master
h 93 lines 2.86 KB
Raw
1 /*
2 * QEMU crypto TLS credential support
3 *
4 * Copyright (c) 2015 Red Hat, Inc.
5 *
6 * This library is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU Lesser General Public
8 * License as published by the Free Software Foundation; either
9 * version 2.1 of the License, or (at your option) any later version.
10 *
11 * This library is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14 * Lesser General Public License for more details.
15 *
16 * You should have received a copy of the GNU Lesser General Public
17 * License along with this library; if not, see <http://www.gnu.org/licenses/>.
18 *
19 */
20
21 #ifndef QCRYPTO_TLSCREDS_H
22 #define QCRYPTO_TLSCREDS_H
23
24 #include "qapi/qapi-types-crypto.h"
25 #include "qom/object.h"
26
27 #define TYPE_QCRYPTO_TLS_CREDS "tls-creds"
28 typedef struct QCryptoTLSCreds QCryptoTLSCreds;
29 typedef struct QCryptoTLSCredsClass QCryptoTLSCredsClass;
30 DECLARE_OBJ_CHECKERS(QCryptoTLSCreds, QCryptoTLSCredsClass, QCRYPTO_TLS_CREDS,
31 TYPE_QCRYPTO_TLS_CREDS)
32
33
34 #define QCRYPTO_TLS_CREDS_DH_PARAMS "dh-params.pem"
35
36
37 typedef bool (*CryptoTLSCredsReload)(QCryptoTLSCreds *, Error **);
38 /**
39 * QCryptoTLSCreds:
40 *
41 * The QCryptoTLSCreds object is an abstract base for different
42 * types of TLS handshake credentials. Most commonly the
43 * QCryptoTLSCredsX509 subclass will be used to provide x509
44 * certificate credentials.
45 */
46
47 struct QCryptoTLSCredsClass {
48 ObjectClass parent_class;
49 CryptoTLSCredsReload reload;
50 const char *prioritySuffix;
51 };
52
53 /**
54 * qcrypto_tls_creds_check_endpoint:
55 * @creds: pointer to a TLS credentials object
56 * @endpoint: type of network endpoint that will be using the credentials
57 * @errp: pointer to a NULL-initialized error object
58 *
59 * Check whether the credentials is setup according to
60 * the type of @endpoint argument.
61 *
62 * Returns true if the credentials is setup for the endpoint, false otherwise
63 */
64 bool qcrypto_tls_creds_check_endpoint(QCryptoTLSCreds *creds,
65 QCryptoTLSCredsEndpoint endpoint,
66 Error **errp);
67
68
69 /**
70 * qcrypto_tls_creds_get_priority:
71 * @creds: pointer to a TLS credentials object
72 *
73 * Get the TLS credentials priority string. The caller
74 * must free the returned string when no longer required.
75 *
76 * Returns: a non-NULL priority string
77 */
78 char *qcrypto_tls_creds_get_priority(QCryptoTLSCreds *creds);
79
80
81 /**
82 * qcrypto_tls_creds_reload:
83 * @creds: pointer to a TLS credentials object
84 * @errp: pointer to a NULL-initialized error object
85 *
86 * Request a reload of the TLS credentials, if supported
87 *
88 * Returns: true on success, false on error or if not supported
89 */
90 bool qcrypto_tls_creds_reload(QCryptoTLSCreds *creds,
91 Error **errp);
92
93 #endif /* QCRYPTO_TLSCREDS_H */