/**************************************************************************** * * Copyright (c) 2001 Novell, Inc. All Rights Reserved. * * This program is free software; you can redistribute it and/or * modify it under the terms of version 2 of the GNU General Public License * as published by the Free Software Foundation. * * This program is distributed in the hope that it will be useful, * but WITHOUT ANY WARRANTY; without even the implied warranty of * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the * GNU General Public License for more details. * * You should have received a copy of the GNU General Public License * along with this program; if not, contact Novell, Inc. * * To contact Novell about this file by physical or electronic mail, you * may find current contact information at www.novell.com. * ****************************************************************************/ #ifndef BONGO_ACME_H #define BONGO_ACME_H #include #include #include #ifdef __cplusplus extern "C" { #endif #define BONGO_ACME_URL_SIZE 2048 #define BONGO_ACME_ERROR_SIZE 1024 typedef struct BongoAcmeConfiguration { const char *directory_url; const char *contact_email; const char *profile; const char *challenge_type; const char *challenge_directory; const char *dns_provider_config_path; const char *account_key_path; const char *candidate_key_path; const char *candidate_certificate_path; const char *certificate_path; const char *private_key_path; const char *ca_file; int terms_of_service_agreed; unsigned int certificate_key_bits; int connect_timeout_seconds; int operation_timeout_seconds; unsigned int dns_ttl_seconds; int dns_propagation_timeout_seconds; int dns_poll_interval_seconds; int ari_min_check_seconds; int ari_max_check_seconds; int fallback_renewal_percent; } BongoAcmeConfiguration; typedef struct BongoAcmeReport { int certificate_renewed; int ari_supported; int ari_used; time_t next_check; time_t retry_after; time_t certificate_not_after; char explanation_url[BONGO_ACME_URL_SIZE]; } BongoAcmeReport; /* * Complete one RFC 8555 / RFC 9773 maintenance pass. A return value of one * means the pass completed (including "not due yet"); zero means a retryable * or permanent error described in error. The caller must persist and honor * report.next_check even when the return value is zero. */ int BongoAcmeMaintain(const BongoAcmeConfiguration *configuration, const char *const *dns_names, size_t dns_name_count, int force_renewal, BongoAcmeReport *report, char *error, size_t error_size); /* * Inspect a PEM certificate using a lifetime-relative fallback schedule. * Returns 1 when renewal is due, 0 when it is not due, and -1 on error. */ int BongoAcmeCertificateNeedsRenewal( const char *certificate_path, const char *const *dns_names, size_t dns_name_count, int fallback_renewal_percent, time_t now, time_t *not_after, time_t *fallback_renewal_time, char *error, size_t error_size); /* RFC 9773 certificate identifier: base64url(AKI).base64url(serial). */ int BongoAcmeCertificateIdentifier(const char *certificate_path, char **identifier, char *error, size_t error_size); /* Atomically deploy the validated candidate. Must be called with root euid. */ int BongoAcmeInstallCandidate(const BongoAcmeConfiguration *configuration, uid_t owner, gid_t service_group, char *error, size_t error_size); /* Binary-safe unpadded RFC 4648 base64url helper. */ char *BongoAcmeBase64UrlEncode(const void *data, size_t length); #ifdef __cplusplus } #endif #endif