PQS: Post Quantum Shell Protocol 1.1.0.0a (A2)
A quantum secure secure shell protocol
pqskey.h
Go to the documentation of this file.
1/* 2025-2026 Quantum Resistant Cryptographic Solutions Corporation
2 * All Rights Reserved.
3 *
4 * NOTICE:
5 * This software and all accompanying materials are the exclusive property of
6 * Quantum Resistant Cryptographic Solutions Corporation (QRCS). The intellectual
7 * and technical concepts contained herein are proprietary to QRCS and are
8 * protected under applicable Canadian, U.S., and international copyright,
9 * patent, and trade secret laws.
10 *
11 * CRYPTOGRAPHIC ALGORITHMS AND IMPLEMENTATIONS:
12 * - This software includes implementations of cryptographic primitives and
13 * algorithms that are standardized or in the public domain, such as AES
14 * and SHA-3, which are not proprietary to QRCS.
15 * - This software also includes cryptographic primitives, constructions, and
16 * algorithms designed by QRCS, including but not limited to RCS, SCB, CSX, QMAC, and
17 * related components, which are proprietary to QRCS.
18 * - All source code, implementations, protocol compositions, optimizations,
19 * parameter selections, and engineering work contained in this software are
20 * original works of QRCS and are protected under this license.
21 *
22 * LICENSE AND USE RESTRICTIONS:
23 * - This software is licensed under the Quantum Resistant Cryptographic Solutions
24 * Public Research and Evaluation License (QRCS-PREL), 2025-2026.
25 * - Permission is granted solely for non-commercial evaluation, academic research,
26 * cryptographic analysis, interoperability testing, and feasibility assessment.
27 * - Commercial use, production deployment, commercial redistribution, or
28 * integration into products or services is strictly prohibited without a
29 * separate written license agreement executed with QRCS.
30 * - Licensing and authorized distribution are solely at the discretion of QRCS.
31 *
32 * EXPERIMENTAL CRYPTOGRAPHY NOTICE:
33 * Portions of this software may include experimental, novel, or evolving
34 * cryptographic designs. Use of this software is entirely at the user's risk.
35 *
36 * DISCLAIMER:
37 * THIS SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
38 * IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS
39 * FOR A PARTICULAR PURPOSE, SECURITY, OR NON-INFRINGEMENT. QRCS DISCLAIMS ALL
40 * LIABILITY FOR ANY DIRECT, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL DAMAGES
41 * ARISING FROM THE USE OR MISUSE OF THIS SOFTWARE.
42 *
43 * FULL LICENSE:
44 * This software is subject to the Quantum Resistant Cryptographic Solutions
45 * Public Research and Evaluation License (QRCS-PREL), 2025-2026. The complete license terms
46 * are provided in the accompanying LICENSE file or at https://www.qrcscorp.ca.
47 *
48 * Written by: John G. Underhill
49 * Contact: contact@qrcscorp.ca
50 */
51
52#ifndef PQS_KEY_H
53#define PQS_KEY_H
54
55#include "pqscommon.h"
56#include "qsms.h"
57
62
66#define PQS_KEY_FINGERPRINT_SIZE 32U
67
71#define PQS_KEY_FINGERPRINT_STRING_SIZE ((PQS_KEY_FINGERPRINT_SIZE * 2U) + PQS_STRING_TERMINATOR_SIZE)
72
76#define PQS_KEY_KNOWN_HOST_LINE_MAX 384U
77
81#define PQS_KEY_HOST_NAME_MAX 256U
82
86#define PQS_KEY_KNOWN_HOST_MAGIC "# PQSKNOWNHOSTS1"
87
95PQS_EXPORT_API bool pqs_key_host_is_valid(const char* host);
96
108PQS_EXPORT_API bool pqs_key_private_file_permissions_are_strict(const char* fpath);
109
118PQS_EXPORT_API void pqs_key_fingerprint(uint8_t output[PQS_KEY_FINGERPRINT_SIZE], const qsms_client_verification_key* pubkey);
119
129PQS_EXPORT_API bool pqs_key_fingerprint_string(char* output, size_t outlen, const qsms_client_verification_key* pubkey);
130
140PQS_EXPORT_API bool pqs_key_fingerprint_file(char* output, size_t outlen, const char* fpath);
141
152PQS_EXPORT_API bool pqs_key_known_host_find(const char* fpath, const char* host, char* fingerprint, size_t fplen);
153
163PQS_EXPORT_API bool pqs_key_known_host_set(const char* fpath, const char* host, const char* fingerprint);
164
173PQS_EXPORT_API bool pqs_key_known_host_remove(const char* fpath, const char* host);
174
182PQS_EXPORT_API bool pqs_key_fingerprint_is_valid(const char* fingerprint);
183
193PQS_EXPORT_API bool pqs_key_known_host_verify(const char* fpath, const char* host, const char* fingerprint);
194
195#endif
PQS_EXPORT_API bool pqs_key_known_host_remove(const char *fpath, const char *host)
Remove a host fingerprint from a known-hosts file.
Definition pqskey.c:328
PQS_EXPORT_API bool pqs_key_known_host_find(const char *fpath, const char *host, char *fingerprint, size_t fplen)
Read the expected fingerprint for a host from a known-hosts file.
Definition pqskey.c:399
PQS_EXPORT_API bool pqs_key_fingerprint_is_valid(const char *fingerprint)
Test whether a string is a valid PQS host-key fingerprint.
Definition pqskey.c:231
PQS_EXPORT_API bool pqs_key_fingerprint_string(char *output, size_t outlen, const qsms_client_verification_key *pubkey)
Compute the PQS host-key fingerprint as hexadecimal text.
Definition pqskey.c:208
PQS_EXPORT_API void pqs_key_fingerprint(uint8_t output[PQS_KEY_FINGERPRINT_SIZE], const qsms_client_verification_key *pubkey)
Compute the PQS host-key fingerprint.
Definition pqskey.c:186
PQS_EXPORT_API bool pqs_key_fingerprint_file(char *output, size_t outlen, const char *fpath)
Compute the PQS host-key fingerprint from an encoded public-key file.
Definition pqskey.c:286
PQS_EXPORT_API bool pqs_key_host_is_valid(const char *host)
Test whether a host token is valid for known-host storage.
Definition pqskey.c:42
PQS_EXPORT_API bool pqs_key_private_file_permissions_are_strict(const char *fpath)
Test whether a private key file has strict local permissions where supported.
Definition pqskey.c:260
PQS_EXPORT_API bool pqs_key_known_host_verify(const char *fpath, const char *host, const char *fingerprint)
Verify a host fingerprint against the known-hosts file.
Definition pqskey.c:511
#define PQS_KEY_FINGERPRINT_SIZE
The binary SHA3-256 host-key fingerprint size.
Definition pqskey.h:66
PQS_EXPORT_API bool pqs_key_known_host_set(const char *fpath, const char *host, const char *fingerprint)
Add or replace a host fingerprint in a known-hosts file.
Definition pqskey.c:433