2 * Copyright (c) 2008-2010,2012-2013 Apple Inc. All Rights Reserved.
4 * @APPLE_LICENSE_HEADER_START@
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. Please obtain a copy of the License at
10 * http://www.opensource.apple.com/apsl/ and read it before using this
13 * The Original Code and all software distributed under the License are
14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 * Please see the License for the specific language governing rights and
19 * limitations under the License.
21 * @APPLE_LICENSE_HEADER_END@
28 #include <CoreFoundation/CoreFoundation.h>
29 #include <Security/SecIdentity.h>
30 #include <Security/SecPolicy.h>
31 #include <Security/SecTrust.h>
33 #ifndef _SECURITY_SECCMS_H_
34 #define _SECURITY_SECCMS_H_
38 extern const void * kSecCMSBulkEncryptionAlgorithm
;
39 extern const void * kSecCMSSignDigest
;
40 extern const void * kSecCMSSignDetached
;
41 extern const void * kSecCMSSignHashAlgorithm
;
42 extern const void * kSecCMSCertChainMode
;
43 extern const void * kSecCMSAdditionalCerts
;
44 extern const void * kSecCMSSignedAttributes
;
45 extern const void * kSecCMSSignDate
;
46 extern const void * kSecCMSAllCerts
;
47 extern const void * kSecCMSHashAgility
;
49 extern const void * kSecCMSEncryptionAlgorithmDESCBC
;
50 extern const void * kSecCMSEncryptionAlgorithmAESCBC
;
51 extern const void * kSecCMSHashingAlgorithmMD5
52 __IOS_DEPRECATED(__IPHONE_3_1
, __IPHONE_10_0
, "Disuse this constant in order to upgrade to SHA-1");
53 extern const void * kSecCMSCertChainModeNone
;
55 extern const void * kSecCMSHashingAlgorithmSHA1
;
56 extern const void * kSecCMSHashingAlgorithmSHA256
;
57 extern const void * kSecCMSHashingAlgorithmSHA384
;
58 extern const void * kSecCMSHashingAlgorithmSHA512
;
61 @function SecCMSVerifyCopyDataAndAttributes
62 @abstract verify a signed data cms blob.
63 @param message the cms message to be parsed
64 @param detached_contents to pass detached contents (optional)
65 @param policy specifies policy or array thereof should be used (optional).
66 if none is passed the blob will **not** be verified and only
67 the attached contents will be returned.
68 @param trustref (output/optional) if specified, the trust chain built during
69 verification will not be evaluated but returned to the caller to do so.
70 @param attached_contents (output/optional) return a copy of the attached
72 @param signed_attributes (output/optional) return a copy of the signed
73 attributes as a CFDictionary from oids (CFData) to values
75 @result A result code. See "Security Error Codes" (SecBase.h).
76 errSecDecode not a CMS message we can parse,
77 errSecAuthFailed bad signature, or untrusted signer if caller doesn't
79 errSecParam garbage in, garbage out.
81 OSStatus
SecCMSVerifyCopyDataAndAttributes(CFDataRef message
, CFDataRef detached_contents
,
82 CFTypeRef policy
, SecTrustRef
*trustref
,
83 CFDataRef
*attached_contents
, CFDictionaryRef
*signed_attributes
);
86 @function SecCMSVerify
87 @abstract same as SecCMSVerifyCopyDataAndAttributes, for binary compatibility.
89 OSStatus
SecCMSVerify(CFDataRef message
, CFDataRef detached_contents
,
90 CFTypeRef policy
, SecTrustRef
*trustref
, CFDataRef
*attached_contents
);
93 /* Return an array of certificates contained in message, if message is of the
94 type SignedData and has no signers, return NULL otherwise. Not that if
95 the message is properly formed but has no certificates an empty array will
97 CFArrayRef
SecCMSCertificatesOnlyMessageCopyCertificates(CFDataRef message
);
99 /* Create a degenerate PKCS#7 containing a cert or a CFArray of certs. */
100 CFDataRef
SecCMSCreateCertificatesOnlyMessage(CFTypeRef cert_or_array_thereof
);
101 CFDataRef
SecCMSCreateCertificatesOnlyMessageIAP(SecCertificateRef cert
);
104 @function SecCMSSignDataAndAttributes
105 @abstract create a signed data cms blob.
106 @param identity signer
107 @param data message to be signed
108 @param detached sign detached or not
109 @param signed_data (output) return signed message.
110 @param signed_attributes (input/optional) signed attributes to insert
111 as a CFDictionary from oids (CFData) to value (CFData).
112 @result A result code. See "Security Error Codes" (SecBase.h).
113 errSecParam garbage in, garbage out.
115 OSStatus
SecCMSSignDataAndAttributes(SecIdentityRef identity
, CFDataRef data
,
116 bool detached
, CFMutableDataRef signed_data
, CFDictionaryRef signed_attributes
);
119 @function SecCMSSignDigestAndAttributes
120 @abstract create a detached signed data cms blob for a SHA-1 hash.
121 @param identity signer
122 @param digest SHA-1 digest of message to be signed
123 @param signed_data (output) return signed message.
124 @param signed_attributes (input/optional) signed attributes to insert
125 as a CFDictionary from oids (CFData) to value (CFData).
126 @result A result code. See "Security Error Codes" (SecBase.h).
127 errSecParam garbage in, garbage out.
129 OSStatus
SecCMSSignDigestAndAttributes(SecIdentityRef identity
, CFDataRef digest
,
130 CFMutableDataRef signed_data
, CFDictionaryRef signed_attributes
);
133 @function SecCMSCreateSignedData
134 @abstract create a signed data cms blob.
135 @param identity signer
136 @param data SHA-1 digest or message to be signed
137 @param parameters (input/optional) specify algorithm, detached, digest
138 @param signed_attributes (input/optional) signed attributes to insert
139 as a CFDictionary from oids (CFData) to value (CFData).
140 @param signed_data (output) return signed message.
141 @result A result code. See "Security Error Codes" (SecBase.h).
142 errSecParam garbage in, garbage out.
144 OSStatus
SecCMSCreateSignedData(SecIdentityRef identity
, CFDataRef data
,
145 CFDictionaryRef parameters
, CFDictionaryRef signed_attributes
,
146 CFMutableDataRef signed_data
);
149 @function SecCMSCreateEnvelopedData
150 @abstract create a enveloped cms blob for recipients
151 @param recipient_or_cfarray_thereof SecCertificateRef for each recipient
152 @param params CFDictionaryRef with encryption parameters
153 @param data Data to be encrypted
154 @param enveloped_data (output) return enveloped message.
155 @result A result code. See "Security Error Codes" (SecBase.h).
156 errSecParam garbage in, garbage out.
158 OSStatus
SecCMSCreateEnvelopedData(CFTypeRef recipient_or_cfarray_thereof
,
159 CFDictionaryRef params
, CFDataRef data
, CFMutableDataRef enveloped_data
);
163 @function SecCMSDecryptEnvelopedData
164 @abstract open an enveloped cms blob. expects recipients identity in keychain.
165 @param message Eveloped message
166 @param data (output) return decrypted message.
167 @param recipient (output/optional) return addressed recipient
168 @result A result code. See "Security Error Codes" (SecBase.h).
169 errSecParam garbage in, garbage out.
171 OSStatus
SecCMSDecryptEnvelopedData(CFDataRef message
,
172 CFMutableDataRef data
, SecCertificateRef
*recipient
);
174 OSStatus
SecCMSVerifySignedData(CFDataRef message
, CFDataRef detached_contents
,
175 CFTypeRef policy
, SecTrustRef
*trustref
, CFArrayRef additional_certificates
,
176 CFDataRef
*attached_contents
, CFDictionaryRef
*message_attributes
);
180 #endif /* !_SECURITY_SECCMS_H_ */