1/* SPDX-License-Identifier: LGPL-2.1-or-later */
2/*
3 * Copyright (C) 2017 Red Hat, Inc.
4 */
5
6#ifndef __NM_SETTING_MACSEC_H__
7#define __NM_SETTING_MACSEC_H__
8
9#if !defined(__NETWORKMANAGER_H_INSIDE__) && !defined(NETWORKMANAGER_COMPILATION)
10#error "Only <NetworkManager.h> can be included directly."
11#endif
12
13#include "nm-setting.h"
14
15G_BEGIN_DECLS
16
17#define NM_TYPE_SETTING_MACSEC (nm_setting_macsec_get_type())
18#define NM_SETTING_MACSEC(obj) \
19 (G_TYPE_CHECK_INSTANCE_CAST((obj), NM_TYPE_SETTING_MACSEC, NMSettingMacsec))
20#define NM_SETTING_MACSEC_CLASS(klass) \
21 (G_TYPE_CHECK_CLASS_CAST((klass), NM_TYPE_SETTING_MACSECCONFIG, NMSettingMacsecClass))
22#define NM_IS_SETTING_MACSEC(obj) (G_TYPE_CHECK_INSTANCE_TYPE((obj), NM_TYPE_SETTING_MACSEC))
23#define NM_IS_SETTING_MACSEC_CLASS(klass) (G_TYPE_CHECK_CLASS_TYPE((klass), NM_TYPE_SETTING_MACSEC))
24#define NM_SETTING_MACSEC_GET_CLASS(obj) \
25 (G_TYPE_INSTANCE_GET_CLASS((obj), NM_TYPE_SETTING_MACSEC, NMSettingMacsecClass))
26
27#define NM_SETTING_MACSEC_SETTING_NAME "macsec"
28
29#define NM_SETTING_MACSEC_PARENT "parent"
30#define NM_SETTING_MACSEC_MODE "mode"
31#define NM_SETTING_MACSEC_ENCRYPT "encrypt"
32#define NM_SETTING_MACSEC_MKA_CAK "mka-cak"
33#define NM_SETTING_MACSEC_MKA_CAK_FLAGS "mka-cak-flags"
34#define NM_SETTING_MACSEC_MKA_CKN "mka-ckn"
35#define NM_SETTING_MACSEC_PORT "port"
36#define NM_SETTING_MACSEC_VALIDATION "validation"
37#define NM_SETTING_MACSEC_SEND_SCI "send-sci"
38#define NM_SETTING_MACSEC_OFFLOAD "offload"
39
40typedef struct _NMSettingMacsecClass NMSettingMacsecClass;
41
42/**
43 * NMSettingMacsecMode:
44 * @NM_SETTING_MACSEC_MODE_PSK: The CAK is pre-shared
45 * @NM_SETTING_MACSEC_MODE_EAP: The CAK is the result of participation in EAP
46 *
47 * #NMSettingMacsecMode controls how the CAK (Connectivity Association Key) used
48 * in MKA (MACsec Key Agreement) is obtained.
49 *
50 * Since: 1.6
51 */
52typedef enum {
53 NM_SETTING_MACSEC_MODE_PSK = 0,
54 NM_SETTING_MACSEC_MODE_EAP = 1,
55} NMSettingMacsecMode;
56
57/**
58 * NMSettingMacsecValidation:
59 * @NM_SETTING_MACSEC_VALIDATION_DISABLE: All incoming frames are accepted if
60 * possible
61 * @NM_SETTING_MACSEC_VALIDATION_CHECK: Non protected, invalid, or impossible to
62 * verify frames are accepted and counted as "invalid"
63 * @NM_SETTING_MACSEC_VALIDATION_STRICT: Non protected, invalid, or impossible to
64 * verify frames are dropped
65 *
66 * #NMSettingMacsecValidation specifies a validation mode for incoming frames.
67 *
68 * Since: 1.6
69 */
70typedef enum {
71 NM_SETTING_MACSEC_VALIDATION_DISABLE = 0,
72 NM_SETTING_MACSEC_VALIDATION_CHECK = 1,
73 NM_SETTING_MACSEC_VALIDATION_STRICT = 2,
74} NMSettingMacsecValidation;
75
76#define NM_SETTING_MACSEC_MKA_CAK_LENGTH 32
77
78/* Deprecated. The CKN can be between 2 and 64 characters. */
79#define NM_SETTING_MACSEC_MKA_CKN_LENGTH 64
80
81/**
82 * NMSettingMacsecOffload:
83 * @NM_SETTING_MACSEC_OFFLOAD_DEFAULT: use the global default; disable if not defined
84 * @NM_SETTING_MACSEC_OFFLOAD_OFF: disable offload
85 * @NM_SETTING_MACSEC_OFFLOAD_PHY: request offload to the PHY
86 * @NM_SETTING_MACSEC_OFFLOAD_MAC: request offload to the MAC
87 *
88 * These flags control the MACsec offload mode.
89 *
90 * Since: 1.46
91 **/
92typedef enum {
93 NM_SETTING_MACSEC_OFFLOAD_DEFAULT = -1,
94 NM_SETTING_MACSEC_OFFLOAD_OFF = 0,
95 NM_SETTING_MACSEC_OFFLOAD_PHY = 1,
96 NM_SETTING_MACSEC_OFFLOAD_MAC = 2,
97} NMSettingMacsecOffload;
98
99NM_AVAILABLE_IN_1_6
100GType nm_setting_macsec_get_type(void);
101NM_AVAILABLE_IN_1_6
102NMSetting *nm_setting_macsec_new(void);
103
104NM_AVAILABLE_IN_1_6
105const char *nm_setting_macsec_get_parent(NMSettingMacsec *setting);
106NM_AVAILABLE_IN_1_6
107NMSettingMacsecMode nm_setting_macsec_get_mode(NMSettingMacsec *setting);
108NM_AVAILABLE_IN_1_6
109gboolean nm_setting_macsec_get_encrypt(NMSettingMacsec *setting);
110NM_AVAILABLE_IN_1_6
111const char *nm_setting_macsec_get_mka_cak(NMSettingMacsec *setting);
112NM_AVAILABLE_IN_1_6
113NMSettingSecretFlags nm_setting_macsec_get_mka_cak_flags(NMSettingMacsec *setting);
114NM_AVAILABLE_IN_1_6
115const char *nm_setting_macsec_get_mka_ckn(NMSettingMacsec *setting);
116NM_AVAILABLE_IN_1_6
117int nm_setting_macsec_get_port(NMSettingMacsec *setting);
118NM_AVAILABLE_IN_1_6
119NMSettingMacsecValidation nm_setting_macsec_get_validation(NMSettingMacsec *setting);
120NM_AVAILABLE_IN_1_12
121gboolean nm_setting_macsec_get_send_sci(NMSettingMacsec *setting);
122NM_AVAILABLE_IN_1_46
123NMSettingMacsecOffload nm_setting_macsec_get_offload(NMSettingMacsec *setting);
124
125G_END_DECLS
126
127#endif /* __NM_SETTING_MACSEC_H__ */
128

source code of include/libnm/nm-setting-macsec.h