mirror of
https://github.com/ibm-s390-linux/s390-tools.git
synced 2026-08-05 02:14:52 +00:00
When key properties are changed with the 'change' command, also update the key properties in the KMS, if the key is bound to a KMS. Do not allow to change the associated APQNs for KMS bound keys. KMS bound keys inherit the APQNs from the KMS plugin. When a key is renamed in the repository, also update the key name property in the KMS if the key is KMS bound. Signed-off-by: Ingo Franzki <ifranzki@linux.ibm.com> Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
87 lines
2.6 KiB
C
87 lines
2.6 KiB
C
/*
|
|
* zkey - Generate, re-encipher, and validate secure keys
|
|
*
|
|
* This header file defines functions for Key Management System (KMS) plugin
|
|
* handling
|
|
*
|
|
* Copyright IBM Corp. 2020
|
|
*
|
|
* s390-tools is free software; you can redistribute it and/or modify
|
|
* it under the terms of the MIT license. See LICENSE for details.
|
|
*/
|
|
|
|
#ifndef KMS_H
|
|
#define KMS_H
|
|
|
|
#include "kms-plugin.h"
|
|
#include "properties.h"
|
|
#include "keystore.h"
|
|
|
|
struct kms_info {
|
|
void *plugin_lib;
|
|
const struct kms_functions *funcs;
|
|
char *plugin_name;
|
|
struct properties *props;
|
|
struct kms_apqn *apqns;
|
|
size_t num_apqns;
|
|
kms_handle_t handle;
|
|
};
|
|
|
|
struct keystore;
|
|
|
|
int list_kms_plugins(bool verbose);
|
|
|
|
int check_for_kms_plugin(struct kms_info *kms_info, bool verbose);
|
|
|
|
int init_kms_plugin(struct kms_info *kms_info, bool verbose);
|
|
|
|
void free_kms_plugin(struct kms_info *kms_info);
|
|
|
|
void print_last_kms_error(const struct kms_info *kms_info);
|
|
|
|
int bind_kms_plugin(struct keystore *keystore, const char *plugin,
|
|
bool verbose);
|
|
|
|
int unbind_kms_plugin(struct kms_info *kms_info, struct keystore *keystore,
|
|
bool verbose);
|
|
|
|
int print_kms_info(struct kms_info *kms_info);
|
|
|
|
int get_kms_options(struct kms_info *kms_info, struct util_opt *opt_vec,
|
|
const char *placeholder_cmd, const char *plugin_command,
|
|
const char *opt_vec_command, int *first_plugin_opt,
|
|
bool verbose);
|
|
|
|
int handle_kms_option(struct kms_info *kms_info, struct util_opt *opt_vec,
|
|
int first_kms_option, const char *command, int option,
|
|
const char *optarg, struct kms_option **kms_options,
|
|
size_t *num_kms_options, bool verbose);
|
|
|
|
int configure_kms_plugin(struct keystore *keystore, const char *apqns,
|
|
struct kms_option *kms_options, size_t num_kms_options,
|
|
bool has_plugin_optins, bool verbose);
|
|
|
|
int reencipher_kms(struct kms_info *kms_info, bool from_old, bool to_new,
|
|
bool inplace, bool staged, bool complete,
|
|
struct kms_option *kms_options, size_t num_kms_options,
|
|
bool verbose);
|
|
|
|
int perform_kms_login(struct kms_info *kms_info, bool verbose);
|
|
|
|
int get_kms_apqns_for_key_type(struct kms_info *kms_info, const char *key_type,
|
|
bool cross_check, char **apqns, bool verbose);
|
|
|
|
int generate_kms_key(struct kms_info *kms_info, const char *name,
|
|
const char *key_type, struct properties *key_props,
|
|
bool xts, size_t keybits, const char *filename,
|
|
struct kms_option *kms_options, size_t num_kms_options,
|
|
bool verbose);
|
|
|
|
int set_kms_key_properties(struct kms_info *kms_info,
|
|
struct properties *key_props,
|
|
const char *name, const char *description,
|
|
const char *volumes, const char *vol_type,
|
|
const char *sector_size, bool verbose);
|
|
|
|
#endif
|