[BACK]Return to authfd.h CVS log [TXT][DIR] Up to [local] / src / usr.bin / ssh

Annotation of src/usr.bin/ssh/authfd.h, Revision 1.39

1.39    ! markus      1: /* $OpenBSD: authfd.h,v 1.38 2015/01/14 20:05:27 djm Exp $ */
1.23      stevesk     2:
1.1       deraadt     3: /*
1.5       deraadt     4:  * Author: Tatu Ylonen <ylo@cs.hut.fi>
                      5:  * Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
                      6:  *                    All rights reserved
                      7:  * Functions to interface with the SSH_AUTHENTICATION_FD socket.
1.7       markus      8:  *
1.11      deraadt     9:  * As far as I am concerned, the code I have written for this software
                     10:  * can be used freely for any purpose.  Any derived versions of this
                     11:  * software must be clearly marked as such, and if the derived work is
                     12:  * incompatible with the protocol description in the RFC file, it must be
                     13:  * called by a name other than "ssh" or "Secure Shell".
1.5       deraadt    14:  */
1.1       deraadt    15:
                     16: #ifndef AUTHFD_H
                     17: #define AUTHFD_H
                     18:
1.38      djm        19: /* List of identities returned by ssh_fetch_identitylist() */
                     20: struct ssh_identitylist {
                     21:        size_t nkeys;
                     22:        struct sshkey **keys;
                     23:        char **comments;
                     24: };
                     25:
                     26: int    ssh_get_authentication_socket(int *fdp);
                     27: void   ssh_close_authentication_socket(int sock);
                     28:
                     29: int    ssh_lock_agent(int sock, int lock, const char *password);
                     30: int    ssh_fetch_identitylist(int sock, int version,
                     31:            struct ssh_identitylist **idlp);
                     32: void   ssh_free_identitylist(struct ssh_identitylist *idl);
                     33: int    ssh_add_identity_constrained(int sock, struct sshkey *key,
                     34:            const char *comment, u_int life, u_int confirm);
                     35: int    ssh_remove_identity(int sock, struct sshkey *key);
                     36: int    ssh_update_card(int sock, int add, const char *reader_id,
                     37:            const char *pin, u_int life, u_int confirm);
                     38: int    ssh_remove_all_identities(int sock, int version);
                     39:
                     40: int    ssh_decrypt_challenge(int sock, struct sshkey* key, BIGNUM *challenge,
                     41:            u_char session_id[16], u_char response[16]);
                     42: int    ssh_agent_sign(int sock, struct sshkey *key,
                     43:            u_char **sigp, size_t *lenp,
1.39    ! markus     44:            const u_char *data, size_t datalen, const char *alg, u_int compat);
1.38      djm        45:
1.1       deraadt    46: /* Messages for the authentication agent connection. */
                     47: #define SSH_AGENTC_REQUEST_RSA_IDENTITIES      1
                     48: #define SSH_AGENT_RSA_IDENTITIES_ANSWER                2
                     49: #define SSH_AGENTC_RSA_CHALLENGE               3
                     50: #define SSH_AGENT_RSA_RESPONSE                 4
                     51: #define SSH_AGENT_FAILURE                      5
                     52: #define SSH_AGENT_SUCCESS                      6
                     53: #define SSH_AGENTC_ADD_RSA_IDENTITY            7
                     54: #define SSH_AGENTC_REMOVE_RSA_IDENTITY         8
                     55: #define SSH_AGENTC_REMOVE_ALL_RSA_IDENTITIES   9
                     56:
1.13      markus     57: /* private OpenSSH extensions for SSH2 */
1.9       markus     58: #define SSH2_AGENTC_REQUEST_IDENTITIES         11
                     59: #define SSH2_AGENT_IDENTITIES_ANSWER           12
                     60: #define SSH2_AGENTC_SIGN_REQUEST               13
                     61: #define SSH2_AGENT_SIGN_RESPONSE               14
                     62: #define SSH2_AGENTC_ADD_IDENTITY               17
                     63: #define SSH2_AGENTC_REMOVE_IDENTITY            18
                     64: #define SSH2_AGENTC_REMOVE_ALL_IDENTITIES      19
1.13      markus     65:
1.17      markus     66: /* smartcard */
                     67: #define SSH_AGENTC_ADD_SMARTCARD_KEY           20
1.30      deraadt    68: #define SSH_AGENTC_REMOVE_SMARTCARD_KEY                21
1.21      markus     69:
1.25      markus     70: /* lock/unlock the agent */
                     71: #define SSH_AGENTC_LOCK                                22
1.30      deraadt    72: #define SSH_AGENTC_UNLOCK                      23
1.25      markus     73:
1.29      markus     74: /* add key with constraints */
                     75: #define SSH_AGENTC_ADD_RSA_ID_CONSTRAINED      24
                     76: #define SSH2_AGENTC_ADD_ID_CONSTRAINED         25
1.33      djm        77: #define SSH_AGENTC_ADD_SMARTCARD_KEY_CONSTRAINED 26
1.27      markus     78:
1.28      markus     79: #define        SSH_AGENT_CONSTRAIN_LIFETIME            1
1.32      markus     80: #define        SSH_AGENT_CONSTRAIN_CONFIRM             2
1.26      markus     81:
1.21      markus     82: /* extended failure messages */
                     83: #define SSH2_AGENT_FAILURE                     30
1.17      markus     84:
1.13      markus     85: /* additional error code for ssh.com's ssh-agent2 */
1.30      deraadt    86: #define SSH_COM_AGENT2_FAILURE                 102
1.12      markus     87:
                     88: #define        SSH_AGENT_OLD_SIGNATURE                 0x01
1.39    ! markus     89: #define        SSH_AGENT_RSA_SHA2_256                  0x02
        !            90: #define        SSH_AGENT_RSA_SHA2_512                  0x04
1.1       deraadt    91:
1.5       deraadt    92: #endif                         /* AUTHFD_H */