]> git.saurik.com Git - apple/security.git/blob - keychain/ot/OTEscrowKeys.h
Security-59306.11.20.tar.gz
[apple/security.git] / keychain / ot / OTEscrowKeys.h
1 /*
2 * Copyright (c) 2017 Apple Inc. All Rights Reserved.
3 *
4 * @APPLE_LICENSE_HEADER_START@
5 *
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. Please obtain a copy of the License at
10 * http://www.opensource.apple.com/apsl/ and read it before using this
11 * file.
12 *
13 * The Original Code and all software distributed under the License are
14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 * Please see the License for the specific language governing rights and
19 * limitations under the License.
20 *
21 * @APPLE_LICENSE_HEADER_END@
22 */
23
24 #ifndef OTEscrow_h
25 #define OTEscrow_h
26 #if OCTAGON
27
28 #import <Foundation/Foundation.h>
29 #import <SecurityFoundation/SFKey.h>
30 NS_ASSUME_NONNULL_BEGIN
31
32 typedef enum {
33 kOTEscrowKeySigning = 1,
34 kOTEscrowKeyEncryption = 2,
35 kOTEscrowKeySymmetric = 3,
36 } escrowKeyType;
37
38 @interface OTEscrowKeys : NSObject
39
40 @property (nonatomic, readonly) SFECKeyPair* encryptionKey;
41 @property (nonatomic, readonly) SFECKeyPair* signingKey;
42 @property (nonatomic, readonly) SFAESKey* symmetricKey;
43
44 @property (nonatomic, readonly) NSData* secret;
45 @property (nonatomic, readonly) NSString* dsid;
46
47 -(instancetype) init NS_UNAVAILABLE;
48
49 - (nullable instancetype) initWithSecret:(NSData*)secret
50 dsid:(NSString*)dsid
51 error:(NSError* __autoreleasing *)error;
52
53 - (nullable instancetype) initWithSigningKey:(SFECKeyPair*)signingKey
54 encryptionKey:(SFECKeyPair*)encryptionKey
55 symmetricKey:(SFAESKey*)symmetricKey;
56
57 + (SecKeyRef) createSecKey:(NSData*)keyData;
58 + (BOOL) setKeyMaterialInKeychain:(NSDictionary*)query error:(NSError* __autoreleasing *)error;
59 + (BOOL)findEscrowKeysForLabel:(NSString*)label
60 foundSigningKey:(SFECKeyPair*_Nonnull*_Nullable)signingKey
61 foundEncryptionKey:(SFECKeyPair*_Nonnull*_Nullable)encryptionKey
62 foundSymmetricKey:(SFAESKey*_Nonnull*_Nullable)symmetricKey
63 error:(NSError**)error;
64 + (NSString*) hashEscrowedSigningPublicKey:(NSData*)keyData;
65
66 + (NSData* _Nullable) generateEscrowKey:(escrowKeyType)keyType
67 masterSecret:(NSData*)masterSecret
68 dsid:(NSString *)dsid
69 error:(NSError**)error;
70
71 @end
72 NS_ASSUME_NONNULL_END
73 #endif
74 #endif /* OTEscrow_h */