use crate::context::Function;
use crate::error::{Result, Rv};
use crate::mechanism::Mechanism;
use crate::object::ObjectHandle;
use crate::session::Session;
use cryptoki_sys::*;
use std::convert::TryInto;
impl Session {
pub fn sign(&self, mechanism: &Mechanism, key: ObjectHandle, data: &[u8]) -> Result<Vec<u8>> {
let mut mechanism: CK_MECHANISM = mechanism.into();
let mut signature_len = 0;
unsafe {
Rv::from(get_pkcs11!(self.client(), C_SignInit)(
self.handle(),
&mut mechanism as CK_MECHANISM_PTR,
key.handle(),
))
.into_result(Function::SignInit)?;
}
unsafe {
Rv::from(get_pkcs11!(self.client(), C_Sign)(
self.handle(),
data.as_ptr() as *mut u8,
data.len().try_into()?,
std::ptr::null_mut(),
&mut signature_len,
))
.into_result(Function::Sign)?;
}
let mut signature = vec![0; signature_len.try_into()?];
unsafe {
Rv::from(get_pkcs11!(self.client(), C_Sign)(
self.handle(),
data.as_ptr() as *mut u8,
data.len().try_into()?,
signature.as_mut_ptr(),
&mut signature_len,
))
.into_result(Function::Sign)?;
}
signature.truncate(signature_len.try_into()?);
Ok(signature)
}
pub fn sign_init(&self, mechanism: &Mechanism, key: ObjectHandle) -> Result<()> {
let mut mechanism: CK_MECHANISM = mechanism.into();
unsafe {
Rv::from(get_pkcs11!(self.client(), C_SignInit)(
self.handle(),
&mut mechanism as CK_MECHANISM_PTR,
key.handle(),
))
.into_result(Function::SignInit)?;
}
Ok(())
}
pub fn sign_update(&self, data: &[u8]) -> Result<()> {
unsafe {
Rv::from(get_pkcs11!(self.client(), C_SignUpdate)(
self.handle(),
data.as_ptr() as *mut u8,
data.len().try_into()?,
))
.into_result(Function::SignUpdate)?;
}
Ok(())
}
pub fn sign_final(&self) -> Result<Vec<u8>> {
let mut signature_len = 0;
unsafe {
Rv::from(get_pkcs11!(self.client(), C_SignFinal)(
self.handle(),
std::ptr::null_mut(),
&mut signature_len,
))
.into_result(Function::SignFinal)?;
}
let mut signature = vec![0; signature_len.try_into()?];
unsafe {
Rv::from(get_pkcs11!(self.client(), C_SignFinal)(
self.handle(),
signature.as_mut_ptr(),
&mut signature_len,
))
.into_result(Function::SignFinal)?;
}
signature.truncate(signature_len.try_into()?);
Ok(signature)
}
pub fn verify(
&self,
mechanism: &Mechanism,
key: ObjectHandle,
data: &[u8],
signature: &[u8],
) -> Result<()> {
let mut mechanism: CK_MECHANISM = mechanism.into();
unsafe {
Rv::from(get_pkcs11!(self.client(), C_VerifyInit)(
self.handle(),
&mut mechanism as CK_MECHANISM_PTR,
key.handle(),
))
.into_result(Function::VerifyInit)?;
}
unsafe {
Rv::from(get_pkcs11!(self.client(), C_Verify)(
self.handle(),
data.as_ptr() as *mut u8,
data.len().try_into()?,
signature.as_ptr() as *mut u8,
signature.len().try_into()?,
))
.into_result(Function::Verify)
}
}
pub fn verify_init(&self, mechanism: &Mechanism, key: ObjectHandle) -> Result<()> {
let mut mechanism: CK_MECHANISM = mechanism.into();
unsafe {
Rv::from(get_pkcs11!(self.client(), C_VerifyInit)(
self.handle(),
&mut mechanism as CK_MECHANISM_PTR,
key.handle(),
))
.into_result(Function::VerifyInit)?;
}
Ok(())
}
pub fn verify_update(&self, data: &[u8]) -> Result<()> {
unsafe {
Rv::from(get_pkcs11!(self.client(), C_VerifyUpdate)(
self.handle(),
data.as_ptr() as *mut u8,
data.len().try_into()?,
))
.into_result(Function::VerifyUpdate)?;
}
Ok(())
}
pub fn verify_final(&self, signature: &[u8]) -> Result<()> {
unsafe {
Rv::from(get_pkcs11!(self.client(), C_VerifyFinal)(
self.handle(),
signature.as_ptr() as *mut u8,
signature.len().try_into()?,
))
.into_result(Function::VerifyFinal)?;
}
Ok(())
}
pub fn verify_signature_init(
&self,
mechanism: &Mechanism,
key: ObjectHandle,
signature: &[u8],
) -> Result<()> {
let mut mechanism: CK_MECHANISM = mechanism.into();
unsafe {
Rv::from(get_pkcs11!(self.client(), C_VerifySignatureInit)(
self.handle(),
&mut mechanism as CK_MECHANISM_PTR,
key.handle(),
signature.as_ptr() as *mut u8,
signature.len().try_into()?,
))
.into_result(Function::VerifySignatureInit)?;
}
Ok(())
}
pub fn verify_signature(&self, data: &[u8]) -> Result<()> {
unsafe {
Rv::from(get_pkcs11!(self.client(), C_VerifySignature)(
self.handle(),
data.as_ptr() as *mut u8,
data.len().try_into()?,
))
.into_result(Function::VerifySignature)?;
}
Ok(())
}
pub fn verify_signature_update(&self, data: &[u8]) -> Result<()> {
unsafe {
Rv::from(get_pkcs11!(self.client(), C_VerifySignatureUpdate)(
self.handle(),
data.as_ptr() as *mut u8,
data.len().try_into()?,
))
.into_result(Function::VerifySignatureUpdate)?;
}
Ok(())
}
pub fn verify_signature_final(&self) -> Result<()> {
unsafe {
Rv::from(get_pkcs11!(self.client(), C_VerifySignatureFinal)(
self.handle(),
))
.into_result(Function::VerifySignatureFinal)?;
}
Ok(())
}
}