/*
* CDDL HEADER START
*
* The contents of this file are subject to the terms of the
* Common Development and Distribution License (the "License").
* You may not use this file except in compliance with the License.
*
* You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
* See the License for the specific language governing permissions
* and limitations under the License.
*
* When distributing Covered Code, include this CDDL HEADER in each
* file and include the License file at usr/src/OPENSOLARIS.LICENSE.
* If applicable, add the following below this CDDL HEADER, with the
* fields enclosed by brackets "[]" replaced with your own identifying
* information: Portions Copyright [yyyy] [name of copyright owner]
*
* CDDL HEADER END
*/
/*
*/
#include <stdlib.h>
#include <strings.h>
#include <security/cryptoki.h>
#include <cryptoutil.h>
#include <errno.h>
#include <aes_impl.h>
#include "kmsGlobal.h"
#include "kmsSlot.h"
#include "kmsKeystoreUtil.h"
/*
* Just basic AES mechanisms (for now...)
*/
};
/*
* KMS only supports 256 bit keys, so the range below is MAX-MAX
* instead of MIN-MAX.
*/
};
/* ARGSUSED */
{
if (!kms_initialized)
return (CKR_CRYPTOKI_NOT_INITIALIZED);
return (CKR_ARGUMENTS_BAD);
}
/*
* If KMS is not available or initialized, return 0 slots
* but CKR_OK status.
*/
if (!kms_is_initialized()) {
*pulCount = 0;
return (CKR_OK);
}
return (CKR_OK);
}
return (CKR_BUFFER_TOO_SMALL);
}
*pulCount = 1;
pSlotList[0] = KMS_TOKEN_SLOTID;
return (CKR_OK);
}
{
if (!kms_initialized)
return (CKR_CRYPTOKI_NOT_INITIALIZED);
if (slotID != KMS_TOKEN_SLOTID ||
!kms_is_initialized()) {
return (CKR_SLOT_ID_INVALID);
}
return (CKR_ARGUMENTS_BAD);
/* Provide information about the slot in the provided buffer */
64);
return (CKR_OK);
}
{
if (!kms_initialized)
return (CKR_CRYPTOKI_NOT_INITIALIZED);
if (slotID != KMS_TOKEN_SLOTID ||
return (CKR_SLOT_ID_INVALID);
return (CKR_ARGUMENTS_BAD);
/* Provide information about a token in the provided buffer */
if ((kmsflags & KMSAGENT_PROFILE_EXISTS_FLAG) &&
else
}
return (CKR_OK);
}
/*ARGSUSED*/
{
if (!kms_initialized)
return (CKR_CRYPTOKI_NOT_INITIALIZED);
return (CKR_FUNCTION_NOT_SUPPORTED);
}
{
int i;
/*
* Just check to see if the library has been
* properly initialized.
*/
if (!kms_initialized)
return (CKR_CRYPTOKI_NOT_INITIALIZED);
/*
* This is different from above check, this verifies that
* the KMS token is actually configured.
*/
if (slotID != KMS_TOKEN_SLOTID ||
return (CKR_SLOT_ID_INVALID);
if (pMechanismList == NULL) {
return (CKR_OK);
}
return (CKR_BUFFER_TOO_SMALL);
}
for (i = 0; i < mechnum; i++)
pMechanismList[i] = kms_mechanisms[i];
return (CKR_OK);
}
{
if (!kms_initialized)
return (CKR_CRYPTOKI_NOT_INITIALIZED);
if (slotID != KMS_TOKEN_SLOTID ||
return (CKR_SLOT_ID_INVALID);
return (CKR_ARGUMENTS_BAD);
}
for (i = 0; i < mechnum; i++) {
if (kms_mechanisms[i] == type)
break;
}
if (i == mechnum)
/* unsupported mechanism */
return (CKR_MECHANISM_INVALID);
return (CKR_OK);
}
/*ARGSUSED*/
{
if (!kms_initialized)
return (CKR_CRYPTOKI_NOT_INITIALIZED);
if (slotID != KMS_TOKEN_SLOTID ||
return (CKR_SLOT_ID_INVALID);
return (CKR_FUNCTION_FAILED);
if (!(kmsflags & KMSAGENT_PROFILE_EXISTS_FLAG) ||
/*
* Attempt to enroll and load a KMS profile.
* This will force the KMSAgent library to fetch
* the profile, the CA certificate, and the
* client private key and store them locally so that
* the KMS agent API can be used later.
*/
&kmscfg,
(const char *)pPin,
}
return (rv);
}
/*ARGSUSED*/
{
if (!kms_initialized)
return (CKR_CRYPTOKI_NOT_INITIALIZED);
/*
* Could be supported once the agent library supports
* storing the client certificate in a PKCS#12 file.
*/
return (CKR_FUNCTION_NOT_SUPPORTED);
}
{
if (!kms_initialized)
return (CKR_CRYPTOKI_NOT_INITIALIZED);
/*
* Obtain the session pointer. Also, increment the session
* reference count.
*/
return (rv);
/* Make sure it is a RW session. */
return (rv);
}
/*
* If the token is not yet initialized, we cannot set the pin.
*/
if (!kms_is_initialized()) {
return (CKR_FUNCTION_FAILED);
}
return (CKR_ARGUMENTS_BAD);
}
if (!kms_is_pin_set()) {
/*
* We don't yet support this mode since
* the KMS private key file will automatically
* be generated using the KMS Agent passphrase
* which is initialized out-of-band.
*/
} else {
/*
* Login to KMS by attempting to load the profile using
* the given password.
*/
(const char *)pOldPin,
if (rv == CKR_USER_ANOTHER_ALREADY_LOGGED_IN)
(const char *)pOldPin,
(const char *)pNewPin);
}
return (rv);
}