1/* $KAME: key.h,v 1.11 2000/03/25 07:24:12 sumikawa Exp $ */ 2 3/* 4 * Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project. 5 * All rights reserved. 6 * 7 * Redistribution and use in source and binary forms, with or without 8 * modification, are permitted provided that the following conditions 9 * are met: 10 * 1. Redistributions of source code must retain the above copyright 11 * notice, this list of conditions and the following disclaimer. 12 * 2. Redistributions in binary form must reproduce the above copyright 13 * notice, this list of conditions and the following disclaimer in the 14 * documentation and/or other materials provided with the distribution. 15 * 3. Neither the name of the project nor the names of its contributors 16 * may be used to endorse or promote products derived from this software 17 * without specific prior written permission. 18 * 19 * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND 20 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 21 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 22 * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE 23 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 24 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 25 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 26 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 27 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 28 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 29 * SUCH DAMAGE. 30 */ 31 32#ifndef _NETKEY_KEY_H_ 33#define _NETKEY_KEY_H_ 34#include <sys/appleapiopts.h> 35 36#ifdef BSD_KERNEL_PRIVATE 37 38#define KEY_SADB_UNLOCKED 0 39#define KEY_SADB_LOCKED 1 40 41extern struct key_cb key_cb; 42 43struct secpolicy; 44struct secpolicyindex; 45struct ipsecrequest; 46struct secasvar; 47struct sockaddr; 48struct socket; 49struct sadb_msg; 50struct sadb_x_policy; 51struct secasindex; 52struct secashead; 53struct sadb_key; 54struct sadb_lifetime; 55 56extern struct secpolicy *key_allocsp(struct secpolicyindex *, u_int); 57extern struct secasvar *key_allocsa_policy(struct secasindex *); 58extern struct secpolicy *key_gettunnel(struct sockaddr *, 59 struct sockaddr *, struct sockaddr *, struct sockaddr *); 60extern int key_checkrequest(struct ipsecrequest *isr, struct secasindex *, 61 struct secasvar **sav); 62extern struct secasvar *key_allocsa(u_int, caddr_t, caddr_t, 63 u_int, u_int32_t); 64extern u_int16_t key_natt_get_translated_port(struct secasvar *); 65extern void key_freesp(struct secpolicy *, int); 66extern void key_freeso(struct socket *); 67extern void key_freesav(struct secasvar *, int); 68extern struct secpolicy *key_newsp(void); 69extern struct secpolicy *key_msg2sp(struct sadb_x_policy *, size_t, int *); 70extern struct mbuf *key_sp2msg(struct secpolicy *); 71extern int key_ismyaddr(struct sockaddr *); 72extern int key_spdacquire(struct secpolicy *); 73extern void key_timehandler(void); 74extern u_int32_t key_random(void); 75extern void key_randomfill(void *, size_t); 76extern void key_freereg(struct socket *); 77extern int key_parse(struct mbuf *, struct socket *); 78extern int key_checktunnelsanity(struct secasvar *, u_int, caddr_t, caddr_t); 79extern void key_sa_recordxfer(struct secasvar *, struct mbuf *); 80extern void key_sa_routechange(struct sockaddr *); 81extern void key_sa_chgstate(struct secasvar *, u_int8_t); 82extern void key_sa_stir_iv(struct secasvar *); 83extern void key_delsah(struct secashead *sah); 84extern struct secashead *key_newsah2 (struct secasindex *saidx, u_int8_t dir); 85extern u_int32_t key_getspi2(struct sockaddr *src, 86 struct sockaddr *dst, 87 u_int8_t proto, 88 u_int8_t mode, 89 u_int32_t reqid, 90 struct sadb_spirange *spirange); 91extern struct secasvar * key_newsav2(struct secashead *sah, 92 u_int8_t satype, 93 u_int8_t alg_auth, 94 u_int8_t alg_enc, 95 u_int32_t flags, 96 u_int8_t replay, 97 struct sadb_key *key_auth, 98 u_int16_t key_auth_len, 99 struct sadb_key *key_enc, 100 u_int16_t key_enc_len, 101 u_int16_t natt_port, 102 u_int32_t seq, 103 u_int32_t spi, 104 u_int32_t pid, 105 struct sadb_lifetime *lifetime_hard, 106 struct sadb_lifetime *lifetime_soft); 107extern void key_delsav(struct secasvar *sav); 108extern struct secpolicy *key_getspbyid(u_int32_t); 109extern void key_delsp_for_ipsec_if(ifnet_t ipsec_if); 110 111 112#endif /* BSD_KERNEL_PRIVATE */ 113#endif /* _NETKEY_KEY_H_ */ 114