[BACK]Return to authfd.h CVS log [TXT][DIR] Up to [local] / src / usr.bin / ssh

Annotation of src/usr.bin/ssh/authfd.h, Revision 1.41

1.41    ! djm         1: /* $OpenBSD: authfd.h,v 1.40 2017/05/05 10:42:49 naddy Exp $ */
1.23      stevesk     2:
1.1       deraadt     3: /*
1.5       deraadt     4:  * Author: Tatu Ylonen <ylo@cs.hut.fi>
                      5:  * Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
                      6:  *                    All rights reserved
                      7:  * Functions to interface with the SSH_AUTHENTICATION_FD socket.
1.7       markus      8:  *
1.11      deraadt     9:  * As far as I am concerned, the code I have written for this software
                     10:  * can be used freely for any purpose.  Any derived versions of this
                     11:  * software must be clearly marked as such, and if the derived work is
                     12:  * incompatible with the protocol description in the RFC file, it must be
                     13:  * called by a name other than "ssh" or "Secure Shell".
1.5       deraadt    14:  */
1.1       deraadt    15:
                     16: #ifndef AUTHFD_H
                     17: #define AUTHFD_H
                     18:
1.38      djm        19: /* List of identities returned by ssh_fetch_identitylist() */
                     20: struct ssh_identitylist {
                     21:        size_t nkeys;
                     22:        struct sshkey **keys;
                     23:        char **comments;
                     24: };
                     25:
                     26: int    ssh_get_authentication_socket(int *fdp);
                     27: void   ssh_close_authentication_socket(int sock);
                     28:
                     29: int    ssh_lock_agent(int sock, int lock, const char *password);
1.40      naddy      30: int    ssh_fetch_identitylist(int sock, struct ssh_identitylist **idlp);
1.38      djm        31: void   ssh_free_identitylist(struct ssh_identitylist *idl);
                     32: int    ssh_add_identity_constrained(int sock, struct sshkey *key,
                     33:            const char *comment, u_int life, u_int confirm);
                     34: int    ssh_remove_identity(int sock, struct sshkey *key);
                     35: int    ssh_update_card(int sock, int add, const char *reader_id,
                     36:            const char *pin, u_int life, u_int confirm);
                     37: int    ssh_remove_all_identities(int sock, int version);
                     38:
                     39: int    ssh_decrypt_challenge(int sock, struct sshkey* key, BIGNUM *challenge,
                     40:            u_char session_id[16], u_char response[16]);
1.41    ! djm        41: int    ssh_agent_sign(int sock, const struct sshkey *key,
1.38      djm        42:            u_char **sigp, size_t *lenp,
1.39      markus     43:            const u_char *data, size_t datalen, const char *alg, u_int compat);
1.38      djm        44:
1.1       deraadt    45: /* Messages for the authentication agent connection. */
                     46: #define SSH_AGENTC_REQUEST_RSA_IDENTITIES      1
                     47: #define SSH_AGENT_RSA_IDENTITIES_ANSWER                2
                     48: #define SSH_AGENTC_RSA_CHALLENGE               3
                     49: #define SSH_AGENT_RSA_RESPONSE                 4
                     50: #define SSH_AGENT_FAILURE                      5
                     51: #define SSH_AGENT_SUCCESS                      6
                     52: #define SSH_AGENTC_ADD_RSA_IDENTITY            7
                     53: #define SSH_AGENTC_REMOVE_RSA_IDENTITY         8
                     54: #define SSH_AGENTC_REMOVE_ALL_RSA_IDENTITIES   9
                     55:
1.13      markus     56: /* private OpenSSH extensions for SSH2 */
1.9       markus     57: #define SSH2_AGENTC_REQUEST_IDENTITIES         11
                     58: #define SSH2_AGENT_IDENTITIES_ANSWER           12
                     59: #define SSH2_AGENTC_SIGN_REQUEST               13
                     60: #define SSH2_AGENT_SIGN_RESPONSE               14
                     61: #define SSH2_AGENTC_ADD_IDENTITY               17
                     62: #define SSH2_AGENTC_REMOVE_IDENTITY            18
                     63: #define SSH2_AGENTC_REMOVE_ALL_IDENTITIES      19
1.13      markus     64:
1.17      markus     65: /* smartcard */
                     66: #define SSH_AGENTC_ADD_SMARTCARD_KEY           20
1.30      deraadt    67: #define SSH_AGENTC_REMOVE_SMARTCARD_KEY                21
1.21      markus     68:
1.25      markus     69: /* lock/unlock the agent */
                     70: #define SSH_AGENTC_LOCK                                22
1.30      deraadt    71: #define SSH_AGENTC_UNLOCK                      23
1.25      markus     72:
1.29      markus     73: /* add key with constraints */
                     74: #define SSH_AGENTC_ADD_RSA_ID_CONSTRAINED      24
                     75: #define SSH2_AGENTC_ADD_ID_CONSTRAINED         25
1.33      djm        76: #define SSH_AGENTC_ADD_SMARTCARD_KEY_CONSTRAINED 26
1.27      markus     77:
1.28      markus     78: #define        SSH_AGENT_CONSTRAIN_LIFETIME            1
1.32      markus     79: #define        SSH_AGENT_CONSTRAIN_CONFIRM             2
1.26      markus     80:
1.21      markus     81: /* extended failure messages */
                     82: #define SSH2_AGENT_FAILURE                     30
1.17      markus     83:
1.13      markus     84: /* additional error code for ssh.com's ssh-agent2 */
1.30      deraadt    85: #define SSH_COM_AGENT2_FAILURE                 102
1.12      markus     86:
                     87: #define        SSH_AGENT_OLD_SIGNATURE                 0x01
1.39      markus     88: #define        SSH_AGENT_RSA_SHA2_256                  0x02
                     89: #define        SSH_AGENT_RSA_SHA2_512                  0x04
1.1       deraadt    90:
1.5       deraadt    91: #endif                         /* AUTHFD_H */