PLCnext API Documentation 23.0.2.9
IdentityStore.hpp
1
2//
3// Copyright PHOENIX CONTACT Electronics GmbH
4//
6#pragma once
8#include "Arp/System/Core/AppDomainSingleton.hxx"
9#include "Arp/System/Commons/Logging.h"
10#include "Arp/System/Commons/Io/Path.hpp"
11#include "Arp/System/Commons/Security/KeyPair.hpp"
12#include "Arp/System/Commons/Security/Certificate.hpp"
13#include "Arp/System/Commons/Security/SecurityListType.hpp"
14#include "Arp/System/Commons/Security/ItemInfo.hpp"
15#include "Arp/System/Commons/Security/KeyPairType.hpp"
16#include "Arp/System/Commons/Security/SecurityConfigurationError.hpp"
17#include <map>
18#include <vector>
19#include <openssl/evp.h>
20
21namespace Arp { namespace System { namespace Commons { namespace Security
22{
23
26class IdentityStore : private Loggable<IdentityStore>
27{
28public: // type definitions
29 enum KeyMustExist : bool
30 {
31 IgnoreMissingKey = false,
32 RequireKeyExists = true
33 };
34
35public: // construction/destruction
37 IdentityStore(const String& basePath, const String& name, KeyMustExist requireKeyExists = RequireKeyExists);
39 IdentityStore(const IdentityStore& arg) = delete;
41 IdentityStore& operator=(const IdentityStore& arg) = delete;
43 ~IdentityStore(void) = default;
44
45public: // operators
46
47public: // static operations
48
49public: // setter/getter operations
51 String GetName(void) const;
55 String GetFullKeyFileName(void) const;
57 String GetFullTpmKeyFileName(void) const;
59 bool HasCertificate(void);
61 const std::shared_ptr<KeyPair>& GetKeyPair(void);
63 KeyPairType GetKeyType(void);
64
65public: // operations
68 void InitSslContext(SSL_CTX* pSslCtx)const;
69
72 std::vector<byte> GetPublicKey(void);
73
77 SecurityConfigurationError SetKeyPair(const std::vector<byte>& pemData);
78
82 SecurityConfigurationError SetCertificate(const std::vector<byte>& pemData);
83
86 std::vector<byte> GetPemCertificate(void);
87
90 std::vector<byte> GetDerCertificate(void);
91
94 std::vector<byte> GetPemCertificateWithChain(void);
95
98 std::vector<byte> GetDerCertificateWithChain(void);
99
101 std::vector<std::vector<byte>> GetIssuerPemCertificates(void);
102
105
107
109 SecurityConfigurationError ListContent(SecurityListType type, std::vector<ItemInfo>& result);
110
112
114 SecurityConfigurationError AddElement(SecurityListType type, const std::vector<byte>& pemData);
115
117
119 SecurityConfigurationError DeleteElement(SecurityListType type, const String& identifier);
120
122
124 SecurityConfigurationError GenerateKeyPair(KeyPairType type);
125
128 std::vector<byte> GenerateCSR();
129
132 bool VerifyCertMatchesWithPrivateKey(void);
133
134protected: // operations
135
136private: // static methods
137
138private: // methods
139 void loadKeyPair(KeyMustExist requireKeyExists);
140 bool LoadSoftwareKeyPair();
141 bool LoadHardwareKeyPair();
142 void loadCertWithChain(const String& file);
143 void listIssuerList(std::vector<ItemInfo>& result);
144 void listIdentityCert(std::vector<ItemInfo>& result);
145
146 void save(void);
147
148private: // fields
149 String storePath;
150
151 std::shared_ptr<KeyPair> keyPair;
152 Certificate cert;
153 std::vector<Certificate> issuers;
154
155private: // static fields
156
157 static const String CertificateFileName;
158 static const String KeyFileName;
159 static const String TpmKeyFileName;
160 static const String DirectorySeparator;
161};
162
164// inline methods of class CertificateStore
165
167{
168 return Io::Path::GetFileName(this->storePath);
169}
170
172{
173 return this->storePath + DirectorySeparator + CertificateFileName;
174}
175
177{
178 return this->storePath + DirectorySeparator + KeyFileName;
179}
180
182{
183 return this->storePath + DirectorySeparator + TpmKeyFileName;
184}
185
186inline KeyPairType IdentityStore::GetKeyType(void)
187{
188 return this->keyPair->GetKeyType();
189}
190
191}}}} // end of namespace Arp::System::Commons::Security
Class to handle x.509 certificates
Definition: Certificate.hpp:26
Class with represents a Identity (Certificate with Chain and private Key) and is able to initialze an...
Definition: IdentityStore.hpp:27
void CreateAllDirectories(void)
summary>list all elements in the list referenced by ListType
const std::shared_ptr< KeyPair > & GetKeyPair(void)
summary>Returns the type of the key pair
String GetName(void) const
Returns the name of the IdentityStore
Definition: IdentityStore.hpp:166
SecurityConfigurationError GenerateKeyPair(KeyPairType type)
SecurityConfigurationError DeleteElement(SecurityListType type, const String &identifier)
summary>Generate a new KeyPair for this IdentityStore
SecurityConfigurationError SetKeyPair(const std::vector< byte > &pemData)
IdentityStore(const IdentityStore &arg)=delete
Copy constructor.
SecurityConfigurationError AddElement(SecurityListType type, const std::vector< byte > &pemData)
summary>delete an elements from the list referenced by ListType, identified by identifier
std::vector< byte > GetPemCertificateWithChain(void)
std::vector< byte > GetDerCertificateWithChain(void)
summary>get the issuer certificates in PEM format
void InitSslContext(SSL_CTX *pSslCtx) const
Initializes a OpenSSL SSL_:CTX Structure with the private key and certificate
String GetFullTpmKeyFileName(void) const
summary>checks if a certificate is available for this IdentityStore
Definition: IdentityStore.hpp:181
std::vector< byte > GetPemCertificate(void)
SecurityConfigurationError SetCertificate(const std::vector< byte > &pemData)
String GetFullCertificateFileName(void) const
summary>Returns the absolute path to the key file
Definition: IdentityStore.hpp:171
IdentityStore & operator=(const IdentityStore &arg)=delete
Assignment operator.
std::vector< std::vector< byte > > GetIssuerPemCertificates(void)
summary>creates all needed directories inside the folder of this IdentityStore
SecurityConfigurationError ListContent(SecurityListType type, std::vector< ItemInfo > &result)
summary>add an element into the list referenced by ListType
std::vector< byte > GetDerCertificate(void)
~IdentityStore(void)=default
Destructs this instance and frees all resources.
IdentityStore(const String &basePath, const String &name, KeyMustExist requireKeyExists=RequireKeyExists)
Constructs an IdentityStore instance.
String GetFullKeyFileName(void) const
summary>Returns the absolute path to the tpm key file
Definition: IdentityStore.hpp:176
@ System
System components used by the System, Device, Plc or Io domains.
Root namespace for the PLCnext API