moved TNCCS layer out of eap_tnc plugin

This commit is contained in:
Andreas Steffen 2010-09-28 23:34:04 +02:00
parent 280c8ea2f0
commit 4e8e74fcfa
17 changed files with 460 additions and 48 deletions

View File

@ -115,6 +115,7 @@ ARG_ENABL_SET([eap-tls], [enable EAP TLS authentication module.])
ARG_ENABL_SET([eap-ttls], [enable EAP TTLS authentication module.])
ARG_ENABL_SET([eap-tnc], [enable EAP TNC trusted network connect module.])
ARG_ENABL_SET([eap-radius], [enable RADIUS proxy authentication module.])
ARG_ENABL_SET([tnccs-11], [enable TNCCS 1.1 protocol module.])
ARG_DISBL_SET([kernel-netlink], [disable the netlink kernel interface.])
ARG_ENABL_SET([kernel-pfkey], [enable the PF_KEY kernel interface.])
ARG_ENABL_SET([kernel-pfroute], [enable the PF_ROUTE kernel interface.])
@ -754,6 +755,7 @@ ADD_PLUGIN([eap-radius], [c libcharon])
ADD_PLUGIN([eap-tls], [c libcharon])
ADD_PLUGIN([eap-ttls], [c libcharon])
ADD_PLUGIN([eap-tnc], [c libcharon])
ADD_PLUGIN([tnccs-11], [c libcharon])
ADD_PLUGIN([medsrv], [c libcharon])
ADD_PLUGIN([medcli], [c libcharon])
ADD_PLUGIN([nm], [c libcharon])
@ -850,6 +852,7 @@ AM_CONDITIONAL(USE_EAP_TLS, test x$eap_tls = xtrue)
AM_CONDITIONAL(USE_EAP_TTLS, test x$eap_ttls = xtrue)
AM_CONDITIONAL(USE_EAP_TNC, test x$eap_tnc = xtrue)
AM_CONDITIONAL(USE_EAP_RADIUS, test x$eap_radius = xtrue)
AM_CONDITIONAL(USE_TNCCS_11, test x$tnccs_11 = xtrue)
AM_CONDITIONAL(USE_SOCKET_DEFAULT, test x$socket_default = xtrue)
AM_CONDITIONAL(USE_SOCKET_RAW, test x$socket_raw = xtrue)
AM_CONDITIONAL(USE_SOCKET_DYNAMIC, test x$socket_dynamic = xtrue)
@ -987,6 +990,7 @@ AC_OUTPUT(
src/libcharon/plugins/eap_ttls/Makefile
src/libcharon/plugins/eap_tnc/Makefile
src/libcharon/plugins/eap_radius/Makefile
src/libcharon/plugins/tnccs_11/Makefile
src/libcharon/plugins/socket_default/Makefile
src/libcharon/plugins/socket_raw/Makefile
src/libcharon/plugins/socket_dynamic/Makefile

View File

@ -86,7 +86,9 @@ sa/tasks/ike_rekey.c sa/tasks/ike_rekey.h \
sa/tasks/ike_reauth.c sa/tasks/ike_reauth.h \
sa/tasks/ike_auth_lifetime.c sa/tasks/ike_auth_lifetime.h \
sa/tasks/ike_vendor.c sa/tasks/ike_vendor.h \
sa/tasks/task.c sa/tasks/task.h
sa/tasks/task.c sa/tasks/task.h \
tnccs/tnccs.c tnccs/tnccs.h \
tnccs/tnccs_manager.h tnccs/tnccs_manager.c
daemon.lo : $(top_builddir)/config.status
@ -312,6 +314,13 @@ if MONOLITHIC
endif
endif
if USE_TNCCS_11
SUBDIRS += plugins/tnccs_11
if MONOLITHIC
libcharon_la_LIBADD += plugins/eap_tnc/libstrongswan-tnccs-11.la
endif
endif
if USE_MEDSRV
SUBDIRS += plugins/medsrv
if MONOLITHIC

View File

@ -120,6 +120,7 @@ static void destroy(private_daemon_t *this)
DESTROY_IF(this->public.controller);
DESTROY_IF(this->public.eap);
DESTROY_IF(this->public.sim);
DESTROY_IF(this->public.tnccs);
#ifdef ME
DESTROY_IF(this->public.connect_manager);
DESTROY_IF(this->public.mediation_manager);
@ -365,6 +366,7 @@ METHOD(daemon_t, initialize, bool,
this->public.controller = controller_create();
this->public.eap = eap_manager_create();
this->public.sim = sim_manager_create();
this->public.tnccs = tnccs_manager_create();
this->public.backends = backend_manager_create();
this->public.socket = socket_manager_create();
this->public.traps = trap_manager_create();

View File

@ -149,6 +149,7 @@ typedef struct daemon_t daemon_t;
#include <config/backend_manager.h>
#include <sa/authenticators/eap/eap_manager.h>
#include <sa/authenticators/eap/sim_manager.h>
#include <tnccs/tnccs_manager.h>
#ifdef ME
#include <sa/connect_manager.h>
@ -235,6 +236,11 @@ struct daemon_t {
*/
sim_manager_t *sim;
/**
* TNCCS manager to maintain registered TNCCS protocols
*/
tnccs_manager_t *tnccs;
#ifdef ME
/**
* Connect manager

View File

@ -12,7 +12,6 @@ libstrongswan_eap_tnc_la_LIBADD = $(top_builddir)/src/libtls/libtls.la
endif
libstrongswan_eap_tnc_la_SOURCES = \
eap_tnc_plugin.h eap_tnc_plugin.c eap_tnc.h eap_tnc.c \
tnc_if_tnccs.h tnc_if_tnccs.c
eap_tnc_plugin.h eap_tnc_plugin.c eap_tnc.h eap_tnc.c
libstrongswan_eap_tnc_la_LDFLAGS = -module -avoid-version

View File

@ -1,6 +1,6 @@
/*
* Copyright (C) 2010 Andreas Steffen
* Hochschule fuer Technik Rapperswil
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
@ -14,7 +14,6 @@
*/
#include "eap_tnc.h"
#include "tnc_if_tnccs.h"
#include <tls_eap.h>
@ -115,7 +114,7 @@ static eap_tnc_t *eap_tnc_create(identification_t *server,
private_eap_tnc_t *this;
size_t frag_size;
int max_msg_count;
tls_t *tnc_if_tnccs;
tnccs_t *tnccs;
INIT(this,
.public = {
@ -134,8 +133,8 @@ static eap_tnc_t *eap_tnc_create(identification_t *server,
"charon.plugins.eap-tnc.fragment_size", MAX_FRAGMENT_LEN);
max_msg_count = lib->settings->get_int(lib->settings,
"charon.plugins.eap-tnc.max_message_count", MAX_MESSAGE_COUNT);
tnc_if_tnccs = tnc_if_tnccs_create(is_server, TLS_PURPOSE_EAP_TNC);
this->tls_eap = tls_eap_create(EAP_TNC, tnc_if_tnccs, frag_size, max_msg_count);
tnccs = charon->tnccs->create_instance(charon->tnccs, TNCCS_1_1, is_server);
this->tls_eap = tls_eap_create(EAP_TNC, (tls_t*)tnccs, frag_size, max_msg_count);
if (!this->tls_eap)
{
free(this);

View File

@ -0,0 +1,17 @@
INCLUDES = -I$(top_srcdir)/src/libstrongswan -I$(top_srcdir)/src/libhydra \
-I$(top_srcdir)/src/libcharon -I$(top_srcdir)/src/libtls
AM_CFLAGS = -rdynamic
if MONOLITHIC
noinst_LTLIBRARIES = libstrongswan-tnccs-11.la
else
plugin_LTLIBRARIES = libstrongswan-tnccs-11.la
libstrongswan_tnccs_11_la_LIBADD = $(top_builddir)/src/libtls/libtls.la
endif
libstrongswan_tnccs_11_la_SOURCES = \
tnccs_11_plugin.h tnccs_11_plugin.c tnccs_11.h tnccs_11.c
libstrongswan_tnccs_11_la_LDFLAGS = -module -avoid-version

View File

@ -1,6 +1,6 @@
/*
* Copyright (C) 2010 Andreas Steffen
* Copyright (C) 2010 HSR Hochschule fuer Technik Rapperswil
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
@ -13,16 +13,16 @@
* for more details.
*/
#include "tnc_if_tnccs.h"
#include "tnccs_11.h"
#include <debug.h>
typedef struct private_tnc_if_tnccs_t private_tnc_if_tnccs_t;
typedef struct private_tnccs_11_t private_tnccs_11_t;
/**
* Private data of a tnc_if_tnccs_t object.
* Private data of a tnccs_11_t object.
*/
struct private_tnc_if_tnccs_t {
struct private_tnccs_11_t {
/**
* Public tls_t interface.
@ -30,18 +30,13 @@ struct private_tnc_if_tnccs_t {
tls_t public;
/**
* Role this TNC IF-TNCCS stack acts as.
* Role this TNCCS protocol stack acts as.
*/
bool is_server;
/**
* TLS stack purpose, as given to constructor
*/
tls_purpose_t purpose;
};
METHOD(tls_t, process, status_t,
private_tnc_if_tnccs_t *this, void *buf, size_t buflen)
private_tnccs_11_t *this, void *buf, size_t buflen)
{
chunk_t in = { buf, buflen };
@ -51,7 +46,7 @@ METHOD(tls_t, process, status_t,
}
METHOD(tls_t, build, status_t,
private_tnc_if_tnccs_t *this, void *buf, size_t *buflen, size_t *msglen)
private_tnccs_11_t *this, void *buf, size_t *buflen, size_t *msglen)
{
char output[] =
"<?xml version=\"1.0\"?>\n"
@ -75,32 +70,32 @@ METHOD(tls_t, build, status_t,
}
METHOD(tls_t, is_server, bool,
private_tnc_if_tnccs_t *this)
private_tnccs_11_t *this)
{
return this->is_server;
}
METHOD(tls_t, get_purpose, tls_purpose_t,
private_tnc_if_tnccs_t *this)
private_tnccs_11_t *this)
{
return this->purpose;
return TLS_PURPOSE_EAP_TNC;
}
METHOD(tls_t, is_complete, bool,
private_tnc_if_tnccs_t *this)
private_tnccs_11_t *this)
{
/* TODO */
return FALSE;
}
METHOD(tls_t, get_eap_msk, chunk_t,
private_tnc_if_tnccs_t *this)
private_tnccs_11_t *this)
{
return chunk_empty;
}
METHOD(tls_t, destroy, void,
private_tnc_if_tnccs_t *this)
private_tnccs_11_t *this)
{
free(this);
}
@ -108,17 +103,9 @@ METHOD(tls_t, destroy, void,
/**
* See header
*/
tls_t *tnc_if_tnccs_create(bool is_server, tls_purpose_t purpose)
tls_t *tnccs_11_create(bool is_server)
{
private_tnc_if_tnccs_t *this;
switch (purpose)
{
case TLS_PURPOSE_EAP_TNC:
break;
default:
return NULL;
}
private_tnccs_11_t *this;
INIT(this,
.public = {
@ -131,7 +118,6 @@ tls_t *tnc_if_tnccs_create(bool is_server, tls_purpose_t purpose)
.destroy = _destroy,
},
.is_server = is_server,
.purpose = purpose,
);
return &this->public;

View File

@ -1,6 +1,6 @@
/*
* Copyright (C) 2010 Andreas Steffen
* Hochschule fuer Technik Rapperswil
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
@ -14,12 +14,12 @@
*/
/**
* @defgroup tnc_if_tnccs tnc_if_tnccs
* @{ @ingroup tnc_if_tnccs
* @defgroup tnccs_11 tnccs_11
* @{ @ingroup tnccs_11
*/
#ifndef TNC_IF_TNCCS_H_
#define TNC_IF_TNCCS_H_
#ifndef TNCCS_11_H_
#define TNCCS_11_H_
#include <library.h>
@ -28,10 +28,9 @@
/**
* Create an instance of the TNC IF-TNCCS 1.1 protocol handler.
*
* @param is_server TRUE to act as server, FALSE for client
* @param purpose purpose this TLS stack instance is used for
* @return TNC_IF_TNCCS stack
* @param is_server TRUE to act as TNC Server, FALSE for TNC Client
* @return TNC_IF_TNCCS 1.1 protocol stack
*/
tls_t *tnc_if_tnccs_create(bool is_server, tls_purpose_t purpose);
tls_t *tnccs_11_create(bool is_server);
#endif /** TNC_IF_TNCCS_H_ @}*/
#endif /** TNCCS_11_H_ @}*/

View File

@ -0,0 +1,47 @@
/*
* Copyright (C) 2010 Andreas Steffen
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#include "tnccs_11_plugin.h"
#include "tnccs_11.h"
#include <daemon.h>
METHOD(plugin_t, destroy, void,
tnccs_11_plugin_t *this)
{
charon->tnccs->remove_method(charon->tnccs,
(tnccs_constructor_t)tnccs_11_create);
free(this);
}
/*
* see header file
*/
plugin_t *tnccs_11_plugin_create()
{
tnccs_11_plugin_t *this;
INIT(this,
.plugin = {
.destroy = _destroy,
},
);
charon->tnccs->add_method(charon->tnccs, TNCCS_1_1,
(tnccs_constructor_t)tnccs_11_create);
return &this->plugin;
}

View File

@ -0,0 +1,42 @@
/*
* Copyright (C) 2010 Andreas Steffen
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup tnccs_11 tnccs_11
* @ingroup cplugins
*
* @defgroup tnccs_11_plugin tnccs_11_plugin
* @{ @ingroup tnccs_11
*/
#ifndef TNCCS_11_PLUGIN_H_
#define TNCCS_11_PLUGIN_H_
#include <plugins/plugin.h>
typedef struct tnccs_11_plugin_t tnccs_11_plugin_t;
/**
* EAP-TNC plugin
*/
struct tnccs_11_plugin_t {
/**
* implements plugin interface
*/
plugin_t plugin;
};
#endif /** TNCCS_11_PLUGIN_H_ @}*/

View File

@ -0,0 +1,22 @@
/*
* Copyright (C) 2010 Andreas Steffen
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#include "tnccs.h"
ENUM(eap_type_names, TNCCS_1_1, TNCCS_2_0,
"TNCCS 1.1",
"TNCCS SOH",
"TNCCS 2.0",
);

View File

@ -0,0 +1,52 @@
/*
* Copyright (C) 2010 Andreas Steffen
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup tnccs tnccs
* @{ @ingroup libcharon
*/
#ifndef TNCCS_H_
#define TNCCS_H_
typedef enum tnccs_type_t tnccs_type_t;
#include <library.h>
/**
* Type of TNC Client/Server protocol
*/
enum tnccs_type_t {
TNCCS_1_1,
TNCCS_SOH,
TNCCS_2_0
};
/**
* enum names for tnccs_type_t.
*/
extern enum_name_t *tnccs_type_names;
typedef struct tnccs_t tnccs_t;
/**
* Constructor definition for a pluggable TNCCS protocol implementation.
*
* @is_server TRUE if TNC Server, FALSE if TNC Client
* @return implementation of the tnccs_t interface
*/
typedef tnccs_t* (*tnccs_constructor_t)(bool is_server);
#endif /** TNC_H_ @}*/

View File

@ -0,0 +1,148 @@
/*
* Copyright (C) 2010 Andreas Steffen
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#include "tnccs_manager.h"
#include <utils/linked_list.h>
#include <threading/rwlock.h>
typedef struct private_tnccs_manager_t private_tnccs_manager_t;
typedef struct tnccs_entry_t tnccs_entry_t;
/**
* TNCCS constructor entry
*/
struct tnccs_entry_t {
/**
* TNCCS protocol type
*/
tnccs_type_t type;
/**
* constructor function to create instance
*/
tnccs_constructor_t constructor;
};
/**
* private data of tnccs_manager
*/
struct private_tnccs_manager_t {
/**
* public functions
*/
tnccs_manager_t public;
/**
* list of tnccs_entry_t's
*/
linked_list_t *protocols;
/**
* rwlock to lock methods
*/
rwlock_t *lock;
};
METHOD(tnccs_manager_t, add_method, void,
private_tnccs_manager_t *this, tnccs_type_t type,
tnccs_constructor_t constructor)
{
tnccs_entry_t *entry = malloc_thing(tnccs_entry_t);
entry->type = type;
entry->constructor = constructor;
this->lock->write_lock(this->lock);
this->protocols->insert_last(this->protocols, entry);
this->lock->unlock(this->lock);
}
METHOD(tnccs_manager_t, remove_method, void,
private_tnccs_manager_t *this, tnccs_constructor_t constructor)
{
enumerator_t *enumerator;
tnccs_entry_t *entry;
this->lock->write_lock(this->lock);
enumerator = this->protocols->create_enumerator(this->protocols);
while (enumerator->enumerate(enumerator, &entry))
{
if (constructor == entry->constructor)
{
this->protocols->remove_at(this->protocols, enumerator);
free(entry);
}
}
enumerator->destroy(enumerator);
this->lock->unlock(this->lock);
}
METHOD(tnccs_manager_t, create_instance, tnccs_t*,
private_tnccs_manager_t *this, tnccs_type_t type, bool is_server)
{
enumerator_t *enumerator;
tnccs_entry_t *entry;
tnccs_t *protocol = NULL;
this->lock->read_lock(this->lock);
enumerator = this->protocols->create_enumerator(this->protocols);
while (enumerator->enumerate(enumerator, &entry))
{
if (type == entry->type)
{
protocol = entry->constructor(is_server);
if (protocol)
{
break;
}
}
}
enumerator->destroy(enumerator);
this->lock->unlock(this->lock);
return protocol;
}
METHOD(tnccs_manager_t, destroy, void,
private_tnccs_manager_t *this)
{
this->protocols->destroy_function(this->protocols, free);
this->lock->destroy(this->lock);
free(this);
}
/*
* See header
*/
tnccs_manager_t *tnccs_manager_create()
{
private_tnccs_manager_t *this;
INIT(this,
.public = {
.add_method = _add_method,
.remove_method = _remove_method,
.create_instance = _create_instance,
.destroy = _destroy,
},
.protocols = linked_list_create(),
.lock = rwlock_create(RWLOCK_TYPE_DEFAULT),
);
return &this->public;
}

View File

@ -0,0 +1,74 @@
/*
* Copyright (C) 2010 Andreas Steffen
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup tnccs_manager tnccs_manager
* @{ @ingroup tnccs
*/
#ifndef TNCCS_MANAGER_H_
#define TNCCS_MANAGER_H_
#include "tnccs.h"
typedef struct tnccs_manager_t tnccs_manager_t;
/**
* The TNCCS manager manages all TNCCS implementations and creates instances.
*
* A plugin registers its implemented TNCCS protocol with the manager by
* providing type and a constructor function. The manager then creates
* TNCCS protocol instances via the provided constructor.
*/
struct tnccs_manager_t {
/**
* Register a TNCCS protocol implementation.
*
* @param type TNCCS protocol type
* @param constructor constructor, returns a TNCCS protocol implementation
*/
void (*add_method)(tnccs_manager_t *this, tnccs_type_t type,
tnccs_constructor_t constructor);
/**
* Unregister a TNCCS protocol implementation using it's constructor.
*
* @param constructor constructor function to remove, as added in add_method
*/
void (*remove_method)(tnccs_manager_t *this, tnccs_constructor_t constructor);
/**
* Create a new TNCCS protocol instance.
*
* @param type type of the TNCCS protocol
* @is_server TRUE if TNC Server, FALSE if TNC Client
* @return TNCCS protocol instance, NULL if no constructor found
*/
tnccs_t* (*create_instance)(tnccs_manager_t *this, tnccs_type_t type,
bool is_server);
/**
* Destroy a tnccs_manager instance.
*/
void (*destroy)(tnccs_manager_t *this);
};
/**
* Create a tnccs_manager instance.
*/
tnccs_manager_t *tnccs_manager_create();
#endif /** TNCCS_MANAGER_H_ @}*/

View File

@ -187,6 +187,11 @@ then
echo -n " --enable-eap-tnc" >> $INSTALLSHELL
fi
if [ "$USE_TNCCS_11" = "yes" ]
then
echo -n " --enable-tnccs-11" >> $INSTALLSHELL
fi
if [ "$USE_SQL" = "yes" ]
then
echo -n " --enable-sql --enable-sqlite" >> $INSTALLSHELL

View File

@ -45,6 +45,7 @@ USE_EAP_RADIUS="yes"
USE_EAP_TLS="yes"
USE_EAP_TTLS="yes"
USE_EAP_TNC="yes"
USE_TNCCS_11="yes"
USE_SQL="yes"
USE_MEDIATION="yes"
USE_OPENSSL="yes"