2 * Copyright (c) 2000-2001,2011,2014 Apple Inc. All Rights Reserved.
4 * The contents of this file constitute Original Code as defined in and are
5 * subject to the Apple Public Source License Version 1.2 (the 'License').
6 * You may not use this file except in compliance with the License. Please obtain
7 * a copy of the License at http://www.apple.com/publicsource and read it before
10 * This Original Code and all software distributed under the License are
11 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS
12 * OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, INCLUDING WITHOUT
13 * LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR
14 * PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. Please see the License for the
15 * specific language governing rights and limitations under the License.
20 // SSKey.h - CSP-wide SSKey base class
25 #include <security_cdsa_plugin/CSPsession.h>
27 #include "SSDatabase.h"
29 #include <security_cdsa_client/dlclient.h>
30 #include <securityd_client/ssclient.h>
37 } // end namespace Security
43 class SSKey
: public ReferencedKey
46 SSKey(SSCSPSession
&session
, SecurityServer::KeyHandle keyHandle
,
47 CssmKey
&ioKey
, SSDatabase
&inSSDatabase
, uint32 inKeyAttr
,
48 const CssmData
*inKeyLabel
);
49 SSKey(SSDLSession
&session
, CssmKey
&ioKey
, SSDatabase
&inSSDatabase
,
50 const SSUniqueRecord
&uniqueId
, CSSM_DB_RECORDTYPE recordType
,
54 void free(const AccessCredentials
*accessCred
, CssmKey
&ioKey
,
57 SecurityServer::ClientSession
&clientSession();
59 /* Might return SecurityServer::noKey if the key has not yet been instantiated. */
60 SecurityServer::KeyHandle
optionalKeyHandle() const;
62 /* Will instantiate the key if needed. */
63 SecurityServer::KeyHandle
keyHandle();
65 // ACL retrieval and change operations
66 void getOwner(CSSM_ACL_OWNER_PROTOTYPE
&owner
, Allocator
&allocator
);
67 void changeOwner(const AccessCredentials
&accessCred
,
68 const AclOwnerPrototype
&newOwner
);
69 void getAcl(const char *selectionTag
, uint32
&numberOfAclInfos
,
70 AclEntryInfo
*&aclInfos
, Allocator
&allocator
);
71 void changeAcl(const AccessCredentials
&accessCred
,
72 const AclEdit
&aclEdit
);
74 // Reencode and write to disk if we are a persistant key.
78 Allocator
&mAllocator
;
79 SecurityServer::KeyHandle mKeyHandle
;
80 SSDatabase mSSDatabase
;
81 SSUniqueRecord mUniqueId
;
82 CSSM_DB_RECORDTYPE mRecordType
;
83 SecurityServer::ClientSession
&mClientSession
;