resolved-dns-trust-anchor.h revision c9c72065419e6595131a6fe1e663e2184a843f7c
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder/*-*- Mode: C; c-basic-offset: 8; indent-tabs-mode: nil -*-*/
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder#pragma once
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder/***
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder This file is part of systemd.
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder Copyright 2015 Lennart Poettering
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder systemd is free software; you can redistribute it and/or modify it
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder under the terms of the GNU Lesser General Public License as published by
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder the Free Software Foundation; either version 2.1 of the License, or
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder (at your option) any later version.
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder systemd is distributed in the hope that it will be useful, but
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder WITHOUT ANY WARRANTY; without even the implied warranty of
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder Lesser General Public License for more details.
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder You should have received a copy of the GNU Lesser General Public License
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder along with systemd; If not, see <http://www.gnu.org/licenses/>.
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder***/
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maedertypedef struct DnsTrustAnchor DnsTrustAnchor;
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder#include "hashmap.h"
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder#include "resolved-dns-answer.h"
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder#include "resolved-dns-rr.h"
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder/* This contains a fixed database mapping domain names to DS or DNSKEY records. */
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maederstruct DnsTrustAnchor {
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder Hashmap *positive_by_key;
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder Set *negative_by_name;
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder Set *revoked_by_rr;
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder};
11ad38296d4182aac74ce6d5bef27911fbc9690dChristian Maeder
int dns_trust_anchor_load(DnsTrustAnchor *d);
void dns_trust_anchor_flush(DnsTrustAnchor *d);
int dns_trust_anchor_lookup_positive(DnsTrustAnchor *d, const DnsResourceKey* key, DnsAnswer **answer);
int dns_trust_anchor_lookup_negative(DnsTrustAnchor *d, const char *name);
int dns_trust_anchor_check_revoked(DnsTrustAnchor *d, DnsResourceRecord *dnskey, DnsAnswer *rrs);
int dns_trust_anchor_is_revoked(DnsTrustAnchor *d, DnsResourceRecord *rr);