Make access requestor IP address available to TNC server

This commit is contained in:
Andreas Steffen
2015-03-08 17:17:11 +01:00
parent 8b2af616ac
commit 00cd79b678
24 changed files with 550 additions and 244 deletions
+24 -2
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2010-2013 Andreas Steffen
* Copyright (C) 2010-2015 Andreas Steffen
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
@@ -256,6 +256,8 @@ static eap_tnc_t *eap_tnc_create(identification_t *server,
private_eap_tnc_t *this;
int max_msg_count;
char* protocol;
ike_sa_t *ike_sa;
host_t *server_ip, *peer_ip;
tnccs_t *tnccs;
tnccs_type_t tnccs_type;
@@ -302,8 +304,28 @@ static eap_tnc_t *eap_tnc_create(identification_t *server,
free(this);
return NULL;
}
/* Determine IP addresses of server and peer */
ike_sa = charon->bus->get_sa(charon->bus);
if (!ike_sa)
{
DBG1(DBG_TNC, "%N constructor did not find IKE_SA",
eap_type_names, type);
return NULL;
}
if (is_server)
{
server_ip = ike_sa->get_my_host(ike_sa);
peer_ip = ike_sa->get_other_host(ike_sa);
}
else
{
peer_ip = ike_sa->get_my_host(ike_sa);
server_ip = ike_sa->get_other_host(ike_sa);
}
tnccs = tnc->tnccs->create_instance(tnc->tnccs, tnccs_type,
is_server, server, peer,
is_server, server, peer, server_ip, peer_ip,
(type == EAP_TNC) ? TNC_IFT_EAP_1_1 : TNC_IFT_EAP_2_0,
is_server ? enforce_recommendation : NULL);
if (!tnccs)
+15 -10
View File
@@ -1,5 +1,5 @@
/*
* Copyright (C) 2012-2013 Andreas Steffen
* Copyright (C) 2012-2015 Andreas Steffen
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
@@ -646,8 +646,8 @@ static bool pt_tls_receive(private_tnc_pdp_t *this, int fd, watcher_event_t even
int pt_tls_fd;
struct sockaddr_storage addr;
socklen_t addrlen = sizeof(addr);
identification_t *peer;
host_t *host;
identification_t *client_id;
host_t *server_ip, *client_ip;
pt_tls_server_t *pt_tls;
tnccs_t *tnccs;
pt_tls_auth_t auth = PT_TLS_AUTH_TLS_OR_SASL;
@@ -658,17 +658,22 @@ static bool pt_tls_receive(private_tnc_pdp_t *this, int fd, watcher_event_t even
DBG1(DBG_TNC, "accepting PT-TLS stream failed: %s", strerror(errno));
return FALSE;
}
host = host_create_from_sockaddr((sockaddr_t*)&addr);
DBG1(DBG_TNC, "accepting PT-TLS stream from %H", host);
host->destroy(host);
client_ip = host_create_from_sockaddr((sockaddr_t*)&addr);
DBG1(DBG_TNC, "accepting PT-TLS stream from %H", client_ip);
/* At this moment the peer identity is not known yet */
peer = identification_create_from_encoding(ID_ANY, chunk_empty),
/* Currently we do not determine the IP address of the server interface */
server_ip = host_create_any(client_ip->get_family(client_ip));
/* At this moment the client identity is not known yet */
client_id = identification_create_from_encoding(ID_ANY, chunk_empty),
tnccs = tnc->tnccs->create_instance(tnc->tnccs, TNCCS_2_0, TRUE,
this->server, peer, TNC_IFT_TLS_2_0,
this->server, client_id, server_ip,
client_ip, TNC_IFT_TLS_2_0,
(tnccs_cb_t)get_recommendation);
peer->destroy(peer);
client_id->destroy(client_id);
server_ip->destroy(server_ip);
client_ip->destroy(client_ip);
if (!tnccs)
{