Kea 3.3.3
tsig.h
Go to the documentation of this file.
1// Copyright (C) 2011-2026 Internet Systems Consortium, Inc. ("ISC")
2//
3// This Source Code Form is subject to the terms of the Mozilla Public
4// License, v. 2.0. If a copy of the MPL was not distributed with this
5// file, You can obtain one at http://mozilla.org/MPL/2.0/.
6
7// IMPORTANT: the server side of this code MUST NOT be used until
8// it was fixed, cf RFC 8945. Note that Kea uses only the client side.
9
10#ifndef TSIG_H
11#define TSIG_H
12
13#include <dns/tsigerror.h>
14#include <dns/tsigkey.h>
15#include <dns/tsigrecord.h>
17
18#include <cstdint>
19
20#include <boost/noncopyable.hpp>
21#include <boost/shared_ptr.hpp>
22
23namespace isc {
24namespace dns {
25
33public:
34 TSIGContextError(const char* file, size_t line, const char* what) :
35 isc::Exception(file, line, what) {}
36};
37
172class TSIGContext : boost::noncopyable {
173public:
189
192
193
198 explicit TSIGContext(const TSIGKey& key);
199
201 TSIGContext(const Name& key_name, const Name& algorithm_name,
202 const TSIGKeyRing& keyring);
203
205 virtual ~TSIGContext();
207
264 virtual ConstTSIGRecordPtr
265 sign(const uint16_t qid, const void* const data, const size_t data_len);
266
354 virtual TSIGError
355 verify(const TSIGRecord* const record, const void* const data, const size_t data_len);
356
368 virtual bool lastHadSignature() const;
369
389 virtual size_t getTSIGLength() const;
390
398 virtual State getState() const;
399
406 virtual TSIGError getError() const;
407
410
411
415 static const uint16_t DEFAULT_FUDGE = 300;
417
418protected:
429 void update(const void* const data, size_t len);
430
431private:
432 struct TSIGContextImpl;
433 boost::shared_ptr<TSIGContextImpl> impl_;
434};
435
436typedef boost::shared_ptr<TSIGContext> TSIGContextPtr;
437typedef boost::shared_ptr<TSIGKey> TSIGKeyPtr;
438
439}
440}
441
442#endif // TSIG_H
This is a base class for exceptions thrown from the DNS library module.
Exception(const char *file, size_t line, const char *what)
Constructor for a given type for exceptions with file name and file line number.
virtual const char * what() const
Returns a C-style character string of the cause of the exception.
The Name class encapsulates DNS names.
Definition name.h:217
TSIGContextError(const char *file, size_t line, const char *what)
Definition tsig.h:34
virtual ConstTSIGRecordPtr sign(const uint16_t qid, const void *const data, const size_t data_len)
Sign a DNS message.
Definition tsig.cc:336
static const uint16_t DEFAULT_FUDGE
The recommended fudge value (in seconds) by RFC2845.
Definition tsig.h:415
virtual TSIGError getError() const
Return the TSIG error as a result of the latest verification.
Definition tsig.cc:331
virtual size_t getTSIGLength() const
Return the expected length of TSIG RR after sign().
Definition tsig.cc:287
virtual ~TSIGContext()
The destructor.
Definition tsig.cc:283
void update(const void *const data, size_t len)
Update internal HMAC state by more data.
Definition tsig.cc:566
TSIGContext(const TSIGKey &key)
Constructor from a TSIG key.
Definition tsig.cc:264
virtual TSIGError verify(const TSIGRecord *const record, const void *const data, const size_t data_len)
Verify a DNS message.
Definition tsig.cc:419
virtual State getState() const
Return the current state of the context.
Definition tsig.cc:326
virtual bool lastHadSignature() const
Check whether the last verified message was signed.
Definition tsig.cc:558
State
Internal state of context.
Definition tsig.h:182
@ RECEIVED_REQUEST
Server received a signed request.
Definition tsig.h:185
@ SENT_REQUEST
Client sent a signed request, waiting response.
Definition tsig.h:184
@ SENT_RESPONSE
Server sent a signed response.
Definition tsig.h:186
@ VERIFIED_RESPONSE
Client successfully verified a response.
Definition tsig.h:187
@ INIT
Initial state.
Definition tsig.h:183
TSIG errors.
Definition tsigerror.h:23
A simple repository of a set of TSIGKey objects.
Definition tsigkey.h:247
TSIG key.
Definition tsigkey.h:58
TSIG resource record.
Definition tsigrecord.h:51
boost::shared_ptr< TSIGContext > TSIGContextPtr
Definition tsig.h:436
boost::shared_ptr< const TSIGRecord > ConstTSIGRecordPtr
A pointer-like type pointing to an immutable TSIGRecord object.
Definition tsigrecord.h:283
boost::shared_ptr< TSIGKey > TSIGKeyPtr
Definition tsig.h:437
Defines the logger used by the top-level component of kea-lfc.