2007-04-10 06:01:03 +00:00
|
|
|
/*
|
|
|
|
* Copyright (C) 2005-2007 Martin Willi
|
|
|
|
* Copyright (C) 2005 Jan Hutter
|
|
|
|
* Hochschule fuer Technik Rapperswil
|
|
|
|
*
|
|
|
|
* This program is free software; you can redistribute it and/or modify it
|
|
|
|
* under the terms of the GNU General Public License as published by the
|
|
|
|
* Free Software Foundation; either version 2 of the License, or (at your
|
|
|
|
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
|
|
|
*
|
|
|
|
* This program is distributed in the hope that it will be useful, but
|
|
|
|
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
|
|
|
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
|
|
|
* for more details.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include "ike_cfg.h"
|
|
|
|
|
|
|
|
#include <string.h>
|
|
|
|
|
2008-06-12 11:42:19 +00:00
|
|
|
#include <daemon.h>
|
|
|
|
|
2007-04-10 06:01:03 +00:00
|
|
|
|
|
|
|
typedef struct private_ike_cfg_t private_ike_cfg_t;
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Private data of an ike_cfg_t object
|
|
|
|
*/
|
|
|
|
struct private_ike_cfg_t {
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Public part
|
|
|
|
*/
|
|
|
|
ike_cfg_t public;
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2007-04-10 06:01:03 +00:00
|
|
|
/**
|
|
|
|
* Number of references hold by others to this ike_cfg
|
|
|
|
*/
|
|
|
|
refcount_t refcount;
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Address of local host
|
|
|
|
*/
|
2008-06-06 15:05:54 +00:00
|
|
|
char *me;
|
2007-04-10 06:01:03 +00:00
|
|
|
|
|
|
|
/**
|
|
|
|
* Address of remote host
|
2009-09-04 11:46:09 +00:00
|
|
|
*/
|
2008-06-06 15:05:54 +00:00
|
|
|
char *other;
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2007-04-10 06:01:03 +00:00
|
|
|
/**
|
|
|
|
* should we send a certificate request?
|
|
|
|
*/
|
|
|
|
bool certreq;
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2007-10-01 16:41:34 +00:00
|
|
|
/**
|
|
|
|
* enforce UDP encapsulation
|
|
|
|
*/
|
|
|
|
bool force_encap;
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2007-04-10 06:01:03 +00:00
|
|
|
/**
|
|
|
|
* List of proposals to use
|
|
|
|
*/
|
|
|
|
linked_list_t *proposals;
|
|
|
|
};
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Implementation of ike_cfg_t.certreq.
|
|
|
|
*/
|
|
|
|
static bool send_certreq(private_ike_cfg_t *this)
|
|
|
|
{
|
|
|
|
return this->certreq;
|
|
|
|
}
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2007-10-01 16:41:34 +00:00
|
|
|
/**
|
|
|
|
* Implementation of ike_cfg_t.force_encap.
|
|
|
|
*/
|
|
|
|
static bool force_encap_meth(private_ike_cfg_t *this)
|
|
|
|
{
|
|
|
|
return this->force_encap;
|
|
|
|
}
|
2007-04-10 06:01:03 +00:00
|
|
|
|
|
|
|
/**
|
2008-06-06 15:05:54 +00:00
|
|
|
* Implementation of ike_cfg_t.get_my_addr.
|
2007-04-10 06:01:03 +00:00
|
|
|
*/
|
2008-06-06 15:05:54 +00:00
|
|
|
static char *get_my_addr(private_ike_cfg_t *this)
|
2007-04-10 06:01:03 +00:00
|
|
|
{
|
2008-06-06 15:05:54 +00:00
|
|
|
return this->me;
|
2007-04-10 06:01:03 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
2008-06-06 15:05:54 +00:00
|
|
|
* Implementation of ike_cfg_t.get_other_addr.
|
2007-04-10 06:01:03 +00:00
|
|
|
*/
|
2008-06-06 15:05:54 +00:00
|
|
|
static char *get_other_addr(private_ike_cfg_t *this)
|
2007-04-10 06:01:03 +00:00
|
|
|
{
|
2008-06-06 15:05:54 +00:00
|
|
|
return this->other;
|
2007-04-10 06:01:03 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Implementation of ike_cfg_t.add_proposal.
|
|
|
|
*/
|
|
|
|
static void add_proposal(private_ike_cfg_t *this, proposal_t *proposal)
|
|
|
|
{
|
|
|
|
this->proposals->insert_last(this->proposals, proposal);
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Implementation of ike_cfg_t.get_proposals.
|
|
|
|
*/
|
|
|
|
static linked_list_t* get_proposals(private_ike_cfg_t *this)
|
|
|
|
{
|
|
|
|
iterator_t *iterator;
|
|
|
|
proposal_t *current;
|
|
|
|
linked_list_t *proposals = linked_list_create();
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2007-04-10 06:01:03 +00:00
|
|
|
iterator = this->proposals->create_iterator(this->proposals, TRUE);
|
|
|
|
while (iterator->iterate(iterator, (void**)¤t))
|
|
|
|
{
|
|
|
|
current = current->clone(current);
|
|
|
|
proposals->insert_last(proposals, (void*)current);
|
|
|
|
}
|
|
|
|
iterator->destroy(iterator);
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2007-04-10 06:01:03 +00:00
|
|
|
return proposals;
|
|
|
|
}
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2007-04-10 06:01:03 +00:00
|
|
|
/**
|
|
|
|
* Implementation of ike_cfg_t.select_proposal.
|
|
|
|
*/
|
|
|
|
static proposal_t *select_proposal(private_ike_cfg_t *this,
|
|
|
|
linked_list_t *proposals)
|
|
|
|
{
|
|
|
|
iterator_t *stored_iter, *supplied_iter;
|
|
|
|
proposal_t *stored, *supplied, *selected;
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2007-04-10 06:01:03 +00:00
|
|
|
stored_iter = this->proposals->create_iterator(this->proposals, TRUE);
|
|
|
|
supplied_iter = proposals->create_iterator(proposals, TRUE);
|
2009-09-04 11:46:09 +00:00
|
|
|
|
|
|
|
|
2007-04-10 06:01:03 +00:00
|
|
|
/* compare all stored proposals with all supplied. Stored ones are preferred.*/
|
|
|
|
while (stored_iter->iterate(stored_iter, (void**)&stored))
|
|
|
|
{
|
|
|
|
supplied_iter->reset(supplied_iter);
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2007-04-10 06:01:03 +00:00
|
|
|
while (supplied_iter->iterate(supplied_iter, (void**)&supplied))
|
|
|
|
{
|
|
|
|
selected = stored->select(stored, supplied);
|
|
|
|
if (selected)
|
|
|
|
{
|
|
|
|
/* they match, return */
|
|
|
|
stored_iter->destroy(stored_iter);
|
|
|
|
supplied_iter->destroy(supplied_iter);
|
2008-06-12 11:42:19 +00:00
|
|
|
DBG2(DBG_CFG, "received proposals: %#P", proposals);
|
|
|
|
DBG2(DBG_CFG, "configured proposals: %#P", this->proposals);
|
|
|
|
DBG2(DBG_CFG, "selected proposal: %P", selected);
|
2007-04-10 06:01:03 +00:00
|
|
|
return selected;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
/* no proposal match :-(, will result in a NO_PROPOSAL_CHOSEN... */
|
|
|
|
stored_iter->destroy(stored_iter);
|
|
|
|
supplied_iter->destroy(supplied_iter);
|
2008-06-12 11:42:19 +00:00
|
|
|
DBG1(DBG_CFG, "received proposals: %#P", proposals);
|
|
|
|
DBG1(DBG_CFG, "configured proposals: %#P", this->proposals);
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2007-04-10 06:01:03 +00:00
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Implementation of ike_cfg_t.get_dh_group.
|
|
|
|
*/
|
|
|
|
static diffie_hellman_group_t get_dh_group(private_ike_cfg_t *this)
|
|
|
|
{
|
2008-03-26 10:06:45 +00:00
|
|
|
enumerator_t *enumerator;
|
2007-04-10 06:01:03 +00:00
|
|
|
proposal_t *proposal;
|
2008-03-26 10:06:45 +00:00
|
|
|
u_int16_t dh_group = MODP_NONE;
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2008-03-26 10:06:45 +00:00
|
|
|
enumerator = this->proposals->create_enumerator(this->proposals);
|
|
|
|
while (enumerator->enumerate(enumerator, &proposal))
|
2007-04-10 06:01:03 +00:00
|
|
|
{
|
2008-03-26 10:06:45 +00:00
|
|
|
if (proposal->get_algorithm(proposal, DIFFIE_HELLMAN_GROUP, &dh_group, NULL))
|
2007-04-10 06:01:03 +00:00
|
|
|
{
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
2008-03-26 10:06:45 +00:00
|
|
|
enumerator->destroy(enumerator);
|
2007-04-10 06:01:03 +00:00
|
|
|
return dh_group;
|
|
|
|
}
|
|
|
|
|
2008-03-26 10:06:45 +00:00
|
|
|
/**
|
|
|
|
* Implementation of ike_cfg_t.equals.
|
|
|
|
*/
|
|
|
|
static bool equals(private_ike_cfg_t *this, private_ike_cfg_t *other)
|
|
|
|
{
|
|
|
|
enumerator_t *e1, *e2;
|
|
|
|
proposal_t *p1, *p2;
|
|
|
|
bool eq = TRUE;
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2008-03-26 10:06:45 +00:00
|
|
|
if (this == other)
|
|
|
|
{
|
|
|
|
return TRUE;
|
|
|
|
}
|
|
|
|
if (this->public.equals != other->public.equals)
|
|
|
|
{
|
|
|
|
return FALSE;
|
|
|
|
}
|
|
|
|
if (this->proposals->get_count(this->proposals) !=
|
|
|
|
other->proposals->get_count(other->proposals))
|
|
|
|
{
|
|
|
|
return FALSE;
|
|
|
|
}
|
|
|
|
e1 = this->proposals->create_enumerator(this->proposals);
|
|
|
|
e2 = this->proposals->create_enumerator(this->proposals);
|
|
|
|
while (e1->enumerate(e1, &p1) && e2->enumerate(e2, &p2))
|
|
|
|
{
|
|
|
|
if (!p1->equals(p1, p2))
|
|
|
|
{
|
|
|
|
eq = FALSE;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
e1->destroy(e1);
|
|
|
|
e2->destroy(e2);
|
|
|
|
|
|
|
|
return (eq &&
|
|
|
|
this->certreq == other->certreq &&
|
|
|
|
this->force_encap == other->force_encap &&
|
2008-06-06 15:05:54 +00:00
|
|
|
streq(this->me, other->me) &&
|
|
|
|
streq(this->other, other->other));
|
2008-03-26 10:06:45 +00:00
|
|
|
}
|
|
|
|
|
2007-04-10 06:01:03 +00:00
|
|
|
/**
|
|
|
|
* Implementation of ike_cfg_t.get_ref.
|
|
|
|
*/
|
2008-05-06 10:55:42 +00:00
|
|
|
static ike_cfg_t* get_ref(private_ike_cfg_t *this)
|
2007-04-10 06:01:03 +00:00
|
|
|
{
|
|
|
|
ref_get(&this->refcount);
|
2008-05-06 10:55:42 +00:00
|
|
|
return &this->public;
|
2007-04-10 06:01:03 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Implementation of ike_cfg_t.destroy.
|
|
|
|
*/
|
|
|
|
static void destroy(private_ike_cfg_t *this)
|
|
|
|
{
|
|
|
|
if (ref_put(&this->refcount))
|
|
|
|
{
|
|
|
|
this->proposals->destroy_offset(this->proposals,
|
|
|
|
offsetof(proposal_t, destroy));
|
2008-06-06 15:05:54 +00:00
|
|
|
free(this->me);
|
|
|
|
free(this->other);
|
2007-04-10 06:01:03 +00:00
|
|
|
free(this);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/**
|
|
|
|
* Described in header.
|
|
|
|
*/
|
2007-10-01 16:41:34 +00:00
|
|
|
ike_cfg_t *ike_cfg_create(bool certreq, bool force_encap,
|
2008-06-06 15:05:54 +00:00
|
|
|
char *me, char *other)
|
2007-04-10 06:01:03 +00:00
|
|
|
{
|
|
|
|
private_ike_cfg_t *this = malloc_thing(private_ike_cfg_t);
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2007-04-10 06:01:03 +00:00
|
|
|
/* public functions */
|
|
|
|
this->public.send_certreq = (bool(*)(ike_cfg_t*))send_certreq;
|
2007-10-01 16:41:34 +00:00
|
|
|
this->public.force_encap = (bool (*) (ike_cfg_t *))force_encap_meth;
|
2008-06-06 15:05:54 +00:00
|
|
|
this->public.get_my_addr = (char*(*)(ike_cfg_t*))get_my_addr;
|
|
|
|
this->public.get_other_addr = (char*(*)(ike_cfg_t*))get_other_addr;
|
2007-04-10 06:01:03 +00:00
|
|
|
this->public.add_proposal = (void(*)(ike_cfg_t*, proposal_t*)) add_proposal;
|
|
|
|
this->public.get_proposals = (linked_list_t*(*)(ike_cfg_t*))get_proposals;
|
|
|
|
this->public.select_proposal = (proposal_t*(*)(ike_cfg_t*,linked_list_t*))select_proposal;
|
|
|
|
this->public.get_dh_group = (diffie_hellman_group_t(*)(ike_cfg_t*)) get_dh_group;
|
2008-03-26 10:06:45 +00:00
|
|
|
this->public.equals = (bool(*)(ike_cfg_t*,ike_cfg_t*)) equals;
|
2008-05-06 10:55:42 +00:00
|
|
|
this->public.get_ref = (ike_cfg_t*(*)(ike_cfg_t*))get_ref;
|
2007-04-10 06:01:03 +00:00
|
|
|
this->public.destroy = (void(*)(ike_cfg_t*))destroy;
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2007-04-10 06:01:03 +00:00
|
|
|
/* private variables */
|
|
|
|
this->refcount = 1;
|
|
|
|
this->certreq = certreq;
|
2007-10-01 16:41:34 +00:00
|
|
|
this->force_encap = force_encap;
|
2008-06-06 15:05:54 +00:00
|
|
|
this->me = strdup(me);
|
|
|
|
this->other = strdup(other);
|
2007-04-10 06:01:03 +00:00
|
|
|
this->proposals = linked_list_create();
|
2009-09-04 11:46:09 +00:00
|
|
|
|
2007-04-10 06:01:03 +00:00
|
|
|
return &this->public;
|
|
|
|
}
|