LibreOffice Module xmlsecurity (master) 1
securityenvironment_nssimpl.hxx
Go to the documentation of this file.
1/* -*- Mode: C++; tab-width: 4; indent-tabs-mode: nil; c-basic-offset: 4 -*- */
2/*
3 * This file is part of the LibreOffice project.
4 *
5 * This Source Code Form is subject to the terms of the Mozilla Public
6 * License, v. 2.0. If a copy of the MPL was not distributed with this
7 * file, You can obtain one at http://mozilla.org/MPL/2.0/.
8 *
9 * This file incorporates work covered by the following license notice:
10 *
11 * Licensed to the Apache Software Foundation (ASF) under one or more
12 * contributor license agreements. See the NOTICE file distributed
13 * with this work for additional information regarding copyright
14 * ownership. The ASF licenses this file to you under the Apache
15 * License, Version 2.0 (the "License"); you may not use this file
16 * except in compliance with the License. You may obtain a copy of
17 * the License at http://www.apache.org/licenses/LICENSE-2.0 .
18 */
19
20#pragma once
21
22#include <sal/config.h>
23#include <rtl/ustring.hxx>
24#include <rtl/ref.hxx>
26
27#include <com/sun/star/uno/Reference.hxx>
28
29#include <com/sun/star/lang/XServiceInfo.hpp>
30#include <com/sun/star/xml/crypto/XSecurityEnvironment.hpp>
31#include <com/sun/star/xml/crypto/XCertificateCreator.hpp>
32
33#include <mutex>
34
35#include <keythi.h>
36#include <certt.h>
37
38#include <string_view>
39#include <vector>
40
41#include <xmlsec-wrapper.h>
42
43namespace com::sun::star::security { class XCertificate; }
45
46class SecurityEnvironment_NssImpl : public ::cppu::WeakImplHelper<
47 css::xml::crypto::XSecurityEnvironment,
48 css::xml::crypto::XCertificateCreator,
49 css::lang::XServiceInfo >
50{
51private:
52
53 std::vector< PK11SlotInfo* > m_Slots;
55 css::uno::Reference<css::security::XCertificate> m_xSigningCertificate;
56
57 std::mutex m_mutex;
58
59 CERTCertDBHandle* m_pHandler ;
60 std::vector< PK11SymKey* > m_tSymKeyList ;
61
62 public:
64 virtual ~SecurityEnvironment_NssImpl() override;
65
66 //Methods from XSecurityEnvironment
67
68 //Methods from XServiceInfo
69 virtual OUString SAL_CALL getImplementationName() override ;
70
71 virtual sal_Bool SAL_CALL supportsService(
72 const OUString& ServiceName
73 ) override ;
74
75 virtual css::uno::Sequence< OUString > SAL_CALL getSupportedServiceNames() override ;
76
77 virtual ::sal_Int32 SAL_CALL verifyCertificate(
78 const css::uno::Reference<
79 css::security::XCertificate >& xCert,
80 const css::uno::Sequence<
81 css::uno::Reference< css::security::XCertificate > > &
82 intermediateCerts) override ;
83
84 virtual ::sal_Int32 SAL_CALL getCertificateCharacters( const css::uno::Reference< css::security::XCertificate >& xCert ) override ;
85
86 virtual OUString SAL_CALL getSecurityEnvironmentInformation( ) override;
87
90 void setCertDb( CERTCertDBHandle* aCertDb ) ;
91
94 void adoptSymKey( PK11SymKey* aSymKey ) ;
95
96 virtual css::uno::Sequence< css::uno::Reference< css::security::XCertificate > > SAL_CALL getPersonalCertificates() override ;
97 virtual css::uno::Sequence< css::uno::Reference< css::security::XCertificate > > SAL_CALL getAllCertificates() override
98 { return css::uno::Sequence< css::uno::Reference< css::security::XCertificate > >(); }
99
100 virtual css::uno::Reference< css::security::XCertificate > SAL_CALL getCertificate( const OUString& issuerName, const css::uno::Sequence< sal_Int8 >& serialNumber ) override ;
101
102 virtual css::uno::Sequence< css::uno::Reference< css::security::XCertificate > > SAL_CALL buildCertificatePath( const css::uno::Reference< css::security::XCertificate >& beginCert ) override ;
103
104 virtual css::uno::Reference< css::security::XCertificate > SAL_CALL createCertificateFromRaw( const css::uno::Sequence< sal_Int8 >& rawCertificate ) override ;
105 virtual css::uno::Reference< css::security::XCertificate > SAL_CALL createCertificateFromAscii( const OUString& asciiCertificate ) override ;
106
107 // Methods of XCertificateCreator
108 css::uno::Reference<css::security::XCertificate> SAL_CALL addDERCertificateToTheDatabase(
109 css::uno::Sequence<sal_Int8> const & raDERCertificate,
110 OUString const & raTrustString) override;
111
112 css::uno::Reference<css::security::XCertificate> SAL_CALL createDERCertificateWithPrivateKey(
113 css::uno::Sequence<sal_Int8> const & raDERCertificate,
114 css::uno::Sequence<sal_Int8> const & raPrivateKey) override;
115
116 //Native methods
118 xmlSecKeysMngrPtr createKeysManager() ;
121 static void destroyKeysManager(xmlSecKeysMngrPtr pKeysMngr) ;
122
123private:
124
125 void updateSlots();
126
128 const css::uno::Sequence<sal_Int8>& raDerCertificate,
129 std::u16string_view raString);
130 static SECKEYPrivateKey* insertPrivateKey(css::uno::Sequence<sal_Int8> const & raPrivateKey);
131
132 static rtl::Reference<X509Certificate_NssImpl> createX509CertificateFromDER(const css::uno::Sequence<sal_Int8>& raDerCertificate);
133
136 void addCryptoSlot( PK11SlotInfo* aSlot ) ;
137} ;
138
139/* vim:set shiftwidth=4 softtabstop=4 expandtab: */
css::uno::Reference< css::security::XCertificate > SAL_CALL addDERCertificateToTheDatabase(css::uno::Sequence< sal_Int8 > const &raDERCertificate, OUString const &raTrustString) override
css::uno::Reference< css::security::XCertificate > SAL_CALL createDERCertificateWithPrivateKey(css::uno::Sequence< sal_Int8 > const &raDERCertificate, css::uno::Sequence< sal_Int8 > const &raPrivateKey) override
virtual css::uno::Sequence< css::uno::Reference< css::security::XCertificate > > SAL_CALL getPersonalCertificates() override
virtual css::uno::Reference< css::security::XCertificate > SAL_CALL createCertificateFromAscii(const OUString &asciiCertificate) override
virtual css::uno::Sequence< OUString > SAL_CALL getSupportedServiceNames() override
virtual css::uno::Sequence< css::uno::Reference< css::security::XCertificate > > SAL_CALL buildCertificatePath(const css::uno::Reference< css::security::XCertificate > &beginCert) override
static rtl::Reference< X509Certificate_NssImpl > createX509CertificateFromDER(const css::uno::Sequence< sal_Int8 > &raDerCertificate)
static void destroyKeysManager(xmlSecKeysMngrPtr pKeysMngr)
static rtl::Reference< X509Certificate_NssImpl > createAndAddCertificateFromPackage(const css::uno::Sequence< sal_Int8 > &raDerCertificate, std::u16string_view raString)
static SECKEYPrivateKey * insertPrivateKey(css::uno::Sequence< sal_Int8 > const &raPrivateKey)
virtual css::uno::Reference< css::security::XCertificate > SAL_CALL createCertificateFromRaw(const css::uno::Sequence< sal_Int8 > &rawCertificate) override
virtual css::uno::Sequence< css::uno::Reference< css::security::XCertificate > > SAL_CALL getAllCertificates() override
css::uno::Reference< css::security::XCertificate > m_xSigningCertificate
The last used certificate which has the private key for signing.
virtual ::sal_Int32 SAL_CALL verifyCertificate(const css::uno::Reference< css::security::XCertificate > &xCert, const css::uno::Sequence< css::uno::Reference< css::security::XCertificate > > &intermediateCerts) override
std::vector< PK11SymKey * > m_tSymKeyList
virtual OUString SAL_CALL getImplementationName() override
virtual css::uno::Reference< css::security::XCertificate > SAL_CALL getCertificate(const OUString &issuerName, const css::uno::Sequence< sal_Int8 > &serialNumber) override
std::vector< PK11SlotInfo * > m_Slots
void setCertDb(CERTCertDBHandle *aCertDb)
virtual sal_Bool SAL_CALL supportsService(const OUString &ServiceName) override
virtual ::sal_Int32 SAL_CALL getCertificateCharacters(const css::uno::Reference< css::security::XCertificate > &xCert) override
virtual OUString SAL_CALL getSecurityEnvironmentInformation() override
unsigned char sal_Bool