218 lines
17 KiB
HTML
218 lines
17 KiB
HTML
|
||||
|
|
|
|||
|
|
<!DOCTYPE html>
|
|||
|
|
<html class="writer-html5" lang="en" data-content_root="../">
|
|||
|
|
<head>
|
|||
|
|
<meta charset="utf-8" /><meta name="viewport" content="width=device-width, initial-scale=1" />
|
|||
|
|
|
|||
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
|||
|
|
<title>Security salts and hashes — TeamSpeak SDK documentation</title>
|
|||
|
|
<link rel="stylesheet" type="text/css" href="../_static/pygments.css?v=b86133f3" />
|
|||
|
|
<link rel="stylesheet" type="text/css" href="../_static/css/theme.css?v=9edc463e" />
|
|||
|
|
|
|||
|
|
|
|||
|
|
<script src="../_static/jquery.js?v=5d32c60e"></script>
|
|||
|
|
<script src="../_static/_sphinx_javascript_frameworks_compat.js?v=2cd50e6c"></script>
|
|||
|
|
<script src="../_static/documentation_options.js?v=7f41d439"></script>
|
|||
|
|
<script src="../_static/doctools.js?v=9bcbadda"></script>
|
|||
|
|
<script src="../_static/sphinx_highlight.js?v=dc90522c"></script>
|
|||
|
|
<script src="../_static/js/theme.js"></script>
|
|||
|
|
<link rel="index" title="Index" href="../genindex.html" />
|
|||
|
|
<link rel="search" title="Search" href="../search.html" />
|
|||
|
|
<link rel="next" title="Disabling protocol commands" href="disable-commands.html" />
|
|||
|
|
<link rel="prev" title="Permission checks" href="permissions.html" />
|
|||
|
|
</head>
|
|||
|
|
|
|||
|
|
<body class="wy-body-for-nav">
|
|||
|
|
<div class="wy-grid-for-nav">
|
|||
|
|
<nav data-toggle="wy-nav-shift" class="wy-nav-side">
|
|||
|
|
<div class="wy-side-scroll">
|
|||
|
|
<div class="wy-side-nav-search" >
|
|||
|
|
|
|||
|
|
|
|||
|
|
|
|||
|
|
<a href="../index.html" class="icon icon-home">
|
|||
|
|
TeamSpeak SDK
|
|||
|
|
<img src="../_static/logo.png" class="logo" alt="Logo"/>
|
|||
|
|
</a>
|
|||
|
|
<div role="search">
|
|||
|
|
<form id="rtd-search-form" class="wy-form" action="../search.html" method="get">
|
|||
|
|
<input type="text" name="q" placeholder="Search docs" aria-label="Search docs" />
|
|||
|
|
<input type="hidden" name="check_keywords" value="yes" />
|
|||
|
|
<input type="hidden" name="area" value="default" />
|
|||
|
|
</form>
|
|||
|
|
</div>
|
|||
|
|
</div><div class="wy-menu wy-menu-vertical" data-spy="affix" role="navigation" aria-label="Navigation menu">
|
|||
|
|
<p class="caption" role="heading"><span class="caption-text">API</span></p>
|
|||
|
|
<ul>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../errors.html">TeamSpeak Error Codes</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../properties.html">Property Enums</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../enumerations.html">Structures & Enumerations</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client_api.html">TeamSpeak Client Functions</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../server_api.html">TeamSpeak Server Functions</a></li>
|
|||
|
|
</ul>
|
|||
|
|
<p class="caption" role="heading"><span class="caption-text">Server</span></p>
|
|||
|
|
<ul class="current">
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="intro.html">Introduction</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="basic.html">Getting started</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="list-items.html">List available clients, channels, servers</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="vserver-manage.html">Create and stop virtual servers</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="advanced-create.html">Advanced virtual server creation</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="info.html">Retrieve and store information</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="channels.html">Managing channels</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="clients.html">Managing clients</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="whisper.html">Whisper lists</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="encryption.html">Custom encryption</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="passwords.html">Custom passwords</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="permissions.html">Permission checks</a></li>
|
|||
|
|
<li class="toctree-l1 current"><a class="current reference internal" href="#">Security salts and hashes</a><ul>
|
|||
|
|
<li class="toctree-l2"><a class="reference internal" href="#creating-a-channel-salt">Creating a channel salt</a></li>
|
|||
|
|
<li class="toctree-l2"><a class="reference internal" href="#creating-a-client-hash">Creating a client hash</a></li>
|
|||
|
|
</ul>
|
|||
|
|
</li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="disable-commands.html">Disabling protocol commands</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="filetransfer.html">Filetransfer</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="faq.html">FAQ</a></li>
|
|||
|
|
</ul>
|
|||
|
|
<p class="caption" role="heading"><span class="caption-text">Client</span></p>
|
|||
|
|
<ul>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/intro.html">Introduction</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/basic.html">Getting started</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/connections.html">Managing server connections</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/logging.html">Logging</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/audio.html">Client Audio</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/wave-files.html">Playing wave files</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/3dsound.html">3D Sound</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/whisper.html">Whisper lists</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/voice-encryption.html">Channel voice data encryption</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/info.html">Retrieve and store information</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/channels.html">Channel Management</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/client-list.html">List clients</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/client-kick.html">Kicking clients</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/local-mute.html">Muting other clients</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/textmessages.html">Text chat</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/filetransfer.html">Filetransfer</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/encryption.html">Custom encryption</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/passwords.html">Custom passwords</a></li>
|
|||
|
|
<li class="toctree-l1"><a class="reference internal" href="../client/faq.html">FAQ</a></li>
|
|||
|
|
</ul>
|
|||
|
|
|
|||
|
|
</div>
|
|||
|
|
</div>
|
|||
|
|
</nav>
|
|||
|
|
|
|||
|
|
<section data-toggle="wy-nav-shift" class="wy-nav-content-wrap"><nav class="wy-nav-top" aria-label="Mobile navigation menu" >
|
|||
|
|
<i data-toggle="wy-nav-top" class="fa fa-bars"></i>
|
|||
|
|
<a href="../index.html">TeamSpeak SDK</a>
|
|||
|
|
</nav>
|
|||
|
|
|
|||
|
|
<div class="wy-nav-content">
|
|||
|
|
<div class="rst-content">
|
|||
|
|
<div role="navigation" aria-label="Page navigation">
|
|||
|
|
<ul class="wy-breadcrumbs">
|
|||
|
|
<li><a href="../index.html" class="icon icon-home" aria-label="Home"></a></li>
|
|||
|
|
<li class="breadcrumb-item active">Security salts and hashes</li>
|
|||
|
|
<li class="wy-breadcrumbs-aside">
|
|||
|
|
</li>
|
|||
|
|
</ul>
|
|||
|
|
<hr/>
|
|||
|
|
</div>
|
|||
|
|
<div role="main" class="document" itemscope="itemscope" itemtype="http://schema.org/Article">
|
|||
|
|
<div itemprop="articleBody">
|
|||
|
|
|
|||
|
|
<section id="security-salts-and-hashes">
|
|||
|
|
<h1>Security salts and hashes<a class="headerlink" href="#security-salts-and-hashes" title="Link to this heading"></a></h1>
|
|||
|
|
<p>As an optional security feature, the TeamSpeak SDK offers to restrict
|
|||
|
|
access of clients to specific channels by using a salt and hash
|
|||
|
|
mechanism. The motivation here is to enforce clients to use a specific
|
|||
|
|
identity, nickname and metadata when they connect to the TeamSpeak
|
|||
|
|
server.</p>
|
|||
|
|
<p>In the server, a security salt is created over a clients unique data by
|
|||
|
|
calling <a class="reference internal" href="#c.ts3server_createSecuritySalt" title="ts3server_createSecuritySalt"><code class="xref c c-func docutils literal notranslate"><span class="pre">ts3server_createSecuritySalt()</span></code></a>.</p>
|
|||
|
|
<p>This salt is then attached to a channel during channel creation or by editing existing
|
|||
|
|
channels by setting the channel variable <a class="reference internal" href="../properties.html#c.ChannelProperties.CHANNEL_SECURITY_SALT" title="CHANNEL_SECURITY_SALT"><code class="xref c c-enumerator docutils literal notranslate"><span class="pre">CHANNEL_SECURITY_SALT</span></code></a>.</p>
|
|||
|
|
<p>When a client attempts to enter such a channel, the clients <a class="reference internal" href="../properties.html#c.ClientProperties.CLIENT_SECURITY_HASH" title="CLIENT_SECURITY_HASH"><code class="xref c c-enumerator docutils literal notranslate"><span class="pre">CLIENT_SECURITY_HASH</span></code></a>
|
|||
|
|
variable is checked against the clients data (unique id, optionally nickname and meta_data) using the salt.
|
|||
|
|
If the hash is not correct, the client is not allowed to enter the channel.</p>
|
|||
|
|
<p>The clients hash value is calculated by the server using <a class="reference internal" href="#c.ts3server_calculateSecurityHash" title="ts3server_calculateSecurityHash"><code class="xref c c-func docutils literal notranslate"><span class="pre">ts3server_calculateSecurityHash()</span></code></a>.
|
|||
|
|
This security hash has to be transmitted to the client by ways outside of the TeamSpeak SDK. The
|
|||
|
|
client will set the hash in its <a class="reference internal" href="../properties.html#c.ClientProperties.CLIENT_SECURITY_HASH" title="CLIENT_SECURITY_HASH"><code class="xref c c-enumerator docutils literal notranslate"><span class="pre">CLIENT_SECURITY_HASH</span></code></a> variable.</p>
|
|||
|
|
<section id="creating-a-channel-salt">
|
|||
|
|
<h2>Creating a channel salt<a class="headerlink" href="#creating-a-channel-salt" title="Link to this heading"></a></h2>
|
|||
|
|
<dl class="c function">
|
|||
|
|
<dt class="sig sig-object c">
|
|||
|
|
<span class="kt"><span class="pre">unsigned</span></span><span class="w"> </span><span class="kt"><span class="pre">int</span></span><span class="w"> </span><span class="sig-name descname"><span class="n"><span class="pre">ts3server_createSecuritySalt</span></span></span><span class="sig-paren">(</span><span class="kt"><span class="pre">int</span></span><span class="w"> </span><span class="n"><span class="pre">options</span></span>, <span class="kt"><span class="pre">void</span></span><span class="w"> </span><span class="p"><span class="pre">*</span></span><span class="n"><span class="pre">salt</span></span>, <span class="kt"><span class="pre">int</span></span><span class="w"> </span><span class="n"><span class="pre">saltByteSize</span></span>, <span class="kt"><span class="pre">char</span></span><span class="w"> </span><span class="p"><span class="pre">*</span></span><span class="p"><span class="pre">*</span></span><span class="n"><span class="pre">securitySalt</span></span><span class="sig-paren">)</span><br /></dt>
|
|||
|
|
<dd><p>Create a security salt to lock channel to identities. See the :ref:SDK Documentation<<code class="docutils literal notranslate"><span class="pre">channel_security_salt</span></code>> on the topic for more in depth explanation. </p>
|
|||
|
|
<dl class="field-list simple">
|
|||
|
|
<dt class="field-odd">Parameters<span class="colon">:</span></dt>
|
|||
|
|
<dd class="field-odd"><ul class="simple">
|
|||
|
|
<li><p><strong>options</strong> – specifies which parameters to include in the security salt. A combination of values from the <a class="reference internal" href="../enumerations.html#public__definitions_8h_1a33449bae9acaa426cceb4a8d52d6eed2"><span class="std std-ref">SecuritySaltOptions</span></a> enum. </p></li>
|
|||
|
|
<li><p><strong>salt</strong> – pointer to random data of cryptographic quality. </p></li>
|
|||
|
|
<li><p><strong>saltByteSize</strong> – number of bytes of random data to use. Larger is better but slower. </p></li>
|
|||
|
|
<li><p><strong>securitySalt</strong> – address of a variable to receive the security salt. Memory is allocated by the server library and needs to be freed by caller using <a class="reference internal" href="../server_api.html#serverlib_8h_1a6993000e98ccfa4ecf0a6f3d92406e5e"><span class="std std-ref">ts3server_freeMemory</span></a></p></li>
|
|||
|
|
</ul>
|
|||
|
|
</dd>
|
|||
|
|
<dt class="field-even">Returns<span class="colon">:</span></dt>
|
|||
|
|
<dd class="field-even"><p>An Error code from the <a class="reference internal" href="../errors.html#public__errors_8h_1a0bcf1e0a5e32989890f6e85064327f7b"><span class="std std-ref">Ts3ErrorType</span></a> enum indicating either success or the failure reason </p>
|
|||
|
|
</dd>
|
|||
|
|
</dl>
|
|||
|
|
</dd></dl>
|
|||
|
|
|
|||
|
|
</section>
|
|||
|
|
<section id="creating-a-client-hash">
|
|||
|
|
<h2>Creating a client hash<a class="headerlink" href="#creating-a-client-hash" title="Link to this heading"></a></h2>
|
|||
|
|
<dl class="c function">
|
|||
|
|
<dt class="sig sig-object c">
|
|||
|
|
<span class="kt"><span class="pre">unsigned</span></span><span class="w"> </span><span class="kt"><span class="pre">int</span></span><span class="w"> </span><span class="sig-name descname"><span class="n"><span class="pre">ts3server_calculateSecurityHash</span></span></span><span class="sig-paren">(</span><span class="k"><span class="pre">const</span></span><span class="w"> </span><span class="kt"><span class="pre">char</span></span><span class="w"> </span><span class="p"><span class="pre">*</span></span><span class="n"><span class="pre">securitySalt</span></span>, <span class="k"><span class="pre">const</span></span><span class="w"> </span><span class="kt"><span class="pre">char</span></span><span class="w"> </span><span class="p"><span class="pre">*</span></span><span class="n"><span class="pre">clientUniqueIdentifier</span></span>, <span class="k"><span class="pre">const</span></span><span class="w"> </span><span class="kt"><span class="pre">char</span></span><span class="w"> </span><span class="p"><span class="pre">*</span></span><span class="n"><span class="pre">clientNickName</span></span>, <span class="k"><span class="pre">const</span></span><span class="w"> </span><span class="kt"><span class="pre">char</span></span><span class="w"> </span><span class="p"><span class="pre">*</span></span><span class="n"><span class="pre">clientMetaData</span></span>, <span class="kt"><span class="pre">char</span></span><span class="w"> </span><span class="p"><span class="pre">*</span></span><span class="p"><span class="pre">*</span></span><span class="n"><span class="pre">securityHash</span></span><span class="sig-paren">)</span><br /></dt>
|
|||
|
|
<dd><p>create a hash for a specific client from a security salt to lock an identity to a channel. See the :ref:SDK Documentation<<code class="docutils literal notranslate"><span class="pre">channel_security_salt</span></code>> on the topic for more in depth explanation. </p>
|
|||
|
|
<dl class="field-list simple">
|
|||
|
|
<dt class="field-odd">Parameters<span class="colon">:</span></dt>
|
|||
|
|
<dd class="field-odd"><ul class="simple">
|
|||
|
|
<li><p><strong>securitySalt</strong> – the security salt of a channel as generated by <a class="reference internal" href="../server_api.html#serverlib_8h_1a718c03b28330e46df2de3a96a083e316"><span class="std std-ref">ts3server_createSecuritySalt</span></a></p></li>
|
|||
|
|
<li><p><strong>clientUniqueIdentifier</strong> – public identity of a client to generate a security hash for </p></li>
|
|||
|
|
<li><p><strong>clientNickName</strong> – nickname of the client to include in the hash if specified by the salt. </p></li>
|
|||
|
|
<li><p><strong>clientMetaData</strong> – meta data of the client to include in the hash if specified by the salt. </p></li>
|
|||
|
|
<li><p><strong>securityHash</strong> – address of a variable to receive the security hash. Memory is allocated by the server library and must be freed by caller using <a class="reference internal" href="../server_api.html#serverlib_8h_1a6993000e98ccfa4ecf0a6f3d92406e5e"><span class="std std-ref">ts3server_freeMemory</span></a></p></li>
|
|||
|
|
</ul>
|
|||
|
|
</dd>
|
|||
|
|
<dt class="field-even">Returns<span class="colon">:</span></dt>
|
|||
|
|
<dd class="field-even"><p>An Error code from the <a class="reference internal" href="../errors.html#public__errors_8h_1a0bcf1e0a5e32989890f6e85064327f7b"><span class="std std-ref">Ts3ErrorType</span></a> enum indicating either success or the failure reason </p>
|
|||
|
|
</dd>
|
|||
|
|
</dl>
|
|||
|
|
</dd></dl>
|
|||
|
|
|
|||
|
|
</section>
|
|||
|
|
</section>
|
|||
|
|
|
|||
|
|
|
|||
|
|
</div>
|
|||
|
|
</div>
|
|||
|
|
<footer><div class="rst-footer-buttons" role="navigation" aria-label="Footer">
|
|||
|
|
<a href="permissions.html" class="btn btn-neutral float-left" title="Permission checks" accesskey="p" rel="prev"><span class="fa fa-arrow-circle-left" aria-hidden="true"></span> Previous</a>
|
|||
|
|
<a href="disable-commands.html" class="btn btn-neutral float-right" title="Disabling protocol commands" accesskey="n" rel="next">Next <span class="fa fa-arrow-circle-right" aria-hidden="true"></span></a>
|
|||
|
|
</div>
|
|||
|
|
|
|||
|
|
<hr/>
|
|||
|
|
|
|||
|
|
<div role="contentinfo">
|
|||
|
|
<p>© Copyright 2020, TeamSpeak Systems GmbH.</p>
|
|||
|
|
</div>
|
|||
|
|
|
|||
|
|
Built with <a href="https://www.sphinx-doc.org/">Sphinx</a> using a
|
|||
|
|
<a href="https://github.com/readthedocs/sphinx_rtd_theme">theme</a>
|
|||
|
|
provided by <a href="https://readthedocs.org">Read the Docs</a>.
|
|||
|
|
|
|||
|
|
|
|||
|
|
</footer>
|
|||
|
|
</div>
|
|||
|
|
</div>
|
|||
|
|
</section>
|
|||
|
|
</div>
|
|||
|
|
<script>
|
|||
|
|
jQuery(function () {
|
|||
|
|
SphinxRtdTheme.Navigation.enable(true);
|
|||
|
|
});
|
|||
|
|
</script>
|
|||
|
|
|
|||
|
|
</body>
|
|||
|
|
</html>
|