unsupported
  +   ˆl–äY>”ËmJq@³p/\h
bÑ¿Ã„d m¯_†I|¥�+ÇÆ ?÷     /*
 * Copyright (C) Internet Systems Consortium, Inc. ("ISC")
 *
 * This Source Code Form is subject to the terms of the Mozilla Public
 * License, v. 2.0. If a copy of the MPL was not distributed with this
 * file, you can obtain one at https://mozilla.org/MPL/2.0/.
 *
 * See the COPYRIGHT file distributed with this work for additional
 * information regarding copyright ownership.
 */

#ifndef DST_DST_H
#define DST_DST_H 1

/*! \file dst/dst.h */

#include <inttypes.h>
#include <stdbool.h>

#include <isc/lang.h>
#include <isc/stdtime.h>

#include <dns/ds.h>
#include <dns/dsdigest.h>
#include <dns/log.h>
#include <dns/name.h>
#include <dns/secalg.h>
#include <dns/types.h>

#include <dst/gssapi.h>

ISC_LANG_BEGINDECLS

/***
 *** Types
 ***/

/*%
 * The dst_key structure is opaque.  Applications should use the accessor
 * functions provided to retrieve key attributes.  If an application needs
 * to set attributes, new accessor functions will be written.
 */

typedef struct dst_key	   dst_key_t;
typedef struct dst_context dst_context_t;

/*%
 * Key states for the DNSSEC records related to a key: DNSKEY, RRSIG (ksk),
 * RRSIG (zsk), and DS.
 *
 * DST_KEY_STATE_HIDDEN:      Records of this type are not published in zone.
 *                            This may be because the key parts were never
 *                            introduced in the zone, or because the key has
 *                            retired and has no records of this type left in
 *                            the zone.
 * DST_KEY_STATE_RUMOURED:    Records of this type are published in zone, but
 *                            not long enough to ensure all resolvers know
 *                            about it.
 * DST_KEY_STATE_OMNIPRESENT: Records of this type are published in zone long
 *                            enough so that all resolvers that know about
 *                            these records, no longer have outdated data.
 * DST_KEY_STATE_UNRETENTIVE: Records of this type have been removed from the
 *                            zone, but there may be resolvers that still have
 *                            have predecessor records cached.  Note that RRSIG
 *                            records in this state may actually still be in the
 *                            zone because they are reused, but retired RRSIG
 *                            records will never be refreshed: A successor key
 *                            is used to create signatures.
 * DST_KEY_STATE_NA:          The state is not applicable for this record type.
 */
typedef enum dst_key_state {
	DST_KEY_STATE_HIDDEN = 0,
	DST_KEY_STATE_RUMOURED = 1,
	DST_KEY_STATE_OMNIPRESENT = 2,
	DST_KEY_STATE_UNRETENTIVE = 3,
	DST_KEY_STATE_NA = 4
} dst_key_state_t;

/* DST algorithm codes */
#define DST_ALG_UNKNOWN	     0
#define DST_ALG_RSA	     1 /* Used for parsing RSASHA1, RSASHA256 and RSASHA512 */
#define DST_ALG_RSAMD5	     1
#define DST_ALG_DH	     2
#define DST_ALG_DSA	     3
#define DST_ALG_ECC	     4
#define DST_ALG_RSASHA1	     5
#define DST_ALG_NSEC3DSA     6
#define DST_ALG_NSEC3RSASHA1 7
#define DST_ALG_RSASHA256    8
#define DST_ALG_RSASHA512    10
#define DST_ALG_ECCGOST	     12
#define DST_ALG_ECDSA256     13
#define DST_ALG_ECDSA384     14
#define DST_ALG_ED25519	     15
#define DST_ALG_ED448	     16
#define DST_ALG_HMACMD5	     157
#define DST_ALG_GSSAPI	     160
#define DST_ALG_HMACSHA1     161 /* XXXMPA */
#define DST_ALG_HMACSHA224   162 /* XXXMPA */
#define DST_ALG_HMACSHA256   163 /* XXXMPA */
#define DST_ALG_HMACSHA384   164 /* XXXMPA */
#define DST_ALG_HMACSHA512   165 /* XXXMPA */
#define DST_ALG_INDIRECT     252
#define DST_ALG_PRIVATE	     254
#define DST_MAX_ALGS	     256

/*% A buffer of this size is large enough to hold any key */
#define DST_KEY_MAXSIZE 1280

/*%
 * A buffer of this size is large enough to hold the textual representation
 * of any key
 */
#define DST_KEY_MAXTEXTSIZE 2048

/*% 'Type' for dst_read_key() */
#define DST_TYPE_KEY	 0x1000000 /* KEY key */
#define DST_TYPE_PRIVATE 0x2