+/* fides.h - Light-weight, decentralised trust and authorisation management
+ Copyright (C) 2008-2009 Guus Sliepen <guus@tinc-vpn.org>
+
+ Fides is free software; you can redistribute it and/or modify
+ it under the terms of the GNU Lesser General Public License as
+ published by the Free Software Foundation; either version 2.1 of
+ the License, or (at your option) any later version.
+
+ Fides is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ GNU Lesser General Public License for more details.
+
+ You should have received a copy of the GNU Lesser General Public
+ License along with this program; if not, see <http://www.gnu.org/licenses/>.
+*/
+
#ifndef __FIDES_H__
#define __FIDES_H__
#include <stdexcept>
-#include <regex.h>
-#include <botan/botan.h>
#include <sys/time.h>
#include <map>
+#include <vector>
-class fides {
- std::string homedir;
- std::string certdir;
- std::string obsoletedir;
- std::string keydir;
-
- bool firstrun;
- struct timeval latest;
- static Botan::AutoSeeded_RNG rng;
-
- public:
- // Utility functions
-
- static std::string b64encode(const std::string &in);
- static std::string b64decode(const std::string &in);
- static std::string hexencode(const std::string &in);
- static std::string hexdecode(const std::string &in);
-
- class regexp {
- regex_t comp;
-
- public:
- static const int EXTENDED = REG_EXTENDED;
- static const int ICASE = REG_ICASE;
- static const int NOSUB = REG_NOSUB;
- static const int NEWLINE = REG_NEWLINE;
-
- static const int NOTBOL = REG_NOTBOL;
- static const int NOTEAL = REG_NOTEOL;
-
- regexp(const std::string &exp, int cflags = 0) {
- int err = regcomp(&comp, exp.c_str(), cflags | NOSUB);
- if(err)
- throw exception("Could not compile regular expression");
- }
-
- ~regexp() {
- regfree(&comp);
- }
-
- bool match(const std::string &in, int eflags = 0) {
- return regexec(&comp, in.c_str(), 0, 0, eflags) == 0;
- }
- };
-
- // Exception class
+#include "certificate.h"
+#include "publickey.h"
+#include "privatekey.h"
+#include "utility.h"
+namespace Fides {
class exception: public std::runtime_error {
- public:
- exception(const std::string reason): runtime_error(reason) {}
- };
-
- // Objects manipulated by fides
-
- class publickey {
- protected:
- Botan::ECDSA_PublicKey *pub;
-
public:
- publickey();
- ~publickey();
-
- int trust;
- void load(std::istream &in);
- void save(std::ostream &out);
- void load(const std::string &filename);
- void save(const std::string &filename);
- bool verify(const std::string &data, const std::string &signature);
- std::string to_string();
- void from_string(const std::string &in);
- std::string fingerprint(unsigned int bits = 64);
+ exception(const std::string reason): runtime_error(reason) {}
};
- class privatekey: public publickey {
- Botan::ECDSA_PrivateKey *priv;
-
- public:
- privatekey();
- ~privatekey();
-
- void load_private(std::istream &in);
- void save_private(std::ostream &out);
- void load_private(const std::string &filename);
- void save_private(const std::string &filename);
- void generate(const std::string &field);
- void generate(unsigned int bits = 224);
- std::string sign(const std::string &data);
- };
+ class Manager {
+ std::string homedir;
+ std::string certdir;
+ std::string obsoletedir;
+ std::string keydir;
- class certificate {
- friend class fides;
- publickey *signer;
- struct timeval timestamp;
- std::string statement;
- std::string signature;
+ bool firstrun;
+ struct timeval latest;
- public:
- certificate(publickey *pub, struct timeval timestamp, const std::string &statement, const std::string &signature);
- certificate(privatekey *priv, struct timeval timestamp, const std::string &statement);
+ private:
+ PrivateKey mykey;
+ std::map<std::string, PublicKey *> keys;
+ std::map<std::string, Certificate *> certs;
- std::string to_string() const;
- std::string fingerprint(unsigned int bits = 64);
- bool validate();
- };
+ void merge(Certificate *cert);
+ void merge(PublicKey *key);
- // Fides class itself
-
- private:
- privatekey mykey;
- std::map<std::string, publickey *> keys;
- std::map<std::string, certificate *> certs;
- std::set<publickey *> trustedkeys;
-
- void merge(certificate *cert);
- void merge(publickey *key);
-
- public:
- fides(const std::string &homedir = "");
- ~fides();
+ public:
+ Manager(const std::string &homedir = "");
+ ~Manager();
- bool is_firstrun();
- bool fsck();
- std::string get_homedir();
+ bool is_firstrun() const;
+ bool fsck() const;
+ std::string get_homedir() const;
- void sign(const std::string &statement);
+ void sign(const std::string &statement);
- void allow(const std::string &statement, publickey *key = 0);
- void dontcare(const std::string &statement, publickey *key = 0);
- void deny(const std::string &statement, publickey *key = 0);
- bool is_allowed(const std::string &statement, publickey *key = 0);
- bool is_denied(const std::string &statement, publickey *key = 0);
+ void allow(const std::string &statement, const PublicKey *key = 0);
+ void dontcare(const std::string &statement, const PublicKey *key = 0);
+ void deny(const std::string &statement, const PublicKey *key = 0);
+ bool is_allowed(const std::string &statement, const PublicKey *key = 0) const;
+ bool is_denied(const std::string &statement, const PublicKey *key = 0) const;
- void auth_stats(const std::string &statement, int &self, int &trusted, int &all);
- void trust(publickey *key);
- void dctrust(publickey *key);
- void distrust(publickey *key);
- bool is_trusted(publickey *key);
- bool is_distrusted(publickey *key);
- publickey *find_key(const std::string &fingerprint);
- void update_trust();
+ void auth_stats(const std::string &statement, int &self, int &trusted, int &all) const;
+ void trust(const PublicKey *key);
+ void dctrust(const PublicKey *key);
+ void distrust(const PublicKey *key);
+ bool is_trusted(const PublicKey *key) const;
+ bool is_distrusted(const PublicKey *key) const;
+ PublicKey *find_key(const std::string &fingerprint) const;
+ void update_trust();
- std::vector<certificate *> find_certificates(publickey *key, const std::string &statement);
- std::vector<certificate *> find_certificates(const std::string &statement);
- std::vector<certificate *> find_certificates(publickey *key);
+ std::vector<const Certificate *> find_certificates(const PublicKey *key, const std::string &statement) const;
+ std::vector<const Certificate *> find_certificates(const std::string &statement) const;
+ std::vector<const Certificate *> find_certificates(const PublicKey *key) const;
- certificate *import_certificate(const std::string &certificate);
- std::string export_certificate(const certificate *);
+ const Certificate *import_certificate(const std::string &Certificate);
+ std::string export_certificate(const Certificate *) const;
- publickey *import_key(const std::string &key);
- std::string export_key(const publickey *key);
+ const PublicKey *import_key(const std::string &key);
+ std::string export_key(const PublicKey *key) const;
- void import_all(std::istream &in);
- void export_all(std::ostream &out);
+ void import_all(std::istream &in);
+ void export_all(std::ostream &out) const;
- certificate *certificate_from_string(const std::string &certificate);
- certificate *certificate_load(const std::string &filename);
- void certificate_save(const certificate *cert, const std::string &filename);
+ Certificate *certificate_from_string(const std::string &Certificate);
+ Certificate *certificate_load(const std::string &filename);
+ void certificate_save(const Certificate *cert, const std::string &filename) const;
-};
+ };
+}
#endif