Go to the documentation of this file.
36 #ifndef HEADER_GRIDSITE_H
37 #define HEADER_GRIDSITE_H
40 #define GRST_VERSION 010500
47 #ifndef GRST_NO_OPENSSL
50 #include <openssl/ssl.h>
53 #ifndef HEADER_CRYPTO_H
54 #include <openssl/crypto.h>
82 #define GRST_RET_FAILED 1000
85 #define GRST_RET_CERT_NOT_FOUND 1001
88 #define GRST_RET_BAD_SIGNATURE 1002
91 #define GRST_RET_NO_SUCH_FILE 1003
95 #define GRSTerrorLog(GRSTerrorLevel, ...) ((GRSTerrorLogFunc != NULL) && ((GRSTerrorLogFunc)(__FILE__, __LINE__, GRSTerrorLevel, __VA_ARGS__)))
101 #define GRST_LOG_EMERG 0
102 #define GRST_LOG_ALERT 1
103 #define GRST_LOG_CRIT 2
104 #define GRST_LOG_ERR 3
105 #define GRST_LOG_WARNING 4
106 #define GRST_LOG_NOTICE 5
107 #define GRST_LOG_INFO 6
108 #define GRST_LOG_DEBUG 7
110 #define GRST_MAX_TIME_T INT32_MAX
121 typedef struct {
char *name;
137 #define GRST_PERM_NONE 0
138 #define GRST_PERM_READ 1
139 #define GRST_PERM_EXEC 2
140 #define GRST_PERM_LIST 4
141 #define GRST_PERM_WRITE 8
142 #define GRST_PERM_ADMIN 16
143 #define GRST_PERM_ALL 31
146 #define GRSTgaclPermIsNone(perm) ((perm) == 0)
148 #define GRSTgaclPermHasNone(perm) ((perm) == 0)
149 #define GRSTgaclPermHasRead(perm) (((perm) & GRST_PERM_READ ) != 0)
150 #define GRSTgaclPermHasExec(perm) (((perm) & GRST_PERM_EXEC ) != 0)
151 #define GRSTgaclPermHasList(perm) (((perm) & GRST_PERM_LIST ) != 0)
152 #define GRSTgaclPermHasWrite(perm) (((perm) & GRST_PERM_WRITE) != 0)
153 #define GRSTgaclPermHasAdmin(perm) (((perm) & GRST_PERM_ADMIN) != 0)
155 #define GRST_ACTION_ALLOW 0
156 #define GRST_ACTION_DENY 1
158 #define GRST_HIST_PREFIX ".grsthist"
159 #define GRST_ACL_FILE ".gacl"
160 #define GRST_DN_LISTS "/etc/grid-security/dn-lists"
161 #define GRST_RECURS_LIMIT 9
163 #define GRST_PROXYCERTINFO_OLD_OID "1.3.6.1.4.1.3536.1.222"
164 #define GRST_PROXYCERTINFO_OID "1.3.6.1.5.5.7.1.14"
165 #define GRST_VOMS_OID "1.3.6.1.4.1.8005.100.100.5"
166 #define GRST_VOMS_PK_CERT_LIST_OID "1.3.6.1.4.1.8005.100.100.10"
167 #define GRST_VOMS_DIR "/etc/grid-security/vomsdir"
168 #define GRST_KEYUSAGE_OID "2.5.29.15"
170 #define GRST_ASN1_MAXCOORDLEN 50
171 #define GRST_ASN1_MAXTAGS 500
179 #define GRST_X509_SERIAL_DIGITS 49
189 char serial[GRST_X509_SERIAL_DIGITS+1];
194 #define GRST_CERT_BAD_FORMAT 1
195 #define GRST_CERT_BAD_CHAIN 2
196 #define GRST_CERT_BAD_SIG 4
197 #define GRST_CERT_BAD_TIME 8
198 #define GRST_CERT_BAD_OCSP 16
200 #define GRST_CERT_TYPE_CA 1
201 #define GRST_CERT_TYPE_EEC 2
202 #define GRST_CERT_TYPE_PROXY 3
203 #define GRST_CERT_TYPE_VOMS 4
204 #define GRST_CERT_TYPE_ROBOT 5
209 #ifndef GRST_NO_OPENSSL
212 STACK_OF(X509) *certstack, X509 *lastcert,
213 char *capath,
char *vomsdir);
218 #define GRST_HTTP_PORT 777
219 #define GRST_HTTPS_PORT 488
220 #define GRST_HTCP_PORT 777
221 #define GRST_GSIFTP_PORT 2811
223 #define GRSThtcpNOPop 0
224 #define GRSThtcpTSTop 1
230 #define GRSThtcpCountstrLen(string) (256*((string)->length_msb) + (string)->length_lsb)
262 #define GRSTgaclCredGetAuri(cred) ((cred)->auri)
264 #define GRSTgaclCredSetNotBefore(cred, time) ((cred)->notbefore = (time))
265 #define GRSTgaclCredGetNotBefore(cred) ((cred)->notbefore)
267 #define GRSTgaclCredSetNotAfter(cred, time) ((cred)->notafter = (time))
268 #define GRSTgaclCredGetNotAfter(cred) ((cred)->notafter)
270 #define GRSTgaclCredSetDelegation(cred, level) ((cred)->delegation = (level))
271 #define GRSTgaclCredGetDelegation(cred) ((cred)->delegation)
273 #define GRSTgaclCredSetNistLoa(cred, level) ((cred)->nist_loa = (level))
274 #define GRSTgaclCredGetNistLoa(cred) ((cred)->nist_loa)
390 #ifndef GRST_NO_OPENSSL
410 #ifndef GRST_NO_OPENSSL
421 char *delegation_id,
char *user_dn,
int keysize);
425 #ifndef GRST_NO_OPENSSL
433 #define GRST_HEADFILE "gridsitehead.txt"
434 #define GRST_FOOTFILE "gridsitefoot.txt"
435 #define GRST_ADMIN_FILE "gridsite-admin.cgi"
455 #ifndef GRST_NO_OPENSSL
468 #ifndef GRST_PASSCODE_JS
470 #define GRST_PASSCODE_JS "<script type=\"text/javascript\" language=\"Javascript\"><!--\nfunction changeValue(formName){ if( document.forms[formName].passcode.value==\"\" ) document.forms[formName].passcode.value=getCookie(\"GRIDHTTP_PASSCODE\"); return true; } \nfunction getCookie(c_name){ if (document.cookie.length>0) { c_start=document.cookie.indexOf(c_name + \"=\"); if (c_start!=-1) { c_start=c_start + c_name.length+1; c_end=document.cookie.indexOf(\";\",c_start); if (c_end==-1) c_end=document.cookie.length; return unescape(document.cookie.substring(c_start,c_end)); }} return \"\"; } \n -->\n</script>"
477 #endif // HEADER_GRIDSITE_H
GRSTgaclPerm GRSTgaclPermFromChar(char *)
Definition: grst_gacl.c:546
char * GRSTgaclPermToChar(GRSTgaclPerm)
Definition: grst_gacl.c:531
char * GRSTx509CachedProxyKeyFind(char *, char *, char *, STACK_OF(X509) *)
Find a temporary proxy private key file in the proxy cache.
Definition: grst_canl_x509.c:2091
char * GRSThttpUrlEncode(char *)
Definition: grst_http.c:369
int GRSTgaclUserAddCred(GRSTgaclUser *, GRSTgaclCred *)
Definition: grst_gacl.c:959
int GRSTx509CheckChain(int *, X509_STORE_CTX *)
Definition: grst_canl_x509.c:1355
int GRSTx509MakeProxyRequestKS(char **reqtxt, char *proxydir, char *delegation_id, char *user_dn, int keysize)
Definition: grst_canl_x509.c:2338
char * GRSThttpGetCGI(char *)
Definition: grst_http.c:237
GRSTgaclEntry * GRSTgaclEntryNew(void)
Definition: grst_gacl.c:367
int GRSTx509MakeProxyRequest(char **, char *, char *, char *)
Create a X.509 request for a GSI proxy and its private key.
Definition: grst_canl_x509.c:2352
unsigned char length_msb
Definition: gridsite.h:226
void * next
Definition: gridsite.h:438
void * next
Definition: gridsite.h:192
Definition: gridsite.h:207
void * next
Definition: gridsite.h:117
void GRSThttpWriteOut(GRSThttpBody *)
Definition: grst_http.c:150
Definition: gridsite.h:181
int GRSTgaclPermPrint(GRSTgaclPerm, FILE *)
Definition: grst_gacl.c:489
int GRSTgaclEntryAllowPerm(GRSTgaclEntry *, GRSTgaclPerm)
Definition: grst_gacl.c:503
Definition: gridsite.h:112
int GRSTgaclDNlistHasUser(char *listurl, GRSTgaclUser *user)
Definition: grst_gacl.c:1279
char char X509 *char * GRSTx509CachedProxyFind(char *, char *, char *)
Find a proxy file in the proxy cache.
Definition: grst_canl_x509.c:2056
int GRSTasn1GetX509Name(char *, int, char *, char *, struct GRSTasn1TagList taglist[], int)
Definition: grst_asn1.c:497
GRSTgaclCred * GRSTgaclCredNew(char *type)
Definition: grst_gacl.c:137
GRSTgaclCred * GRSTgaclUserFindCredtype(GRSTgaclUser *, char *)
Definition: grst_gacl.c:1046
GRSTgaclUser * GRSTgaclUserNew(GRSTgaclCred *)
Definition: grst_gacl.c:929
time_t notafter
Definition: gridsite.h:116
unsigned char total_length_lsb
Definition: gridsite.h:233
int GRSTx509CreateProxyRequest(char **, char **, char *)
Create a X.509 request for a GSI proxy and its private key.
Definition: grst_canl_x509.c:2236
int delegation
Definition: gridsite.h:113
int GRSTx509StringToChain(STACK_OF(X509) **, char *)
Create a stack of X509 certificate from a PEM-encoded string.
Definition: grst_canl_x509.c:2593
GRSTgaclPerm allowed
Definition: gridsite.h:129
Definition: gridsite.h:133
int start
Definition: gridsite.h:174
int GRSTgaclCredCmpAuri(GRSTgaclCred *, GRSTgaclCred *)
Definition: grst_gacl.c:342
int GRSTx509CreateProxyRequestKS(char **reqtxt, char **keytxt, char *ocspurl, int keysize)
Definition: grst_canl_x509.c:2225
int headerlength
Definition: gridsite.h:175
unsigned char data_length_msb
Definition: gridsite.h:236
void * next
Definition: gridsite.h:131
GRSTgaclUser *int GRSTgaclUserHasAURI(GRSTgaclUser *, char *)
Definition: grst_gacl.c:1284
char * auri
Definition: gridsite.h:112
int GRSThtcpTSTrequestMake(char **, int *, unsigned int, char *, char *, char *)
Definition: grst_htcp.c:116
unsigned char version_lsb
Definition: gridsite.h:235
int GRSTgaclEntryPrint(GRSTgaclEntry *, FILE *)
Definition: grst_gacl.c:449
int GRSTgaclEntryUndenyPerm(GRSTgaclEntry *, GRSTgaclPerm)
Definition: grst_gacl.c:524
int GRSTgaclFileIsAcl(char *)
Definition: grst_gacl.c:835
Definition: gridsite.h:128
GRSTgaclCred * firstcred
Definition: gridsite.h:135
int GRSTgaclUserHasCred(GRSTgaclUser *, GRSTgaclCred *)
Definition: grst_gacl.c:982
char * GRSTx509FindProxyFileName(void)
Find proxy file name of the current user.
Definition: grst_canl_x509.c:1740
time_t GRSTasn1TimeToTimeT(char *, size_t)
ASN1 time string (in a char *) to time_t.
Definition: grst_asn1.c:24
char * issuer
Definition: gridsite.h:183
int GRSTgaclAction
Definition: gridsite.h:125
int GRSTgaclEntryDenyPerm(GRSTgaclEntry *, GRSTgaclPerm)
Definition: grst_gacl.c:517
unsigned int f1
Definition: gridsite.h:241
int GRSTasn1ParseDump(BIO *, unsigned char *, long, struct GRSTasn1TagList taglist[], int, int *)
Definition: grst_asn1.c:457
GRSTgaclCred * GRSTgaclCredCreate(char *, char *)
Definition: grst_gacl.c:97
int GRSTgaclEntryAddCred(GRSTgaclEntry *, GRSTgaclCred *)
Definition: grst_gacl.c:267
int GRSTgaclCredAddValue(GRSTgaclCred *cred, char *name, char *rawvalue)
Definition: grst_gacl.c:160
unsigned int opcode
Definition: gridsite.h:239
void GRSThttpBodyInit(GRSThttpBody *)
Definition: grst_http.c:53
Definition: gridsite.h:232
Definition: gridsite.h:440
int GRSTx509ChainLoadCheck(GRSTx509Chain **, STACK_OF(X509) *, X509 *, char *, char *)
Check certificate chain for GSI proxy acceptability.
Definition: grst_canl_x509.c:1323
int GRSTx509ProxyGetTimes(char *, char *, char *, time_t *, time_t *)
Get start and finish validity times of stored GSI proxy file.
Definition: grst_canl_x509.c:2551
int type
Definition: gridsite.h:181
unsigned char total_length_msb
Definition: gridsite.h:232
time_t notafter
Definition: gridsite.h:187
unsigned int response
Definition: gridsite.h:238
int GRSTx509IsCA(X509 *)
Check if certificate can be used as a CA to sign standard X509 certs.
Definition: grst_canl_x509.c:299
GRSThtcpCountstr * uri
Definition: gridsite.h:245
char * GRSThttpUrlMildencode(char *)
Definition: grst_http.c:402
Definition: gridsite.h:135
time_t notbefore
Definition: gridsite.h:186
char * GRSThttpUrlDecode(char *)
Definition: grst_http.c:330
char * GRSTx509MakeProxyFileName(char *, STACK_OF(X509) *)
Return the short file name for the given delegation_id and user_dn.
Definition: grst_canl_x509.c:2692
int GRSTx509MakeProxyCert(char **, FILE *, char *, char *, char *, int)
Make a GSI Proxy chain from a request, certificate and private key.
Definition: grst_canl_x509.c:1768
int GRSTx509KnownCriticalExts(X509 *)
Check critical extensions.
Definition: grst_canl_x509.c:262
int GRSTx509ProxyDestroy(char *, char *, char *)
Destroy stored GSI proxy files.
Definition: grst_canl_x509.c:2503
int GRSTx509GetVomsCreds(int *lastcred, int maxcreds, size_t credlen, char *creds, X509 *usercert, STACK_OF(X509) *certstack, char *vomsdir)
Get the VOMS attributes in the extensions to the given cert stack.
Definition: grst_canl_x509.c:1538
unsigned int GRSTgaclPerm
Definition: gridsite.h:126
int GRSTx509ChainFree(GRSTx509Chain *)
Definition: grst_canl_x509.c:314
char *int GRSTgaclUserLoadDNlists(GRSTgaclUser *, char *)
Definition: grst_gacl.c:1185
GRSThtcpCountstr * entity_hdrs
Definition: gridsite.h:249
unsigned int rr
Definition: gridsite.h:240
char * GRSTgaclFileFindAclname(char *)
Definition: grst_gacl.c:848
GRSThttpCharsList * last
Definition: gridsite.h:442
GRSTgaclCred * firstcred
Definition: gridsite.h:128
GRSTgaclNamevalue
Definition: gridsite.h:123
int GRSTgaclAclSave(GRSTgaclAcl *, char *)
Definition: grst_gacl.c:605
unsigned char version_msb
Definition: gridsite.h:234
GRSThtcpCountstr * resp_hdrs
Definition: gridsite.h:248
int GRSTgaclCredCredPrint(GRSTgaclCred *, FILE *)
char X509 STACK_OF(X509) *
GRSTx509Cert * firstcert
Definition: gridsite.h:207
int GRSTgaclUserSetDNlists(GRSTgaclUser *user, char *dnlists)
Definition: grst_gacl.c:1076
int GRSTgaclEntryDelCred(GRSTgaclEntry *, GRSTgaclCred *)
Definition: grst_gacl.c:296
int(* GRSTerrorLogFunc)(char *, int, int, char *,...)
Definition: grst_err.c:40
int GRSTgaclEntryFree(GRSTgaclEntry *)
Definition: grst_gacl.c:386
int GRSTx509CertLoad(GRSTx509Cert *, X509 *)
unsigned char data_length_lsb
Definition: gridsite.h:237
GRSThttpCharsList * first
Definition: gridsite.h:441
int GRSTx509CacheProxy(char *, char *, char *, char *)
Store a GSI proxy chain in the proxy cache, along with the private key.
Definition: grst_canl_x509.c:2779
Definition: gridsite.h:437
int GRSTgaclEntryUnallowPerm(GRSTgaclEntry *, GRSTgaclPerm)
Definition: grst_gacl.c:510
int GRSThtcpNOPresponseMake(char **, int *, unsigned int)
Definition: grst_htcp.c:81
int GRSTasn1SearchTaglist(struct GRSTasn1TagList taglist[], int, char *)
Definition: grst_asn1.c:119
int GRSThttpPrintHeader(GRSThttpBody *, char *)
Definition: grst_http.c:205
int tag
Definition: gridsite.h:177
int length
Definition: gridsite.h:176
GRSTgaclPerm GRSTgaclAclTestexclUser(GRSTgaclAcl *, GRSTgaclUser *)
Definition: grst_gacl.c:1343
GRSTgaclAcl * GRSTgaclAclNew(void)
Definition: grst_gacl.c:563
char * dn
Definition: gridsite.h:184
unsigned char length_lsb
Definition: gridsite.h:227
GRSTgaclAcl * GRSTgaclAclLoadFile(char *)
Definition: grst_gacl.c:758
Definition: gridsite.h:173
int GRSTx509VerifyCallback(int, X509_STORE_CTX *)
Example VerifyCallback routine.
Definition: grst_canl_x509.c:1381
void GRSThttpPrintf(GRSThttpBody *, char *,...)
Definition: grst_http.c:58
char * value
Definition: gridsite.h:185
int GRSTgaclCredFree(GRSTgaclCred *)
Definition: grst_gacl.c:223
__attribute__((deprecated)) typedef struct
Definition: gridsite.h:120
GRSTgaclCred * GRSTx509CompactToCred(char *grst_cred)
Turn a Compact Cred line into a GRSTgaclCred object.
Definition: grst_canl_x509.c:1596
int GRSTx509NameCmp(char *, char *)
Compare X509 Distinguished Name strings.
Definition: grst_canl_x509.c:223
GRSThtcpCountstr * version
Definition: gridsite.h:246
GRSThtcpCountstr * cache_hdrs
Definition: gridsite.h:250
GRSThtcpCountstr * req_hdrs
Definition: gridsite.h:247
int GRSTgaclInit(void)
Definition: grst_gacl.c:77
int GRSThttpCopy(GRSThttpBody *, char *)
Definition: grst_http.c:95
char * text
Definition: gridsite.h:437
int GRSThtcpMessageParse(GRSThtcpMessage *, char *, int)
Definition: grst_htcp.c:233
GRSTgaclPerm GRSTgaclAclTestUser(GRSTgaclAcl *, GRSTgaclUser *)
Definition: grst_gacl.c:1298
GRSTgaclEntry * firstentry
Definition: gridsite.h:133
Definition: gridsite.h:226
int GRSTgaclAclPrint(GRSTgaclAcl *, FILE *)
Definition: grst_gacl.c:591
GRSTgaclPerm denied
Definition: gridsite.h:130
int GRSThttpPrintFooter(GRSThttpBody *, char *)
Definition: grst_http.c:221
int GRSThtcpTSTresponseMake(char **, int *, unsigned int, char *, char *, char *)
Definition: grst_htcp.c:165
unsigned int reserved
Definition: gridsite.h:242
int GRSTgaclAclAddEntry(GRSTgaclAcl *, GRSTgaclEntry *)
Definition: grst_gacl.c:433
int GRSTx509CompactCreds(int *lastcred, int maxcreds, size_t credlen, char *creds, STACK_OF(X509) *certstack, char *vomsdir, X509 *peercert)
Get the credentials in an X509 cert/GSI proxy, including any VOMS.
Definition: grst_canl_x509.c:1657
char treecoords[GRST_ASN1_MAXCOORDLEN+1]
Definition: gridsite.h:173
unsigned int trans_id
Definition: gridsite.h:243
int GRSTgaclUserFree(GRSTgaclUser *)
Definition: grst_gacl.c:946
int nist_loa
Definition: gridsite.h:114
void * raw
Definition: gridsite.h:191
size_t size
Definition: gridsite.h:440
int GRSTgaclAclFree(GRSTgaclAcl *)
Definition: grst_gacl.c:579
int GRSThttpPrintHeaderFooter(GRSThttpBody *, char *, char *)
Definition: grst_http.c:168
int GRSThtcpNOPrequestMake(char **, int *, unsigned int)
Definition: grst_htcp.c:47
int GRSTx509ChainLoad(GRSTx509Chain **chain, STACK_OF(X509) *certstack, X509 *lastcert, char *capath, char *vomsdir)
Definition: grst_canl_x509.c:1015
GRSThtcpCountstr * method
Definition: gridsite.h:244
int errors
Definition: gridsite.h:182
time_t notbefore
Definition: gridsite.h:115
GRSTgaclAcl * GRSTgaclAclLoadforFile(char *)
Definition: grst_gacl.c:906
char * GRSTx509MakeDelegationID(void)
Returns a Delegation ID based on hash of GRST_CRED_0, ...
Definition: grst_canl_x509.c:2643
char * ocsp
Definition: gridsite.h:190
int GRST_is_id_safe(const char *)
Definition: grst_canl_x509.c:2876
int
Definition: gridsite.h:398
int delegation
Definition: gridsite.h:188