[BACK]Return to authfd.h CVS log [TXT][DIR] Up to [local] / src / usr.bin / ssh

Annotation of src/usr.bin/ssh/authfd.h, Revision 1.45

1.45    ! djm         1: /* $OpenBSD: authfd.h,v 1.44 2018/07/12 04:35:25 djm Exp $ */
1.23      stevesk     2:
1.1       deraadt     3: /*
1.5       deraadt     4:  * Author: Tatu Ylonen <ylo@cs.hut.fi>
                      5:  * Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
                      6:  *                    All rights reserved
                      7:  * Functions to interface with the SSH_AUTHENTICATION_FD socket.
1.7       markus      8:  *
1.11      deraadt     9:  * As far as I am concerned, the code I have written for this software
                     10:  * can be used freely for any purpose.  Any derived versions of this
                     11:  * software must be clearly marked as such, and if the derived work is
                     12:  * incompatible with the protocol description in the RFC file, it must be
                     13:  * called by a name other than "ssh" or "Secure Shell".
1.5       deraadt    14:  */
1.1       deraadt    15:
                     16: #ifndef AUTHFD_H
                     17: #define AUTHFD_H
                     18:
1.38      djm        19: /* List of identities returned by ssh_fetch_identitylist() */
                     20: struct ssh_identitylist {
                     21:        size_t nkeys;
                     22:        struct sshkey **keys;
                     23:        char **comments;
                     24: };
                     25:
                     26: int    ssh_get_authentication_socket(int *fdp);
                     27: void   ssh_close_authentication_socket(int sock);
                     28:
                     29: int    ssh_lock_agent(int sock, int lock, const char *password);
1.40      naddy      30: int    ssh_fetch_identitylist(int sock, struct ssh_identitylist **idlp);
1.38      djm        31: void   ssh_free_identitylist(struct ssh_identitylist *idl);
1.45    ! djm        32: int    ssh_add_identity_constrained(int sock, struct sshkey *key,
1.43      markus     33:            const char *comment, u_int life, u_int confirm, u_int maxsign);
1.38      djm        34: int    ssh_remove_identity(int sock, struct sshkey *key);
                     35: int    ssh_update_card(int sock, int add, const char *reader_id,
                     36:            const char *pin, u_int life, u_int confirm);
                     37: int    ssh_remove_all_identities(int sock, int version);
                     38:
1.41      djm        39: int    ssh_agent_sign(int sock, const struct sshkey *key,
1.38      djm        40:            u_char **sigp, size_t *lenp,
1.39      markus     41:            const u_char *data, size_t datalen, const char *alg, u_int compat);
1.38      djm        42:
1.1       deraadt    43: /* Messages for the authentication agent connection. */
                     44: #define SSH_AGENTC_REQUEST_RSA_IDENTITIES      1
                     45: #define SSH_AGENT_RSA_IDENTITIES_ANSWER                2
                     46: #define SSH_AGENTC_RSA_CHALLENGE               3
                     47: #define SSH_AGENT_RSA_RESPONSE                 4
                     48: #define SSH_AGENT_FAILURE                      5
                     49: #define SSH_AGENT_SUCCESS                      6
                     50: #define SSH_AGENTC_ADD_RSA_IDENTITY            7
                     51: #define SSH_AGENTC_REMOVE_RSA_IDENTITY         8
                     52: #define SSH_AGENTC_REMOVE_ALL_RSA_IDENTITIES   9
                     53:
1.13      markus     54: /* private OpenSSH extensions for SSH2 */
1.9       markus     55: #define SSH2_AGENTC_REQUEST_IDENTITIES         11
                     56: #define SSH2_AGENT_IDENTITIES_ANSWER           12
                     57: #define SSH2_AGENTC_SIGN_REQUEST               13
                     58: #define SSH2_AGENT_SIGN_RESPONSE               14
                     59: #define SSH2_AGENTC_ADD_IDENTITY               17
                     60: #define SSH2_AGENTC_REMOVE_IDENTITY            18
                     61: #define SSH2_AGENTC_REMOVE_ALL_IDENTITIES      19
1.13      markus     62:
1.17      markus     63: /* smartcard */
                     64: #define SSH_AGENTC_ADD_SMARTCARD_KEY           20
1.30      deraadt    65: #define SSH_AGENTC_REMOVE_SMARTCARD_KEY                21
1.21      markus     66:
1.25      markus     67: /* lock/unlock the agent */
                     68: #define SSH_AGENTC_LOCK                                22
1.30      deraadt    69: #define SSH_AGENTC_UNLOCK                      23
1.25      markus     70:
1.29      markus     71: /* add key with constraints */
                     72: #define SSH_AGENTC_ADD_RSA_ID_CONSTRAINED      24
                     73: #define SSH2_AGENTC_ADD_ID_CONSTRAINED         25
1.33      djm        74: #define SSH_AGENTC_ADD_SMARTCARD_KEY_CONSTRAINED 26
1.27      markus     75:
1.28      markus     76: #define        SSH_AGENT_CONSTRAIN_LIFETIME            1
1.32      markus     77: #define        SSH_AGENT_CONSTRAIN_CONFIRM             2
1.43      markus     78: #define        SSH_AGENT_CONSTRAIN_MAXSIGN             3
1.26      markus     79:
1.21      markus     80: /* extended failure messages */
                     81: #define SSH2_AGENT_FAILURE                     30
1.17      markus     82:
1.13      markus     83: /* additional error code for ssh.com's ssh-agent2 */
1.30      deraadt    84: #define SSH_COM_AGENT2_FAILURE                 102
1.12      markus     85:
                     86: #define        SSH_AGENT_OLD_SIGNATURE                 0x01
1.39      markus     87: #define        SSH_AGENT_RSA_SHA2_256                  0x02
                     88: #define        SSH_AGENT_RSA_SHA2_512                  0x04
1.1       deraadt    89:
1.5       deraadt    90: #endif                         /* AUTHFD_H */