Botan 3.10.0
Crypto and TLS for C&
certstor_sql.h
Go to the documentation of this file.
1/*
2* Certificate Store in SQL
3* (C) 2016 Kai Michaelis, Rohde & Schwarz Cybersecurity
4*
5* Botan is released under the Simplified BSD License (see license.txt)
6*/
7
8#ifndef BOTAN_CERT_STORE_SQL_H_
9#define BOTAN_CERT_STORE_SQL_H_
10
11#include <botan/certstor.h>
12#include <botan/database.h>
13#include <botan/x509_crl.h>
14#include <botan/x509cert.h>
15
16namespace Botan {
17
18class Private_Key;
20
21/**
22 * Certificate and private key store backed by an SQL database.
23 */
25 public:
26 /**
27 * Create/open a certificate store.
28 * @param db underlying database storage
29 * @param passwd password to encrypt private keys in the database
30 * @param rng used for encrypting keys
31 * @param table_prefix optional prefix for db table names
32 */
33 explicit Certificate_Store_In_SQL(std::shared_ptr<SQL_Database> db,
34 std::string_view passwd,
36 std::string_view table_prefix = "");
37
38 /**
39 * Returns the first certificate with matching subject DN and optional key ID.
40 */
41 std::optional<X509_Certificate> find_cert(const X509_DN& subject_dn,
42 const std::vector<uint8_t>& key_id) const override;
43
44 /*
45 * Find all certificates with a given Subject DN.
46 * Subject DN and even the key identifier might not be unique.
47 */
48 std::vector<X509_Certificate> find_all_certs(const X509_DN& subject_dn,
49 const std::vector<uint8_t>& key_id) const override;
50
51 std::optional<X509_Certificate> find_cert_by_pubkey_sha1(const std::vector<uint8_t>& key_hash) const override;
52
53 std::optional<X509_Certificate> find_cert_by_raw_subject_dn_sha256(
54 const std::vector<uint8_t>& subject_hash) const override;
55
56 std::optional<X509_Certificate> find_cert_by_issuer_dn_and_serial_number(
57 const X509_DN& issuer_dn, std::span<const uint8_t> serial_number) const override;
58
59 /**
60 * Returns all subject DNs known to the store instance.
61 */
62 std::vector<X509_DN> all_subjects() const override;
63
64 /**
65 * Inserts "cert" into the store, returns false if the certificate is
66 * already known and true if insertion was successful.
67 */
68 bool insert_cert(const X509_Certificate& cert);
69
70 /**
71 * Removes "cert" from the store. Returns false if the certificate could not
72 * be found and true if removal was successful.
73 */
74 bool remove_cert(const X509_Certificate& cert);
75
76 /// Returns the private key for "cert" or an empty shared_ptr if none was found.
77 std::shared_ptr<const Private_Key> find_key(const X509_Certificate& cert) const;
78
79 /// Returns all certificates for private key "key".
80 std::vector<X509_Certificate> find_certs_for_key(const Private_Key& key) const;
81
82 /**
83 * Inserts "key" for "cert" into the store, returns false if the key is
84 * already known and true if insertion was successful.
85 */
86 bool insert_key(const X509_Certificate& cert, const Private_Key& key);
87
88 /// Removes "key" from the store.
89 void remove_key(const Private_Key& key);
90
91 /// Marks "cert" as revoked starting from "time".
92 void revoke_cert(const X509_Certificate& cert, CRL_Code reason, const X509_Time& time = X509_Time());
93
94 /// Reverses the revocation for "cert".
95 void affirm_cert(const X509_Certificate& cert);
96
97 /**
98 * Generates Certificate Revocation Lists for all certificates marked as revoked.
99 * A CRL is returned for each unique issuer DN.
100 */
101 std::vector<X509_CRL> generate_crls() const;
102
103 /**
104 * Generates a CRL for all certificates issued by the given issuer.
105 */
106 std::optional<X509_CRL> find_crl_for(const X509_Certificate& issuer) const override;
107
108 private:
110 std::shared_ptr<SQL_Database> m_database;
111 std::string m_prefix;
112 std::string m_password;
113};
114
115} // namespace Botan
116#endif
#define BOTAN_PUBLIC_API(maj, min)
Definition api.h:21
std::optional< X509_Certificate > find_cert_by_issuer_dn_and_serial_number(const X509_DN &issuer_dn, std::span< const uint8_t > serial_number) const override
std::vector< X509_DN > all_subjects() const override
bool insert_cert(const X509_Certificate &cert)
std::vector< X509_Certificate > find_all_certs(const X509_DN &subject_dn, const std::vector< uint8_t > &key_id) const override
std::optional< X509_Certificate > find_cert_by_raw_subject_dn_sha256(const std::vector< uint8_t > &subject_hash) const override
std::optional< X509_CRL > find_crl_for(const X509_Certificate &issuer) const override
void revoke_cert(const X509_Certificate &cert, CRL_Code reason, const X509_Time &time=X509_Time())
Marks "cert" as revoked starting from "time".
Certificate_Store_In_SQL(std::shared_ptr< SQL_Database > db, std::string_view passwd, RandomNumberGenerator &rng, std::string_view table_prefix="")
std::vector< X509_Certificate > find_certs_for_key(const Private_Key &key) const
Returns all certificates for private key "key".
void affirm_cert(const X509_Certificate &cert)
Reverses the revocation for "cert".
bool remove_cert(const X509_Certificate &cert)
std::shared_ptr< const Private_Key > find_key(const X509_Certificate &cert) const
Returns the private key for "cert" or an empty shared_ptr if none was found.
std::optional< X509_Certificate > find_cert(const X509_DN &subject_dn, const std::vector< uint8_t > &key_id) const override
void remove_key(const Private_Key &key)
Removes "key" from the store.
bool insert_key(const X509_Certificate &cert, const Private_Key &key)
std::optional< X509_Certificate > find_cert_by_pubkey_sha1(const std::vector< uint8_t > &key_hash) const override
std::vector< X509_CRL > generate_crls() const
ASN1_Time X509_Time
Definition asn1_obj.h:424