dxd - dynax driver framework 3.0.1d223
cross platform open source driver development framework
Loading...
Searching...
No Matches
dx::license Class Reference

the first certificate of the platform's store naming the product that the root signed, whose constraints this machine and device satisfy and that, unless perpetual, has not expired; kernel and user mode alike over the platform part (dx_platform_license.h: the store's candidates and their DER, the time, the machine's serial number and ethernet addresses, what to keep and the missing/forged hooks) More...

#include <dx_license.h>

Inheritance diagram for dx::license:
Collaboration diagram for dx::license:

Public Types

typedef licensing::type type_t

Public Member Functions

bool bound (const char *name, size_t names, const char *value, size_t values)
 the identities as a constraint term: DSN the device's serial number, SN the machine's, MAC any of its ethernet addresses; other names are unsatisfiable
type_t check (const char *subject, const uint8_t *root, size_t size, const char *device="")
 the built in constraints alone; device: the device's serial number, none when empty
template<typename satisfied_t>
type_t check (const char *subject, const uint8_t *root, size_t size, satisfied_t satisfied)
::CFStringRef cn () const
::CFIndex count () const noexcept
const uint8_t * data () const noexcept
 the DER bytes
::CFArrayRef emails () const
void free () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
CFTypeID id () noexcept
reference & initialize (::SecCertificateRef cf_object, bool retain=true)
::CFDataRef issuers () const noexcept
 The issuer is a sequence in the format used by SecItemCopyMatching. The content returned is a DER-encoded X.509 distinguished name. For a display version of the issuer, call SecCertificateCopyValues. The caller must CFRelease the value returned.
std::string name (::DWORD type=CERT_NAME_SIMPLE_DISPLAY_TYPE, ::DWORD flags=0) const
 a name of the certificate (CertGetNameString), the subject's simple display name by default
 operator bool () const noexcept
 operator type<> () const noexcept
bool operator!= (::SecCertificateRef cf_object) const noexcept
 operator::CFDataRef () const noexcept
 operator::CFDictionaryRef () const noexcept
 operator::CFTypeID () const noexcept
 operator::CFTypeRef () const noexcept
 operator::PCCERT_CONTEXT () const noexcept
 operator::SecCertificateRef () const noexcept
 operator::SecKeyRef () const noexcept
 Retrieves the public key for a given certificate.
bool operator== (::SecCertificateRef cf_object) const noexcept
::CFTypeRef operator[] (::CFArrayRef array) const noexcept
::CFTypeRef operator[] (::CFStringRef oid) const
reference & release () noexcept
const reference & retain () const noexcept
::CFDataRef serial () const noexcept
 Return the content of a DER-encoded integer (without the tag and length fields) for this certificate's serial number. The caller must CFRelease the value returned.
size_t size () const noexcept
::CFDataRef subjects () const noexcept
 The subject is a sequence in the format used by SecItemCopyMatching. The content returned is a DER-encoded X.509 distinguished name. For a display version of the subject, call SecCertificateCopyValues. The caller must CFRelease the value returned.
::CFStringRef summary () const noexcept
::CFDateRef valid_after () const noexcept
 Returns the absolute time at which the given certificate becomes valid, or NULL if this value could not be obtained. The caller must CFRelease the value returned.
::CFDateRef valid_before () const noexcept
 Returns the absolute time at which the given certificate becomes valid, or NULL if this value could not be obtained. The caller must CFRelease the value returned.

Public Attributes

type_t type {}

Protected Types

typedef sec::certificate candidate
typedef crypt::certificate candidate
typedef const void * candidate

Protected Member Functions

void keep (candidate &certificate)
void keep (candidate &certificate) noexcept

Static Protected Member Functions

template<typename visit_t>
static bool each (const char *, visit_t visit)
 every certificate of the machine's Personal store (the subject is left to the check), until visit(candidate, DER bytes, size) returns false
template<typename visit_t>
static bool each (const char *subject, visit_t visit)
 every keychain certificate whose subject starts with the product's name, until visit(candidate, DER bytes, size) returns false
template<typename visit_t>
static bool each (const char *subject, visit_t visit)
 every certificate of the stores whose subject names the product, until visit(candidate, DER bytes, size) returns false
template<typename visit_t>
static void ethernet (visit_t visit)
 every ethernet address of the machine, until visit(chars, length) returns false
template<typename visit_t>
static void ethernet (visit_t visit)
 every ethernet address of the machine, until visit(chars, length) returns false
template<typename visit_t>
static void ethernet (visit_t visit)
 every ethernet address of the machine (the NDIS adapters' permanent ones), until visit(chars, length) returns false
static void forged ()
 a candidate naming the product that the root did not sign
static void forged () noexcept
 a candidate naming the product that the root did not sign
static void forged () noexcept
 a candidate naming the product that the root did not sign
static void keep (candidate &) noexcept
static void missing ()
 no candidate stood: the keychain holds no license
static void missing () noexcept
 no candidate stood: the stores hold no license
static void missing () noexcept
 no candidate stood: the store holds no license
static int64_t now () noexcept
static int64_t now () noexcept
static int64_t now () noexcept
 seconds since 1970 off the system time (100 ns since 1601)
template<typename visit_t>
static void serial (visit_t visit)
 the machine's serial number: visit(chars, length)
template<typename visit_t>
static void serial (visit_t visit)
 the machine's serial number: visit(chars, length)
template<typename visit_t>
static void serial (visit_t visit)
 the machine's serial number: visit(chars, length)

Protected Attributes

::SecCertificateRef cf_object
::PCCERT_CONTEXT context {}

Detailed Description

the first certificate of the platform's store naming the product that the root signed, whose constraints this machine and device satisfy and that, unless perpetual, has not expired; kernel and user mode alike over the platform part (dx_platform_license.h: the store's candidates and their DER, the time, the machine's serial number and ethernet addresses, what to keep and the missing/forged hooks)

The constraints' names are identities: DSN the device's serial number (the license travels with the device), SN the machine's, MAC any of its ethernet addresses; a product with names of its own passes its satisfied(name, names, value, values) to check(), falling back on bound() for these. The check runs when the device's serial number is known - check(), not the constructor.

Member Typedef Documentation

◆ candidate [1/3]

◆ candidate [2/3]

◆ candidate [3/3]

typedef const void* dx::platform::license::candidate
protectedinherited

nothing is kept: the type says it all

◆ type_t

Member Function Documentation

◆ bound()

bool dx::license::bound ( const char * name,
size_t names,
const char * value,
size_t values )
inline

the identities as a constraint term: DSN the device's serial number, SN the machine's, MAC any of its ethernet addresses; other names are unsatisfiable

Here is the call graph for this function:
Here is the caller graph for this function:

◆ check() [1/2]

type_t dx::license::check ( const char * subject,
const uint8_t * root,
size_t size,
const char * device = "" )
inline

the built in constraints alone; device: the device's serial number, none when empty

Here is the call graph for this function:

◆ check() [2/2]

template<typename satisfied_t>
type_t dx::license::check ( const char * subject,
const uint8_t * root,
size_t size,
satisfied_t satisfied )
inline
Parameters
subjectthe certificates' common name starts with it: the platform's store is searched by it
rootthe root CA's DER, the only trust anchor
satisfiedthe constraint predicate: satisfied(name, names, value, values)
Here is the call graph for this function:
Here is the caller graph for this function:

◆ cn()

::CFStringRef sec::certificate::cn ( ) const
inlineinherited
Here is the call graph for this function:
Here is the caller graph for this function:

◆ count()

::CFIndex cf::reference< ::SecCertificateRef >::count ( ) const
inlinenoexceptinherited

◆ data()

const uint8_t * crypt::certificate::data ( ) const
inlinenoexceptinherited

the DER bytes

Here is the caller graph for this function:

◆ each() [1/3]

template<typename visit_t>
bool dx::platform::license::each ( const char * ,
visit_t visit )
inlinestaticprotectedinherited

every certificate of the machine's Personal store (the subject is left to the check), until visit(candidate, DER bytes, size) returns false

Here is the call graph for this function:
Here is the caller graph for this function:

◆ each() [2/3]

template<typename visit_t>
bool dx::platform::license::each ( const char * subject,
visit_t visit )
inlinestaticprotectedinherited

every keychain certificate whose subject starts with the product's name, until visit(candidate, DER bytes, size) returns false

Here is the call graph for this function:

◆ each() [3/3]

template<typename visit_t>
bool dx::platform::license::each ( const char * subject,
visit_t visit )
inlinestaticprotectedinherited

every certificate of the stores whose subject names the product, until visit(candidate, DER bytes, size) returns false

Here is the call graph for this function:

◆ emails()

::CFArrayRef sec::certificate::emails ( ) const
inlineinherited
Here is the call graph for this function:
Here is the caller graph for this function:

◆ ethernet() [1/3]

template<typename visit_t>
void dx::platform::license::ethernet ( visit_t visit)
inlinestaticprotectedinherited

every ethernet address of the machine, until visit(chars, length) returns false

Here is the call graph for this function:

◆ ethernet() [2/3]

template<typename visit_t>
void dx::platform::license::ethernet ( visit_t visit)
inlinestaticprotectedinherited

every ethernet address of the machine, until visit(chars, length) returns false

Here is the call graph for this function:

◆ ethernet() [3/3]

template<typename visit_t>
void dx::platform::license::ethernet ( visit_t visit)
inlinestaticprotectedinherited

every ethernet address of the machine (the NDIS adapters' permanent ones), until visit(chars, length) returns false

Here is the call graph for this function:
Here is the caller graph for this function:

◆ forged() [1/3]

void dx::platform::license::forged ( )
inlinestaticprotectedinherited

a candidate naming the product that the root did not sign

◆ forged() [2/3]

void dx::platform::license::forged ( )
inlinestaticprotectednoexceptinherited

a candidate naming the product that the root did not sign

◆ forged() [3/3]

void dx::platform::license::forged ( )
inlinestaticprotectednoexceptinherited

a candidate naming the product that the root did not sign

Here is the call graph for this function:
Here is the caller graph for this function:

◆ free()

void crypt::certificate::free ( )
inlinenoexceptinherited
Here is the caller graph for this function:

◆ id() [1/23]

CFTypeID cf::reference<::CFMutableArrayRef >::id ( )
inlinenoexceptinherited

◆ id() [2/23]

CFTypeID cf::reference<::CFArrayRef >::id ( )
inlinenoexceptinherited

◆ id() [3/23]

CFTypeID cf::reference<::CFBundleRef >::id ( )
inlinenoexceptinherited

◆ id() [4/23]

CFTypeID cf::reference<::CFDataRef >::id ( )
inlinenoexceptinherited

◆ id() [5/23]

CFTypeID cf::reference<::CFMutableDictionaryRef >::id ( )
inlinenoexceptinherited

◆ id() [6/23]

CFTypeID cf::reference<::CFDictionaryRef >::id ( )
inlinenoexceptinherited

◆ id() [7/23]

CFTypeID cf::reference<::CFErrorRef >::id ( )
inlinenoexceptinherited

◆ id() [8/23]

CFTypeID cf::reference<::CFBooleanRef >::id ( )
inlinenoexceptinherited

◆ id() [9/23]

CFTypeID cf::reference<::CFNumberRef >::id ( )
inlinenoexceptinherited

◆ id() [10/23]

CFTypeID cf::reference<::CFRunLoopObserverRef >::id ( )
inlinenoexceptinherited

◆ id() [11/23]

CFTypeID cf::reference<::CFRunLoopSourceRef >::id ( )
inlinenoexceptinherited

◆ id() [12/23]

CFTypeID cf::reference<::CFRunLoopRef >::id ( )
inlinenoexceptinherited

◆ id() [13/23]

CFTypeID cf::reference<::CFReadStreamRef >::id ( )
inlinenoexceptinherited

◆ id() [14/23]

CFTypeID cf::reference<::CFMutableStringRef >::id ( )
inlinenoexceptinherited

◆ id() [15/23]

CFTypeID cf::reference<::CFStringRef >::id ( )
inlinenoexceptinherited

◆ id() [16/23]

CFTypeID cf::reference<::CFURLRef >::id ( )
inlinenoexceptinherited

◆ id() [17/23]

CFTypeID cf::reference<::CFUUIDRef >::id ( )
inlinenoexceptinherited

◆ id() [18/23]

CFTypeID cf::reference<::SCPreferencesRef >::id ( )
inlinenoexceptinherited

◆ id() [19/23]

CFTypeID cf::reference<::SecTrustRef >::id ( )
inlinenoexceptinherited

◆ id() [20/23]

CFTypeID cf::reference<::SecCertificateRef >::id ( )
inlinenoexceptinherited

◆ id() [21/23]

CFTypeID cf::reference<::SecStaticCodeRef >::id ( )
inlinenoexceptinherited

◆ id() [22/23]

CFTypeID cf::reference<::SecCodeRef >::id ( )
inlinenoexceptinherited

◆ id() [23/23]

CFTypeID cf::reference<::SecRequirementRef >::id ( )
inlinenoexceptinherited

◆ initialize()

reference & cf::reference< ::SecCertificateRef >::initialize ( ::SecCertificateRef cf_object,
bool retain = true )
inlineinherited

◆ issuers()

::CFDataRef sec::certificate::issuers ( ) const
inlinenoexceptinherited

The issuer is a sequence in the format used by SecItemCopyMatching. The content returned is a DER-encoded X.509 distinguished name. For a display version of the issuer, call SecCertificateCopyValues. The caller must CFRelease the value returned.

Here is the call graph for this function:

◆ keep() [1/3]

void dx::platform::license::keep ( candidate & )
inlinestaticprotectednoexceptinherited
Here is the caller graph for this function:

◆ keep() [2/3]

void dx::platform::license::keep ( candidate & certificate)
inlineprotectedinherited
Here is the call graph for this function:

◆ keep() [3/3]

void dx::platform::license::keep ( candidate & certificate)
inlineprotectednoexceptinherited
Here is the call graph for this function:

◆ missing() [1/3]

void dx::platform::license::missing ( )
inlinestaticprotectedinherited

no candidate stood: the keychain holds no license

◆ missing() [2/3]

void dx::platform::license::missing ( )
inlinestaticprotectednoexceptinherited

no candidate stood: the stores hold no license

◆ missing() [3/3]

void dx::platform::license::missing ( )
inlinestaticprotectednoexceptinherited

no candidate stood: the store holds no license

Here is the call graph for this function:
Here is the caller graph for this function:

◆ name()

std::string crypt::certificate::name ( ::DWORD type = CERT_NAME_SIMPLE_DISPLAY_TYPE,
::DWORD flags = 0 ) const
inlineinherited

a name of the certificate (CertGetNameString), the subject's simple display name by default

Here is the call graph for this function:
Here is the caller graph for this function:

◆ now() [1/3]

int64_t dx::platform::license::now ( )
inlinestaticprotectednoexceptinherited

◆ now() [2/3]

int64_t dx::platform::license::now ( )
inlinestaticprotectednoexceptinherited

◆ now() [3/3]

int64_t dx::platform::license::now ( )
inlinestaticprotectednoexceptinherited

seconds since 1970 off the system time (100 ns since 1601)

Here is the call graph for this function:
Here is the caller graph for this function:

◆ operator bool()

dx::license::operator bool ( ) const
inlinevirtualnoexcept

◆ operator type<>()

cf::reference< ::SecCertificateRef >::operator type<> ( ) const
noexceptinherited

◆ operator!=()

bool cf::reference< ::SecCertificateRef >::operator!= ( ::SecCertificateRef cf_object) const
inlinenoexceptinherited

◆ operator::CFDataRef()

sec::certificate::operator::CFDataRef ( ) const
inlinenoexceptinherited
Here is the caller graph for this function:

◆ operator::CFDictionaryRef()

sec::certificate::operator::CFDictionaryRef ( ) const
inlinenoexceptinherited

◆ operator::CFTypeID()

cf::reference< ::SecCertificateRef >::operator::CFTypeID ( ) const
inlineexplicitnoexceptinherited

◆ operator::CFTypeRef()

cf::reference< ::SecCertificateRef >::operator::CFTypeRef ( ) const
inlinenoexceptinherited
Here is the caller graph for this function:

◆ operator::PCCERT_CONTEXT()

crypt::certificate::operator::PCCERT_CONTEXT ( ) const
inlinenoexceptinherited
Here is the caller graph for this function:

◆ operator::SecCertificateRef()

cf::reference< ::SecCertificateRef >::operator ::SecCertificateRef ( ) const
inlinenoexceptinherited
Here is the caller graph for this function:

◆ operator::SecKeyRef()

sec::certificate::operator::SecKeyRef ( ) const
inlinenoexceptinherited

Retrieves the public key for a given certificate.

◆ operator==()

bool cf::reference< ::SecCertificateRef >::operator== ( ::SecCertificateRef cf_object) const
inlinenoexceptinherited

◆ operator[]() [1/2]

::CFTypeRef sec::certificate::operator[] ( ::CFArrayRef array) const
inlinenoexceptinherited
Here is the call graph for this function:

◆ operator[]() [2/2]

::CFTypeRef sec::certificate::operator[] ( ::CFStringRef oid) const
inlineinherited
Here is the call graph for this function:

◆ release()

reference & cf::reference< ::SecCertificateRef >::release ( )
inlinenoexceptinherited

◆ retain()

const reference & cf::reference< ::SecCertificateRef >::retain ( ) const
inlinenoexceptinherited

◆ serial() [1/4]

template<typename visit_t>
void dx::platform::license::serial ( visit_t visit)
inlinestaticprotectedinherited

the machine's serial number: visit(chars, length)

Here is the call graph for this function:

◆ serial() [2/4]

template<typename visit_t>
void dx::platform::license::serial ( visit_t visit)
inlinestaticprotectedinherited

the machine's serial number: visit(chars, length)

Todo
DX_SEC_ENFORCEMENT on Windows
Here is the call graph for this function:

◆ serial() [3/4]

template<typename visit_t>
void dx::platform::license::serial ( visit_t visit)
inlinestaticprotectedinherited

the machine's serial number: visit(chars, length)

Here is the call graph for this function:
Here is the caller graph for this function:

◆ serial() [4/4]

::CFDataRef sec::certificate::serial ( ) const
inlinenoexceptinherited

Return the content of a DER-encoded integer (without the tag and length fields) for this certificate's serial number. The caller must CFRelease the value returned.

Here is the call graph for this function:
Here is the caller graph for this function:

◆ size()

size_t crypt::certificate::size ( ) const
inlinenoexceptinherited
Here is the caller graph for this function:

◆ subjects()

::CFDataRef sec::certificate::subjects ( ) const
inlinenoexceptinherited

The subject is a sequence in the format used by SecItemCopyMatching. The content returned is a DER-encoded X.509 distinguished name. For a display version of the subject, call SecCertificateCopyValues. The caller must CFRelease the value returned.

Here is the call graph for this function:

◆ summary()

::CFStringRef sec::certificate::summary ( ) const
inlinenoexceptinherited

◆ valid_after()

::CFDateRef sec::certificate::valid_after ( ) const
inlinenoexceptinherited

Returns the absolute time at which the given certificate becomes valid, or NULL if this value could not be obtained. The caller must CFRelease the value returned.

◆ valid_before()

::CFDateRef sec::certificate::valid_before ( ) const
inlinenoexceptinherited

Returns the absolute time at which the given certificate becomes valid, or NULL if this value could not be obtained. The caller must CFRelease the value returned.

Member Data Documentation

◆ cf_object

::SecCertificateRef cf::reference< ::SecCertificateRef >::cf_object
protectedinherited

◆ context

::PCCERT_CONTEXT crypt::certificate::context {}
protectedinherited

◆ type

type_t dx::license::type {}

The documentation for this class was generated from the following file:

(c) copyright 2009 dynamic acoustics e.U. generated on

a closed source license may be obtained by requesting a written permission from dynamic acoustics e.U.
however - governmental use generally and military use especially is strictly prohibited though.