2006-10-30 14:07:05 +00:00
|
|
|
/*
|
2009-04-14 10:34:24 +00:00
|
|
|
* Copyright (C) 2005-2009 Martin Willi
|
2008-06-10 09:08:27 +00:00
|
|
|
* Copyright (C) 2008 Tobias Brunner
|
2006-10-30 14:07:05 +00:00
|
|
|
* Copyright (C) 2005 Jan Hutter
|
|
|
|
* Hochschule fuer Technik Rapperswil
|
|
|
|
*
|
|
|
|
* This program is free software; you can redistribute it and/or modify it
|
|
|
|
* under the terms of the GNU General Public License as published by the
|
|
|
|
* Free Software Foundation; either version 2 of the License, or (at your
|
|
|
|
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful, but
|
|
|
|
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
|
|
|
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
|
|
|
* for more details.
|
2008-03-13 14:14:44 +00:00
|
|
|
*/
|
|
|
|
|
|
|
|
/**
|
|
|
|
* @defgroup authenticator authenticator
|
|
|
|
* @{ @ingroup authenticators
|
2006-10-30 14:07:05 +00:00
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef AUTHENTICATOR_H_
|
|
|
|
#define AUTHENTICATOR_H_
|
|
|
|
|
|
|
|
typedef enum auth_method_t auth_method_t;
|
2008-08-22 10:44:51 +00:00
|
|
|
typedef enum auth_class_t auth_class_t;
|
2006-10-30 14:07:05 +00:00
|
|
|
typedef struct authenticator_t authenticator_t;
|
|
|
|
|
2006-10-31 12:27:59 +00:00
|
|
|
#include <library.h>
|
2009-04-14 10:34:24 +00:00
|
|
|
#include <config/auth_cfg.h>
|
2006-10-30 14:07:05 +00:00
|
|
|
#include <sa/ike_sa.h>
|
|
|
|
|
|
|
|
/**
|
2008-08-22 10:44:51 +00:00
|
|
|
* Method to use for authentication, as defined in IKEv2.
|
2006-10-30 14:07:05 +00:00
|
|
|
*/
|
|
|
|
enum auth_method_t {
|
|
|
|
/**
|
2009-09-04 11:46:09 +00:00
|
|
|
* Computed as specified in section 2.15 of RFC using
|
2006-10-30 14:07:05 +00:00
|
|
|
* an RSA private key over a PKCS#1 padded hash.
|
|
|
|
*/
|
|
|
|
AUTH_RSA = 1,
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2006-10-30 14:07:05 +00:00
|
|
|
/**
|
2009-09-04 11:46:09 +00:00
|
|
|
* Computed as specified in section 2.15 of RFC using the
|
|
|
|
* shared key associated with the identity in the ID payload
|
2006-10-30 14:07:05 +00:00
|
|
|
* and the negotiated prf function
|
|
|
|
*/
|
|
|
|
AUTH_PSK = 2,
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2006-10-30 14:07:05 +00:00
|
|
|
/**
|
2009-09-04 11:46:09 +00:00
|
|
|
* Computed as specified in section 2.15 of RFC using a
|
2006-10-30 14:07:05 +00:00
|
|
|
* DSS private key over a SHA-1 hash.
|
|
|
|
*/
|
|
|
|
AUTH_DSS = 3,
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2008-06-10 09:08:27 +00:00
|
|
|
/**
|
|
|
|
* ECDSA with SHA-256 on the P-256 curve as specified in RFC 4754
|
|
|
|
*/
|
|
|
|
AUTH_ECDSA_256 = 9,
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2008-06-10 09:08:27 +00:00
|
|
|
/**
|
|
|
|
* ECDSA with SHA-384 on the P-384 curve as specified in RFC 4754
|
|
|
|
*/
|
|
|
|
AUTH_ECDSA_384 = 10,
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2008-06-10 09:08:27 +00:00
|
|
|
/**
|
|
|
|
* ECDSA with SHA-512 on the P-521 curve as specified in RFC 4754
|
|
|
|
*/
|
|
|
|
AUTH_ECDSA_521 = 11,
|
2006-10-30 14:07:05 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
/**
|
|
|
|
* enum names for auth_method_t.
|
|
|
|
*/
|
|
|
|
extern enum_name_t *auth_method_names;
|
|
|
|
|
2008-08-22 10:44:51 +00:00
|
|
|
/**
|
|
|
|
* Class of authentication to use. This is different to auth_method_t in that
|
|
|
|
* it does not specify a method, but a class of acceptable methods. The found
|
|
|
|
* certificate finally dictates wich method is used.
|
|
|
|
*/
|
|
|
|
enum auth_class_t {
|
2009-04-14 10:34:24 +00:00
|
|
|
/** any class acceptable */
|
|
|
|
AUTH_CLASS_ANY = 0,
|
2008-08-22 10:44:51 +00:00
|
|
|
/** authentication using public keys (RSA, ECDSA) */
|
|
|
|
AUTH_CLASS_PUBKEY = 1,
|
|
|
|
/** authentication using a pre-shared secrets */
|
|
|
|
AUTH_CLASS_PSK = 2,
|
|
|
|
/** authentication using EAP */
|
|
|
|
AUTH_CLASS_EAP = 3,
|
|
|
|
};
|
|
|
|
|
|
|
|
/**
|
|
|
|
* enum strings for auth_class_t
|
|
|
|
*/
|
|
|
|
extern enum_name_t *auth_class_names;
|
|
|
|
|
2006-10-30 14:07:05 +00:00
|
|
|
/**
|
2008-03-13 14:14:44 +00:00
|
|
|
* Authenticator interface implemented by the various authenticators.
|
2006-10-30 14:07:05 +00:00
|
|
|
*
|
2009-04-14 10:34:24 +00:00
|
|
|
* An authenticator implementation handles AUTH and EAP payloads. Received
|
|
|
|
* messages are passed to the process() method, to send authentication data
|
|
|
|
* the message is passed to the build() method.
|
2006-10-30 14:07:05 +00:00
|
|
|
*/
|
|
|
|
struct authenticator_t {
|
|
|
|
|
|
|
|
/**
|
2009-04-14 10:34:24 +00:00
|
|
|
* Process an incoming message using the authenticator.
|
2006-10-30 14:07:05 +00:00
|
|
|
*
|
2009-04-14 10:34:24 +00:00
|
|
|
* @param message message containing authentication payloads
|
2006-10-30 14:07:05 +00:00
|
|
|
* @return
|
2009-04-14 10:34:24 +00:00
|
|
|
* - SUCCESS if authentication successful
|
|
|
|
* - FAILED if authentication failed
|
|
|
|
* - NEED_MORE if another exchange required
|
2006-10-30 14:07:05 +00:00
|
|
|
*/
|
2009-04-14 10:34:24 +00:00
|
|
|
status_t (*process)(authenticator_t *this, message_t *message);
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2006-10-30 14:07:05 +00:00
|
|
|
/**
|
2009-04-14 10:34:24 +00:00
|
|
|
* Attach authentication data to an outgoing message.
|
2006-10-30 14:07:05 +00:00
|
|
|
*
|
2009-04-14 10:34:24 +00:00
|
|
|
* @param message message to add authentication data to
|
2006-10-30 14:07:05 +00:00
|
|
|
* @return
|
2009-04-14 10:34:24 +00:00
|
|
|
* - SUCCESS if authentication successful
|
|
|
|
* - FAILED if authentication failed
|
|
|
|
* - NEED_MORE if another exchange required
|
2006-10-30 14:07:05 +00:00
|
|
|
*/
|
2009-04-14 10:34:24 +00:00
|
|
|
status_t (*build)(authenticator_t *this, message_t *message);
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2006-10-30 14:07:05 +00:00
|
|
|
/**
|
2009-04-14 10:34:24 +00:00
|
|
|
* Destroy authenticator instance.
|
2006-10-30 14:07:05 +00:00
|
|
|
*/
|
|
|
|
void (*destroy) (authenticator_t *this);
|
|
|
|
};
|
|
|
|
|
|
|
|
/**
|
2009-04-14 10:34:24 +00:00
|
|
|
* Create an authenticator to build signatures.
|
2006-10-30 14:07:05 +00:00
|
|
|
*
|
2009-04-14 10:34:24 +00:00
|
|
|
* @param ike_sa associated ike_sa
|
|
|
|
* @param cfg authentication configuration
|
|
|
|
* @param received_nonce nonce received in IKE_SA_INIT
|
2009-05-11 08:35:44 +00:00
|
|
|
* @param sent_nonce nonce sent in IKE_SA_INIT
|
|
|
|
* @param received_init received IKE_SA_INIT message data
|
2009-04-14 10:34:24 +00:00
|
|
|
* @param sent_init sent IKE_SA_INIT message data
|
|
|
|
* @return authenticator, NULL if not supported
|
2006-10-30 14:07:05 +00:00
|
|
|
*/
|
2009-04-14 10:34:24 +00:00
|
|
|
authenticator_t *authenticator_create_builder(
|
|
|
|
ike_sa_t *ike_sa, auth_cfg_t *cfg,
|
2009-05-11 08:35:44 +00:00
|
|
|
chunk_t received_nonce, chunk_t sent_nonce,
|
|
|
|
chunk_t received_init, chunk_t sent_init);
|
2008-06-10 09:08:27 +00:00
|
|
|
|
|
|
|
/**
|
2009-04-14 10:34:24 +00:00
|
|
|
* Create an authenticator to verify signatures.
|
2009-09-04 11:46:09 +00:00
|
|
|
*
|
2009-04-14 10:34:24 +00:00
|
|
|
* @param ike_sa associated ike_sa
|
|
|
|
* @param message message containing authentication data
|
2009-05-11 08:35:44 +00:00
|
|
|
* @param received_nonce nonce received in IKE_SA_INIT
|
2009-04-14 10:34:24 +00:00
|
|
|
* @param sent_nonce nonce sent in IKE_SA_INIT
|
|
|
|
* @param received_init received IKE_SA_INIT message data
|
2009-05-11 08:35:44 +00:00
|
|
|
* @param sent_init sent IKE_SA_INIT message data
|
2009-04-14 10:34:24 +00:00
|
|
|
* @return authenticator, NULL if not supported
|
2008-06-10 09:08:27 +00:00
|
|
|
*/
|
2009-04-14 10:34:24 +00:00
|
|
|
authenticator_t *authenticator_create_verifier(
|
|
|
|
ike_sa_t *ike_sa, message_t *message,
|
2009-05-11 08:35:44 +00:00
|
|
|
chunk_t received_nonce, chunk_t sent_nonce,
|
|
|
|
chunk_t received_init, chunk_t sent_init);
|
2006-10-30 14:07:05 +00:00
|
|
|
|
2009-03-24 17:43:01 +00:00
|
|
|
#endif /** AUTHENTICATOR_H_ @}*/
|