20#include <winpr/assert.h>
21#include <winpr/library.h>
22#include <winpr/ncrypt.h>
26#include <winpr/print.h>
31#define TAG WINPR_TAG("ncrypt")
33const static char NCRYPT_MAGIC[6] = {
'N',
'C',
'R',
'Y',
'P',
'T' };
35SECURITY_STATUS checkNCryptHandle(NCRYPT_HANDLE handle, NCryptHandleType matchType)
39 WLog_VRB(TAG,
"invalid handle 'NULL'");
40 return ERROR_INVALID_PARAMETER;
44 if (memcmp(base->magic, NCRYPT_MAGIC, ARRAYSIZE(NCRYPT_MAGIC)) != 0)
46 char magic1[ARRAYSIZE(NCRYPT_MAGIC) + 1] = { 0 };
47 char magic2[ARRAYSIZE(NCRYPT_MAGIC) + 1] = { 0 };
49 memcpy(magic1, base->magic, ARRAYSIZE(NCRYPT_MAGIC));
50 memcpy(magic2, NCRYPT_MAGIC, ARRAYSIZE(NCRYPT_MAGIC));
52 WLog_VRB(TAG,
"handle '%p' invalid magic '%s' instead of '%s'",
53 WINPR_CXX_COMPAT_CAST(
const void*, base), magic1, magic2);
54 return ERROR_INVALID_PARAMETER;
59 case WINPR_NCRYPT_PROVIDER:
60 case WINPR_NCRYPT_KEY:
63 WLog_VRB(TAG,
"handle '%p' invalid type %d", WINPR_CXX_COMPAT_CAST(
const void*, base),
64 WINPR_CXX_COMPAT_CAST(int32_t, base->type));
65 return ERROR_INVALID_PARAMETER;
68 if ((matchType != WINPR_NCRYPT_INVALID) && (base->type != matchType))
70 WLog_VRB(TAG,
"handle '%p' invalid type %d, expected %d",
71 WINPR_CXX_COMPAT_CAST(
const void*, base),
72 WINPR_CXX_COMPAT_CAST(int32_t, base->type),
73 WINPR_CXX_COMPAT_CAST(int32_t, matchType));
74 return ERROR_INVALID_PARAMETER;
79void* ncrypt_new_handle(NCryptHandleType kind,
size_t len, NCryptGetPropertyFn getProp,
86 memcpy(ret->magic, NCRYPT_MAGIC,
sizeof(ret->magic));
88 ret->getPropertyFn = getProp;
89 ret->releaseFn = dtor;
93SECURITY_STATUS winpr_NCryptDefault_dtor(NCRYPT_HANDLE handle)
98 memset(h->magic, 0,
sizeof(h->magic));
99 h->type = WINPR_NCRYPT_INVALID;
103 return ERROR_SUCCESS;
106SECURITY_STATUS NCryptEnumStorageProviders(DWORD* wProviderCount,
108 WINPR_ATTR_UNUSED DWORD dwFlags)
111 size_t stringAllocSize = 0;
113 LPWSTR strPtr = NULL;
114 static const WCHAR emptyComment[] = { 0 };
115 size_t copyAmount = 0;
119 *ppProviderList = NULL;
122 *wProviderCount += 1;
123 stringAllocSize += (_wcslen(MS_SCARD_PROV) + 1) * 2;
124 stringAllocSize +=
sizeof(emptyComment);
127 if (!*wProviderCount)
128 return ERROR_SUCCESS;
132 return NTE_NO_MEMORY;
135 strPtr = (LPWSTR)(ret + *wProviderCount);
137 ret->pszName = strPtr;
138 copyAmount = (_wcslen(MS_SCARD_PROV) + 1) * 2;
139 memcpy(strPtr, MS_SCARD_PROV, copyAmount);
140 strPtr += copyAmount / 2;
142 ret->pszComment = strPtr;
143 copyAmount =
sizeof(emptyComment);
144 memcpy(strPtr, emptyComment, copyAmount);
146 *ppProviderList = ret;
149 return ERROR_SUCCESS;
152SECURITY_STATUS NCryptOpenStorageProvider(NCRYPT_PROV_HANDLE* phProvider, LPCWSTR pszProviderName,
155 return winpr_NCryptOpenStorageProviderEx(phProvider, pszProviderName, dwFlags, NULL);
158SECURITY_STATUS winpr_NCryptOpenStorageProviderEx(NCRYPT_PROV_HANDLE* phProvider,
159 LPCWSTR pszProviderName, DWORD dwFlags,
162#if defined(WITH_PKCS11)
163 if (pszProviderName && ((_wcscmp(pszProviderName, MS_SMART_CARD_KEY_STORAGE_PROVIDER) == 0) ||
164 (_wcscmp(pszProviderName, MS_SCARD_PROV) == 0)))
165 return NCryptOpenP11StorageProviderEx(phProvider, pszProviderName, dwFlags, modulePaths);
167 char buffer[128] = { 0 };
168 (void)ConvertWCharToUtf8(pszProviderName, buffer,
sizeof(buffer));
169 WLog_WARN(TAG,
"provider '%s' not supported", buffer);
170 return ERROR_NOT_SUPPORTED;
172 WLog_WARN(TAG,
"rebuild with -DWITH_PKCS11=ON to enable smartcard logon support");
173 return ERROR_NOT_SUPPORTED;
177SECURITY_STATUS NCryptEnumKeys(NCRYPT_PROV_HANDLE hProvider, LPCWSTR pszScope,
178 NCryptKeyName** ppKeyName, PVOID* ppEnumState, DWORD dwFlags)
180 SECURITY_STATUS ret = 0;
183 ret = checkNCryptHandle((NCRYPT_HANDLE)hProvider, WINPR_NCRYPT_PROVIDER);
184 if (ret != ERROR_SUCCESS)
187 return provider->enumKeysFn(hProvider, pszScope, ppKeyName, ppEnumState, dwFlags);
190SECURITY_STATUS NCryptOpenKey(NCRYPT_PROV_HANDLE hProvider, NCRYPT_KEY_HANDLE* phKey,
191 LPCWSTR pszKeyName, DWORD dwLegacyKeySpec, DWORD dwFlags)
193 SECURITY_STATUS ret = 0;
196 ret = checkNCryptHandle((NCRYPT_HANDLE)hProvider, WINPR_NCRYPT_PROVIDER);
197 if (ret != ERROR_SUCCESS)
199 if (!phKey || !pszKeyName)
200 return ERROR_INVALID_PARAMETER;
202 return provider->openKeyFn(hProvider, phKey, pszKeyName, dwLegacyKeySpec, dwFlags);
205static NCryptKeyGetPropertyEnum propertyStringToEnum(LPCWSTR pszProperty)
207 if (_wcscmp(pszProperty, NCRYPT_CERTIFICATE_PROPERTY) == 0)
209 return NCRYPT_PROPERTY_CERTIFICATE;
211 else if (_wcscmp(pszProperty, NCRYPT_READER_PROPERTY) == 0)
213 return NCRYPT_PROPERTY_READER;
215 else if (_wcscmp(pszProperty, NCRYPT_WINPR_SLOTID) == 0)
217 return NCRYPT_PROPERTY_SLOTID;
219 else if (_wcscmp(pszProperty, NCRYPT_NAME_PROPERTY) == 0)
221 return NCRYPT_PROPERTY_NAME;
224 return NCRYPT_PROPERTY_UNKNOWN;
227SECURITY_STATUS NCryptGetProperty(NCRYPT_HANDLE hObject, LPCWSTR pszProperty, PBYTE pbOutput,
228 DWORD cbOutput, DWORD* pcbResult, DWORD dwFlags)
230 NCryptKeyGetPropertyEnum
property = NCRYPT_PROPERTY_UNKNOWN;
234 return ERROR_INVALID_PARAMETER;
237 if (memcmp(base->magic, NCRYPT_MAGIC, 6) != 0)
238 return ERROR_INVALID_HANDLE;
240 property = propertyStringToEnum(pszProperty);
241 if (property == NCRYPT_PROPERTY_UNKNOWN)
242 return ERROR_NOT_SUPPORTED;
244 return base->getPropertyFn(hObject, property, pbOutput, cbOutput, pcbResult, dwFlags);
247SECURITY_STATUS NCryptFreeObject(NCRYPT_HANDLE hObject)
250 SECURITY_STATUS ret = checkNCryptHandle(hObject, WINPR_NCRYPT_INVALID);
251 if (ret != ERROR_SUCCESS)
256 ret = base->releaseFn(hObject);
261SECURITY_STATUS NCryptFreeBuffer(PVOID pvInput)
264 return ERROR_INVALID_PARAMETER;
267 return ERROR_SUCCESS;
271SECURITY_STATUS winpr_NCryptOpenStorageProviderEx(NCRYPT_PROV_HANDLE* phProvider,
272 LPCWSTR pszProviderName, DWORD dwFlags,
275 typedef SECURITY_STATUS (*NCryptOpenStorageProviderFn)(NCRYPT_PROV_HANDLE * phProvider,
276 LPCWSTR pszProviderName, DWORD dwFlags);
277 SECURITY_STATUS ret = NTE_PROV_DLL_NOT_FOUND;
278 HANDLE lib = LoadLibraryA(
"ncrypt.dll");
280 return NTE_PROV_DLL_NOT_FOUND;
282 NCryptOpenStorageProviderFn ncryptOpenStorageProviderFn =
283 GetProcAddressAs(lib,
"NCryptOpenStorageProvider", NCryptOpenStorageProviderFn);
284 if (!ncryptOpenStorageProviderFn)
286 ret = NTE_PROV_DLL_NOT_FOUND;
290 ret = ncryptOpenStorageProviderFn(phProvider, pszProviderName, dwFlags);
298const char* winpr_NCryptSecurityStatusError(SECURITY_STATUS status)
301 case (SECURITY_STATUS)(S): \
306 NTE_CASE(ERROR_SUCCESS);
307 NTE_CASE(ERROR_INVALID_PARAMETER);
308 NTE_CASE(ERROR_INVALID_HANDLE);
309 NTE_CASE(ERROR_NOT_SUPPORTED);
311 NTE_CASE(NTE_BAD_UID);
312 NTE_CASE(NTE_BAD_HASH);
313 NTE_CASE(NTE_BAD_KEY);
314 NTE_CASE(NTE_BAD_LEN);
315 NTE_CASE(NTE_BAD_DATA);
316 NTE_CASE(NTE_BAD_SIGNATURE);
317 NTE_CASE(NTE_BAD_VER);
318 NTE_CASE(NTE_BAD_ALGID);
319 NTE_CASE(NTE_BAD_FLAGS);
320 NTE_CASE(NTE_BAD_TYPE);
321 NTE_CASE(NTE_BAD_KEY_STATE);
322 NTE_CASE(NTE_BAD_HASH_STATE);
323 NTE_CASE(NTE_NO_KEY);
324 NTE_CASE(NTE_NO_MEMORY);
325 NTE_CASE(NTE_EXISTS);
327 NTE_CASE(NTE_NOT_FOUND);
328 NTE_CASE(NTE_DOUBLE_ENCRYPT);
329 NTE_CASE(NTE_BAD_PROVIDER);
330 NTE_CASE(NTE_BAD_PROV_TYPE);
331 NTE_CASE(NTE_BAD_PUBLIC_KEY);
332 NTE_CASE(NTE_BAD_KEYSET);
333 NTE_CASE(NTE_PROV_TYPE_NOT_DEF);
334 NTE_CASE(NTE_PROV_TYPE_ENTRY_BAD);
335 NTE_CASE(NTE_KEYSET_NOT_DEF);
336 NTE_CASE(NTE_KEYSET_ENTRY_BAD);
337 NTE_CASE(NTE_PROV_TYPE_NO_MATCH);
338 NTE_CASE(NTE_SIGNATURE_FILE_BAD);
339 NTE_CASE(NTE_PROVIDER_DLL_FAIL);
340 NTE_CASE(NTE_PROV_DLL_NOT_FOUND);
341 NTE_CASE(NTE_BAD_KEYSET_PARAM);
343 NTE_CASE(NTE_SYS_ERR);
344 NTE_CASE(NTE_SILENT_CONTEXT);
345 NTE_CASE(NTE_TOKEN_KEYSET_STORAGE_FULL);
346 NTE_CASE(NTE_TEMPORARY_PROFILE);
347 NTE_CASE(NTE_FIXEDPARAMETER);
356const char* winpr_NCryptGetModulePath(NCRYPT_PROV_HANDLE phProvider)
358#if defined(WITH_PKCS11)
359 return NCryptGetModulePath(phProvider);
common ncrypt handle items
common ncrypt provider items
a provider name descriptor