because a single object can act as both a
                   1080:           context and a cert, having two explicitly different attribute names
                   1081:           makes things less confusing.  In addition, some public-key attributes
                   1082:           have _PARTIAL variants that load the public-key components but don't
                   1083:           initialise the key/move the context into the high state.  This is
                   1084:           used for formats in which public and private-key components are loaded
                   1085:           separately */
                   1086:        , CRYPT_IATTRIBUTE_FIRST = 8000,
                   1087:        CRYPT_IATTRIBUTE_TYPE,                  /* Object type */
                   1088:        CRYPT_IATTRIBUTE_SUBTYPE,               /* Object subtype */
                   1089:        CRYPT_IATTRIBUTE_STATUS,                /* Object status */
                   1090:        CRYPT_IATTRIBUTE_INTERNAL,              /* Object internal flag */
                   1091:        CRYPT_IATTRIBUTE_ACTIONPERMS,   /* Object action permissions */
                   1092:        CRYPT_IATTRIBUTE_LOCKED,                /* Object locked for exclusive use */
                   1093:        CRYPT_IATTRIBUTE_INITIALISED,   /* Object inited (in high state) */
                   1094:        CRYPT_IATTRIBUTE_KEYSIZE,               /* Ctx: Key size (written to non-native ctxs) */
                   1095:        CRYPT_IATTRIBUTE_KEYFEATURES,   /* Ctx: Key feature info */
                   1096:        CRYPT_IATTRIBUTE_KEYID,                 /* Ctx: Key ID */
                   1097:        CRYPT_IATTRIBUTE_KEYID_PGP,             /* Ctx: PGP key ID */
                   1098:        CRYPT_IATTRIBUTE_KEYID_OPENPGP, /* Ctx: OpenPGP key ID */
                   1099:        CRYPT_IATTRIBUTE_KEY_KEADOMAINPARAMS,/* Ctx: Key agreement domain parameters */
                   1100:        CRYPT_IATTRIBUTE_KEY_KEAPUBLICVALUE,/* Ctx: Key agreement public value */
                   1101:        CRYPT_IATTRIBUTE_KEY_SPKI,              /* Ctx: SubjectPublicKeyInfo */
                   1102:        CRYPT_IATTRIBUTE_KEY_PGP,               /* Ctx: PGP-format public key */
                   1103:        CRYPT_IATTRIBUTE_KEY_SSH,               /* Ctx: SSH-format public key */
                   1104:        CRYPT_IATTRIBUTE_KEY_SSH1,              /* Ctx: SSHv1-format public key */
                   1105:        CRYPT_IATTRIBUTE_KEY_SSL,               /* Ctx: SSL-format public key */
                   1106:        CRYPT_IATTRIBUTE_KEY_SPKI_PARTIAL,/* Ctx: SubjectPublicKeyInfo w/o trigger */
                   1107:        CRYPT_IATTRIBUTE_KEY_PGP_PARTIAL,/* Ctx: PGP public key w/o trigger */
                   1108:        CRYPT_IATTRIBUTE_PGPVALIDITY,   /* Ctx: PGP key validity */
                   1109:        CRYPT_IATTRIBUTE_DEVICEOBJECT,  /* Ctx: Device object handle */
                   1110:        CRYPT_IATTRIBUTE_CRLENTRY,              /* Cert: Individual entry from CRL */
                   1111:        CRYPT_IATTRIBUTE_SUBJECT,               /* Cert: SubjectName */
                   1112:        CRYPT_IATTRIBUTE_ISSUER,                /* Cert: IssuerName */
                   1113:        CRYPT_IATTRIBUTE_ISSUERANDSERIALNUMBER, /* Cert: IssuerAndSerial */
                   1114:        CRYPT_IATTRIBUTE_SPKI,                  /* Cert: Encoded SubjectPublicKeyInfo */
                   1115:        CRYPT_IATTRIBUTE_CERTHASHALGO,  /* Cert: Hash algo.used for cert */
                   1116:        CRYPT_IATTRIBUTE_CERTCOLLECTION,/* Cert: Certs added to cert chain */
                   1117:        CRYPT_IATTRIBUTE_RESPONDERURL,  /* Cert: RTCS/OCSP responder name */
                   1118:        CRYPT_IATTRIBUTE_RTCSREQUEST,   /* Cert: RTCS req.info added to RTCS resp.*/
                   1119:        CRYPT_IATTRIBUTE_OCSPREQUEST,   /* Cert: OCSP req.info added to OCSP resp.*/
                   1120:        CRYPT_IATTRIBUTE_REVREQUEST,    /* Cert: CRMF rev.request added to CRL */
                   1121:        CRYPT_IATTRIBUTE_PKIUSERINFO,   /* Cert: Additional user info added to cert.req.*/
                   1122:        CRYPT_IATTRIBUTE_BLOCKEDATTRS,  /* Cert: Template of disallowed attrs.in cert */
                   1123:        CRYPT_IATTRIBUTE_AUTHCERTID,    /* Cert: Authorising cert ID for a cert/rev.req.*/
                   1124:        CRYPT_IATTRIBUTE_ESSCERTID,             /* Cert: ESSCertID */
                   1125:        CRYPT_IATTRIBUTE_ENTROPY,               /* Dev: Polled entropy data */
                   1126:        CRYPT_IATTRIBUTE_ENTROPY_QUALITY,/* Dev: Quality of entropy data */
                   1127:        CRYPT_IATTRIBUTE_RANDOM_LOPICKET,/* Dev: Low picket for random data attrs.*/
                   1128:        CRYPT_IATTRIBUTE_RANDOM,                /* Dev: Random data */
                   1129:        CRYPT_IATTRIBUTE_RANDOM_NZ,             /* Dev: Nonzero random data */
                   1130:        CRYPT_IATTRIBUTE_RANDOM_HIPICKET,/* Dev: High picket for random data attrs.*/
                   1131:        CRYPT_IATTRIBUTE_RANDOM_NONCE,  /* Dev: Basic nonce */
                   1132:        CRYPT_IATTRIBUTE_SELFTEST,              /* Dev: Perform self-test */
                   1133:        CRYPT_IATTRIBUTE_TIME,                  /* Dev: Reliable (hardware-based) time value */
                   1134:        CRYPT_IATTRIBUTE_INCLUDESIGCERT,/* Env: Whether to include signing cert(s) */
                   1135:        CRYPT_IATTRIBUTE_ATTRONLY,              /* Env: Signed data contains only CMS attrs.*/
                   1136:        CRYPT_IATTRIBUTE_CONFIGDATA,    /* Keyset: Config information */
                   1137:        CRYPT_IATTRIBUTE_USERINDEX,             /* Keyset: Index of users */
                   1138:        CRYPT_IATTRIBUTE_USERID,                /* Keyset: User ID */
                   1139:        CRYPT_IATTRIBUTE_USERINFO,              /* Keyset: User information */
                   1140:        CRYPT_IATTRIBUTE_TRUSTEDCERT,   /* Keyset: First trusted cert */
                   1141:        CRYPT_IATTRIBUTE_TRUSTEDCERT_NEXT,      /* Keyset: Successive trusted certs */
                   1142:        CRYPT_IATTRIBUTE_ENC_TIMESTAMP, /* Session: Encoded TSA timestamp */
                   1143:        CRYPT_IATTRUBUTE_CERTKEYSET,    /* User: Keyset to send trusted certs to */
                   1144:        CRYPT_IATTRIBUTE_CTL,                   /* User: Cert.trust list */
                   1145:        CRYPT_IATTRIBUTE_CERT_TRUSTED,  /* User: Set trusted cert */
                   1146:        CRYPT_IATTRIBUTE_CERT_UNTRUSTED,/* User: Unset trusted cert */
                   1147:        CRYPT_IATTRIBUTE_CERT_CHECKTRUST,/* User: Check trust status of cert */
                   1148:        CRYPT_IATTRIBUTE_CERT_TRUSTEDISSUER,/* User: Get trusted issuer of cert */
                   1149:        CRYPT_IATTRIBUTE_LAST,
                   1150: 
                   1151:        /* Subrange values used internally for range checking */
                   1152:        CRYPT_CERTINFO_FIRST_CERTINFO = CRYPT_CERTINFO_FIRST + 1,
                   1153:        CRYPT_CERTINFO_LAST_CERTINFO = CRYPT_CERTINFO_PKIUSER_REVPASSWORD,
                   1154:                CRYPT_CERTINFO_FIRST_PSEUDOINFO = CRYPT_CERTINFO_SELFSIGNED,
                   1155:                CRYPT_CERTINFO_LAST_PSEUDOINFO = CRYPT_CERTINFO_SIGNATURELEVEL,
                   1156:        CRYPT_CERTINFO_FIRST_NAME = CRYPT_CERTINFO_COUNTRYNAME,
                   1157:        CRYPT_CERTINFO_LAST_NAME = CRYPT_CERTINFO_REGISTEREDID,
                   1158:                CRYPT_CERTINFO_FIRST_DN = CRYPT_CERTINFO_COUNTRYNAME,
                   1159:                CRYPT_CERTINFO_LAST_DN = CRYPT_CERTINFO_COMMONNAME,
                   1160:                CRYPT_CERTINFO_FIRST_GENERALNAME = CRYPT_CERTINFO_OTHERNAME_TYPEID,
                   1161:                CRYPT_CERTINFO_LAST_GENERALNAME = CRYPT_CERTINFO_REGISTEREDID,
                   1162:        CRYPT_CERTINFO_FIRST_EXTENSION = CRYPT_CERTINFO_CHALLENGEPASSWORD,
                   1163:        CRYPT_CERTINFO_LAST_EXTENSION = CRYPT_CERTINFO_SET_TUNNELINGALGID,
                   1164:        CRYPT_CERTINFO_FIRST_CMS = CRYPT_CERTINFO_CMS_CONTENTTYPE,
                   1165:        CRYPT_CERTINFO_LAST_CMS = CRYPT_CERTINFO_LAST - 1,
                   1166:        CRYPT_SESSINFO_FIRST_SPECIFIC = CRYPT_SESSINFO_REQUEST,
                   1167:        CRYPT_SESSINFO_LAST_SPECIFIC = CRYPT_SESSINFO_SSH_CHANNEL_ACTIVE
                   1168: #endif /* _CRYPT_DEFINED */
                   1169:        } CRYPT_ATTRIBUTE_TYPE;
                   1170: 
                   1171: /****************************************************************************
                   1172: *                                                                                                                                                      *
                   1173: *                                              Attribute Subtypes and Related Values                           *
                   1174: *                                                                                                                                                      *
                   1175: ****************************************************************************/
                   1176: 
                   1177: /* Flags for the X.509 keyUsage extension */
                   1178: 
                   1179: #define CRYPT_KEYUSAGE_NONE                                    0x000
                   1180: #define CRYPT_KEYUSAGE_DIGITALSIGNATURE                0x001
                   1181: #define CRYPT_KEYUSAGE_NONREPUDIATION          0x002
                   1182: #define CRYPT_KEYUSAGE_KEYENCIPHERMENT         0x004
                   1183: #define CRYPT_KEYUSAGE_DATAENCIPHERMENT                0x008
                   1184: #define CRYPT_KEYUSAGE_KEYAGREEMENT                    0x010
                   1185: #define CRYPT_KEYUSAGE_KEYCERTSIGN                     0x020
                   1186: #define CRYPT_KEYUSAGE_CRLSIGN                         0x040
                   1187: #define CRYPT_KEYUSAGE_ENCIPHERONLY                    0x080
                   1188: #define CRYPT_KEYUSAGE_DECIPHERONLY                    0x100
                   1189: #define CRYPT_KEYUSAGE_LAST                                    0x200   /* Last possible value */
                   1190: 
                   1191: /* X.509 cRLReason and cryptlib cRLExtReason codes */
                   1192: 
                   1193: enum { CRYPT_CRLREASON_UNSPECIFIED, CRYPT_CRLREASON_KEYCOMPROMISE,
                   1194:           CRYPT_CRLREASON_CACOMPROMISE, CRYPT_CRLREASON_AFFILIATIONCHANGED,
                   1195:           CRYPT_CRLREASON_SUPERSEDED, CRYPT_CRLREASON_CESSATIONOFOPERATION,
                   1196:           CRYPT_CRLREASON_CERTIFICATEHOLD, CRYPT_CRLREASON_REMOVEFROMCRL = 8,
                   1197:           CRYPT_CRLREASON_PRIVILEGEWITHDRAWN, CRYPT_CRLREASON_AACOMPROMISE,
                   1198:           CRYPT_CRLREASON_LAST, /* End of standard CRL reasons */
                   1199:           CRYPT_CRLREASON_NEVERVALID = 20, CRYPT_CRLEXTREASON_LAST };
                   1200: 
                   1201: /* X.509 CRL reason flags.  These identify the same thing as the cRLReason
                   1202:    codes but allow for multiple reasons to be specified.  Note that these
                   1203:    don't follow the X.509 naming since in that scheme the enumerated types
                   1204:    and bitflags have the same names */
                   1205: 
                   1206: #define CRYPT_CRLREASONFLAG_UNUSED                             0x001
                   1207: #define CRYPT_CRLREASONFLAG_KEYCOMPROMISE              0x002
                   1208: #define CRYPT_CRLREASONFLAG_CACOMPROMISE               0x004
                   1209: #define CRYPT_CRLREASONFLAG_AFFILIATIONCHANGED 0x008
                   1210: #define CRYPT_CRLREASONFLAG_SUPERSEDED                 0x010
                   1211: #define CRYPT_CRLREASONFLAG_CESSATIONOFOPERATION 0x020
                   1212: #define CRYPT_CRLREASONFLAG_CERTIFICATEHOLD            0x040
                   1213: #define CRYPT_CRLREASONFLAG_LAST                               0x080   /* Last poss.value */
                   1214: 
                   1215: /* X.509 CRL holdInstruction codes */
                   1216: 
                   1217: enum { CRYPT_HOLDINSTRUCTION_NONE, CRYPT_HOLDINSTRUCTION_CALLISSUER,
                   1218:           CRYPT_HOLDINSTRUCTION_REJECT, CRYPT_HOLDINSTRUCTION_PICKUPTOKEN,
                   1219:           CRYPT_HOLDINSTRUCTION_LAST };
                   1220: 
                   1221: /* Certificate checking compliance levels */
                   1222: 
                   1223: enum { CRYPT_COMPLIANCELEVEL_OBLIVIOUS, CRYPT_COMPLIANCELEVEL_REDUCED,
                   1224:           CRYPT_COMPLIANCELEVEL_STANDARD, CRYPT_COMPLIANCELEVEL_PKIX_PARTIAL,
                   1225:           CRYPT_COMPLIANCELEVEL_PKIX_FULL, CRYPT_COMPLIANCELEVEL_LAST };
                   1226: 
                   1227: /* Flags for the Netscape netscape-cert-type extension */
                   1228: 
                   1229: #define CRYPT_NS_CERTTYPE_SSLCLIENT                    0x001
                   1230: #define CRYPT_NS_CERTTYPE_SSLSERVER                    0x002
                   1231: #define CRYPT_NS_CERTTYPE_SMIME                                0x004
                   1232: #define CRYPT_NS_CERTTYPE_OBJECTSIGNING                0x008
                   1233: #define CRYPT_NS_CERTTYPE_RESERVED                     0x010
                   1234: #define CRYPT_NS_CERTTYPE_SSLCA                                0x020
                   1235: #define CRYPT_NS_CERTTYPE_SMIMECA                      0x040
                   1236: #define CRYPT_NS_CERTTYPE_OBJECTSIGNINGCA      0x080
                   1237: #define CRYPT_NS_CERTTYPE_LAST                         0x100   /* Last possible value */
                   1238: 
                   1239: /* Flags for the SET certificate-type extension */
                   1240: 
                   1241: #define CRYPT_SET_CERTTYPE_CARD                                0x001
                   1242: #define CRYPT_SET_CERTTYPE_MER                         0x002
                   1243: #define CRYPT_SET_CERTTYPE_PGWY                                0x004
                   1244: #define CRYPT_SET_CERTTYPE_CCA                         0x008
                   1245: #define CRYPT_SET_CERTTYPE_MCA                         0x010
                   1246: #define CRYPT_SET_CERTTYPE_PCA                         0x020
                   1247: #define CRYPT_SET_CERTTYPE_GCA                         0x040
                   1248: #define CRYPT_SET_CERTTYPE_BCA                         0x080
                   1249: #define CRYPT_SET_CERTTYPE_RCA                         0x100
                   1250: #define CRYPT_SET_CERTTYPE_ACQ                         0x200
                   1251: #define CRYPT_SET_CERTTYPE_LAST                                0x400   /* Last possible value */
                   1252: 
                   1253: /* CMS contentType values */
                   1254: 
                   1255: typedef enum { CRYPT_CONTENT_NONE, CRYPT_CONTENT_DATA,
                   1256:                           CRYPT_CONTENT_SIGNEDDATA, CRYPT_CONTENT_ENVELOPEDDATA,
                   1257:                           CRYPT_CONTENT_SIGNEDANDENVELOPEDDATA,
                   1258:                           CRYPT_CONTENT_DIGESTEDDATA, CRYPT_CONTENT_ENCRYPTEDDATA,
                   1259:                           CRYPT_CONTENT_COMPRESSEDDATA, CRYPT_CONTENT_TSTINFO,
                   1260:                           CRYPT_CONTENT_SPCINDIRECTDATACONTEXT,
                   1261:                           CRYPT_CONTENT_RTCSREQUEST, CRYPT_CONTENT_RTCSRESPONSE,
                   1262:                           CRYPT_CONTENT_RTCSRESPONSE_EXT, CRYPT_CONTENT_LAST
                   1263:                         } CRYPT_CONTENT_TYPE;
                   1264: 
                   1265: /* ESS securityClassification codes */
                   1266: 
                   1267: enum { CRYPT_CLASSIFICATION_UNMARKED, CRYPT_CLASSIFICATION_UNCLASSIFIED,
                   1268:           CRYPT_CLASSIFICATION_RESTRICTED, CRYPT_CLASSIFICATION_CONFIDENTIAL,
                   1269:           CRYPT_CLASSIFICATION_SECRET, CRYPT_CLASSIFICATION_TOP_SECRET,
                   1270:           CRYPT_CLASSIFICATION_LAST = 255 };
                   1271: 
                   1272: /* RTCS certificate status */
                   1273: 
                   1274: enum { CRYPT_CERTSTATUS_VALID, CRYPT_CERTSTATUS_NOTVALID,
                   1275:           CRYPT_CERTSTATUS_NONAUTHORITATIVE, CRYPT_CERTSTATUS_UNKNOWN };
                   1276: 
                   1277: /* OCSP revocation status */
                   1278: 
                   1279: enum { CRYPT_OCSPSTATUS_NOTREVOKED, CRYPT_OCSPSTATUS_REVOKED,
                   1280:           CRYPT_OCSPSTATUS_UNKNOWN };
                   1281: 
                   1282: /* The amount of detail to include in signatures when signing certificate
                   1283:    objects */
                   1284: 
                   1285: typedef enum {
                   1286:        CRYPT_SIGNATURELEVEL_NONE,              /* Include only signature */
                   1287:        CRYPT_SIGNATURELEVEL_SIGNERCERT,/* Include signer cert */
                   1288:        CRYPT_SIGNATURELEVEL_ALL,               /* Include all relevant info */
                   1289:        CRYPT_SIGNATURELEVEL_LAST               /* Last possible sig.level type */
                   1290:        } CRYPT_SIGNATURELEVEL_TYPE;
                   1291: 
                   1292: /* The certificate export format type, which defines the format in which a
                   1293:    certificate object is exported */
                   1294: 
                   1295: typedef enum {
                   1296:        CRYPT_CERTFORMAT_NONE,                  /* No certificate format */
                   1297:        CRYPT_CERTFORMAT_CERTIFICATE,   /* DER-encoded certificate */
                   1298:        CRYPT_CERTFORMAT_CERTCHAIN,             /* PKCS #7 certificate chain */
                   1299:        CRYPT_CERTFORMAT_TEXT_CERTIFICATE,      /* base-64 wrapped cert */
                   1300:        CRYPT_CERTFORMAT_TEXT_CERTCHAIN,        /* base-64 wrapped cert chain */
                   1301:        CRYPT_CERTFORMAT_XML_CERTIFICATE,       /* XML wrapped cert */
                   1302:        CRYPT_CERTFORMAT_XML_CERTCHAIN, /* XML wrapped cert chain */
                   1303: #ifdef _CRYPT_DEFINED
                   1304:        CRYPT_ICERTFORMAT_CERTSET,              /* SET OF Certificate */
                   1305:        CRYPT_ICERTFORMAT_CERTSEQUENCE, /* SEQUENCE OF Certificate */
                   1306:        CRYPT_ICERTFORMAT_SSL_CERTCHAIN,/* SSL certificate chain */
                   1307:        CRYPT_ICERTFORMAT_DATA,                 /* Non-signed object data */
                   1308: #endif /* CRYPT_DEFINED */
                   1309:        CRYPT_CERTFORMAT_LAST                   /* Last possible cert.format type */
                   1310: #ifdef _CRYPT_DEFINED
                   1311:        /* The following is used as an internal format specifier when the format
                   1312:           is autodetected, to tell the base64 decoding code to strip MIME
                   1313:           headers before the base64 data */
                   1314:        , CRYPT_ICERTFORMAT_SMIME_CERTIFICATE,/* S/MIME cert.request or cert chain */
                   1315:        CRYPT_CERTFORMAT_LAST_EXTERNAL = CRYPT_CERTFORMAT_XML_CERTCHAIN + 1
                   1316: #endif /* _CRYPT_DEFINED */
                   1317:        } CRYPT_CERTFORMAT_TYPE;
                   1318: 
                   1319: /* CMP request types */
                   1320: 
                   1321: typedef enum {
                   1322:        CRYPT_REQUESTTYPE_NONE,                 /* No request type */
                   1323:        CRYPT_REQUESTTYPE_INITIALISATION,       /* Initialisation request */
                   1324:                CRYPT_REQUESTTYPE_INITIALIZATION = CRYPT_REQUESTTYPE_INITIALISATION,
                   1325:        CRYPT_REQUESTTYPE_CERTIFICATE,  /* Certification request */
                   1326:        CRYPT_REQUESTTYPE_KEYUPDATE,    /* Key update request */
                   1327:        CRYPT_REQUESTTYPE_REVOCATION,   /* Cert revocation request */
                   1328:        CRYPT_REQUESTTYPE_PKIBOOT,              /* PKIBoot request */
                   1329:        CRYPT_REQUESTTYPE_LAST                  /* Last possible request type */
                   1330:        } CRYPT_REQUESTTYPE_TYPE;
                   1331: 
                   1332: /* Key ID types */
                   1333: 
                   1334: typedef enum {
                   1335:        CRYPT_KEYID_NONE,                               /* No key ID type */
                   1336:        CRYPT_KEYID_NAME,                               /* Key owner name */
                   1337:        CRYPT_KEYID_URI,                                /* Key owner URI */
                   1338:                CRYPT_KEYID_EMAIL = CRYPT_KEYID_URI, /* Synonym: owner email addr.*/
                   1339: #ifdef _CRYPT_DEFINED
                   1340:        /* Internal key ID types */
                   1341:        CRYPT_IKEYID_KEYID,                             /* SubjectKeyIdentifier/internal ID */
                   1342:        CRYPT_IKEYID_PGPKEYID,                  /* PGP/OpenPGP key ID */
                   1343:        CRYPT_IKEYID_CERTID,                    /* Certificate hash */
                   1344:        CRYPT_IKEYID_ISSUERID,                  /* Hashed issuerAndSerialNumber */
                   1345:        CRYPT_IKEYID_ISSUERANDSERIALNUMBER,     /* issuerAndSerialNumber */
                   1346: #endif /* _CRYPT_DEFINED */
                   1347:        CRYPT_KEYID_LAST                                /* Last possible key ID type */
                   1348: #ifdef _CRYPT_DEFINED
                   1349:        , CRYPT_KEYID_LAST_EXTERNAL = CRYPT_KEYID_URI + 1/* Last external key ID */
                   1350: #endif /* _CRYPT_DEFINED */
                   1351:        } CRYPT_KEYID_TYPE;
                   1352: 
                   1353: /* The encryption object types */
                   1354: 
                   1355: typedef enum {
                   1356:        CRYPT_OBJECT_NONE,                              /* No object type */
                   1357:        CRYPT_OBJECT_ENCRYPTED_KEY,             /* Conventionally encrypted key */
                   1358:        CRYPT_OBJECT_PKCENCRYPTED_KEY,  /* PKC-encrypted key */
                   1359:        CRYPT_OBJECT_KEYAGREEMENT,              /* Key agreement information */
                   1360:        CRYPT_OBJECT_SIGNATURE,                 /* Signature */
                   1361:        CRYPT_OBJECT_LAST                               /* Last possible object type */
                   1362:        } CRYPT_OBJECT_TYPE;
                   1363: 
                   1364: /* Object/attribute error type information */
                   1365: 
                   1366: typedef enum {
                   1367:        CRYPT_ERRTYPE_NONE,                             /* No error information */
                   1368:        CRYPT_ERRTYPE_ATTR_SIZE,                /* Attribute data too small or large */
                   1369:        CRYPT_ERRTYPE_ATTR_VALUE,               /* Attribute value is invalid */
                   1370:        CRYPT_ERRTYPE_ATTR_ABSENT,              /* Required attribute missing */
                   1371:        CRYPT_ERRTYPE_ATTR_PRESENT,             /* Non-allowed attribute present */
                   1372:        CRYPT_ERRTYPE_CONSTRAINT,               /* Cert: Constraint violation in object */
                   1373:        CRYPT_ERRTYPE_ISSUERCONSTRAINT, /* Cert: Constraint viol.in issuing cert */
                   1374:        CRYPT_ERRTYPE_LAST                              /* Last possible error info type */
                   1375:        } CRYPT_ERRTYPE_TYPE;
                   1376: 
                   1377: /* Cert store management action type */
                   1378: 
                   1379: typedef enum {
                   1380:        CRYPT_CERTACTION_NONE,                  /* No cert management action */
                   1381:        CRYPT_CERTACTION_CREATE,                /* Create cert store */
                   1382:        CRYPT_CERTACTION_CONNECT,               /* Connect to cert store */
                   1383:        CRYPT_CERTACTION_DISCONNECT,    /* Disconnect from cert store */
                   1384:        CRYPT_CERTACTION_ERROR,                 /* Error information */
                   1385:        CRYPT_CERTACTION_ADDUSER,               /* Add PKI user */
                   1386:        CRYPT_CERTACTION_DELETEUSER,    /* Delete PKI user */
                   1387:        CRYPT_CERTACTION_REQUEST_CERT,  /* Cert request */
                   1388:        CRYPT_CERTACTION_REQUEST_RENEWAL,/* Cert renewal request */
                   1389:        CRYPT_CERTACTION_REQUEST_REVOCATION,/* Cert revocation request */
                   1390:        CRYPT_CERTACTION_CERT_CREATION, /* Cert creation */
                   1391:        CRYPT_CERTACTION_CERT_CREATION_COMPLETE,/* Confirmation of cert creation */
                   1392:        CRYPT_CERTACTION_CERT_CREATION_DROP,    /* Cancellation of cert creation */
                   1393:        CRYPT_CERTACTION_CERT_CREATION_REVERSE, /* Cancel of creation w.revocation */
                   1394:        CRYPT_CERTACTION_RESTART_CLEANUP, /* Delete reqs after restart */
                   1395:        CRYPT_CERTACTION_RESTART_REVOKE_CERT, /* Complete revocation after restart */
                   1396:        CRYPT_CERTACTION_ISSUE_CERT,    /* Cert issue */
                   1397:        CRYPT_CERTACTION_ISSUE_CRL,             /* CRL issue */
                   1398:        CRYPT_CERTACTION_REVOKE_CERT,   /* Cert revocation */
                   1399:        CRYPT_CERTACTION_EXPIRE_CERT,   /* Cert expiry */
                   1400:        CRYPT_CERTACTION_CLEANUP,               /* Clean up on restart */
                   1401:        CRYPT_CERTACTION_LAST                   /* Last possible cert store log action */
                   1402: #ifdef _CRYPT_DEFINED
                   1403:        /* User-settable action types for cert mgmt.actions */
                   1404:        , CRYPT_CERTACTION_FIRST_USER = CRYPT_CERTACTION_ISSUE_CERT,
                   1405:        CRYPT_CERTACTION_LAST_USER = CRYPT_CERTACTION_CLEANUP
                   1406: #endif /* _CRYPT_DEFINED */
                   1407:        } CRYPT_CERTACTION_TYPE;
                   1408: 
                   1409: /****************************************************************************
                   1410: *                                                                                                                                                      *
                   1411: *                                                              General Constants                                                       *
                   1412: *                                                                                                                                                      *
                   1413: ****************************************************************************/
                   1414: 
                   1415: /* The maximum user key size - 2048 bits */
                   1416: 
                   1417: #define CRYPT_MAX_KEYSIZE              256
                   1418: 
                   1419: /* The maximum IV size - 256 bits */
                   1420: 
                   1421: #define CRYPT_MAX_IVSIZE               32
                   1422: 
                   1423: /* The maximum public-key component size - 4096 bits */
                   1424: 
                   1425: #define CRYPT_MAX_PKCSIZE              512
                   1426: 
                   1427: /* The maximum hash size - 256 bits */
                   1428: 
                   1429: #define CRYPT_MAX_HASHSIZE             32
                   1430: 
                   1431: /* The maximum size of a text string (e.g.key owner name) */
                   1432: 
                   1433: #define CRYPT_MAX_TEXTSIZE             64
                   1434: 
                   1435: /* A magic value indicating that the default setting for this parameter
                   1436:    should be used */
                   1437: 
                   1438: #define CRYPT_USE_DEFAULT              -100
                   1439: 
                   1440: /* A magic value for unused parameters */
                   1441: 
                   1442: #define CRYPT_UNUSED                   -101
                   1443: 
                   1444: /* Cursor positioning codes for certificate/CRL extensions */
                   1445: 
                   1446: #define CRYPT_CURSOR_FIRST             -200
                   1447: #define CRYPT_CURSOR_PREVIOUS  -201
                   1448: #define CRYPT_CURSOR_NEXT              -202
                   1449: #define CRYPT_CURSOR_LAST              -203
                   1450: 
                   1451: /* The type of information polling to perform to get random seed 
                   1452:    information.  These values have to be negative because they're used
                   1453:    as magic length values for cryptAddRandom() */
                   1454: 
                   1455: #define CRYPT_RANDOM_FASTPOLL  -300
                   1456: #define CRYPT_RANDOM_SLOWPOLL  -301
                   1457: 
                   1458: /* Whether the PKC key is a public or private key */
                   1459: 
                   1460: #define CRYPT_KEYTYPE_PRIVATE  0
                   1461: #define CRYPT_KEYTYPE_PUBLIC   1
                   1462: 
                   1463: /* Keyset open options */
                   1464: 
                   1465: typedef enum {
                   1466:        CRYPT_KEYOPT_NONE,                              /* No options */
                   1467:        CRYPT_KEYOPT_READONLY,                  /* Open keyset in read-only mode */
                   1468:        CRYPT_KEYOPT_CREATE,                    /* Create a new keyset */
                   1469: #ifdef _CRYPT_DEFINED
                   1470:        /* Internal keyset options */
                   1471:        CRYPT_IKEYOPT_EXCLUSIVEACCESS,  /* As _NONE but open for exclusive access */
                   1472: #endif /* _CRYPT_DEFINED */
                   1473:        CRYPT_KEYOPT_LAST                               /* Last possible key option type */
                   1474: #ifdef _CRYPT_DEFINED
                   1475:        , CRYPT_KEYOPT_LAST_EXTERNAL = CRYPT_KEYOPT_CREATE + 1
                   1476:                                                                        /* Last external keyset option */
                   1477: #endif /* _CRYPT_DEFINED */
                   1478:        } CRYPT_KEYOPT_TYPE;
                   1479: 
                   1480: /* The various cryptlib objects - these are just integer handles */
                   1481: 
                   1482: typedef int CRYPT_CERTIFICATE;
                   1483: typedef int CRYPT_CONTEXT;
                   1484: typedef int CRYPT_DEVICE;
                   1485: typedef int CRYPT_ENVELOPE;
                   1486: typedef int CRYPT_KEYSET;
                   1487: typedef int CRYPT_SESSION;
                   1488: typedef int CRYPT_USER;
                   1489: 
                   1490: /* Sometimes we don't know the exact type of a cryptlib object, so we use a
                   1491:    generic handle type to identify it */
                   1492: 
                   1493: typedef int CRYPT_HANDLE;
                   1494: 
                   1495: /****************************************************************************
                   1496: *                                                                                                                                                      *
                   1497: *                                                      Encryption Data Structures                                              *
                   1498: *                                                                                                                                                      *
                   1499: ****************************************************************************/
                   1500: 
                   1501: /* Results returned from the capability query */
                   1502: 
                   1503: typedef struct {
                   1504:        /* Algorithm information */
                   1505:        C_CHR algoName[ CRYPT_MAX_TEXTSIZE ];/* Algorithm name */
                   1506:        int blockSize;                                  /* Block size of the algorithm */
                   1507:        int minKeySize;                                 /* Minimum key size in bytes */
                   1508:        int keySize;                                    /* Recommended key size in bytes */
                   1509:        int maxKeySize;                                 /* Maximum key size in bytes */
                   1510:        } CRYPT_QUERY_INFO;
                   1511: 
                   1512: /* Results returned from the encoded object query.  These provide
                   1513:    information on the objects created by cryptExportKey()/
                   1514:    cryptCreateSignature() */
                   1515: 
                   1516: typedef struct {
                   1517:        /* The object type */
                   1518:        CRYPT_OBJECT_TYPE objectType;
                   1519: 
                   1520:        /* The encryption algorithm and mode */
                   1521:        CRYPT_ALGO_TYPE cryptAlgo;
                   1522:        CRYPT_MODE_TYPE cryptMode;
                   1523: 
                   1524:        /* The hash algorithm for Signature objects */
                   1525:        CRYPT_ALGO_TYPE hashAlgo;
                   1526: 
                   1527:        /* The salt for derived keys */
                   1528:        unsigned char salt[ CRYPT_MAX_HASHSIZE ];
                   1529:        int saltSize;
                   1530:        } CRYPT_OBJECT_INFO;
                   1531: 
                   1532: /* Key information for the public-key encryption algorithms.  These fields
                   1533:    are not accessed directly, but can be manipulated with the init/set/
                   1534:    destroyComponents() macros */
                   1535: 
                   1536: typedef struct {
                   1537:        /* Status information */
                   1538:        int isPublicKey;                        /* Whether this is a public or private key */
                   1539: 
                   1540:        /* Public components */
                   1541:        unsigned char n[ CRYPT_MAX_PKCSIZE ];   /* Modulus */
                   1542:        int nLen;                                       /* Length of modulus in bits */
                   1543:        unsigned char e[ CRYPT_MAX_PKCSIZE ];   /* Public exponent */
                   1544:        int eLen;                                       /* Length of public exponent in bits */
                   1545: 
                   1546:        /* Private components */
                   1547:        unsigned char d[ CRYPT_MAX_PKCSIZE ];   /* Private exponent */
                   1548:        int dLen;                                       /* Length of private exponent in bits */
                   1549:        unsigned char p[ CRYPT_MAX_PKCSIZE ];   /* Prime factor 1 */
                   1550:        int pLen;                                       /* Length of prime factor 1 in bits */
                   1551:        unsigned char q[ CRYPT_MAX_PKCSIZE ];   /* Prime factor 2 */
                   1552:        int qLen;                                       /* Length of prime factor 2 in bits */
                   1553:        unsigned char u[ CRYPT_MAX_PKCSIZE ];   /* Mult.inverse of q, mod p */
                   1554:        int uLen;                                       /* Length of private exponent in bits */
                   1555:        unsigned char e1[ CRYPT_MAX_PKCSIZE ];  /* Private exponent 1 (PKCS) */
                   1556:        int e1Len;                                      /* Length of private exponent in bits */
                   1557:        unsigned char e2[ CRYPT_MAX_PKCSIZE ];  /* Private exponent 2 (PKCS) */
                   1558:        int e2Len;                                      /* Length of private exponent in bits */
                   1559:        } CRYPT_PKCINFO_RSA;
                   1560: 
                   1561: typedef struct {
                   1562:        /* Status information */
                   1563:        int isPublicKey;                        /* Whether this is a public or private key */
                   1564: 
                   1565:        /* Public components */
                   1566:        unsigned char p[ CRYPT_MAX_PKCSIZE ];   /* Prime modulus */
                   1567:        int pLen;                                       /* Length of prime modulus in bits */
                   1568:        unsigned char q[ CRYPT_MAX_PKCSIZE ];   /* Prime divisor */
                   1569:        int qLen;                                       /* Length of prime divisor in bits */
                   1570:        unsigned char g[ CRYPT_MAX_PKCSIZE ];   /* h^( ( p - 1 ) / q ) mod p */
                   1571:        int gLen;                                       /* Length of g in bits */
                   1572:        unsigned char y[ CRYPT_MAX_PKCSIZE ];   /* Public random integer */
                   1573:        int yLen;                                       /* Length of public integer in bits */
                   1574: 
                   1575:        /* Private components */
                   1576:        unsigned char x[ CRYPT_MAX_PKCSIZE ];   /* Private random integer */
                   1577:        int xLen;                                       /* Length of private integer in bits */
                   1578:        } CRYPT_PKCINFO_DLP;
                   1579: 
                   1580: /* Macros to initialise and destroy the structure that stores the components
                   1581:    of a public key */
                   1582: 
                   1583: #define cryptInitComponents( componentInfo, componentKeyType ) \
                   1584:        { memset( ( componentInfo ), 0, sizeof( *componentInfo ) ); \
                   1585:          ( componentInfo )->isPublicKey = ( ( componentKeyType ) ? 1 : 0 ); }
                   1586: 
                   1587: #define cryptDestroyComponents( componentInfo ) \
                   1588:        memset( ( componentInfo ), 0, sizeof( *componentInfo ) )
                   1589: 
                   1590: /* Macros to set a component of a public key */
                   1591: 
                   1592: #define cryptSetComponent( destination, source, length ) \
                   1593:        { memcpy( ( destination ), ( source ), ( ( length ) + 7 ) >> 3 ); \
                   1594:          ( destination##Len ) = length; }
                   1595: 
                   1596: /****************************************************************************
                   1597: *                                                                                                                                                      *
                   1598: *                                                              Status Codes                                                            *
                   1599: *                                                                                                                                                      *
                   1600: ****************************************************************************/
                   1601: 
                   1602: /* No error in function call */
                   1603: 
                   1604: #define CRYPT_OK                               0       /* No error */
                   1605: 
                   1606: /* Error in parameters passed to function */
                   1607: 
                   1608: #define CRYPT_ERROR_PARAM1             -1      /* Bad argument, parameter 1 */
                   1609: #define CRYPT_ERROR_PARAM2             -2      /* Bad argument, parameter 2 */
                   1610: #define CRYPT_ERROR_PARAM3             -3      /* Bad argument, parameter 3 */
                   1611: #define CRYPT_ERROR_PARAM4             -4      /* Bad argument, parameter 4 */
                   1612: #define CRYPT_ERROR_PARAM5             -5      /* Bad argument, parameter 5 */
                   1613: #define CRYPT_ERROR_PARAM6             -6      /* Bad argument, parameter 6 */
                   1614: #define CRYPT_ERROR_PARAM7             -7      /* Bad argument, parameter 7 */
                   1615: 
                   1616: /* Errors due to insufficient resources */
                   1617: 
                   1618: #define CRYPT_ERROR_MEMORY             -10     /* Out of memory */
                   1619: #define CRYPT_ERROR_NOTINITED  -11     /* Data has not been initialised */
                   1620: #define CRYPT_ERROR_INITED             -12     /* Data has already been init'd */
                   1621: #define CRYPT_ERROR_NOSECURE   -13     /* Opn.not avail.at requested sec.level */
                   1622: #define CRYPT_ERROR_RANDOM             -14     /* No reliable random data available */
                   1623: #define CRYPT_ERROR_FAILED             -15     /* Operation failed */
                   1624: #define CRYPT_ERROR_INTERNAL   -16     /* Internal consistency check failed */
                   1625: 
                   1626: /* Security violations */
                   1627: 
                   1628: #define CRYPT_ERROR_NOTAVAIL   -20     /* This type of opn.not available */
                   1629: #define CRYPT_ERROR_PERMISSION -21     /* No permiss.to perform this operation */
                   1630: #define CRYPT_ERROR_WRONGKEY   -22     /* Incorrect key used to decrypt data */
                   1631: #define CRYPT_ERROR_INCOMPLETE -23     /* Operation incomplete/still in progress */
                   1632: #define CRYPT_ERROR_COMPLETE   -24     /* Operation complete/can't continue */
                   1633: #define CRYPT_ERROR_TIMEOUT            -25     /* Operation timed out before completion */
                   1634: #define CRYPT_ERROR_INVALID            -26     /* Invalid/inconsistent information */
                   1635: #define CRYPT_ERROR_SIGNALLED  -27     /* Resource destroyed by extnl.event */
                   1636: 
                   1637: /* High-level function errors */
                   1638: 
                   1639: #define CRYPT_ERROR_OVERFLOW   -30     /* Resources/space exhausted */
                   1640: #define CRYPT_ERROR_UNDERFLOW  -31     /* Not enough data available */
                   1641: #define CRYPT_ERROR_BADDATA            -32     /* Bad/unrecognised data format */
                   1642: #define CRYPT_ERROR_SIGNATURE  -33     /* Signature/integrity check failed */
                   1643: 
                   1644: /* Data access function errors */
                   1645: 
                   1646: #define CRYPT_ERROR_OPEN               -40     /* Cannot open object */
                   1647: #define CRYPT_ERROR_READ               -41     /* Cannot read item from object */
                   1648: #define CRYPT_ERROR_WRITE              -42     /* Cannot write item to object */
                   1649: #define CRYPT_ERROR_NOTFOUND   -43     /* Requested item not found in object */
                   1650: #define CRYPT_ERROR_DUPLICATE  -44     /* Item already present in object */
                   1651: 
                   1652: /* Data enveloping errors */
                   1653: 
                   1654: #define CRYPT_ENVELOPE_RESOURCE        -50     /* Need resource to proceed */
                   1655: 
                   1656: /* Macros to examine return values */
                   1657: 
                   1658: #define cryptStatusError( status )     ( ( status ) < CRYPT_OK )
                   1659: #define cryptStatusOK( status )                ( ( status ) == CRYPT_OK )
                   1660: 
                   1661: /****************************************************************************
                   1662: *                                                                                                                                                      *
                   1663: *                                                                      General Functions                                               *
                   1664: *                                                                                                                                                      *
                   1665: ****************************************************************************/
                   1666: 
                   1667: /* The following is necessary to stop C++ name mangling */
                   1668: 
                   1669: #ifdef __cplusplus
                   1670: extern "C" {
                   1671: #endif /* __cplusplus */
                   1672: 
                   1673: /* Initialise and shut down cryptlib */
                   1674: 
                   1675: C_RET cryptInit( void );
                   1676: C_RET cryptEnd( void );
                   1677: 
                   1678: /* Query cryptlibs capabilities */
                   1679: 
                   1680: C_RET cryptQueryCapability( C_IN CRYPT_ALGO_TYPE cryptAlgo,
                   1681:                                                        C_OUT CRYPT_QUERY_INFO C_PTR cryptQueryInfo );
                   1682: 
                   1683: /* Create and destroy an encryption context */
                   1684: 
                   1685: C_RET cryptCreateContext( C_OUT CRYPT_CONTEXT C_PTR cryptContext,
                   1686:                                                  C_IN CRYPT_USER cryptUser,
                   1687:                                                  C_IN CRYPT_ALGO_TYPE cryptAlgo );
                   1688: C_RET cryptDestroyContext( C_IN CRYPT_CONTEXT cryptContext );
                   1689: 
                   1690: /* Generic "destroy an object" function */
                   1691: 
                   1692: C_RET cryptDestroyObject( C_IN CRYPT_HANDLE cryptObject );
                   1693: 
                   1694: /* Generate a key into a context */
                   1695: 
                   1696: C_RET cryptGenerateKey( C_IN CRYPT_CONTEXT cryptContext );
                   1697: C_RET cryptGenerateKeyAsync( C_IN CRYPT_CONTEXT cryptContext );
                   1698: C_RET cryptAsyncQuery( C_IN CRYPT_HANDLE cryptObject );
                   1699: C_RET cryptAsyncCancel( C_IN CRYPT_HANDLE cryptObject );
                   1700: 
                   1701: /* Encrypt/decrypt/hash a block of memory */
                   1702: 
                   1703: C_RET cryptEncrypt( C_IN CRYPT_CONTEXT cryptContext, C_INOUT void C_PTR buffer,
                   1704:                                        C_IN int length );
                   1705: C_RET cryptDecrypt( C_IN CRYPT_CONTEXT cryptContext, C_INOUT void C_PTR buffer,
                   1706:                                        C_IN int length );
                   1707: 
                   1708: /* Get/set/delete attribute functions */
                   1709: 
                   1710: C_RET cryptSetAttribute( C_IN CRYPT_HANDLE cryptHandle,
                   1711:                                                 C_IN CRYPT_ATTRIBUTE_TYPE attributeType,
                   1712:                                                 C_IN int value );
                   1713: C_RET cryptSetAttributeString( C_IN CRYPT_HANDLE cryptHandle,
                   1714:                                                           C_IN CRYPT_ATTRIBUTE_TYPE attributeType,
                   1715:                                                           C_IN void C_PTR value, C_IN int valueLength );
                   1716: C_RET cryptGetAttribute( C_IN CRYPT_HANDLE cryptHandle,
                   1717:                                                 C_IN CRYPT_ATTRIBUTE_TYPE attributeType,
                   1718:                                                 C_OUT int C_PTR value );
                   1719: C_RET cryptGetAttributeString( C_IN CRYPT_HANDLE cryptHandle,
                   1720:                                                           C_IN CRYPT_ATTRIBUTE_TYPE attributeType,
                   1721:                                                           C_OUT void C_PTR value,
                   1722:                                                           C_OUT int C_PTR valueLength );
                   1723: C_RET cryptDeleteAttribute( C_IN CRYPT_HANDLE cryptHandle,
                   1724:                                                        C_IN CRYPT_ATTRIBUTE_TYPE attributeType );
                   1725: 
                   1726: /* Oddball functions: Add random data to the pool, query an encoded signature
                   1727:    or key data.  These are due to be replaced once a suitable alternative can
                   1728:    be found */
                   1729: 
                   1730: C_RET cryptAddRandom( C_IN void C_PTR randomData, C_IN int randomDataLength );
                   1731: C_RET cryptQueryObject( C_IN void C_PTR objectData,
                   1732:                                                C_IN int objectDataLength,
                   1733:                                            C_OUT CRYPT_OBJECT_INFO C_PTR cryptObjectInfo );
                   1734: 
                   1735: /****************************************************************************
                   1736: *                                                                                                                                                      *
                   1737: *                                                      Mid-level Encryption Functions                                  *
                   1738: *                                                                                                                                                      *
                   1739: ****************************************************************************/
                   1740: 
                   1741: /* Export and import an encrypted session key */
                   1742: 
                   1743: C_RET cryptExportKey( C_OUT void C_PTR encryptedKey,
                   1744:                                          C_IN int encryptedKeyMaxLength,
                   1745:                                          C_OUT int C_PTR encryptedKeyLength,
                   1746:                                          C_IN CRYPT_HANDLE exportKey,
                   1747:                                          C_IN CRYPT_CONTEXT sessionKeyContext );
                   1748: C_RET cryptExportKeyEx( C_OUT void C_PTR encryptedKey,
                   1749:                                                C_IN int encryptedKeyMaxLength,
                   1750:                                                C_OUT int C_PTR encryptedKeyLength,
                   1751:                                                C_IN CRYPT_FORMAT_TYPE formatType,
                   1752:                                                C_IN CRYPT_HANDLE exportKey,
                   1753:                                                C_IN CRYPT_CONTEXT sessionKeyContext );
                   1754: C_RET cryptImportKey( C_IN void C_PTR encryptedKey,
                   1755:                                          C_IN int encryptedKeyLength,
                   1756:                                          C_IN CRYPT_CONTEXT importKey,
                   1757:                                          C_IN CRYPT_CONTEXT sessionKeyContext );
                   1758: C_RET cryptImportKeyEx( C_IN void C_PTR encryptedKey,
                   1759:                                                C_IN int encryptedKeyLength,
                   1760:                                                C_IN CRYPT_CONTEXT importKey,
                   1761:                                                C_IN CRYPT_CONTEXT sessionKeyContext,
                   1762:                                                C_OUT CRYPT_CONTEXT C_PTR returnedContext );
                   1763: 
                   1764: /* Create and check a digital signature */
                   1765: 
                   1766: C_RET cryptCreateSignature( C_OUT void C_PTR signature,
                   1767:                                                        C_IN int signatureMaxLength,
                   1768:                                                        C_OUT int C_PTR signatureLength,
                   1769:                                                        C_IN CRYPT_CONTEXT signContext,
                   1770:                                                        C_IN CRYPT_CONTEXT hashContext );
                   1771: C_RET cryptCreateSignatureEx( C_OUT void C_PTR signature,
                   1772:                                                          C_IN int signatureMaxLength,
                   1773:                                                          C_OUT int C_PTR signatureLength,
                   1774:                                                          C_IN CRYPT_FORMAT_TYPE formatType,
                   1775:                                                          C_IN CRYPT_CONTEXT signContext,
                   1776:                                                          C_IN CRYPT_CONTEXT hashContext,
                   1777:                                                          C_IN CRYPT_CERTIFICATE extraData );
                   1778: C_RET cryptCheckSignature( C_IN void C_PTR signature,
                   1779:                                                   C_IN int signatureLength,
                   1780:                                                   C_IN CRYPT_HANDLE sigCheckKey,
                   1781:                                                   C_IN CRYPT_CONTEXT hashContext );
                   1782: C_RET cryptCheckSignatureEx( C_IN void C_PTR signature,
                   1783:                                                         C_IN int signatureLength,
                   1784:                                                         C_IN CRYPT_HANDLE sigCheckKey,
                   1785:                                                         C_IN CRYPT_CONTEXT hashContext,
                   1786:                                                         C_OUT CRYPT_HANDLE C_PTR extraData );
                   1787: 
                   1788: /****************************************************************************
                   1789: *                                                                                                                                                      *
                   1790: *                                                                      Keyset Functions                                                *
                   1791: *                                                                                                                                                      *
                   1792: ****************************************************************************/
                   1793: 
                   1794: /* Open and close a keyset */
                   1795: 
                   1796: C_RET cryptKeysetOpen( C_OUT CRYPT_KEYSET C_PTR keyset,
                   1797:                                           C_IN CRYPT_USER cryptUser,
                   1798:                                           C_IN CRYPT_KEYSET_TYPE keysetType,
                   1799:                                           C_IN C_STR name, C_IN CRYPT_KEYOPT_TYPE options );
                   1800: C_RET cryptKeysetClose( C_IN CRYPT_KEYSET keyset );
                   1801: 
                   1802: /* Get a key from a keyset */
                   1803: 
                   1804: C_RET cryptGetPublicKey( C_IN CRYPT_KEYSET keyset,
                   1805:                                                 C_OUT CRYPT_CONTEXT C_PTR cryptContext,
                   1806:                                                 C_IN CRYPT_KEYID_TYPE keyIDtype,
                   1807:                                                 C_IN C_STR keyID );
                   1808: C_RET cryptGetPrivateKey( C_IN CRYPT_KEYSET keyset,
                   1809:                                                  C_OUT CRYPT_CONTEXT C_PTR cryptContext,
                   1810:                                                  C_IN CRYPT_KEYID_TYPE keyIDtype,
                   1811:                                                  C_IN C_STR keyID, C_IN C_STR password );
                   1812: 
                   1813: /* Add/delete a key to/from a keyset */
                   1814: 
                   1815: C_RET cryptAddPublicKey( C_IN CRYPT_KEYSET keyset,
                   1816:                                                 C_IN CRYPT_CERTIFICATE certificate );
                   1817: C_RET cryptAddPrivateKey( C_IN CRYPT_KEYSET keyset,
                   1818:                                                  C_IN CRYPT_HANDLE cryptKey,
                   1819:                                                  C_IN C_STR password );
                   1820: C_RET cryptDeleteKey( C_IN CRYPT_KEYSET keyset,
                   1821:                                          C_IN CRYPT_KEYID_TYPE keyIDtype,
                   1822:                                          C_IN C_STR keyID );
                   1823: 
                   1824: /****************************************************************************
                   1825: *                                                                                                                                                      *
                   1826: *                                                              Certificate Functions                                           *
                   1827: *                                                                                                                                                      *
                   1828: ****************************************************************************/
                   1829: 
                   1830: /* Create/destroy a certificate */
                   1831: 
                   1832: C_RET cryptCreateCert( C_OUT CRYPT_CERTIFICATE C_PTR certificate,
                   1833:                                           C_IN CRYPT_USER cryptUser,
                   1834:                                           C_IN CRYPT_CERTTYPE_TYPE certType );
                   1835: C_RET cryptDestroyCert( C_IN CRYPT_CERTIFICATE certificate );
                   1836: 
                   1837: /* Get/add/delete certificate extensions.  These are direct data insertion
                   1838:    functions whose use is discouraged, so they fix the string at char *
                   1839:    rather than C_STR */
                   1840: 
                   1841: C_RET cryptGetCertExtension( C_IN CRYPT_CERTIFICATE certificate,
                   1842:                                                         C_IN char C_PTR oid,
                   1843:                                                         C_OUT int C_PTR criticalFlag,
                   1844:                                                         C_OUT void C_PTR extension,
                   1845:                                                         C_IN int extensionMaxLength,
                   1846:                                                         C_OUT int C_PTR extensionLength );
                   1847: C_RET cryptAddCertExtension( C_IN CRYPT_CERTIFICATE certificate,
                   1848:                                                         C_IN char C_PTR oid, C_IN int criticalFlag,
                   1849:                                                         C_IN void C_PTR extension,
                   1850:                                                         C_IN int extensionLength );
                   1851: C_RET cryptDeleteCertExtension( C_IN CRYPT_CERTIFICATE certificate,
                   1852:                                                            C_IN char C_PTR oid );
                   1853: 
                   1854: /* Sign/sig.check a certificate/certification request */
                   1855: 
                   1856: C_RET cryptSignCert( C_IN CRYPT_CERTIFICATE certificate,
                   1857:                                         C_IN CRYPT_CONTEXT signContext );
                   1858: C_RET cryptCheckCert( C_IN CRYPT_CERTIFICATE certificate,
                   1859:                                          C_IN CRYPT_HANDLE sigCheckKey );
                   1860: 
                   1861: /* Import/export a certificate/certification request */
                   1862: 
                   1863: C_RET cryptImportCert( C_IN void C_PTR certObject,
                   1864:                                           C_IN int certObjectLength,
                   1865:                                           C_IN CRYPT_USER cryptUser,
                   1866:                                           C_OUT CRYPT_CERTIFICATE C_PTR certificate );
                   1867: C_RET cryptExportCert( C_OUT void C_PTR certObject,
                   1868:                                           C_IN int certObjectMaxLength,
                   1869:                                           C_OUT int C_PTR certObjectLength,
                   1870:                                           C_IN CRYPT_CERTFORMAT_TYPE certFormatType,
                   1871:                                           C_IN CRYPT_CERTIFICATE certificate );
                   1872: 
                   1873: /* CA management functions */
                   1874: 
                   1875: C_RET cryptCAAddItem( C_IN CRYPT_KEYSET keyset,
                   1876:                                          C_IN CRYPT_CERTIFICATE certificate );
                   1877: C_RET cryptCAGetItem( C_IN CRYPT_KEYSET keyset,
                   1878:                                          C_OUT CRYPT_CERTIFICATE C_PTR certificate,
                   1879:                                          C_IN CRYPT_CERTTYPE_TYPE certType,
                   1880:                                          C_IN CRYPT_KEYID_TYPE keyIDtype,
                   1881:                                          C_IN C_STR keyID );
                   1882: C_RET cryptCADeleteItem( C_IN CRYPT_KEYSET keyset,
                   1883:                                                 C_IN CRYPT_CERTTYPE_TYPE certType,
                   1884:                                                 C_IN CRYPT_KEYID_TYPE keyIDtype,
                   1885:                                                 C_IN C_STR keyID );
                   1886: C_RET cryptCACertManagement( C_OUT CRYPT_CERTIFICATE C_PTR certificate,
                   1887:                                                         C_IN CRYPT_CERTACTION_TYPE action,
                   1888:                                                         C_IN CRYPT_KEYSET keyset,
                   1889:                                                         C_IN CRYPT_CONTEXT caKey,
                   1890:                                                         C_IN CRYPT_CERTIFICATE certRequest );
                   1891: 
                   1892: /****************************************************************************
                   1893: *                                                                                                                                                      *
                   1894: *                                                      Envelope and Session Functions                                  *
                   1895: *                                                                                                                                                      *
                   1896: ****************************************************************************/
                   1897: 
                   1898: /* Create/destroy an envelope */
                   1899: 
                   1900: C_RET cryptCreateEnvelope( C_OUT CRYPT_ENVELOPE C_PTR envelope,
                   1901:                                                   C_IN CRYPT_USER cryptUser,
                   1902:                                                   C_IN CRYPT_FORMAT_TYPE formatType );
                   1903: C_RET cryptDestroyEnvelope( C_IN CRYPT_ENVELOPE envelope );
                   1904: 
                   1905: /* Create/destroy a session */
                   1906: 
                   1907: C_RET cryptCreateSession( C_OUT CRYPT_SESSION C_PTR session,
                   1908:                                                  C_IN CRYPT_USER cryptUser,
                   1909:                                                  C_IN CRYPT_SESSION_TYPE formatType );
                   1910: C_RET cryptDestroySession( C_IN CRYPT_SESSION session );
                   1911: 
                   1912: /* Add/remove data to/from and envelope or session */
                   1913: 
                   1914: C_RET cryptPushData( C_IN CRYPT_HANDLE envelope, C_IN void C_PTR buffer,
                   1915:                                         C_IN int length, C_OUT int C_PTR bytesCopied );
                   1916: C_RET cryptFlushData( C_IN CRYPT_HANDLE envelope );
                   1917: C_RET cryptPopData( C_IN CRYPT_HANDLE envelope, C_OUT void C_PTR buffer,
                   1918:                                    C_IN int length, C_OUT int C_PTR bytesCopied );
                   1919: 
                   1920: /****************************************************************************
                   1921: *                                                                                                                                                      *
                   1922: *                                                              Device Functions                                                        *
                   1923: *                                                                                                                                                      *
                   1924: ****************************************************************************/
                   1925: 
                   1926: /* Open and close a device */
                   1927: 
                   1928: C_RET cryptDeviceOpen( C_OUT CRYPT_DEVICE C_PTR device,
                   1929:                                           C_IN CRYPT_USER cryptUser,
                   1930:                                           C_IN CRYPT_DEVICE_TYPE deviceType,
                   1931:                                           C_IN C_STR name );
                   1932: C_RET cryptDeviceClose( C_IN CRYPT_DEVICE device );
                   1933: 
                   1934: /* Query a devices capabilities */
                   1935: 
                   1936: C_RET cryptDeviceQueryCapability( C_IN CRYPT_DEVICE device,
                   1937:                                                                  C_IN CRYPT_ALGO_TYPE cryptAlgo,
                   1938:                                                                  C_OUT CRYPT_QUERY_INFO C_PTR cryptQueryInfo );
                   1939: 
                   1940: /* Create an encryption context via the device */
                   1941: 
                   1942: C_RET cryptDeviceCreateContext( C_IN CRYPT_DEVICE device,
                   1943:                                                            C_OUT CRYPT_CONTEXT C_PTR cryptContext,
                   1944:                                                            C_IN CRYPT_ALGO_TYPE cryptAlgo );
                   1945: 
                   1946: /****************************************************************************
                   1947: *                                                                                                                                                      *
                   1948: *                                                      User Management Functions                                               *
                   1949: *                                                                                                                                                      *
                   1950: ****************************************************************************/
                   1951: 
                   1952: /* Log on and off (create/destroy a user object) */
                   1953: 
                   1954: C_RET cryptLogin( C_OUT CRYPT_USER C_PTR user,
                   1955:                                  C_IN C_STR name, C_IN C_STR password );
                   1956: C_RET cryptLogout( C_IN CRYPT_USER user );
                   1957: 
                   1958: #if ( defined( WIN32 ) || defined( _WIN32 ) || defined( __WIN32__ ) ) && \
                   1959:        !( defined( _SCCTK ) || defined( _CVI_ ) )
                   1960: 
                   1961: /****************************************************************************
                   1962: *                                                                                                                                                      *
                   1963: *                                                      User Interface Functions                                                *
                   1964: *                                                                                                                                                      *
                   1965: ****************************************************************************/
                   1966: 
                   1967: /* User interface functions, only available under Win32 */
                   1968: 
                   1969: C_RET cryptUIGenerateKey( C_IN CRYPT_DEVICE cryptDevice,
                   1970:                                                  C_OUT CRYPT_CONTEXT C_PTR cryptContext,
                   1971:                                                  C_IN CRYPT_CERTIFICATE cryptCert,
                   1972:                                                  C_OUT char C_PTR password, C_IN HWND hWnd );
                   1973: C_RET cryptUIDisplayCert( C_IN CRYPT_CERTIFICATE cryptCert,
                   1974:                                                  C_IN HWND hWnd );
                   1975: 
                   1976: #endif /* Win32 */
                   1977: 
                   1978: #ifdef __cplusplus
                   1979: }
                   1980: #endif /* __cplusplus */
                   1981: 
                   1982: #endif /* _CRYPTLIB_DEFINED */

unix.superglobalmegacorp.com

This archive runs on limited infrastructure. Preserving old code on modern bandwidth. Automated agents are requested to crawl responsibly.