1/* 2 * Copyright (c) 2012-2014 Apple Inc. All Rights Reserved. 3 * 4 * @APPLE_LICENSE_HEADER_START@ 5 * 6 * This file contains Original Code and/or Modifications of Original Code 7 * as defined in and that are subject to the Apple Public Source License 8 * Version 2.0 (the 'License'). You may not use this file except in 9 * compliance with the License. Please obtain a copy of the License at 10 * http://www.opensource.apple.com/apsl/ and read it before using this 11 * file. 12 * 13 * The Original Code and all software distributed under the License are 14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER 15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, 16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, 17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. 18 * Please see the License for the specific language governing rights and 19 * limitations under the License. 20 * 21 * @APPLE_LICENSE_HEADER_END@ 22 */ 23 24 25/*! 26 @header SOSCircle.h 27 The functions provided in SOSCircle.h provide an interface to a 28 secure object syncing circle for a single class 29 */ 30 31#ifndef _SOSCIRCLE_H_ 32#define _SOSCIRCLE_H_ 33 34#include <Security/Security.h> 35#include <SecureObjectSync/SOSFullPeerInfo.h> 36#include <SecureObjectSync/SOSPeerInfo.h> 37#include <SecureObjectSync/SOSPeer.h> 38 39__BEGIN_DECLS 40 41typedef struct __OpaqueSOSCircle *SOSCircleRef; 42 43CFTypeID SOSCircleGetTypeID(); 44 45SOSCircleRef SOSCircleCreate(CFAllocatorRef allocator, CFStringRef circleName, CFErrorRef *error); 46SOSCircleRef SOSCircleCreateFromDER(CFAllocatorRef allocator, CFErrorRef* error, 47 const uint8_t** der_p, const uint8_t *der_end); 48SOSCircleRef SOSCircleCreateFromData(CFAllocatorRef allocator, CFDataRef circleData, CFErrorRef *error); 49SOSCircleRef SOSCircleCopyCircle(CFAllocatorRef allocator, SOSCircleRef otherCircle, CFErrorRef *error); 50 51bool SOSCircleSign(SOSCircleRef circle, SecKeyRef privkey, CFErrorRef *error); 52bool SOSCircleVerifySignatureExists(SOSCircleRef circle, SecKeyRef pubKey, CFErrorRef *error); 53bool SOSCircleVerify(SOSCircleRef circle, SecKeyRef pubkey, CFErrorRef *error); 54 55bool SOSCircleVerifyPeerSigned(SOSCircleRef circle, SOSPeerInfoRef peer, CFErrorRef *error); 56 57bool SOSCircleGenerationSign(SOSCircleRef circle, SecKeyRef user_approver, SOSFullPeerInfoRef peerinfo, CFErrorRef *error); 58bool SOSCircleGenerationUpdate(SOSCircleRef circle, SecKeyRef user_approver, SOSFullPeerInfoRef peerinfo, CFErrorRef *error); 59 60size_t SOSCircleGetDEREncodedSize(SOSCircleRef cir, CFErrorRef *error); 61uint8_t* SOSCircleEncodeToDER(SOSCircleRef cir, CFErrorRef* error, const uint8_t* der, uint8_t* der_end); 62CFDataRef SOSCircleCopyEncodedData(SOSCircleRef circle, CFAllocatorRef allocator, CFErrorRef *error); 63 64int SOSCircleCountApplicants(SOSCircleRef circle); 65bool SOSCircleHasApplicant(SOSCircleRef circle, SOSPeerInfoRef peerInfo, CFErrorRef *error); 66CFMutableSetRef SOSCircleCopyApplicants(SOSCircleRef c, CFAllocatorRef allocator); 67void SOSCircleForEachApplicant(SOSCircleRef circle, void (^action)(SOSPeerInfoRef peer)); 68 69int SOSCircleCountRejectedApplicants(SOSCircleRef circle); 70bool SOSCircleHasRejectedApplicant(SOSCircleRef circle, SOSPeerInfoRef peerInfo, CFErrorRef *error); 71SOSPeerInfoRef SOSCircleCopyRejectedApplicant(SOSCircleRef circle, SOSPeerInfoRef peerInfo, CFErrorRef *error); 72CFMutableArrayRef SOSCircleCopyRejectedApplicants(SOSCircleRef c, CFAllocatorRef allocator); 73 74CFStringRef SOSCircleGetName(SOSCircleRef circle); 75const char *SOSCircleGetNameC(SOSCircleRef circle); 76 77void SOSCircleGenerationSetValue(SOSCircleRef circle, int64_t value); 78CFNumberRef SOSCircleGetGeneration(SOSCircleRef circle); 79int64_t SOSCircleGetGenerationSint(SOSCircleRef circle); 80void SOSCircleGenerationIncrement(SOSCircleRef circle); 81 82CFMutableSetRef SOSCircleCopyPeers(SOSCircleRef circle, CFAllocatorRef allocator); 83bool SOSCircleAppendConcurringPeers(SOSCircleRef circle, CFMutableArrayRef appendHere, CFErrorRef *error); 84CFMutableArrayRef SOSCircleCopyConcurringPeers(SOSCircleRef circle, CFErrorRef* error); 85SOSPeerInfoRef SOSCircleCopyPeerWithID(SOSCircleRef circle, CFStringRef peerid, CFErrorRef *error); 86 87int SOSCircleCountPeers(SOSCircleRef circle); 88int SOSCircleCountActivePeers(SOSCircleRef circle); 89int SOSCircleCountActiveValidPeers(SOSCircleRef circle, SecKeyRef pubkey); 90int SOSCircleCountRetiredPeers(SOSCircleRef circle); 91 92void SOSCircleForEachPeer(SOSCircleRef circle, void (^action)(SOSPeerInfoRef peer)); 93void SOSCircleForEachRetiredPeer(SOSCircleRef circle, void (^action)(SOSPeerInfoRef peer)); 94void SOSCircleForEachActivePeer(SOSCircleRef circle, void (^action)(SOSPeerInfoRef peer)); 95void SOSCircleForEachActiveValidPeer(SOSCircleRef circle, SecKeyRef user_public_key, void (^action)(SOSPeerInfoRef peer)); 96 97bool SOSCircleHasPeerWithID(SOSCircleRef circle, CFStringRef peerid, CFErrorRef *error); 98bool SOSCircleHasPeer(SOSCircleRef circle, SOSPeerInfoRef peerInfo, CFErrorRef *error); 99bool SOSCircleHasActivePeerWithID(SOSCircleRef circle, CFStringRef peerid, CFErrorRef *error); 100bool SOSCircleHasActivePeer(SOSCircleRef circle, SOSPeerInfoRef peerInfo, CFErrorRef *error); 101bool SOSCircleHasActiveValidPeerWithID(SOSCircleRef circle, CFStringRef peerid, SecKeyRef user_public_key, CFErrorRef *error); 102bool SOSCircleHasActiveValidPeer(SOSCircleRef circle, SOSPeerInfoRef peerInfo, SecKeyRef user_public_key, CFErrorRef *error); 103 104bool SOSCircleResetToOffering(SOSCircleRef circle, SecKeyRef user_privkey, SOSFullPeerInfoRef requestor, CFErrorRef *error); 105bool SOSCircleResetToEmpty(SOSCircleRef circle, CFErrorRef *error); 106bool SOSCircleRequestAdmission(SOSCircleRef circle, SecKeyRef user_privkey, SOSFullPeerInfoRef requestor, CFErrorRef *error); 107bool SOSCircleRequestReadmission(SOSCircleRef circle, SecKeyRef user_pubkey, SOSFullPeerInfoRef requestor, CFErrorRef *error); 108 109bool SOSCircleAcceptRequest(SOSCircleRef circle, SecKeyRef user_privkey, SOSFullPeerInfoRef device_approver, SOSPeerInfoRef peerInfo, CFErrorRef *error); 110bool SOSCircleRejectRequest(SOSCircleRef circle, SOSFullPeerInfoRef device_approver, SOSPeerInfoRef peerInfo, CFErrorRef *error); 111bool SOSCircleWithdrawRequest(SOSCircleRef circle, SOSPeerInfoRef peerInfo, CFErrorRef *error); 112bool SOSCircleRemoveRejectedPeer(SOSCircleRef circle, SOSPeerInfoRef peerInfo, CFErrorRef *error); 113bool SOSCirclePeerSigUpdate(SOSCircleRef circle, SecKeyRef userPrivKey, SOSFullPeerInfoRef fpi, 114 CFErrorRef *error); 115// 116// Update a peer's meta information. 117// No resigning of the circle is done, only updates to their own self signed description. 118// 119bool SOSCircleUpdatePeerInfo(SOSCircleRef circle, SOSPeerInfoRef replacement_peer_info); 120 121bool SOSCircleRemovePeer(SOSCircleRef circle, SecKeyRef user_privkey, SOSFullPeerInfoRef device_approver, SOSPeerInfoRef peerInfo, CFErrorRef *error); 122 123bool SOSCircleRemoveRetired(SOSCircleRef circle, CFErrorRef *error); 124 125bool SOSCircleAcceptRequests(SOSCircleRef circle, SecKeyRef user_privkey, SOSFullPeerInfoRef device_approver, CFErrorRef *error); 126 127// Stuff above this line is really SOSCircleInfo below the line is the active SOSCircle functionality 128 129SOSFullPeerInfoRef SOSCircleGetiCloudFullPeerInfoRef(SOSCircleRef circle); 130 131bool SOSCircleConcordanceSign(SOSCircleRef circle, SOSFullPeerInfoRef peerinfo, CFErrorRef *error); 132 133enum { 134 kSOSConcordanceTrusted = 0, 135 kSOSConcordanceGenOld = 1, // kSOSErrorReplay 136 kSOSConcordanceNoUserSig = 2, // kSOSErrorBadSignature 137 kSOSConcordanceNoUserKey = 3, // kSOSErrorNoKey 138 kSOSConcordanceNoPeer = 4, // kSOSErrorPeerNotFound 139 kSOSConcordanceBadUserSig = 5, // kSOSErrorBadSignature 140 kSOSConcordanceBadPeerSig = 6, // kSOSErrorBadSignature 141 kSOSConcordanceNoPeerSig = 7, 142 kSOSConcordanceWeSigned = 8, 143}; 144typedef uint32_t SOSConcordanceStatus; 145 146bool SOSCircleSharedTrustedPeers(SOSCircleRef current, SOSCircleRef proposed, SOSPeerInfoRef me); 147 148SOSConcordanceStatus SOSCircleConcordanceTrust(SOSCircleRef known_circle, SOSCircleRef proposed_circle, 149 SecKeyRef known_pubkey, SecKeyRef user_pubkey, 150 SOSPeerInfoRef exclude, CFErrorRef *error); 151// 152// Testing routines: 153// 154 155CFDataRef SOSCircleCreateIncompatibleCircleDER(CFErrorRef* error); 156 157__END_DECLS 158 159#endif /* !_SOSCIRCLE_H_ */ 160