Documentation ¶
Overview ¶
The csra package implements the CSRA client protocol.
Introduction ¶
The Certificate Services Remote Administration Protocol consists of a set of Distributed Component Object Model (DCOM) interfaces, as specified in [MS-DCOM], that allow administrative tools to configure the state and policy of a certification authority (CA) on a server.
For a complete understanding of this protocol, familiarity with public key infrastructure (PKI) concepts such as asymmetric and symmetric cryptography, asymmetric and symmetric encryption techniques, digital certificate concepts, and cryptographic key establishment is required. A comprehensive understanding of the X.509 standard, as specified in [X509], is also required.
The Handbook of Applied Cryptography provides an excellent introduction to cryptography and PKI concepts. For more information, see [CRYPTO]. The X.509 standard, as specified in [X509], provides an excellent introduction to PKI and certificate concepts. Certificate revocation and status checking provides an excellent introduction to certificate revocation lists (CRLs) and revocation concepts. For more information, see [MSFT-CRL].
Overview ¶
The Certificate Services Remote Administration Protocol consists of a set of DCOM interfaces, as specified in [MS-DCOM], that allow administrative tools to configure the state and policy of a CA on a server. The administrative tools can perform such functions as getting or setting properties on a CA, retrieving data, revoking certificates, or retrieving escrowed private keys from a CA.
The following figure reflects only CA administration, not the normal operation of the CA. The protocol for the normal operation of the Microsoft CA is specified in [MS-WCCE].
Index ¶
Constants ¶
This section is empty.
Variables ¶
var (
// import guard
GoPackage = "dcom/csra"
)
Functions ¶
This section is empty.
Types ¶
type CATransportProperty ¶
type CATransportProperty struct { PropertyID int32 `idl:"name:lPropID" json:"property_id"` PropertyType uint8 `idl:"name:propType" json:"property_type"` PropertyFlags uint16 `idl:"name:propFlags" json:"property_flags"` DisplayNameOffset uint32 `idl:"name:obwszDisplayName" json:"display_name_offset"` // contains filtered or unexported fields }
CATransportProperty structure represents CATRANSPROP RPC structure.
The CATRANSPROP structure encapsulates information about a CA property. The CATRANSPROP structure and the marshaling of one or more CATRANSPROP structures into a CERTTRANSBLOB structure is specified in [MS-WCCE] section 2.2.2.3.
func (*CATransportProperty) MarshalNDR ¶
func (*CATransportProperty) UnmarshalNDR ¶
type CertAdminD ¶
type CertAdminD dcom.InterfacePointer
CertAdminD structure represents ICertAdminD RPC structure.
func (*CertAdminD) InterfacePointer ¶
func (o *CertAdminD) InterfacePointer() *dcom.InterfacePointer
func (*CertAdminD) MarshalNDR ¶
func (*CertAdminD) NDRSizeInfo ¶
func (o *CertAdminD) NDRSizeInfo() []uint64
func (*CertAdminD) UnmarshalNDR ¶
type CertAdminD2 ¶
type CertAdminD2 dcom.InterfacePointer
CertAdminD2 structure represents ICertAdminD2 RPC structure.
func (*CertAdminD2) InterfacePointer ¶
func (o *CertAdminD2) InterfacePointer() *dcom.InterfacePointer
func (*CertAdminD2) MarshalNDR ¶
func (*CertAdminD2) NDRSizeInfo ¶
func (o *CertAdminD2) NDRSizeInfo() []uint64
func (*CertAdminD2) UnmarshalNDR ¶
type CertTransDBAttribute ¶
type CertTransDBAttribute struct { // obwszName: An integer that contains the offset from the beginning of the byte array // buffer that is pointed to by the pb member in the containing CERTTRANSBLOB structure // to where the string that contains the name of this attribute can be found. The format // is a null-terminated UNICODE string. The offset MUST be divisible by 4. NameOffset uint32 `idl:"name:obwszName" json:"name_offset"` // obwszValue: An integer that contains the offset from the beginning of the byte array // buffer that is pointed to by the pb member in the containing CERTTRANSBLOB structure // to where the string that contains the value of this attribute can be found. The format // is a null-terminated UNICODE string. The offset MUST be divisible by 4. ValueOffset uint32 `idl:"name:obwszValue" json:"value_offset"` }
CertTransDBAttribute structure represents CERTTRANSDBATTRIBUTE RPC structure.
The CERTTRANSDBATTRIBUTE structure is encoded within a CERTTRANSBLOB structure. The CERTTRANSDBATTRIBUTE structure is used by the server to return attribute information that is associated with a request to the client (upon the client's query via invocation of the EnumAttributesOrExtensions method of the ICertAdminD interface).
func (*CertTransDBAttribute) MarshalNDR ¶
func (*CertTransDBAttribute) UnmarshalNDR ¶
type CertTransDBColumn ¶
type CertTransDBColumn struct { // Type: This field describes the column. It consists of two WORDs, a high WORD and // a low WORD, which are used separately. // // +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ // | 0 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 1 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 2 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 3 | 1 | // | | | | | | | | | | | 0 | | | | | | | | | | 0 | | | | | | | | | | 0 | | // +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ // +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ // | Column Flags | Column Type | // +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ Type uint32 `idl:"name:Type" json:"type"` // Index: An unsigned integer value that specifies the identifier for the column in // the server database. Index uint32 `idl:"name:Index" json:"index"` // cbMax: An unsigned integer value that specifies the maximum data size, in bytes, // that this column can contain. MaxLength uint32 `idl:"name:cbMax" json:"max_length"` // obwszName: An integer that contains the offset from the beginning of the byte array // buffer that is pointed to by the pb member in the containing CERTTRANSBLOB structure, // to where the string that contains the name of this column can be found. The string // format is a null-terminated UNICODE string. The offset MUST be divisible by 4. NameOffset uint32 `idl:"name:obwszName" json:"name_offset"` // obwszDisplayName: An integer that contains the offset from the beginning of the // byte array buffer that is pointed to by the pb member in the containing CERTTRANSBLOB // structure, to where the string that contains the display name of this column can // be found. The string format is a null-terminated UNICODE string. The offset MUST // be divisible by 4. DisplayNameOffset uint32 `idl:"name:obwszDisplayName" json:"display_name_offset"` }
CertTransDBColumn structure represents CERTTRANSDBCOLUMN RPC structure.
The CERTTRANSDBCOLUMN structure is encoded within a CERTTRANSBLOB structure. The CERTTRANSDBCOLUMN structure contains schema information about a particular database column that is associated with a specific table to the client. This associated table is invoked when the client queries the EnumViewColumn or EnumViewColumnTable method of the ICertAdminD and ICertAdminD2 interfaces, respectively.
The CERTTRANSDBCOLUMN structure (section 2.2.1.7) is encoded within the byte array that is referenced by the pb member of a CERTTRANSBLOB structure (section 2.2.1.4).
The packet that contains an array of some number, "N", of CERTTRANSDBCOLUMN structures is specified in the following packet diagrams. The actual value of "N" is a separate return parameter for the EnumViewColumn (section 3.1.4.1.9) and EnumViewColumnTable (section 3.2.4.2.5) methods.
+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ | 0 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 1 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 2 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 3 | 1 | | | | | | | | | | | | 0 | | | | | | | | | | 0 | | | | | | | | | | 0 | | +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ | CERTTRANSDBCOLUMN Structures (variable) | +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ | ... | +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ | ... | +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ | Column_Schema_Data (variable) | +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ | ... | +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ | ... | +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+
func (*CertTransDBColumn) MarshalNDR ¶
func (*CertTransDBColumn) UnmarshalNDR ¶
type CertTransDBExtension ¶
type CertTransDBExtension struct { // obwszName: An unsigned integer that contains the offset from the beginning of the // byte array buffer that is pointed to by the pb member in the containing CERTTRANSBLOB // structure to the string representation of an OID (1) of this extension (as specified // in [X680]). The string format is a null-terminated UNICODE string. The offset MUST // be divisible by 4. NameOffset uint32 `idl:"name:obwszName" json:"name_offset"` // ExtFlags: An integer value that specifies the flags that are associated with the // extension. The following diagram shows its contents. // // +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ // | 0 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 1 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 2 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 3 | 1 | // | | | | | | | | | | | 0 | | | | | | | | | | 0 | | | | | | | | | | 0 | | // +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ // +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ // | Nigiro | // +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ // // C (1 bit): C is the ExtensionCriticalFlag, as defined in section 3.1.1.3, the Extension_Flags // ADM element. A value of 0 means the extension is not critical. A value of 1 means // the extension is critical. // // D (1 bit): D is the ExtensionDisabledFlag, as defined in section 3.1.1.3, the Extension_Flags // ADM element. A value of 0 means the extension is not disabled. A value of 1 means // the extension is disabled. // // Nigiro (2 bytes): The Nigiro field is defined as follows: // // +------------------------+----------------------------------------------------------------------------------+ // | MIRRORED (NIGIRO) | | // | BYTE | MEANING | // | | | // +------------------------+----------------------------------------------------------------------------------+ // +------------------------+----------------------------------------------------------------------------------+ // | 0x8000 | The extension comes from the request. | // +------------------------+----------------------------------------------------------------------------------+ // | 0x4000 | The extension was added by the CA. The CA assigns a value of 2 if the extension | // | | was added by the policy module of the CA. | // +------------------------+----------------------------------------------------------------------------------+ // | 0xC000 | The extension was added by the CA. The CA assigns a value of 3 if the extension | // | | was added interactively by a human administrator of the CA. | // +------------------------+----------------------------------------------------------------------------------+ // | 0x2000 | The extension was added by the CA. The CA assigns a value of 4 if the extension | // | | was added by the certificate server engine and not the policy module component | // | | of the CA. | // +------------------------+----------------------------------------------------------------------------------+ // | 0xA000 | The extension was in the preceding certificate, which might occur, for example, | // | | when a certificate is renewed. | // +------------------------+----------------------------------------------------------------------------------+ // | 0x6000 | The extension comes from an imported certificate (a certificate that was | // | | imported into the CA database). | // +------------------------+----------------------------------------------------------------------------------+ // | 0xE000 | The extension comes from a PKCS7 request. | // +------------------------+----------------------------------------------------------------------------------+ // | 0x1000 | The extension comes from a CMC request. | // +------------------------+----------------------------------------------------------------------------------+ // | 0x9000 | The extension comes from the current CA signing certificate. | // +------------------------+----------------------------------------------------------------------------------+ ExtFlags int32 `idl:"name:ExtFlags" json:"ext_flags"` // cbValue: An unsigned integer value that contains the length, in bytes, of data that // is referenced by the obValue parameter. ValueLength uint32 `idl:"name:cbValue" json:"value_length"` // obValue: An unsigned integer that contains the offset from the beginning of the // byte array buffer that is pointed to by the pb member in the containing CERTTRANSBLOB // structure to where the value for this extension can be found. The length of the value // is specified in the cbValue field. The value is in ASN.1 Distinguished Encoding Rules // (DER) format for the extension, as specified in [X660]. The offset MUST be divisible // by 4. ValueOffset uint32 `idl:"name:obValue" json:"value_offset"` }
CertTransDBExtension structure represents CERTTRANSDBEXTENSION RPC structure.
The CERTTRANSDBEXTENSION structure is encoded within a CERTTRANSBLOB structure. The CERTTRANSDBEXTENSION structure is used by the server to return certificate extension information, as specified in [RFC3280] section 4, that is associated with a request. This associated request to the client occurs when the client performs a query by invoking the EnumAttributesOrExtensions method of the ICertAdminD interface.
func (*CertTransDBExtension) MarshalNDR ¶
func (*CertTransDBExtension) UnmarshalNDR ¶
type CertTransDBResultColumn ¶
type CertTransDBResultColumn struct { // Type: This field describes the column. It consists of two WORDs, a high WORD and // a low WORD, which are used separately. // // +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ // | 0 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 1 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 2 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 3 | 1 | // | | | | | | | | | | | 0 | | | | | | | | | | 0 | | | | | | | | | | 0 | | // +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ // +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ // | Column Flags | Column Type | // +---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+---+ Type uint32 `idl:"name:Type" json:"type"` // Index: An unsigned integer value that specifies the identifier for the column in // the relevant table. Index uint32 `idl:"name:Index" json:"index"` // obValue: An unsigned integer that contains the offset from the beginning of the // corresponding CERTTRANSDBRESULTROW structure to where the value for this column can // be found. The length of the value is specified in the cbValue field. The offset MUST // be DWORD aligned. ValueOffset uint32 `idl:"name:obValue" json:"value_offset"` // cbValue: An unsigned integer value that specifies the length, in bytes, of the value // for the specific column. ValueLength uint32 `idl:"name:cbValue" json:"value_length"` }
CertTransDBResultColumn structure represents CERTTRANSDBRESULTCOLUMN RPC structure.
The CERTTRANSDBRESULTCOLUMN structure is encoded within a CERTTRANSBLOB structure. The CERTTRANSDBRESULTCOLUMN structure is used by the server to return the result of a CA database query that is done by the client (upon the client's query via invocation of the OpenView or EnumView method of the ICertAdminD interface).
The OpenView and EnumView methods return data in the form of a CERTTRANSBLOB structure whose pb member points to an array of one or more CERTTRANSDBRESULTROW structures. Each CERTTRANSDBRESULTROW structure contains one or more CERTTRANSDBRESULTCOLUMN structures.
The CERTTRANSDBRESULTCOLUMN structure contains data for a specific column in a specific row.
func (*CertTransDBResultColumn) MarshalNDR ¶
func (*CertTransDBResultColumn) UnmarshalNDR ¶
type CertTransDBResultRow ¶
type CertTransDBResultRow struct { // rowid: Unsigned integer value that specifies the identifier for the row. RowID uint32 `idl:"name:rowid" json:"row_id"` // ccol: Unsigned integer value that specifies the count of CERTTRANSDBRESULTCOLUMN // structures. Each structure contains the value of a specific column in the row identified // by rowid. ColumnsCount uint32 `idl:"name:ccol" json:"columns_count"` // cbrow: Unsigned integer value that specifies the total size of row data (in bytes). // This is the sum of the size of CERTTRANSDBRESULTROW structure, size of each CERTTRANSDBRESULTCOLUMN // structure for the row (the count of which is specified by ccol), and the DWORD-rounded-up // size of each column value. RowLength uint32 `idl:"name:cbrow" json:"row_length"` }
CertTransDBResultRow structure represents CERTTRANSDBRESULTROW RPC structure.
The CERTTRANSDBRESULTROW structure is encoded within a CERTTRANSBLOB structure. The CERTTRANSDBRESULTROW structure is used by the server to return the result of the database query done by the client (upon the client's query via invocation of OpenView or EnumView methods of the ICertAdminD interface). This structure contains data for a specific row.
func (*CertTransDBResultRow) MarshalNDR ¶
func (*CertTransDBResultRow) UnmarshalNDR ¶
type CertTransportBlob ¶
type CertTransportBlob struct { // cb: An unsigned integer value that MUST contain the length, in bytes, of the buffer // that is pointed to by pb. Length uint32 `idl:"name:cb" json:"length"` // pb: The BYTE buffer that contains the binary contents being transported in this // CERTTRANSBLOB. That content consists of any of the following entities: // // * A certificate. // // * A certificate request. // // * CA ( c6451297-197d-4b4b-b786-3f3187b67b8f#gt_c925d5d7-a442-4ba4-9586-5f94ccec847a // ) properties. // // * Any common structure that is defined in section 2.2.1 ( d9e0f247-2b38-466d-934b-83093c6a11a5 // ) other than VARIANT ( 8d5e0fb0-f357-48b2-808c-bb125fd0609e ) or CERTVIEWRESTRICTION // ( 5503c7fa-c78e-4fda-adc9-21030751bce7 ). // // * Any common structure that is defined in [MS-WCCE] ( ../ms-wcce/446a0fca-7f27-4436-965d-191635518466 // ) section 2.2.2 ( ../ms-wcce/a2d33e71-31d9-4934-a369-07ed8c502ae5 ). // // The CERTTRANSBLOB structure is empty when cb is set to 0 and pb is set to NULL. // // The marshaling of other structures that can be passed in the pb byte buffer of CERTTRANSBLOB // is defined in [MS-WCCE] section 2.2.2. // // All instances of CERTTRANSBLOB that are used by this protocol MUST use the marshaling // rules that are described in the following sections or in [MS-WCCE] section 2.2.2. Buffer []byte `idl:"name:pb;size_is:(cb);pointer:unique" json:"buffer"` }
CertTransportBlob structure represents CERTTRANSBLOB RPC structure.
The CERTTRANSBLOB structure defines a byte buffer that is used to store and request certificates, transmit responses, manipulate Unicode strings, and marshal property values.
func (*CertTransportBlob) MarshalNDR ¶
func (*CertTransportBlob) UnmarshalNDR ¶
type CertViewRestriction ¶
type CertViewRestriction struct { // ColumnIndex: An unsigned integer value that specifies the identifier for the database // column that is receiving the restriction. ColumnIndex uint32 `idl:"name:ColumnIndex" json:"column_index"` // SeekOperator: An integer value that specifies the logical operator of the data-query // qualifier for the column. This parameter MUST be set to one of the following values. // // +------------+--------------------------+ // | | | // | VALUE | MEANING | // | | | // +------------+--------------------------+ // +------------+--------------------------+ // | 0x00000001 | Equal to | // +------------+--------------------------+ // | 0x00000002 | Less than | // +------------+--------------------------+ // | 0x00000004 | Less than or equal to | // +------------+--------------------------+ // | 0x00000008 | Greater than or equal to | // +------------+--------------------------+ // | 0x00000010 | Greater than | // +------------+--------------------------+ SeekOperator int32 `idl:"name:SeekOperator" json:"seek_operator"` // SortOrder: An integer value that specifies the sort order for the column. This parameter // MUST be set to one of the following values. // // +------------+---------------+ // | | | // | VALUE | MEANING | // | | | // +------------+---------------+ // +------------+---------------+ // | 0x00000000 | No sort order | // +------------+---------------+ // | 0x00000001 | Ascending | // +------------+---------------+ // | 0x00000002 | Descending | // +------------+---------------+ SortOrder int32 `idl:"name:SortOrder" json:"sort_order"` // pbValue: A pointer to a byte array that specifies the value against which the value // in the corresponding column (specified by ColumnIndex) is compared, using SeekOperator. Value []byte `idl:"name:pbValue;size_is:(cbValue);pointer:unique" json:"value"` // cbValue: An unsigned integer value that specifies the length of the byte array that // is pointed to by the pbValue field. ValueLength uint32 `idl:"name:cbValue" json:"value_length"` }
CertViewRestriction structure represents CERTVIEWRESTRICTION RPC structure.
The CERTVIEWRESTRICTION structure is used to restrict the data set that is returned by the CA server during calls to the OpenView method for the ICertAdminD interface.
This structure is passed by RPC technology, as specified in [MS-RPCE], and does not need special marshaling.