2 * Copyright (c) 2012-2014 Apple Inc. All Rights Reserved.
4 * @APPLE_LICENSE_HEADER_START@
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. Please obtain a copy of the License at
10 * http://www.opensource.apple.com/apsl/ and read it before using this
13 * The Original Code and all software distributed under the License are
14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 * Please see the License for the specific language governing rights and
19 * limitations under the License.
21 * @APPLE_LICENSE_HEADER_END@
27 The functions provided in SOSCircle.h provide an interface to a
28 secure object syncing circle for a single class
34 #include <Security/Security.h>
35 #include <Security/SecureObjectSync/SOSFullPeerInfo.h>
36 #include <Security/SecureObjectSync/SOSPeerInfo.h>
37 #include <Security/SecureObjectSync/SOSPeer.h>
38 #include <Security/SecureObjectSync/SOSConcordanceTrust.h>
39 #include <Security/SecureObjectSync/SOSGenCount.h>
40 #include <Security/SecureObjectSync/SOSPiggyback.h>
45 typedef struct __OpaqueSOSCircle
*SOSCircleRef
;
47 CFTypeID
SOSCircleGetTypeID(void);
49 SOSCircleRef
SOSCircleCreate(CFAllocatorRef allocator
, CFStringRef circleName
, CFErrorRef
*error
);
50 SOSCircleRef
SOSCircleCreateFromDER(CFAllocatorRef allocator
, CFErrorRef
* error
,
51 const uint8_t** der_p
, const uint8_t *der_end
);
52 SOSCircleRef
SOSCircleCreateFromData(CFAllocatorRef allocator
, CFDataRef circleData
, CFErrorRef
*error
);
53 SOSCircleRef
SOSCircleCopyCircle(CFAllocatorRef allocator
, SOSCircleRef otherCircle
, CFErrorRef
*error
);
55 CFStringRef
SOSCircleCopyHashString(SOSCircleRef circle
);
57 bool SOSCircleSetSignature(SOSCircleRef circle
, SecKeyRef pubkey
, CFDataRef signature
, CFErrorRef
*error
);
58 CFDataRef
SOSCircleGetSignature(SOSCircleRef circle
, SecKeyRef pubkey
, CFErrorRef
*error
);
59 CFDictionaryRef
SOSCircleCopyAllSignatures(SOSCircleRef circle
);
60 bool SOSCircleSign(SOSCircleRef circle
, SecKeyRef privkey
, CFErrorRef
*error
);
61 bool SOSCircleVerifySignatureExists(SOSCircleRef circle
, SecKeyRef pubKey
, CFErrorRef
*error
);
62 bool SOSCircleVerifyPeerSignatureExists(SOSCircleRef circle
, SOSPeerInfoRef peer
);
63 bool SOSCircleVerify(SOSCircleRef circle
, SecKeyRef pubkey
, CFErrorRef
*error
);
65 bool SOSCircleVerifyPeerSigned(SOSCircleRef circle
, SOSPeerInfoRef peer
, CFErrorRef
*error
);
67 bool SOSCircleGenerationSign(SOSCircleRef circle
, SecKeyRef user_approver
, SOSFullPeerInfoRef peerinfo
, CFErrorRef
*error
);
68 bool SOSCircleSignOldStyleResetToOfferingCircle(SOSCircleRef circle
, SOSFullPeerInfoRef peerinfo
, SecKeyRef user_approver
, CFErrorRef
*error
);
71 size_t SOSCircleGetDEREncodedSize(SOSCircleRef cir
, CFErrorRef
*error
);
72 uint8_t* SOSCircleEncodeToDER(SOSCircleRef cir
, CFErrorRef
* error
, const uint8_t* der
, uint8_t* der_end
);
73 CFDataRef
SOSCircleCopyEncodedData(SOSCircleRef circle
, CFAllocatorRef allocator
, CFErrorRef
*error
);
75 size_t SOSCircleGetDEREncodedSize(SOSCircleRef cir
, CFErrorRef
*error
);
76 uint8_t* SOSCircleEncodeToDER(SOSCircleRef cir
, CFErrorRef
* error
, const uint8_t* der
, uint8_t* der_end
);
77 CFDataRef
SOSCircleCopyEncodedData(SOSCircleRef circle
, CFAllocatorRef allocator
, CFErrorRef
*error
);
79 int SOSCircleCountApplicants(SOSCircleRef circle
);
80 bool SOSCircleHasApplicant(SOSCircleRef circle
, SOSPeerInfoRef peerInfo
, CFErrorRef
*error
);
81 CFMutableSetRef
SOSCircleCopyApplicants(SOSCircleRef c
, CFAllocatorRef allocator
);
82 void SOSCircleForEachApplicant(SOSCircleRef circle
, void (^action
)(SOSPeerInfoRef peer
));
84 int SOSCircleCountRejectedApplicants(SOSCircleRef circle
);
85 bool SOSCircleHasRejectedApplicant(SOSCircleRef circle
, SOSPeerInfoRef peerInfo
, CFErrorRef
*error
);
86 SOSPeerInfoRef
SOSCircleCopyRejectedApplicant(SOSCircleRef circle
, SOSPeerInfoRef peerInfo
, CFErrorRef
*error
);
87 CFMutableArrayRef
SOSCircleCopyRejectedApplicants(SOSCircleRef c
, CFAllocatorRef allocator
);
88 void SOSCircleSetGeneration(SOSCircleRef circle
, SOSGenCountRef gencount
);
90 CFStringRef
SOSCircleGetName(SOSCircleRef circle
);
91 const char *SOSCircleGetNameC(SOSCircleRef circle
);
93 void SOSCircleGenerationSetValue(SOSCircleRef circle
, int64_t value
);
94 SOSGenCountRef
SOSCircleGetGeneration(SOSCircleRef circle
);
95 int64_t SOSCircleGetGenerationSint(SOSCircleRef circle
);
96 void SOSCircleGenerationIncrement(SOSCircleRef circle
);
98 CFMutableSetRef
SOSCircleCopyPeers(SOSCircleRef circle
, CFAllocatorRef allocator
);
99 bool SOSCircleAppendConcurringPeers(SOSCircleRef circle
, CFMutableArrayRef appendHere
, CFErrorRef
*error
);
100 CFMutableArrayRef
SOSCircleCopyConcurringPeers(SOSCircleRef circle
, CFErrorRef
* error
);
101 SOSPeerInfoRef
SOSCircleCopyPeerWithID(SOSCircleRef circle
, CFStringRef peerid
, CFErrorRef
*error
);
103 int SOSCircleCountPeers(SOSCircleRef circle
);
104 int SOSCircleCountActivePeers(SOSCircleRef circle
);
105 int SOSCircleCountActiveValidPeers(SOSCircleRef circle
, SecKeyRef pubkey
);
106 int SOSCircleCountValidSyncingPeers(SOSCircleRef circle
, SecKeyRef pubkey
);
108 int SOSCircleCountRetiredPeers(SOSCircleRef circle
);
110 void SOSCircleForEachPeer(SOSCircleRef circle
, void (^action
)(SOSPeerInfoRef peer
));
111 void SOSCircleForEachRetiredPeer(SOSCircleRef circle
, void (^action
)(SOSPeerInfoRef peer
));
112 void SOSCircleForEachiCloudIdentityPeer(SOSCircleRef circle
, void (^action
)(SOSPeerInfoRef peer
));
113 void SOSCircleForEachActivePeer(SOSCircleRef circle
, void (^action
)(SOSPeerInfoRef peer
));
114 void SOSCircleForEachActiveValidPeer(SOSCircleRef circle
, SecKeyRef user_public_key
, void (^action
)(SOSPeerInfoRef peer
));
115 void SOSCircleForEachValidPeer(SOSCircleRef circle
, SecKeyRef user_public_key
, void (^action
)(SOSPeerInfoRef peer
));
116 void SOSCircleForEachValidSyncingPeer(SOSCircleRef circle
, SecKeyRef user_public_key
, void (^action
)(SOSPeerInfoRef peer
));
118 bool SOSCircleHasPeerWithID(SOSCircleRef circle
, CFStringRef peerid
, CFErrorRef
*error
);
120 bool SOSCircleHasPeer(SOSCircleRef circle
, SOSPeerInfoRef peerInfo
, CFErrorRef
*error
);
121 bool SOSCircleHasActivePeerWithID(SOSCircleRef circle
, CFStringRef peerid
, CFErrorRef
*error
);
122 bool SOSCircleHasActivePeer(SOSCircleRef circle
, SOSPeerInfoRef peerInfo
, CFErrorRef
*error
);
123 bool SOSCircleHasActiveValidPeerWithID(SOSCircleRef circle
, CFStringRef peerid
, SecKeyRef user_public_key
, CFErrorRef
*error
);
124 bool SOSCircleHasActiveValidPeer(SOSCircleRef circle
, SOSPeerInfoRef peerInfo
, SecKeyRef user_public_key
, CFErrorRef
*error
);
125 bool SOSCircleHasValidSyncingPeer(SOSCircleRef circle
, SOSPeerInfoRef peerInfo
, SecKeyRef user_public_key
, CFErrorRef
*error
);
127 bool SOSCircleResetToOffering(SOSCircleRef circle
, SecKeyRef user_privkey
, SOSFullPeerInfoRef requestor
, CFErrorRef
*error
);
128 bool SOSCircleResetToEmpty(SOSCircleRef circle
, CFErrorRef
*error
);
129 bool SOSCircleResetToEmptyWithSameGeneration(SOSCircleRef circle
, CFErrorRef
*error
);
130 bool SOSCircleRequestAdmission(SOSCircleRef circle
, SecKeyRef user_privkey
, SOSFullPeerInfoRef requestor
, CFErrorRef
*error
);
131 bool SOSCircleRequestReadmission(SOSCircleRef circle
, SecKeyRef user_pubkey
, SOSPeerInfoRef requestor
, CFErrorRef
*error
);
133 bool SOSCircleAcceptRequest(SOSCircleRef circle
, SecKeyRef user_privkey
, SOSFullPeerInfoRef device_approver
, SOSPeerInfoRef peerInfo
, CFErrorRef
*error
);
134 bool SOSCircleRejectRequest(SOSCircleRef circle
, SOSFullPeerInfoRef device_approver
, SOSPeerInfoRef peerInfo
, CFErrorRef
*error
);
135 bool SOSCircleWithdrawRequest(SOSCircleRef circle
, SOSPeerInfoRef peerInfo
, CFErrorRef
*error
);
136 bool SOSCircleRemoveRejectedPeer(SOSCircleRef circle
, SOSPeerInfoRef peerInfo
, CFErrorRef
*error
);
137 bool SOSCirclePeerSigUpdate(SOSCircleRef circle
, SecKeyRef userPrivKey
, SOSFullPeerInfoRef fpi
,
141 // Update a peer's meta information.
142 // No resigning of the circle is done, only updates to their own self signed description.
144 bool SOSCircleUpdatePeerInfo(SOSCircleRef circle
, SOSPeerInfoRef replacement_peer_info
);
145 bool SOSCircleRemovePeersByIDUnsigned(SOSCircleRef circle
, CFSetRef peersToRemove
);
147 bool SOSCircleRemovePeer(SOSCircleRef circle
, SecKeyRef user_privkey
, SOSFullPeerInfoRef device_approver
, SOSPeerInfoRef peerInfo
, CFErrorRef
*error
);
148 bool SOSCircleRemovePeers(SOSCircleRef circle
, SecKeyRef user_privkey
, SOSFullPeerInfoRef device_approver
, CFSetRef peerInfo
, CFErrorRef
*error
);
149 bool SOSCircleRemovePeersByID(SOSCircleRef circle
, SecKeyRef user_privkey
, SOSFullPeerInfoRef device_approver
, CFSetRef peerIDs
, CFErrorRef
*error
);
150 bool SOSCircleRemoveRetired(SOSCircleRef circle
, CFErrorRef
*error
);
152 bool SOSCircleAcceptRequests(SOSCircleRef circle
, SecKeyRef user_privkey
, SOSFullPeerInfoRef device_approver
, CFErrorRef
*error
);
154 // Stuff above this line is really SOSCircleInfo below the line is the active SOSCircle functionality
156 CF_RETURNS_RETAINED SOSFullPeerInfoRef
SOSCircleCopyiCloudFullPeerInfoRef(SOSCircleRef circle
, CFErrorRef
*error
);
158 bool SOSCircleConcordanceSign(SOSCircleRef circle
, SOSFullPeerInfoRef peerinfo
, CFErrorRef
*error
);
160 bool SOSCircleSharedTrustedPeers(SOSCircleRef current
, SOSCircleRef proposed
, SOSPeerInfoRef me
);
162 bool SOSCircleIsOlderGeneration(SOSCircleRef current
, SOSCircleRef proposed
);
164 SOSConcordanceStatus
SOSCircleConcordanceTrust(SOSCircleRef known_circle
, SOSCircleRef proposed_circle
,
165 SecKeyRef known_pubkey
, SecKeyRef user_pubkey
,
166 SOSPeerInfoRef exclude
, CFErrorRef
*error
);
168 CFDataRef
SOSCircleCopyNextGenSignatureWithPeerAdded(SOSCircleRef circle
, SOSPeerInfoRef peer
, SecKeyRef privKey
, CFErrorRef
*error
);
169 bool SOSCirclePreGenerationSign(SOSCircleRef circle
, SecKeyRef userPubKey
, CFErrorRef
*error
);
175 CFDataRef
SOSCircleCreateIncompatibleCircleDER(CFErrorRef
* error
);
176 void debugDumpCircle(CFStringRef message
, SOSCircleRef circle
);
177 void SOSCircleLogState(char *category
, SOSCircleRef circle
, SecKeyRef pubKey
, CFStringRef myPID
);
179 bool SOSCircleAcceptPeerFromHSA2(SOSCircleRef circle
, SecKeyRef userKey
, SOSGenCountRef gencount
, SecKeyRef pPubKey
, CFDataRef signature
, SOSFullPeerInfoRef fpi
, CFErrorRef
*error
);
183 #endif /* !_SOSCIRCLE_H_ */