1 /* dirmngr.h - Common definitions for the dirmngr
2 * Copyright (C) 2002 Klarälvdalens Datakonsult AB
3 * Copyright (C) 2004, 2015 g10 Code GmbH
4 * Copyright (C) 2014 Werner Koch
6 * This file is part of GnuPG.
8 * GnuPG is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 3 of the License, or
11 * (at your option) any later version.
13 * GnuPG is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, see <https://www.gnu.org/licenses/>.
25 #include "./dirmngr-err.h"
26 #define map_assuan_err(a) \
27 map_assuan_err_with_source (GPG_ERR_SOURCE_DEFAULT, (a))
32 #include "../common/util.h"
33 #include "../common/membuf.h"
34 #include "../common/sysutils.h" /* (gnupg_fd_t) */
35 #include "../common/asshelp.h" /* (assuan_context_t) */
36 #include "../common/i18n.h"
37 #include "http.h" /* (parsed_uri_t) */
39 /* This objects keeps information about a particular LDAP server and
40 is used as item of a single linked list of servers. */
43 struct ldap_server_s* next;
51 typedef struct ldap_server_s *ldap_server_t;
54 /* This objects is used to build a list of URI consisting of the
55 original and the parsed URI. */
58 struct uri_item_s *next;
59 parsed_uri_t parsed_uri; /* The broken down URI. */
60 char uri[1]; /* The original URI. */
62 typedef struct uri_item_s *uri_item_t;
65 /* A list of fingerprints. */
66 struct fingerprint_list_s;
67 typedef struct fingerprint_list_s *fingerprint_list_t;
68 struct fingerprint_list_s
70 fingerprint_list_t next;
75 /* A large struct named "opt" to keep global flags. */
78 unsigned int debug; /* debug flags (DBG_foo_VALUE) */
79 int verbose; /* verbosity level */
80 int quiet; /* be as quiet as possible */
81 int dry_run; /* don't change any persistent data */
82 int batch; /* batch mode */
83 const char *homedir_cache; /* Dir for cache files (/var/cache/dirmngr). */
85 char *config_filename; /* Name of a config file, which will be
86 reread on a HUP if it is not NULL. */
88 char *ldap_wrapper_program; /* Override value for the LDAP wrapper
90 char *http_wrapper_program; /* Override value for the HTTP wrapper
93 int running_detached; /* We are running in detached mode. */
94 int use_tor; /* Tor mode has been enabled. */
95 int allow_version_check; /* --allow-version-check is active. */
97 int force; /* Force loading outdated CRLs. */
99 int disable_http; /* Do not use HTTP at all. */
100 int disable_ldap; /* Do not use LDAP at all. */
101 int disable_ipv4; /* Do not use leagacy IP addresses. */
102 int honor_http_proxy; /* Honor the http_proxy env variable. */
103 const char *http_proxy; /* The default HTTP proxy. */
104 const char *ldap_proxy; /* Use given LDAP proxy. */
105 int only_ldap_proxy; /* Only use the LDAP proxy; no fallback. */
106 int ignore_http_dp; /* Ignore HTTP CRL distribution points. */
107 int ignore_ldap_dp; /* Ignore LDAP CRL distribution points. */
108 int ignore_ocsp_service_url; /* Ignore OCSP service URLs as given in
111 /* A list of certificate extension OIDs which are ignored so that
112 one can claim that a critical extension has been handled. One
114 strlist_t ignored_cert_extensions;
116 int allow_ocsp; /* Allow using OCSP. */
119 unsigned int ldaptimeout;
121 ldap_server_t ldapservers;
122 int add_new_ldapservers;
124 const char *ocsp_responder; /* Standard OCSP responder's URL. */
125 fingerprint_list_t ocsp_signer; /* The list of fingerprints with allowed
126 standard OCSP signer certificates. */
128 unsigned int ocsp_max_clock_skew; /* Allowed seconds of clocks skew. */
129 unsigned int ocsp_max_period; /* Seconds a response is at maximum
130 considered valid after thisUpdate. */
131 unsigned int ocsp_current_period; /* Seconds a response is considered
132 current after nextUpdate. */
134 strlist_t keyserver; /* List of default keyservers. */
138 #define DBG_X509_VALUE 1 /* debug x.509 parsing */
139 #define DBG_CRYPTO_VALUE 4 /* debug low level crypto */
140 #define DBG_DNS_VALUE 16 /* debug DNS calls. */
141 #define DBG_MEMORY_VALUE 32 /* debug memory allocation stuff */
142 #define DBG_CACHE_VALUE 64 /* debug the caching */
143 #define DBG_MEMSTAT_VALUE 128 /* show memory statistics */
144 #define DBG_HASHING_VALUE 512 /* debug hashing operations */
145 #define DBG_IPC_VALUE 1024 /* debug assuan communication */
146 #define DBG_NETWORK_VALUE 2048 /* debug network I/O. */
147 #define DBG_LOOKUP_VALUE 8192 /* debug lookup details */
149 #define DBG_X509 (opt.debug & DBG_X509_VALUE)
150 #define DBG_CRYPTO (opt.debug & DBG_CRYPTO_VALUE)
151 #define DBG_DNS (opt.debug & DBG_DNS_VALUE)
152 #define DBG_MEMORY (opt.debug & DBG_MEMORY_VALUE)
153 #define DBG_CACHE (opt.debug & DBG_CACHE_VALUE)
154 #define DBG_HASHING (opt.debug & DBG_HASHING_VALUE)
155 #define DBG_IPC (opt.debug & DBG_IPC_VALUE)
156 #define DBG_NETWORK (opt.debug & DBG_NETWORK_VALUE)
157 #define DBG_LOOKUP (opt.debug & DBG_LOOKUP_VALUE)
159 /* A simple list of certificate references. */
162 struct cert_ref_s *next;
163 unsigned char fpr[20];
165 typedef struct cert_ref_s *cert_ref_t;
167 /* Forward references; access only through server.c. */
168 struct server_local_s;
170 /* Connection control structure. */
171 struct server_control_s
173 int refcount; /* Count additional references to this object. */
174 int no_server; /* We are not running under server control. */
175 int status_fd; /* Only for non-server mode. */
176 struct server_local_s *server_local;
177 int force_crl_refresh; /* Always load a fresh CRL. */
179 int check_revocations_nest_level; /* Internal to check_revovations. */
180 cert_ref_t ocsp_certs; /* Certificates from the current OCSP
183 int audit_events; /* Send audit events to client. */
184 char *http_proxy; /* The used http_proxy or NULL. */
189 void dirmngr_exit( int ); /* Wrapper for exit() */
190 void dirmngr_init_default_ctrl (ctrl_t ctrl);
191 void dirmngr_deinit_default_ctrl (ctrl_t ctrl);
192 void dirmngr_sighup_action (void);
193 const char* dirmngr_get_current_socket_name (void);
196 /*-- Various housekeeping functions. --*/
197 void ks_hkp_reload (void);
201 ldap_server_t get_ldapservers_from_ctrl (ctrl_t ctrl);
202 ksba_cert_t get_cert_local (ctrl_t ctrl, const char *issuer);
203 ksba_cert_t get_issuing_cert_local (ctrl_t ctrl, const char *issuer);
204 ksba_cert_t get_cert_local_ski (ctrl_t ctrl,
205 const char *name, ksba_sexp_t keyid);
206 gpg_error_t get_istrusted_from_client (ctrl_t ctrl, const char *hexfpr);
207 int dirmngr_assuan_log_monitor (assuan_context_t ctx, unsigned int cat,
209 void start_command_handler (gnupg_fd_t fd);
210 gpg_error_t dirmngr_status (ctrl_t ctrl, const char *keyword, ...);
211 gpg_error_t dirmngr_status_help (ctrl_t ctrl, const char *text);
212 gpg_error_t dirmngr_tick (ctrl_t ctrl);
216 gpg_error_t dirmngr_load_swdb (ctrl_t ctrl, int force);