File: verifier.h

package info (click to toggle)
golang-github-google-certificate-transparency 0.0~git20160709.0.0f6e3d1~ds1-3
  • links: PTS, VCS
  • area: main
  • in suites: bookworm, bullseye, buster
  • size: 5,676 kB
  • sloc: cpp: 35,278; python: 11,838; java: 1,911; sh: 1,885; makefile: 950; xml: 520; ansic: 225
file content (53 lines) | stat: -rw-r--r-- 1,199 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
// A base class for verifying signatures of unstructured data.  This class is
// mockable.

#ifndef CERT_TRANS_LOG_VERIFIER_H_
#define CERT_TRANS_LOG_VERIFIER_H_

#include <openssl/evp.h>
#include <openssl/x509.h>  // for i2d_PUBKEY
#include <stdint.h>

#include "base/macros.h"
#include "proto/ct.pb.h"
#include "util/openssl_scoped_types.h"

namespace cert_trans {

class Verifier {
 public:
  enum Status {
    OK,
    HASH_ALGORITHM_MISMATCH,
    SIGNATURE_ALGORITHM_MISMATCH,
    INVALID_SIGNATURE,
  };

  explicit Verifier(EVP_PKEY* pkey);
  virtual ~Verifier() = default;

  virtual std::string KeyID() const;

  virtual Status Verify(const std::string& input,
                        const ct::DigitallySigned& signature) const;

  static std::string ComputeKeyID(EVP_PKEY* pkey);

 protected:
  // A constructor for mocking.
  Verifier();

 private:
  bool RawVerify(const std::string& data, const std::string& sig_string) const;

  ScopedEVP_PKEY pkey_;
  ct::DigitallySigned::HashAlgorithm hash_algo_;
  ct::DigitallySigned::SignatureAlgorithm sig_algo_;
  std::string key_id_;

  DISALLOW_COPY_AND_ASSIGN(Verifier);
};

}  // namespace cert_trans

#endif  // CERT_TRANS_LOG_VERIFIER_H_