36#ifndef HEADER_GRIDSITE_H
37#define HEADER_GRIDSITE_H
40#define GRST_VERSION 010500
47#ifndef GRST_NO_OPENSSL
50#include <openssl/ssl.h>
53#ifndef HEADER_CRYPTO_H
54#include <openssl/crypto.h>
82#define GRST_RET_FAILED 1000
85#define GRST_RET_CERT_NOT_FOUND 1001
88#define GRST_RET_BAD_SIGNATURE 1002
91#define GRST_RET_NO_SUCH_FILE 1003
95#define GRSTerrorLog(GRSTerrorLevel, ...) ((GRSTerrorLogFunc != NULL) && ((GRSTerrorLogFunc)(__FILE__, __LINE__, GRSTerrorLevel, __VA_ARGS__)))
101#define GRST_LOG_EMERG 0
102#define GRST_LOG_ALERT 1
103#define GRST_LOG_CRIT 2
104#define GRST_LOG_ERR 3
105#define GRST_LOG_WARNING 4
106#define GRST_LOG_NOTICE 5
107#define GRST_LOG_INFO 6
108#define GRST_LOG_DEBUG 7
110#define GRST_MAX_TIME_T INT32_MAX
121typedef struct {
char *name;
137#define GRST_PERM_NONE 0
138#define GRST_PERM_READ 1
139#define GRST_PERM_EXEC 2
140#define GRST_PERM_LIST 4
141#define GRST_PERM_WRITE 8
142#define GRST_PERM_ADMIN 16
143#define GRST_PERM_ALL 31
146#define GRSTgaclPermIsNone(perm) ((perm) == 0)
148#define GRSTgaclPermHasNone(perm) ((perm) == 0)
149#define GRSTgaclPermHasRead(perm) (((perm) & GRST_PERM_READ ) != 0)
150#define GRSTgaclPermHasExec(perm) (((perm) & GRST_PERM_EXEC ) != 0)
151#define GRSTgaclPermHasList(perm) (((perm) & GRST_PERM_LIST ) != 0)
152#define GRSTgaclPermHasWrite(perm) (((perm) & GRST_PERM_WRITE) != 0)
153#define GRSTgaclPermHasAdmin(perm) (((perm) & GRST_PERM_ADMIN) != 0)
155#define GRST_ACTION_ALLOW 0
156#define GRST_ACTION_DENY 1
158#define GRST_HIST_PREFIX ".grsthist"
159#define GRST_ACL_FILE ".gacl"
160#define GRST_DN_LISTS "/etc/grid-security/dn-lists"
161#define GRST_RECURS_LIMIT 9
163#define GRST_PROXYCERTINFO_OLD_OID "1.3.6.1.4.1.3536.1.222"
164#define GRST_PROXYCERTINFO_OID "1.3.6.1.5.5.7.1.14"
165#define GRST_VOMS_OID "1.3.6.1.4.1.8005.100.100.5"
166#define GRST_VOMS_PK_CERT_LIST_OID "1.3.6.1.4.1.8005.100.100.10"
167#define GRST_VOMS_DIR "/etc/grid-security/vomsdir"
168#define GRST_KEYUSAGE_OID "2.5.29.15"
170#define GRST_ASN1_MAXCOORDLEN 50
171#define GRST_ASN1_MAXTAGS 500
179#define GRST_X509_SERIAL_DIGITS 49
189 char serial[GRST_X509_SERIAL_DIGITS+1];
194#define GRST_CERT_BAD_FORMAT 1
195#define GRST_CERT_BAD_CHAIN 2
196#define GRST_CERT_BAD_SIG 4
197#define GRST_CERT_BAD_TIME 8
198#define GRST_CERT_BAD_OCSP 16
200#define GRST_CERT_TYPE_CA 1
201#define GRST_CERT_TYPE_EEC 2
202#define GRST_CERT_TYPE_PROXY 3
203#define GRST_CERT_TYPE_VOMS 4
204#define GRST_CERT_TYPE_ROBOT 5
209#ifndef GRST_NO_OPENSSL
212 STACK_OF(X509) *certstack, X509 *lastcert,
213 char *capath,
char *vomsdir);
218#define GRST_HTTP_PORT 777
219#define GRST_HTTPS_PORT 488
220#define GRST_HTCP_PORT 777
221#define GRST_GSIFTP_PORT 2811
223#define GRSThtcpNOPop 0
224#define GRSThtcpTSTop 1
230#define GRSThtcpCountstrLen(string) (256*((string)->length_msb) + (string)->length_lsb)
262#define GRSTgaclCredGetAuri(cred) ((cred)->auri)
264#define GRSTgaclCredSetNotBefore(cred, time) ((cred)->notbefore = (time))
265#define GRSTgaclCredGetNotBefore(cred) ((cred)->notbefore)
267#define GRSTgaclCredSetNotAfter(cred, time) ((cred)->notafter = (time))
268#define GRSTgaclCredGetNotAfter(cred) ((cred)->notafter)
270#define GRSTgaclCredSetDelegation(cred, level) ((cred)->delegation = (level))
271#define GRSTgaclCredGetDelegation(cred) ((cred)->delegation)
273#define GRSTgaclCredSetNistLoa(cred, level) ((cred)->nist_loa = (level))
274#define GRSTgaclCredGetNistLoa(cred) ((cred)->nist_loa)
390#ifndef GRST_NO_OPENSSL
410#ifndef GRST_NO_OPENSSL
421 char *delegation_id,
char *user_dn,
int keysize);
425#ifndef GRST_NO_OPENSSL
433#define GRST_HEADFILE "gridsitehead.txt"
434#define GRST_FOOTFILE "gridsitefoot.txt"
435#define GRST_ADMIN_FILE "gridsite-admin.cgi"
455#ifndef GRST_NO_OPENSSL
468#ifndef GRST_PASSCODE_JS
470#define GRST_PASSCODE_JS "<script type=\"text/javascript\" language=\"Javascript\"><!--\nfunction changeValue(formName){ if( document.forms[formName].passcode.value==\"\" ) document.forms[formName].passcode.value=getCookie(\"GRIDHTTP_PASSCODE\"); return true; } \nfunction getCookie(c_name){ if (document.cookie.length>0) { c_start=document.cookie.indexOf(c_name + \"=\"); if (c_start!=-1) { c_start=c_start + c_name.length+1; c_end=document.cookie.indexOf(\";\",c_start); if (c_end==-1) c_end=document.cookie.length; return unescape(document.cookie.substring(c_start,c_end)); }} return \"\"; } \n -->\n</script>"
char * GRSTgaclPermToChar(GRSTgaclPerm)
Definition: grst_gacl.c:531
int GRSTx509IsCA(X509 *)
Check if certificate can be used as a CA to sign standard X509 certs.
Definition: grst_canl_x509.c:299
char * GRSThttpGetCGI(char *)
Definition: grst_http.c:237
int GRSTx509ProxyDestroy(char *, char *, char *)
Destroy stored GSI proxy files.
Definition: grst_canl_x509.c:2503
int GRSTx509KnownCriticalExts(X509 *)
Check critical extensions.
Definition: grst_canl_x509.c:262
char *int GRSTgaclUserLoadDNlists(GRSTgaclUser *, char *)
Definition: grst_gacl.c:1185
GRSTgaclAcl * GRSTgaclAclLoadFile(char *)
Definition: grst_gacl.c:758
int(* GRSTerrorLogFunc)(char *, int, int, char *,...)
Definition: grst_err.c:40
int GRSTgaclEntryFree(GRSTgaclEntry *)
Definition: grst_gacl.c:386
int GRSTx509CheckChain(int *, X509_STORE_CTX *)
Definition: grst_canl_x509.c:1355
int GRSTgaclEntryPrint(GRSTgaclEntry *, FILE *)
Definition: grst_gacl.c:449
int GRSTx509MakeProxyCert(char **, FILE *, char *, char *, char *, int)
Make a GSI Proxy chain from a request, certificate and private key.
Definition: grst_canl_x509.c:1768
int GRSTx509MakeProxyRequest(char **, char *, char *, char *)
Create a X.509 request for a GSI proxy and its private key.
Definition: grst_canl_x509.c:2352
int GRSTgaclEntryDelCred(GRSTgaclEntry *, GRSTgaclCred *)
Definition: grst_gacl.c:296
int GRSThtcpTSTrequestMake(char **, int *, unsigned int, char *, char *, char *)
Definition: grst_htcp.c:116
int GRSTgaclFileIsAcl(char *)
Definition: grst_gacl.c:835
int GRSTasn1SearchTaglist(struct GRSTasn1TagList taglist[], int, char *)
Definition: grst_asn1.c:119
GRSTgaclAcl * GRSTgaclAclLoadforFile(char *)
Definition: grst_gacl.c:906
int GRSThtcpNOPresponseMake(char **, int *, unsigned int)
Definition: grst_htcp.c:81
char * GRSTgaclFileFindAclname(char *)
Definition: grst_gacl.c:848
int GRSTgaclEntryAddCred(GRSTgaclEntry *, GRSTgaclCred *)
Definition: grst_gacl.c:267
int GRSTx509CacheProxy(char *, char *, char *, char *)
Store a GSI proxy chain in the proxy cache, along with the private key.
Definition: grst_canl_x509.c:2779
int GRSTgaclUserHasCred(GRSTgaclUser *, GRSTgaclCred *)
Definition: grst_gacl.c:982
int GRSTgaclEntryAllowPerm(GRSTgaclEntry *, GRSTgaclPerm)
Definition: grst_gacl.c:503
int GRSTgaclUserAddCred(GRSTgaclUser *, GRSTgaclCred *)
Definition: grst_gacl.c:959
int GRSTx509NameCmp(char *, char *)
Compare X509 Distinguished Name strings.
Definition: grst_canl_x509.c:223
int
Definition: gridsite.h:398
GRSTgaclAcl * GRSTgaclAclNew(void)
Definition: grst_gacl.c:563
GRSTgaclNamevalue
Definition: gridsite.h:123
int GRSTgaclEntryUndenyPerm(GRSTgaclEntry *, GRSTgaclPerm)
Definition: grst_gacl.c:524
int GRSTgaclCredCredPrint(GRSTgaclCred *, FILE *)
char * GRSTx509FindProxyFileName(void)
Find proxy file name of the current user.
Definition: grst_canl_x509.c:1740
int GRSTx509CreateProxyRequest(char **, char **, char *)
Create a X.509 request for a GSI proxy and its private key.
Definition: grst_canl_x509.c:2236
char * GRSThttpUrlDecode(char *)
Definition: grst_http.c:330
int GRSThtcpMessageParse(GRSThtcpMessage *, char *, int)
Definition: grst_htcp.c:233
GRSTgaclPerm GRSTgaclAclTestexclUser(GRSTgaclAcl *, GRSTgaclUser *)
Definition: grst_gacl.c:1343
int GRSTasn1ParseDump(BIO *, unsigned char *, long, struct GRSTasn1TagList taglist[], int, int *)
Definition: grst_asn1.c:457
int GRSTx509ChainFree(GRSTx509Chain *)
Definition: grst_canl_x509.c:314
char * GRSThttpUrlEncode(char *)
Definition: grst_http.c:369
int GRSTgaclAclAddEntry(GRSTgaclAcl *, GRSTgaclEntry *)
Definition: grst_gacl.c:433
int GRSTx509ProxyGetTimes(char *, char *, char *, time_t *, time_t *)
Get start and finish validity times of stored GSI proxy file.
Definition: grst_canl_x509.c:2551
int GRSTx509VerifyCallback(int, X509_STORE_CTX *)
Example VerifyCallback routine.
Definition: grst_canl_x509.c:1381
int GRSTgaclUserFree(GRSTgaclUser *)
Definition: grst_gacl.c:946
int GRSTx509CreateProxyRequestKS(char **reqtxt, char **keytxt, char *ocspurl, int keysize)
Definition: grst_canl_x509.c:2225
GRSTgaclEntry * GRSTgaclEntryNew(void)
Definition: grst_gacl.c:367
int GRSThtcpNOPrequestMake(char **, int *, unsigned int)
Definition: grst_htcp.c:47
int GRSTasn1GetX509Name(char *, int, char *, char *, struct GRSTasn1TagList taglist[], int)
Definition: grst_asn1.c:497
GRSTgaclUser * GRSTgaclUserNew(GRSTgaclCred *)
Definition: grst_gacl.c:929
int GRSThtcpTSTresponseMake(char **, int *, unsigned int, char *, char *, char *)
Definition: grst_htcp.c:165
int GRSTgaclEntryDenyPerm(GRSTgaclEntry *, GRSTgaclPerm)
Definition: grst_gacl.c:517
time_t GRSTasn1TimeToTimeT(char *, size_t)
ASN1 time string (in a char *) to time_t.
Definition: grst_asn1.c:24
int GRSTx509MakeProxyRequestKS(char **reqtxt, char *proxydir, char *delegation_id, char *user_dn, int keysize)
Definition: grst_canl_x509.c:2338
char char X509 *char * GRSTx509CachedProxyFind(char *, char *, char *)
Find a proxy file in the proxy cache.
Definition: grst_canl_x509.c:2056
int GRST_is_id_safe(const char *)
Definition: grst_canl_x509.c:2876
void GRSThttpWriteOut(GRSThttpBody *)
Definition: grst_http.c:150
int GRSTx509StringToChain(STACK_OF(X509) **, char *)
Create a stack of X509 certificate from a PEM-encoded string.
Definition: grst_canl_x509.c:2593
int GRSTgaclAclPrint(GRSTgaclAcl *, FILE *)
Definition: grst_gacl.c:591
GRSTgaclCred * GRSTgaclUserFindCredtype(GRSTgaclUser *, char *)
Definition: grst_gacl.c:1046
void GRSThttpPrintf(GRSThttpBody *, char *,...)
Definition: grst_http.c:58
char * GRSTx509MakeProxyFileName(char *, STACK_OF(X509) *)
Return the short file name for the given delegation_id and user_dn.
Definition: grst_canl_x509.c:2692
int GRSTgaclInit(void)
Definition: grst_gacl.c:77
char * GRSTx509MakeDelegationID(void)
Returns a Delegation ID based on hash of GRST_CRED_0, ...
Definition: grst_canl_x509.c:2643
char * GRSThttpUrlMildencode(char *)
Definition: grst_http.c:402
int GRSThttpPrintHeaderFooter(GRSThttpBody *, char *, char *)
Definition: grst_http.c:168
GRSTgaclCred * GRSTgaclCredCreate(char *, char *)
Definition: grst_gacl.c:97
int GRSTgaclCredFree(GRSTgaclCred *)
Definition: grst_gacl.c:223
unsigned int GRSTgaclPerm
Definition: gridsite.h:126
int GRSTgaclPermPrint(GRSTgaclPerm, FILE *)
Definition: grst_gacl.c:489
int GRSTgaclCredCmpAuri(GRSTgaclCred *, GRSTgaclCred *)
Definition: grst_gacl.c:342
int GRSTx509ChainLoad(GRSTx509Chain **chain, STACK_OF(X509) *certstack, X509 *lastcert, char *capath, char *vomsdir)
Definition: grst_canl_x509.c:1015
__attribute__((deprecated)) typedef struct
Definition: gridsite.h:120
void GRSThttpBodyInit(GRSThttpBody *)
Definition: grst_http.c:53
int GRSThttpPrintFooter(GRSThttpBody *, char *)
Definition: grst_http.c:221
int GRSTgaclAction
Definition: gridsite.h:125
int GRSTx509ChainLoadCheck(GRSTx509Chain **, STACK_OF(X509) *, X509 *, char *, char *)
Check certificate chain for GSI proxy acceptability.
Definition: grst_canl_x509.c:1323
GRSTgaclUser *int GRSTgaclUserHasAURI(GRSTgaclUser *, char *)
Definition: grst_gacl.c:1284
GRSTgaclPerm GRSTgaclAclTestUser(GRSTgaclAcl *, GRSTgaclUser *)
Definition: grst_gacl.c:1298
int GRSThttpPrintHeader(GRSThttpBody *, char *)
Definition: grst_http.c:205
GRSTgaclPerm GRSTgaclPermFromChar(char *)
Definition: grst_gacl.c:546
char * GRSTx509CachedProxyKeyFind(char *, char *, char *, STACK_OF(X509) *)
Find a temporary proxy private key file in the proxy cache.
Definition: grst_canl_x509.c:2091
int GRSTx509CertLoad(GRSTx509Cert *, X509 *)
char X509 STACK_OF(X509) *
int GRSThttpCopy(GRSThttpBody *, char *)
Definition: grst_http.c:95
int GRSTgaclAclSave(GRSTgaclAcl *, char *)
Definition: grst_gacl.c:605
int GRSTgaclAclFree(GRSTgaclAcl *)
Definition: grst_gacl.c:579
int GRSTgaclEntryUnallowPerm(GRSTgaclEntry *, GRSTgaclPerm)
Definition: grst_gacl.c:510
int GRSTx509GetVomsCreds(int *lastcred, int maxcreds, size_t credlen, char *creds, X509 *usercert, STACK_OF(X509) *certstack, char *vomsdir)
Get the VOMS attributes in the extensions to the given cert stack.
Definition: grst_canl_x509.c:1538
GRSTgaclCred * GRSTx509CompactToCred(char *grst_cred)
Turn a Compact Cred line into a GRSTgaclCred object.
Definition: grst_canl_x509.c:1596
int GRSTx509CompactCreds(int *lastcred, int maxcreds, size_t credlen, char *creds, STACK_OF(X509) *certstack, char *vomsdir, X509 *peercert)
Get the credentials in an X509 cert/GSI proxy, including any VOMS.
Definition: grst_canl_x509.c:1657
int GRSTgaclUserSetDNlists(GRSTgaclUser *user, char *dnlists)
Definition: grst_gacl.c:1076
int GRSTgaclDNlistHasUser(char *listurl, GRSTgaclUser *user)
Definition: grst_gacl.c:1279
int GRSTgaclCredAddValue(GRSTgaclCred *cred, char *name, char *rawvalue)
Definition: grst_gacl.c:160
GRSTgaclCred * GRSTgaclCredNew(char *type)
Definition: grst_gacl.c:137
Definition: gridsite.h:173
int headerlength
Definition: gridsite.h:175
int length
Definition: gridsite.h:176
char treecoords[GRST_ASN1_MAXCOORDLEN+1]
Definition: gridsite.h:173
int tag
Definition: gridsite.h:177
int start
Definition: gridsite.h:174
Definition: gridsite.h:133
GRSTgaclEntry * firstentry
Definition: gridsite.h:133
Definition: gridsite.h:112
void * next
Definition: gridsite.h:117
char * auri
Definition: gridsite.h:112
int delegation
Definition: gridsite.h:113
int nist_loa
Definition: gridsite.h:114
time_t notbefore
Definition: gridsite.h:115
time_t notafter
Definition: gridsite.h:116
Definition: gridsite.h:128
GRSTgaclCred * firstcred
Definition: gridsite.h:128
GRSTgaclPerm denied
Definition: gridsite.h:130
GRSTgaclPerm allowed
Definition: gridsite.h:129
void * next
Definition: gridsite.h:131
Definition: gridsite.h:135
char * dnlists
Definition: gridsite.h:135
Definition: gridsite.h:226
unsigned char length_lsb
Definition: gridsite.h:227
unsigned char length_msb
Definition: gridsite.h:226
Definition: gridsite.h:232
GRSThtcpCountstr * req_hdrs
Definition: gridsite.h:247
unsigned char version_lsb
Definition: gridsite.h:235
unsigned int opcode
Definition: gridsite.h:239
unsigned char total_length_lsb
Definition: gridsite.h:233
GRSThtcpCountstr * cache_hdrs
Definition: gridsite.h:250
unsigned char total_length_msb
Definition: gridsite.h:232
GRSThtcpCountstr * version
Definition: gridsite.h:246
unsigned char data_length_lsb
Definition: gridsite.h:237
unsigned int f1
Definition: gridsite.h:241
unsigned int trans_id
Definition: gridsite.h:243
unsigned int rr
Definition: gridsite.h:240
unsigned int response
Definition: gridsite.h:238
GRSThtcpCountstr * entity_hdrs
Definition: gridsite.h:249
GRSThtcpCountstr * resp_hdrs
Definition: gridsite.h:248
unsigned char data_length_msb
Definition: gridsite.h:236
GRSThtcpCountstr * method
Definition: gridsite.h:244
GRSThtcpCountstr * uri
Definition: gridsite.h:245
unsigned int reserved
Definition: gridsite.h:242
unsigned char version_msb
Definition: gridsite.h:234
Definition: gridsite.h:440
GRSThttpCharsList * last
Definition: gridsite.h:442
GRSThttpCharsList * first
Definition: gridsite.h:441
size_t size
Definition: gridsite.h:440
Definition: gridsite.h:437
char * text
Definition: gridsite.h:437
void * next
Definition: gridsite.h:438
Definition: gridsite.h:181
int type
Definition: gridsite.h:181
time_t notafter
Definition: gridsite.h:187
int errors
Definition: gridsite.h:182
char * value
Definition: gridsite.h:185
char * dn
Definition: gridsite.h:184
char * ocsp
Definition: gridsite.h:190
int delegation
Definition: gridsite.h:188
time_t notbefore
Definition: gridsite.h:186
void * next
Definition: gridsite.h:192
char * issuer
Definition: gridsite.h:183
void * raw
Definition: gridsite.h:191
Definition: gridsite.h:207
GRSTx509Cert * firstcert
Definition: gridsite.h:207