]> git.saurik.com Git - apple/security.git/blob - AppleX509TP/tpPolicies.h
Security-29.tar.gz
[apple/security.git] / AppleX509TP / tpPolicies.h
1 /*
2 * Copyright (c) 2000-2001 Apple Computer, Inc. All Rights Reserved.
3 *
4 * The contents of this file constitute Original Code as defined in and are
5 * subject to the Apple Public Source License Version 1.2 (the 'License').
6 * You may not use this file except in compliance with the License. Please obtain
7 * a copy of the License at http://www.apple.com/publicsource and read it before
8 * using this file.
9 *
10 * This Original Code and all software distributed under the License are
11 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS
12 * OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, INCLUDING WITHOUT
13 * LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR
14 * PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. Please see the License for the
15 * specific language governing rights and limitations under the License.
16 */
17
18
19 /*
20 tpPolicies.h - TP module policy implementation
21
22 Created 10/9/2000 by Doug Mitchell.
23 */
24
25 #ifndef _TP_POLICIES_H_
26 #define _TP_POLICIES_H_
27
28 #include <Security/cssmtype.h>
29 #include <Security/cssmalloc.h>
30 #include "TPCertInfo.h"
31
32 #ifdef __cplusplus
33 extern "C" {
34 #endif /* __cplusplus */
35
36 CSSM_BOOL tp_verifyWithSslRoots(
37 CSSM_CL_HANDLE clHand,
38 CSSM_CSP_HANDLE cspHand,
39 TPCertInfo *certToVfy); // last in chain, not root
40
41 /*
42 * Enumerated policies enforced by this module.
43 */
44 typedef enum {
45 kTPDefault, /* no extension parsing, just sig and expiration */
46 kTPx509Basic, /* basic X.509/RFC2459 */
47 kTPiSign, /* Apple code signing */
48 kTP_SSL /* SecureTransport/SSL */
49 } TPPolicy;
50
51 /*
52 * Perform TP verification on a constructed (ordered) cert group.
53 * Returns CSSM_TRUE on success.
54 */
55 CSSM_RETURN tp_policyVerify(
56 TPPolicy policy,
57 CssmAllocator &alloc,
58 CSSM_CL_HANDLE clHand,
59 CSSM_CSP_HANDLE cspHand,
60 TPCertGroup *certGroup,
61 CSSM_BOOL verifiedToRoot); // last cert is good root
62
63 #ifdef __cplusplus
64 }
65 #endif
66 #endif /* _TP_POLICIES_H_ */