Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
125 changes: 63 additions & 62 deletions src/jdk.crypto.cryptoki/share/legal/pkcs11cryptotoken.md
Original file line number Diff line number Diff line change
@@ -1,76 +1,77 @@
## OASIS PKCS #11 Cryptographic Token Interface v3.1
## OASIS PKCS #11 Cryptographic Token Interface v3.2

### OASIS PKCS #11 Cryptographic Token Interface License
<pre>

Copyright © OASIS Open 2023. All Rights Reserved.
Copyright © OASIS Open 2026. All Rights Reserved.

All capitalized terms in the following text have the meanings
assigned to them in the OASIS Intellectual Property Rights Policy (the
"OASIS IPR Policy"). The full Policy may be found at the OASIS website:
[https://www.oasis-open.org/policies-guidelines/ipr/].
All capitalized terms in the following text have the meanings assigned to them
in the OASIS Intellectual Property Rights Policy (the "OASIS IPR Policy"). The
full Policy may be found at the OASIS website:
<https://www.oasis-open.org/policies-guidelines/ipr/>.

This document and translations of it may be copied and furnished to
others, and derivative works that comment on or otherwise explain it or
assist in its implementation may be prepared, copied, published, and
distributed, in whole or in part, without restriction of any kind,
provided that the above copyright notice and this section are included
on all such copies and derivative works. However, this document itself
may not be modified in any way, including by removing the copyright
notice or references to OASIS, except as needed for the purpose of
developing any document or deliverable produced by an OASIS Technical
Committee (in which case the rules applicable to copyrights, as set
forth in the OASIS IPR Policy, must be followed) or as required to
translate it into languages other than English.
This document and translations of it may be copied and furnished to others, and
derivative works that comment on or otherwise explain it or assist in its
implementation may be prepared, copied, published, and distributed, in whole or
in part, without restriction of any kind, provided that the above copyright
notice and this section are included on all such copies and derivative works.
However, this document itself may not be modified in any way, including by
removing the copyright notice or references to OASIS, except as needed for the
purpose of developing any document or deliverable produced by an OASIS Technical
Committee (in which case the rules applicable to copyrights, as set forth in the
OASIS IPR Policy, must be followed) or as required to translate it into
languages other than English.

The limited permissions granted above are perpetual and will not be
revoked by OASIS or its successors or assigns.
The limited permissions granted above are perpetual and will not be revoked by
OASIS or its successors or assigns.

This document and the information contained herein is provided on an
"AS IS" basis and OASIS DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE
INFORMATION HEREIN WILL NOT INFRINGE ANY OWNERSHIP RIGHTS OR ANY IMPLIED
WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. OASIS
AND ITS MEMBERS WILL NOT BE LIABLE FOR ANY DIRECT, INDIRECT, SPECIAL OR
CONSEQUENTIAL DAMAGES ARISING OUT OF ANY USE OF THIS DOCUMENT OR ANY
PART THEREOF.
This document and the information contained herein is provided on an "AS IS"
basis and OASIS DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT
LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE
ANY OWNERSHIP RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR
A PARTICULAR PURPOSE. OASIS AND ITS MEMBERS WILL NOT BE LIABLE FOR ANY DIRECT,
INDIRECT, SPECIAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF ANY USE OF THIS
DOCUMENT OR ANY PART THEREOF.

As stated in the OASIS IPR Policy, the following three paragraphs in
brackets apply to OASIS Standards Final Deliverable documents (Committee
Specifications, OASIS Standards, or Approved Errata).
As stated in the OASIS IPR Policy, the following three paragraphs in brackets
apply to OASIS Standards Final Deliverable documents (Committee Specifications,
OASIS Standards, or Approved Errata).

[OASIS requests that any OASIS Party or any other party that
believes it has patent claims that would necessarily be infringed by
implementations of this OASIS Standards Final Deliverable, to notify
OASIS TC Administrator and provide an indication of its willingness to
grant patent licenses to such patent claims in a manner consistent with
the IPR Mode of the OASIS Technical Committee that produced this
deliverable.]
[OASIS requests that any OASIS Party or any other party that believes it has
patent claims that would necessarily be infringed by implementations of this
OASIS Standards Final Deliverable, to notify OASIS TC Administrator and provide
an indication of its willingness to grant patent licenses to such patent claims
in a manner consistent with the IPR Mode of the OASIS Technical Committee that
produced this deliverable.]

[OASIS invites any party to contact the OASIS TC Administrator if it
is aware of a claim of ownership of any patent claims that would
necessarily be infringed by implementations of this OASIS Standards
Final Deliverable by a patent holder that is not willing to provide a
license to such patent claims in a manner consistent with the IPR Mode
of the OASIS Technical Committee that produced this OASIS Standards
Final Deliverable. OASIS may include such claims on its website, but
disclaims any obligation to do so.]
[OASIS invites any party to contact the OASIS TC Administrator if it is aware of
a claim of ownership of any patent claims that would necessarily be infringed by
implementations of this OASIS Standards Final Deliverable by a patent holder
that is not willing to provide a license to such patent claims in a manner
consistent with the IPR Mode of the OASIS Technical Committee that produced this
OASIS Standards Final Deliverable. OASIS may include such claims on its website,
but disclaims any obligation to do so.]

[OASIS takes no position regarding the validity or scope of any
intellectual property or other rights that might be claimed to pertain
to the implementation or use of the technology described in this OASIS
Standards Final Deliverable or the extent to which any license under
such rights might or might not be available; neither does it represent
that it has made any effort to identify any such rights. Information on
OASIS' procedures with respect to rights in any document or deliverable
produced by an OASIS Technical Committee can be found on the OASIS
website. Copies of claims of rights made available for publication and
any assurances of licenses to be made available, or the result of an
attempt made to obtain a general license or permission for the use of
such proprietary rights by implementers or users of this OASIS Standards
Final Deliverable, can be obtained from the OASIS TC Administrator.
OASIS makes no representation that any information or list of
intellectual property rights will at any time be complete, or that any
claims in such list are, in fact, Essential Claims.]
[OASIS takes no position regarding the validity or scope of any intellectual
property or other rights that might be claimed to pertain to the implementation
or use of the technology described in this OASIS Standards Final Deliverable or
the extent to which any license under such rights might or might not be
available; neither does it represent that it has made any effort to identify any
such rights. Information on OASIS' procedures with respect to rights in any
document or deliverable produced by an OASIS Technical Committee can be found on
the OASIS website. Copies of claims of rights made available for publication and
any assurances of licenses to be made available, or the result of an attempt
made to obtain a general license or permission for the use of such proprietary
rights by implementers or users of this OASIS Standards Final Deliverable, can
be obtained from the OASIS TC Administrator. OASIS makes no representation that
any information or list of intellectual property rights will at any time be
complete, or that any claims in such list are, in fact, Essential Claims.]

The name "OASIS" is a trademark of OASIS, the owner and developer of this
document, and should be used only to refer to the organization and its official
outputs. OASIS welcomes reference to, and implementation and use of, documents,
while reserving the right to enforce its marks against misleading uses. Please
see <https://www.oasis-open.org/policies-guidelines/trademark/> for above
guidance.

</pre>
36 changes: 27 additions & 9 deletions src/jdk.crypto.cryptoki/share/native/libj2pkcs11/pkcs11.h
Original file line number Diff line number Diff line change
@@ -1,11 +1,12 @@
/*
* PKCS #11 Specification Version 3.1
* OASIS Standard
* 23 July 2023
* Copyright (c) OASIS Open 2023. All Rights Reserved.
* Source: https://docs.oasis-open.org/pkcs11/pkcs11-spec/v3.1/os/include/pkcs11-v3.1/
* Latest stage of narrative specification: https://docs.oasis-open.org/pkcs11/pkcs11-spec/v3.1/pkcs11-spec-v3.1.html
* TC IPR Statement: https://www.oasis-open.org/committees/pkcs11/ipr.php
/* Copyright (c) OASIS Open 2016,2019,2024. All Rights Reserved./
* /Distributed under the terms of the OASIS IPR Policy,
* [http://www.oasis-open.org/policies-guidelines/ipr], AS-IS, WITHOUT ANY
* IMPLIED OR EXPRESS WARRANTY; there is no warranty of MERCHANTABILITY, FITNESS FOR A
* PARTICULAR PURPOSE or NONINFRINGEMENT of the rights of others.
*/

/* Latest version of the specification:
* http://docs.oasis-open.org/pkcs11/pkcs11-base/v3.2/pkcs11-base-v3.2.html
*/

#ifndef _PKCS11_H_
Expand Down Expand Up @@ -204,6 +205,21 @@ extern "C" {
#define CK_PKCS11_FUNCTION_INFO(name) \
__PASTE(CK_,name) name;

/* Create the 3.2 Function list */
struct CK_FUNCTION_LIST_3_2 {

CK_VERSION version; /* Cryptoki version */

/* Pile all the function pointers into the CK_FUNCTION_LIST. */
/* pkcs11f.h has all the information about the Cryptoki
* function prototypes.
*/
#include "pkcs11f.h"

};

#define CK_PKCS11_3_0_ONLY 1 /* don't include the 3.2 and later functions */

/* Create the 3.0 Function list */
struct CK_FUNCTION_LIST_3_0 {

Expand All @@ -217,7 +233,9 @@ struct CK_FUNCTION_LIST_3_0 {

};

#define CK_PKCS11_2_0_ONLY 1
#undef CK_PKCS11_3_0_ONLY

#define CK_PKCS11_2_0_ONLY 1 /* don't include the 3.0 and later functions */

/* Continue to define the old CK_FUNCTION_LIST */
struct CK_FUNCTION_LIST {
Expand Down
154 changes: 144 additions & 10 deletions src/jdk.crypto.cryptoki/share/native/libj2pkcs11/pkcs11f.h
Original file line number Diff line number Diff line change
@@ -1,11 +1,12 @@
/*
* PKCS #11 Specification Version 3.1
* OASIS Standard
* 23 July 2023
* Copyright (c) OASIS Open 2023. All Rights Reserved.
* Source: https://docs.oasis-open.org/pkcs11/pkcs11-spec/v3.1/os/include/pkcs11-v3.1/
* Latest stage of narrative specification: https://docs.oasis-open.org/pkcs11/pkcs11-spec/v3.1/pkcs11-spec-v3.1.html
* TC IPR Statement: https://www.oasis-open.org/committees/pkcs11/ipr.php
/* Copyright (c) OASIS Open 2016, 2019, 2024. All Rights Reserved./
* /Distributed under the terms of the OASIS IPR Policy,
* [http://www.oasis-open.org/policies-guidelines/ipr], AS-IS, WITHOUT ANY
* IMPLIED OR EXPRESS WARRANTY; there is no warranty of MERCHANTABILITY, FITNESS FOR A
* PARTICULAR PURPOSE or NONINFRINGEMENT of the rights of others.
*/

/* Latest version of the specification:
* http://docs.oasis-open.org/pkcs11/pkcs11-spec/v3.2/pkcs11-spec-v3.2.html
*/

/* This header file contains pretty much everything about all the
Expand Down Expand Up @@ -953,7 +954,7 @@ CK_PKCS11_FUNCTION_INFO(C_GetInterface)
CK_UTF8CHAR_PTR pInterfaceName, /* name of the interface */
CK_VERSION_PTR pVersion, /* version of the interface */
CK_INTERFACE_PTR_PTR ppInterface, /* returned interface */
CK_FLAGS flags /* flags controlling the semantics
CK_FLAGS flags /* flags controlling the semantics
* of the interface */
);
#endif
Expand Down Expand Up @@ -1192,5 +1193,138 @@ CK_PKCS11_FUNCTION_INFO(C_MessageVerifyFinal)
);
#endif

#endif /* CK_PKCS11_2_0_ONLY */
#ifndef CK_PKCS11_3_0_ONLY
CK_PKCS11_FUNCTION_INFO(C_EncapsulateKey)
#ifdef CK_NEED_ARG_LIST
(
CK_SESSION_HANDLE hSession, /* the session's handle */
CK_MECHANISM_PTR pMechanism, /* the encapsulation mechanism */
CK_OBJECT_HANDLE hPublicKey, /* the encapsulating key */
CK_ATTRIBUTE_PTR pTemplate, /* new key template */
CK_ULONG ulAttributeCount, /* template length */
CK_BYTE_PTR pCiphertext, /* the wrapped key */
CK_ULONG_PTR pulCiphertextLen, /* the wrapped key size */
CK_OBJECT_HANDLE_PTR phKey /* the encapsulated key */
);
#endif

CK_PKCS11_FUNCTION_INFO(C_DecapsulateKey)
#ifdef CK_NEED_ARG_LIST
(
CK_SESSION_HANDLE hSession, /* the session's handle */
CK_MECHANISM_PTR pMechanism, /* the decapsulation mechanism */
CK_OBJECT_HANDLE hPrivateKey, /* the decapsulating key */
CK_ATTRIBUTE_PTR pTemplate, /* new key template */
CK_ULONG ulAttributeCount, /* template length */
CK_BYTE_PTR pCiphertext, /* the wrapped key */
CK_ULONG ulCiphertextLen, /* the wrapped key size */
CK_OBJECT_HANDLE_PTR phKey /* the decapsulated key */
);
#endif

CK_PKCS11_FUNCTION_INFO(C_VerifySignatureInit)
#ifdef CK_NEED_ARG_LIST
(
CK_SESSION_HANDLE hSession, /* the session's handle */
CK_MECHANISM_PTR pMechanism, /* the verification mechanism */
CK_OBJECT_HANDLE hKey, /* verification key */
CK_BYTE_PTR pSignature, /* signature */
CK_ULONG ulSignatureLen /* signature length */
);
#endif

CK_PKCS11_FUNCTION_INFO(C_VerifySignature)
#ifdef CK_NEED_ARG_LIST
(
CK_SESSION_HANDLE hSession, /* the session's handle */
CK_BYTE_PTR pData, /* signed data */
CK_ULONG ulDataLen /* length of signed data */
);
#endif

CK_PKCS11_FUNCTION_INFO(C_VerifySignatureUpdate)
#ifdef CK_NEED_ARG_LIST
(
CK_SESSION_HANDLE hSession, /* the session's handle */
CK_BYTE_PTR pPart, /* signed data */
CK_ULONG ulPartLen /* length of signed data */
);
#endif

CK_PKCS11_FUNCTION_INFO(C_VerifySignatureFinal)
#ifdef CK_NEED_ARG_LIST
(
CK_SESSION_HANDLE hSession /* the session's handle */
);
#endif

CK_PKCS11_FUNCTION_INFO(C_GetSessionValidationFlags)
#ifdef CK_NEED_ARG_LIST
(
CK_SESSION_HANDLE hSession, /* the session's handle */
CK_SESSION_VALIDATION_FLAGS_TYPE type, /* which state of flags */
CK_FLAGS_PTR pFlags /* validation flags */
);
#endif

CK_PKCS11_FUNCTION_INFO(C_AsyncComplete)
#ifdef CK_NEED_ARG_LIST
(
CK_SESSION_HANDLE hSession, /* the session's handle */
CK_UTF8CHAR_PTR pFunctionName, /* pkcs11 function name */
CK_ASYNC_DATA_PTR pResult /* operation result */
);
#endif

CK_PKCS11_FUNCTION_INFO(C_AsyncGetID)
#ifdef CK_NEED_ARG_LIST
(
CK_SESSION_HANDLE hSession, /* the session's handle */
CK_UTF8CHAR_PTR pFunctionName, /* pkcs11 function name */
CK_ULONG_PTR pulID /* persistent operation id */
);
#endif

CK_PKCS11_FUNCTION_INFO(C_AsyncJoin)
#ifdef CK_NEED_ARG_LIST
(
CK_SESSION_HANDLE hSession, /* the session's handle */
CK_UTF8CHAR_PTR pFunctionName, /* pkcs11 function name */
CK_ULONG ulID, /* persistent operation id */
CK_BYTE_PTR pData, /* location for the data */
CK_ULONG ulData
);
#endif

CK_PKCS11_FUNCTION_INFO(C_WrapKeyAuthenticated)
#ifdef CK_NEED_ARG_LIST
(
CK_SESSION_HANDLE hSession,
CK_MECHANISM_PTR pMechanism,
CK_OBJECT_HANDLE hWrappingKey,
CK_OBJECT_HANDLE hKey,
CK_BYTE_PTR pAssociatedData,
CK_ULONG ulAssociatedDataLen,
CK_BYTE_PTR pWrappedKey,
CK_ULONG_PTR pulWrappedKeyLen
);
#endif

CK_PKCS11_FUNCTION_INFO(C_UnwrapKeyAuthenticated)
#ifdef CK_NEED_ARG_LIST
(
CK_SESSION_HANDLE hSession,
CK_MECHANISM_PTR pMechanism,
CK_OBJECT_HANDLE hUnwrappingKey,
CK_BYTE_PTR pWrappedKey,
CK_ULONG ulWrappedKeyLen,
CK_ATTRIBUTE_PTR pTemplate,
CK_ULONG ulAttributeCount,
CK_BYTE_PTR pAssociatedData,
CK_ULONG ulAssociatedDataLen,
CK_OBJECT_HANDLE_PTR phKey
);
#endif

#endif /* CK_PKCS11_3_0_ONLY */
#endif /* CK_PKCS11_2_0_ONLY */
Loading