Abstraction of private key in crypto transformation. More...
#include <private-key.hpp>
Classes | |
class | Error |
Public Types | |
using | PasswordCallback = std::function< int(char *buf, size_t bufSize, bool shouldConfirm)> |
Callback for application to handle password input. More... | |
Public Member Functions | |
PrivateKey () | |
Creates an empty private key instance. More... | |
~PrivateKey () | |
KeyType | getKeyType () const |
Returns the type of the private key. More... | |
size_t | getKeySize () const |
Returns the size of the private key in bits. More... | |
ConstBufferPtr | getKeyDigest (DigestAlgorithm algo) const |
Returns a digest of the private key. More... | |
void | loadRaw (KeyType type, span< const uint8_t > buf) |
Load a raw private key from a buffer buf . More... | |
void | loadPkcs1 (span< const uint8_t > buf) |
Load the private key in PKCS#1 format from a buffer buf . More... | |
void | loadPkcs1 (std::istream &is) |
Load the private key in PKCS#1 format from a stream is . More... | |
void | loadPkcs1Base64 (span< const uint8_t > buf) |
Load the private key in base64-encoded PKCS#1 format from a buffer buf . More... | |
void | loadPkcs1Base64 (std::istream &is) |
Load the private key in base64-encoded PKCS#1 format from a stream is . More... | |
void | loadPkcs8 (span< const uint8_t > buf, const char *pw, size_t pwLen) |
Load the private key in encrypted PKCS#8 format from a buffer buf with passphrase pw . More... | |
void | loadPkcs8 (span< const uint8_t > buf, PasswordCallback pwCallback=nullptr) |
Load the private key in encrypted PKCS#8 format from a buffer buf with passphrase obtained from pwCallback . More... | |
void | loadPkcs8 (std::istream &is, const char *pw, size_t pwLen) |
Load the private key in encrypted PKCS#8 format from a stream is with passphrase pw . More... | |
void | loadPkcs8 (std::istream &is, PasswordCallback pwCallback=nullptr) |
Load the private key in encrypted PKCS#8 format from a stream is with passphrase obtained from pwCallback . More... | |
void | loadPkcs8Base64 (span< const uint8_t > buf, const char *pw, size_t pwLen) |
Load the private key in base64-encoded encrypted PKCS#8 format from a buffer buf with passphrase pw . More... | |
void | loadPkcs8Base64 (span< const uint8_t > buf, PasswordCallback pwCallback=nullptr) |
Load the private key in encrypted PKCS#8 format from a buffer buf with passphrase obtained from pwCallback . More... | |
void | loadPkcs8Base64 (std::istream &is, const char *pw, size_t pwLen) |
Load the private key in base64-encoded encrypted PKCS#8 format from a stream is with passphrase pw . More... | |
void | loadPkcs8Base64 (std::istream &is, PasswordCallback pwCallback=nullptr) |
Load the private key in base64-encoded encrypted PKCS#8 format from a stream is with passphrase obtained from pwCallback . More... | |
void | savePkcs1 (std::ostream &os) const |
Save the private key in PKCS#1 format into a stream os . More... | |
void | savePkcs1Base64 (std::ostream &os) const |
Save the private key in base64-encoded PKCS#1 format into a stream os . More... | |
void | savePkcs8 (std::ostream &os, const char *pw, size_t pwLen) const |
Save the private key in encrypted PKCS#8 format into a stream os . More... | |
void | savePkcs8 (std::ostream &os, PasswordCallback pwCallback=nullptr) const |
Save the private key in encrypted PKCS#8 format into a stream os with passphrase obtained from pwCallback . More... | |
void | savePkcs8Base64 (std::ostream &os, const char *pw, size_t pwLen) const |
Save the private key in base64-encoded encrypted PKCS#8 format into a stream os . More... | |
void | savePkcs8Base64 (std::ostream &os, PasswordCallback pwCallback=nullptr) const |
Save the private key in base64-encoded encrypted PKCS#8 format into a stream os with passphrase obtained from pwCallback . More... | |
ConstBufferPtr | derivePublicKey () const |
ConstBufferPtr | decrypt (span< const uint8_t > cipherText) const |
Friends | |
class | SignerFilter |
class | VerifierFilter |
unique_ptr< PrivateKey > | generatePrivateKey (const KeyParams &) |
Generate a private key according to keyParams . More... | |
Abstraction of private key in crypto transformation.
Definition at line 38 of file private-key.hpp.
using ndn::security::transform::PrivateKey::PasswordCallback = std::function<int(char* buf, size_t bufSize, bool shouldConfirm)> |
Callback for application to handle password input.
The password must be written to buf
and must not be longer than bufSize
chars. It is recommended to ask the user to verify the password if shouldConfirm
is true, e.g., by prompting for it twice. The callback must return the number of characters in the password or 0 if an error occurred.
Definition at line 55 of file private-key.hpp.
ndn::security::transform::PrivateKey::PrivateKey | ( | ) |
Creates an empty private key instance.
One must call loadXXXX(...)
to load a private key.
Definition at line 66 of file private-key.cpp.
References ~PrivateKey().
|
default |
Referenced by PrivateKey().
KeyType ndn::security::transform::PrivateKey::getKeyType | ( | ) | const |
Returns the type of the private key.
Definition at line 74 of file private-key.cpp.
References ndn::EC, ndn::security::detail::getEvpPkeyType(), ndn::HMAC, ndn::NONE, and ndn::RSA.
Referenced by getKeyDigest(), getKeySize(), and ndn::security::transform::SignerFilter::SignerFilter().
size_t ndn::security::transform::PrivateKey::getKeySize | ( | ) | const |
Returns the size of the private key in bits.
Definition at line 92 of file private-key.cpp.
References ndn::EC, getKeyType(), ndn::HMAC, and ndn::RSA.
Referenced by getKeyDigest().
ConstBufferPtr ndn::security::transform::PrivateKey::getKeyDigest | ( | DigestAlgorithm | algo | ) | const |
Returns a digest of the private key.
Definition at line 109 of file private-key.cpp.
References ndn::OBufferStream::buf(), ndn::security::transform::digestFilter(), getKeySize(), getKeyType(), ndn::HMAC, NDN_THROW, and ndn::security::transform::streamSink().
Referenced by ndn::security::tpm::BackEnd::constructHmacKeyName().
void ndn::security::transform::PrivateKey::loadRaw | ( | KeyType | type, |
span< const uint8_t > | buf | ||
) |
Load a raw private key from a buffer buf
.
Definition at line 128 of file private-key.cpp.
References ENSURE_PRIVATE_KEY_NOT_LOADED, ndn::HMAC, and NDN_THROW.
void ndn::security::transform::PrivateKey::loadPkcs1 | ( | span< const uint8_t > | buf | ) |
Load the private key in PKCS#1 format from a buffer buf
.
Definition at line 147 of file private-key.cpp.
References ENSURE_PRIVATE_KEY_NOT_LOADED, and NDN_THROW.
Referenced by loadPkcs1(), and loadPkcs1Base64().
void ndn::security::transform::PrivateKey::loadPkcs1 | ( | std::istream & | is | ) |
Load the private key in PKCS#1 format from a stream is
.
Definition at line 157 of file private-key.cpp.
References ndn::OBufferStream::buf(), loadPkcs1(), and ndn::security::transform::streamSink().
void ndn::security::transform::PrivateKey::loadPkcs1Base64 | ( | span< const uint8_t > | buf | ) |
Load the private key in base64-encoded PKCS#1 format from a buffer buf
.
Definition at line 165 of file private-key.cpp.
References ndn::security::transform::base64Decode(), ndn::OBufferStream::buf(), loadPkcs1(), and ndn::security::transform::streamSink().
void ndn::security::transform::PrivateKey::loadPkcs1Base64 | ( | std::istream & | is | ) |
Load the private key in base64-encoded PKCS#1 format from a stream is
.
Definition at line 173 of file private-key.cpp.
References ndn::security::transform::base64Decode(), ndn::OBufferStream::buf(), loadPkcs1(), and ndn::security::transform::streamSink().
void ndn::security::transform::PrivateKey::loadPkcs8 | ( | span< const uint8_t > | buf, |
const char * | pw, | ||
size_t | pwLen | ||
) |
Load the private key in encrypted PKCS#8 format from a buffer buf
with passphrase pw
.
Definition at line 181 of file private-key.cpp.
References ENSURE_PRIVATE_KEY_NOT_LOADED, NDN_THROW, and ndn::security::detail::Bio::write().
Referenced by ndn::security::tpm::BackEndOsx::derivePublicKey(), ndn::security::tpm::exportItem(), ndn::security::tpm::BackEndFile::getScheme(), loadPkcs8(), and loadPkcs8Base64().
void ndn::security::transform::PrivateKey::loadPkcs8 | ( | span< const uint8_t > | buf, |
PasswordCallback | pwCallback = nullptr |
||
) |
Load the private key in encrypted PKCS#8 format from a buffer buf
with passphrase obtained from pwCallback
.
The default password callback is provided by OpenSSL
Definition at line 203 of file private-key.cpp.
References ENSURE_PRIVATE_KEY_NOT_LOADED, NDN_THROW, ndn::security::transform::passwordCallbackWrapper(), and ndn::security::detail::Bio::write().
void ndn::security::transform::PrivateKey::loadPkcs8 | ( | std::istream & | is, |
const char * | pw, | ||
size_t | pwLen | ||
) |
Load the private key in encrypted PKCS#8 format from a stream is
with passphrase pw
.
Definition at line 221 of file private-key.cpp.
References ndn::OBufferStream::buf(), loadPkcs8(), and ndn::security::transform::streamSink().
void ndn::security::transform::PrivateKey::loadPkcs8 | ( | std::istream & | is, |
PasswordCallback | pwCallback = nullptr |
||
) |
Load the private key in encrypted PKCS#8 format from a stream is
with passphrase obtained from pwCallback
.
The default password callback is provided by OpenSSL
Definition at line 229 of file private-key.cpp.
References ndn::OBufferStream::buf(), loadPkcs8(), nonstd::optional_lite::std11::move(), and ndn::security::transform::streamSink().
void ndn::security::transform::PrivateKey::loadPkcs8Base64 | ( | span< const uint8_t > | buf, |
const char * | pw, | ||
size_t | pwLen | ||
) |
Load the private key in base64-encoded encrypted PKCS#8 format from a buffer buf
with passphrase pw
.
Definition at line 237 of file private-key.cpp.
References ndn::security::transform::base64Decode(), ndn::OBufferStream::buf(), loadPkcs8(), and ndn::security::transform::streamSink().
void ndn::security::transform::PrivateKey::loadPkcs8Base64 | ( | span< const uint8_t > | buf, |
PasswordCallback | pwCallback = nullptr |
||
) |
Load the private key in encrypted PKCS#8 format from a buffer buf
with passphrase obtained from pwCallback
.
The default password callback is provided by OpenSSL
Definition at line 245 of file private-key.cpp.
References ndn::security::transform::base64Decode(), ndn::OBufferStream::buf(), loadPkcs8(), nonstd::optional_lite::std11::move(), and ndn::security::transform::streamSink().
void ndn::security::transform::PrivateKey::loadPkcs8Base64 | ( | std::istream & | is, |
const char * | pw, | ||
size_t | pwLen | ||
) |
Load the private key in base64-encoded encrypted PKCS#8 format from a stream is
with passphrase pw
.
Definition at line 253 of file private-key.cpp.
References ndn::security::transform::base64Decode(), ndn::OBufferStream::buf(), loadPkcs8(), and ndn::security::transform::streamSink().
void ndn::security::transform::PrivateKey::loadPkcs8Base64 | ( | std::istream & | is, |
PasswordCallback | pwCallback = nullptr |
||
) |
Load the private key in base64-encoded encrypted PKCS#8 format from a stream is
with passphrase obtained from pwCallback
.
The default password callback is provided by OpenSSL
Definition at line 261 of file private-key.cpp.
References ndn::security::transform::base64Decode(), ndn::OBufferStream::buf(), loadPkcs8(), nonstd::optional_lite::std11::move(), and ndn::security::transform::streamSink().
void ndn::security::transform::PrivateKey::savePkcs1 | ( | std::ostream & | os | ) | const |
Save the private key in PKCS#1 format into a stream os
.
Definition at line 269 of file private-key.cpp.
References ndn::security::transform::streamSink().
Referenced by ndn::security::tpm::BackEndOsx::derivePublicKey().
void ndn::security::transform::PrivateKey::savePkcs1Base64 | ( | std::ostream & | os | ) | const |
Save the private key in base64-encoded PKCS#1 format into a stream os
.
Definition at line 275 of file private-key.cpp.
References ndn::security::transform::base64Encode(), and ndn::security::transform::streamSink().
Referenced by ndn::security::tpm::BackEndFile::getScheme().
void ndn::security::transform::PrivateKey::savePkcs8 | ( | std::ostream & | os, |
const char * | pw, | ||
size_t | pwLen | ||
) | const |
Save the private key in encrypted PKCS#8 format into a stream os
.
Definition at line 281 of file private-key.cpp.
References ndn::security::transform::streamSink().
Referenced by ndn::security::tpm::BackEndOsx::derivePublicKey().
void ndn::security::transform::PrivateKey::savePkcs8 | ( | std::ostream & | os, |
PasswordCallback | pwCallback = nullptr |
||
) | const |
Save the private key in encrypted PKCS#8 format into a stream os
with passphrase obtained from pwCallback
.
The default password callback is provided by OpenSSL
Definition at line 287 of file private-key.cpp.
References nonstd::optional_lite::std11::move(), and ndn::security::transform::streamSink().
void ndn::security::transform::PrivateKey::savePkcs8Base64 | ( | std::ostream & | os, |
const char * | pw, | ||
size_t | pwLen | ||
) | const |
Save the private key in base64-encoded encrypted PKCS#8 format into a stream os
.
Definition at line 293 of file private-key.cpp.
References ndn::security::transform::base64Encode(), and ndn::security::transform::streamSink().
void ndn::security::transform::PrivateKey::savePkcs8Base64 | ( | std::ostream & | os, |
PasswordCallback | pwCallback = nullptr |
||
) | const |
Save the private key in base64-encoded encrypted PKCS#8 format into a stream os
with passphrase obtained from pwCallback
.
The default password callback is provided by OpenSSL
Definition at line 299 of file private-key.cpp.
References ndn::security::transform::base64Encode(), nonstd::optional_lite::std11::move(), and ndn::security::transform::streamSink().
ConstBufferPtr ndn::security::transform::PrivateKey::derivePublicKey | ( | ) | const |
Definition at line 305 of file private-key.cpp.
References ENSURE_PRIVATE_KEY_LOADED, and NDN_THROW.
Referenced by ndn::security::tpm::BackEndOsx::derivePublicKey().
ConstBufferPtr ndn::security::transform::PrivateKey::decrypt | ( | span< const uint8_t > | cipherText | ) | const |
cipherText
decrypted using this private key.Only RSA encryption is supported for now.
Definition at line 321 of file private-key.cpp.
References ENSURE_PRIVATE_KEY_LOADED, ndn::random::generateSecureBytes(), ndn::security::detail::getEvpPkeyType(), ndn::HMAC, nonstd::scope::make_scope_exit(), NDN_THROW, ndn::security::transform::passwordCallbackWrapper(), ndn::security::detail::Bio::read(), and ndn::to_string().
|
friend |
Definition at line 242 of file private-key.hpp.
|
friend |
Definition at line 243 of file private-key.hpp.
|
friend |
Generate a private key according to keyParams
.
std::invalid_argument | the specified key type is not supported |
PrivateKey::Error | key generation failed |
Definition at line 492 of file private-key.cpp.