OLD | NEW |
1 // Copyright 2014 The Chromium Authors. All rights reserved. | 1 // Copyright 2014 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #ifndef CHROME_COMMON_EXTENSIONS_API_NETWORKING_PRIVATE_NETWORKING_PRIVATE_CRYPT
O_H_ | 5 #ifndef CHROME_COMMON_EXTENSIONS_API_NETWORKING_PRIVATE_NETWORKING_PRIVATE_CRYPT
O_H_ |
6 #define CHROME_COMMON_EXTENSIONS_API_NETWORKING_PRIVATE_NETWORKING_PRIVATE_CRYPT
O_H_ | 6 #define CHROME_COMMON_EXTENSIONS_API_NETWORKING_PRIVATE_NETWORKING_PRIVATE_CRYPT
O_H_ |
7 | 7 |
8 #include <stdint.h> | 8 #include <stdint.h> |
9 | 9 |
10 #include <string> | 10 #include <string> |
11 #include <vector> | 11 #include <vector> |
12 | 12 |
13 #include "base/basictypes.h" | 13 #include "base/basictypes.h" |
14 | 14 |
15 namespace networking_private_crypto { | 15 namespace networking_private_crypto { |
16 | 16 |
17 // Verify that the credentials described by |certificate| and |signed_data| | 17 // Verify that the credentials described by |certificate| and |signed_data| |
18 // are valid as follows: | 18 // are valid as follows: |
19 // 1) The MAC address listed in the certificate matches |connected_mac|. | 19 // 1) The MAC address listed in the certificate matches |connected_mac|. |
20 // 2) The certificate is a valid PEM encoded certificate signed by trusted CA. | 20 // 2) The certificate is a valid PEM encoded certificate signed by trusted CA. |
21 // 3) |signature| is a valid signature for |data|, using the public key in | 21 // 3) |signature| is a valid signature for |data|, using the public key in |
22 // |certificate| | 22 // |certificate| |
23 bool VerifyCredentials(const std::string& certificate, | 23 bool VerifyCredentials( |
24 const std::string& signature, | 24 const std::string& certificate, |
25 const std::string& data, | 25 const std::vector<std::string>& intermediate_certificates, |
26 const std::string& connected_mac); | 26 const std::string& signature, |
| 27 const std::string& data, |
| 28 const std::string& connected_mac); |
27 | 29 |
28 // Encrypt |data| with |public_key|. |public_key| is a DER-encoded | 30 // Encrypt |data| with |public_key|. |public_key| is a DER-encoded |
29 // RSAPublicKey. |data| is some string of bytes that is smaller than the | 31 // RSAPublicKey. |data| is some string of bytes that is smaller than the |
30 // maximum length permissible for PKCS#1 v1.5 with a key of |public_key| size. | 32 // maximum length permissible for PKCS#1 v1.5 with a key of |public_key| size. |
31 // | 33 // |
32 // Returns true on success, storing the encrypted result in | 34 // Returns true on success, storing the encrypted result in |
33 // |encrypted_output|. | 35 // |encrypted_output|. |
34 bool EncryptByteString(const std::vector<uint8_t>& public_key, | 36 bool EncryptByteString(const std::vector<uint8_t>& public_key, |
35 const std::string& data, | 37 const std::string& data, |
36 std::vector<uint8_t>* encrypted_output); | 38 std::vector<uint8_t>* encrypted_output); |
37 | 39 |
38 // Decrypt |encrypted_data| with |private_key_pem|. |private_key_pem| is the | 40 // Decrypt |encrypted_data| with |private_key_pem|. |private_key_pem| is the |
39 // PKCS8 PEM-encoded private key. |encrypted_data| is data encrypted with | 41 // PKCS8 PEM-encoded private key. |encrypted_data| is data encrypted with |
40 // EncryptByteString. Used in NetworkingPrivateCryptoTest::EncryptString test. | 42 // EncryptByteString. Used in NetworkingPrivateCryptoTest::EncryptString test. |
41 // Returns true on success, storing the decrypted result in | 43 // Returns true on success, storing the decrypted result in |
42 // |decrypted_output|. | 44 // |decrypted_output|. |
43 bool DecryptByteString(const std::string& private_key_pem, | 45 bool DecryptByteString(const std::string& private_key_pem, |
44 const std::vector<uint8_t>& encrypted_data, | 46 const std::vector<uint8_t>& encrypted_data, |
45 std::string* decrypted_output); | 47 std::string* decrypted_output); |
46 | 48 |
47 // The trusted public key as a DER-encoded PKCS#1 RSAPublicKey structure. | |
48 extern const uint8_t kTrustedCAPublicKeyDER[]; | |
49 | |
50 // The length of |kTrustedCAPublicKeyDER| in bytes. | |
51 extern const size_t kTrustedCAPublicKeyDERLength; | |
52 | |
53 } // namespace networking_private_crypto | 49 } // namespace networking_private_crypto |
54 | 50 |
55 #endif // CHROME_COMMON_EXTENSIONS_API_NETWORKING_PRIVATE_NETWORKING_PRIVATE_CR
YPTO_H_ | 51 #endif // CHROME_COMMON_EXTENSIONS_API_NETWORKING_PRIVATE_NETWORKING_PRIVATE_CR
YPTO_H_ |
OLD | NEW |