1/*
2 * Copyright (c) 2012-2014 Apple Inc. All Rights Reserved.
3 *
4 * @APPLE_LICENSE_HEADER_START@
5 *
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. Please obtain a copy of the License at
10 * http://www.opensource.apple.com/apsl/ and read it before using this
11 * file.
12 *
13 * The Original Code and all software distributed under the License are
14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 * Please see the License for the specific language governing rights and
19 * limitations under the License.
20 *
21 * @APPLE_LICENSE_HEADER_END@
22 */
23
24
25/*!
26 @header SOSCircle.h
27 The functions provided in SOSCircle.h provide an interface to a
28 secure object syncing circle for a single class
29 */
30
31#ifndef _SOSCIRCLE_H_
32#define _SOSCIRCLE_H_
33
34#include <Security/Security.h>
35#include <SecureObjectSync/SOSFullPeerInfo.h>
36#include <SecureObjectSync/SOSPeerInfo.h>
37#include <SecureObjectSync/SOSPeer.h>
38
39__BEGIN_DECLS
40
41typedef struct __OpaqueSOSCircle *SOSCircleRef;
42
43CFTypeID SOSCircleGetTypeID();
44
45SOSCircleRef SOSCircleCreate(CFAllocatorRef allocator, CFStringRef circleName, CFErrorRef *error);
46SOSCircleRef SOSCircleCreateFromDER(CFAllocatorRef allocator, CFErrorRef* error,
47                                    const uint8_t** der_p, const uint8_t *der_end);
48SOSCircleRef SOSCircleCreateFromData(CFAllocatorRef allocator, CFDataRef circleData, CFErrorRef *error);
49SOSCircleRef SOSCircleCopyCircle(CFAllocatorRef allocator, SOSCircleRef otherCircle, CFErrorRef *error);
50
51bool SOSCircleSign(SOSCircleRef circle, SecKeyRef privkey, CFErrorRef *error);
52bool SOSCircleVerifySignatureExists(SOSCircleRef circle, SecKeyRef pubKey, CFErrorRef *error);
53bool SOSCircleVerify(SOSCircleRef circle, SecKeyRef pubkey, CFErrorRef *error);
54
55bool SOSCircleVerifyPeerSigned(SOSCircleRef circle, SOSPeerInfoRef peer, CFErrorRef *error);
56
57bool SOSCircleGenerationSign(SOSCircleRef circle, SecKeyRef user_approver, SOSFullPeerInfoRef peerinfo, CFErrorRef *error);
58bool SOSCircleGenerationUpdate(SOSCircleRef circle, SecKeyRef user_approver, SOSFullPeerInfoRef peerinfo, CFErrorRef *error);
59
60size_t SOSCircleGetDEREncodedSize(SOSCircleRef cir, CFErrorRef *error);
61uint8_t* SOSCircleEncodeToDER(SOSCircleRef cir, CFErrorRef* error, const uint8_t* der, uint8_t* der_end);
62CFDataRef SOSCircleCopyEncodedData(SOSCircleRef circle, CFAllocatorRef allocator, CFErrorRef *error);
63
64int SOSCircleCountApplicants(SOSCircleRef circle);
65bool SOSCircleHasApplicant(SOSCircleRef circle, SOSPeerInfoRef peerInfo, CFErrorRef *error);
66CFMutableSetRef SOSCircleCopyApplicants(SOSCircleRef c, CFAllocatorRef allocator);
67void SOSCircleForEachApplicant(SOSCircleRef circle, void (^action)(SOSPeerInfoRef peer));
68
69int SOSCircleCountRejectedApplicants(SOSCircleRef circle);
70bool SOSCircleHasRejectedApplicant(SOSCircleRef circle, SOSPeerInfoRef peerInfo, CFErrorRef *error);
71SOSPeerInfoRef SOSCircleCopyRejectedApplicant(SOSCircleRef circle, SOSPeerInfoRef peerInfo, CFErrorRef *error);
72CFMutableArrayRef SOSCircleCopyRejectedApplicants(SOSCircleRef c, CFAllocatorRef allocator);
73
74CFStringRef SOSCircleGetName(SOSCircleRef circle);
75const char *SOSCircleGetNameC(SOSCircleRef circle);
76
77void SOSCircleGenerationSetValue(SOSCircleRef circle, int64_t value);
78CFNumberRef SOSCircleGetGeneration(SOSCircleRef circle);
79int64_t SOSCircleGetGenerationSint(SOSCircleRef circle);
80void SOSCircleGenerationIncrement(SOSCircleRef circle);
81
82CFMutableSetRef SOSCircleCopyPeers(SOSCircleRef circle, CFAllocatorRef allocator);
83bool SOSCircleAppendConcurringPeers(SOSCircleRef circle, CFMutableArrayRef appendHere, CFErrorRef *error);
84CFMutableArrayRef SOSCircleCopyConcurringPeers(SOSCircleRef circle, CFErrorRef* error);
85SOSPeerInfoRef SOSCircleCopyPeerWithID(SOSCircleRef circle, CFStringRef peerid, CFErrorRef *error);
86
87int SOSCircleCountPeers(SOSCircleRef circle);
88int SOSCircleCountActivePeers(SOSCircleRef circle);
89int SOSCircleCountActiveValidPeers(SOSCircleRef circle, SecKeyRef pubkey);
90int SOSCircleCountRetiredPeers(SOSCircleRef circle);
91
92void SOSCircleForEachPeer(SOSCircleRef circle, void (^action)(SOSPeerInfoRef peer));
93void SOSCircleForEachRetiredPeer(SOSCircleRef circle, void (^action)(SOSPeerInfoRef peer));
94void SOSCircleForEachActivePeer(SOSCircleRef circle, void (^action)(SOSPeerInfoRef peer));
95void SOSCircleForEachActiveValidPeer(SOSCircleRef circle, SecKeyRef user_public_key, void (^action)(SOSPeerInfoRef peer));
96
97bool SOSCircleHasPeerWithID(SOSCircleRef circle, CFStringRef peerid, CFErrorRef *error);
98bool SOSCircleHasPeer(SOSCircleRef circle, SOSPeerInfoRef peerInfo, CFErrorRef *error);
99bool SOSCircleHasActivePeerWithID(SOSCircleRef circle, CFStringRef peerid, CFErrorRef *error);
100bool SOSCircleHasActivePeer(SOSCircleRef circle, SOSPeerInfoRef peerInfo, CFErrorRef *error);
101bool SOSCircleHasActiveValidPeerWithID(SOSCircleRef circle, CFStringRef peerid, SecKeyRef user_public_key, CFErrorRef *error);
102bool SOSCircleHasActiveValidPeer(SOSCircleRef circle, SOSPeerInfoRef peerInfo, SecKeyRef user_public_key, CFErrorRef *error);
103
104bool SOSCircleResetToOffering(SOSCircleRef circle, SecKeyRef user_privkey, SOSFullPeerInfoRef requestor, CFErrorRef *error);
105bool SOSCircleResetToEmpty(SOSCircleRef circle, CFErrorRef *error);
106bool SOSCircleRequestAdmission(SOSCircleRef circle, SecKeyRef user_privkey, SOSFullPeerInfoRef requestor, CFErrorRef *error);
107bool SOSCircleRequestReadmission(SOSCircleRef circle, SecKeyRef user_pubkey, SOSFullPeerInfoRef requestor, CFErrorRef *error);
108
109bool SOSCircleAcceptRequest(SOSCircleRef circle, SecKeyRef user_privkey, SOSFullPeerInfoRef device_approver, SOSPeerInfoRef peerInfo, CFErrorRef *error);
110bool SOSCircleRejectRequest(SOSCircleRef circle, SOSFullPeerInfoRef device_approver, SOSPeerInfoRef peerInfo, CFErrorRef *error);
111bool SOSCircleWithdrawRequest(SOSCircleRef circle, SOSPeerInfoRef peerInfo, CFErrorRef *error);
112bool SOSCircleRemoveRejectedPeer(SOSCircleRef circle, SOSPeerInfoRef peerInfo, CFErrorRef *error);
113bool SOSCirclePeerSigUpdate(SOSCircleRef circle, SecKeyRef userPrivKey, SOSFullPeerInfoRef fpi,
114                            CFErrorRef *error);
115//
116// Update a peer's meta information.
117// No resigning of the circle is done, only updates to their own self signed description.
118//
119bool SOSCircleUpdatePeerInfo(SOSCircleRef circle, SOSPeerInfoRef replacement_peer_info);
120
121bool SOSCircleRemovePeer(SOSCircleRef circle, SecKeyRef user_privkey, SOSFullPeerInfoRef device_approver, SOSPeerInfoRef peerInfo, CFErrorRef *error);
122
123bool SOSCircleRemoveRetired(SOSCircleRef circle, CFErrorRef *error);
124
125bool SOSCircleAcceptRequests(SOSCircleRef circle, SecKeyRef user_privkey, SOSFullPeerInfoRef device_approver, CFErrorRef *error);
126
127// Stuff above this line is really SOSCircleInfo below the line is the active SOSCircle functionality
128
129SOSFullPeerInfoRef SOSCircleGetiCloudFullPeerInfoRef(SOSCircleRef circle);
130
131bool SOSCircleConcordanceSign(SOSCircleRef circle, SOSFullPeerInfoRef peerinfo, CFErrorRef *error);
132
133enum {
134    kSOSConcordanceTrusted = 0,
135    kSOSConcordanceGenOld = 1,     // kSOSErrorReplay
136    kSOSConcordanceNoUserSig = 2,  // kSOSErrorBadSignature
137    kSOSConcordanceNoUserKey = 3,  // kSOSErrorNoKey
138    kSOSConcordanceNoPeer = 4,     // kSOSErrorPeerNotFound
139    kSOSConcordanceBadUserSig = 5, // kSOSErrorBadSignature
140    kSOSConcordanceBadPeerSig = 6, // kSOSErrorBadSignature
141    kSOSConcordanceNoPeerSig = 7,
142    kSOSConcordanceWeSigned = 8,
143};
144typedef uint32_t SOSConcordanceStatus;
145
146bool SOSCircleSharedTrustedPeers(SOSCircleRef current, SOSCircleRef proposed, SOSPeerInfoRef me);
147
148SOSConcordanceStatus SOSCircleConcordanceTrust(SOSCircleRef known_circle, SOSCircleRef proposed_circle,
149                                               SecKeyRef known_pubkey, SecKeyRef user_pubkey,
150                                               SOSPeerInfoRef exclude, CFErrorRef *error);
151//
152// Testing routines:
153//
154
155CFDataRef SOSCircleCreateIncompatibleCircleDER(CFErrorRef* error);
156
157__END_DECLS
158
159#endif /* !_SOSCIRCLE_H_ */
160