Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(1038)

Unified Diff: chrome/browser/extensions/api/networking_private/networking_private_crypto.h

Issue 23710003: Added NetworkingPrivateCrypto and its unit test. (Closed) Base URL: svn://svn.chromium.org/chrome/trunk/src
Patch Set: Created 7 years, 4 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: chrome/browser/extensions/api/networking_private/networking_private_crypto.h
diff --git a/chrome/browser/extensions/api/networking_private/networking_private_crypto.h b/chrome/browser/extensions/api/networking_private/networking_private_crypto.h
new file mode 100644
index 0000000000000000000000000000000000000000..962aef9ddbd57749158419dcf6d81c16f8c4084b
--- /dev/null
+++ b/chrome/browser/extensions/api/networking_private/networking_private_crypto.h
@@ -0,0 +1,63 @@
+// Copyright 2013 The Chromium Authors. All rights reserved.
+// Use of this source code is governed by a BSD-style license that can be
+// found in the LICENSE file.
+
+// Implementation of Crypto support for networking private API.
+
+#ifndef CHROME_BROWSER_EXTENSIONS_API_NETWORKING_PRIVATE_NETWORKING_PRIVATE_CRYPTO_H_
+#define CHROME_BROWSER_EXTENSIONS_API_NETWORKING_PRIVATE_NETWORKING_PRIVATE_CRYPTO_H_
+
+#include <string>
+#include "base/basictypes.h"
+
+// Forward declaration.
+typedef struct SECKEYPrivateKeyStr SECKEYPrivateKey;
+typedef struct SECKEYPublicKeyStr SECKEYPublicKey;
+typedef struct CERTCertificateStr CERTCertificate;
+
+class NetworkingPrivateCrypto {
+ public:
+ NetworkingPrivateCrypto();
+ ~NetworkingPrivateCrypto();
+ // Verify that the destination described by |certificate| is valid.
Ryan Sleevi 2013/08/28 19:02:37 nit: line break between dtor.
mef 2013/08/28 21:28:58 Done.
+ //
+ // 1) The MAC address listed in the certificate matches |connected_mac|.
+ // 2) The certificate is a valid PEM encoded certificate signed by our
+ // trusted CA.
Ryan Sleevi 2013/08/28 19:02:37 comment nit: drop our. Explain exactly what the re
mef 2013/08/28 21:28:58 Done. This comment was copied from original code.
+ // 3) |signed_data| matches the hashed |unsigned_data| encrypted with
+ // the public key in |certificate|.
Ryan Sleevi 2013/08/28 19:02:37 nit: "Verify that the destination" describes what
mef 2013/08/28 21:28:58 Done. This comment was copied from original code.
+ bool VerifyCredentials(const std::string& certificate,
+ const std::string& signed_data,
+ const std::string& unsigned_data,
+ const std::string& connected_mac);
+
+ // Encrypt |data| with |public_key|. |public_key| is the raw bytes of a key
+ // in
+ // RSAPublicKey format. |data| is some string of bytes smaller than the
Ryan Sleevi 2013/08/28 19:02:37 nit: comment style - awkward line wrap. nit: Use S
mef 2013/08/28 21:28:58 Done.
+ // maximum length permissable for encryption with a key of |public_key| size.
+ //
+ // Returns the encrypted result in |encrypted_output| and returns true on
+ // success. Returns false on failure.
Ryan Sleevi 2013/08/28 19:02:37 nit: Returns true on success, storing the encrypte
mef 2013/08/28 21:28:58 Done.
+ bool EncryptByteString(const std::string& public_key,
+ const std::string& data,
+ std::string* encrypted_output);
+
+ // Decrypt |encrypted_data| with |private_key_pem|. |private_key_pem| is the
+ // PEM-encoded private key. |encrypted_data| is data encrypted with
Ryan Sleevi 2013/08/28 19:02:37 nit: "PEM-encoded private key" is an undefined for
mef 2013/08/28 21:28:58 Done.
+ // EncryptByteString.
+ // Returns the decrypted result in |decrypted_output| and returns true on
+ // success. Returns false on failure.
Ryan Sleevi 2013/08/28 19:02:37 nit: same comments as above apply here.
mef 2013/08/28 21:28:58 Done.
+ bool DecryptByteString(const std::string& private_key_pem,
+ const std::string& encrypted_data,
+ std::string* decrypted_output);
+
+ private:
+ SECKEYPublicKey* ca_public_key_;
mef 2013/08/28 18:05:59 These member variables are here only to ease the c
Ryan Sleevi 2013/08/28 19:02:37 Using the NSS objects directly here presumes !Andr
mef 2013/08/28 21:28:58 Done.
+ SECKEYPublicKey* cert_public_key_;
+ CERTCertificate* cert_;
+ SECKEYPublicKey* enc_public_key_;
Ryan Sleevi 2013/08/28 19:02:37 nit: Naming enc_ is not a clear abbreviation.
mef 2013/08/28 21:28:58 Done.
+
+ DISALLOW_COPY_AND_ASSIGN(NetworkingPrivateCrypto);
+};
+
+#endif // CHROME_BROWSER_EXTENSIONS_API_NETWORKING_PRIVATE_NETWORKING_PRIVATE_CRYPTO_H_

Powered by Google App Engine
This is Rietveld 408576698