Make access requestor IP address available to TNC server
This commit is contained in:
@@ -127,7 +127,8 @@ imv_policy_manager_SOURCES = \
|
||||
imv/imv_policy_manager.c \
|
||||
imv/imv_policy_manager_usage.h imv/imv_policy_manager_usage.c
|
||||
imv_policy_manager_LDADD = \
|
||||
$(top_builddir)/src/libstrongswan/libstrongswan.la
|
||||
$(top_builddir)/src/libstrongswan/libstrongswan.la \
|
||||
$(top_builddir)/src/libtncif/libtncif.la
|
||||
#imv/imv_policy_manager.o : $(top_builddir)/config.status
|
||||
|
||||
SUBDIRS = .
|
||||
|
||||
+21
-55
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2011-2014 Andreas Steffen
|
||||
* Copyright (C) 2011-2015 Andreas Steffen
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
@@ -412,14 +412,10 @@ METHOD(imv_agent_t, create_state, TNC_Result,
|
||||
{
|
||||
TNC_ConnectionID conn_id;
|
||||
char *tnccs_p = NULL, *tnccs_v = NULL, *t_p = NULL, *t_v = NULL;
|
||||
bool has_long = FALSE, has_excl = FALSE, has_soh = FALSE, first = TRUE;
|
||||
bool has_long = FALSE, has_excl = FALSE, has_soh = FALSE;
|
||||
linked_list_t *ar_identities;
|
||||
enumerator_t *enumerator;
|
||||
tncif_identity_t *tnc_id;
|
||||
imv_session_t *session;
|
||||
uint32_t max_msg_len;
|
||||
uint32_t ar_id_type = TNC_ID_UNKNOWN;
|
||||
chunk_t ar_id_value = chunk_empty;
|
||||
|
||||
conn_id = state->get_connection_id(state);
|
||||
if (find_connection(this, conn_id))
|
||||
@@ -431,15 +427,24 @@ METHOD(imv_agent_t, create_state, TNC_Result,
|
||||
}
|
||||
|
||||
/* Get and display attributes from TNCS via IF-IMV */
|
||||
has_long = get_bool_attribute(this, conn_id, TNC_ATTRIBUTEID_HAS_LONG_TYPES);
|
||||
has_excl = get_bool_attribute(this, conn_id, TNC_ATTRIBUTEID_HAS_EXCLUSIVE);
|
||||
has_soh = get_bool_attribute(this, conn_id, TNC_ATTRIBUTEID_HAS_SOH);
|
||||
tnccs_p = get_str_attribute(this, conn_id, TNC_ATTRIBUTEID_IFTNCCS_PROTOCOL);
|
||||
tnccs_v = get_str_attribute(this, conn_id, TNC_ATTRIBUTEID_IFTNCCS_VERSION);
|
||||
t_p = get_str_attribute(this, conn_id, TNC_ATTRIBUTEID_IFT_PROTOCOL);
|
||||
t_v = get_str_attribute(this, conn_id, TNC_ATTRIBUTEID_IFT_VERSION);
|
||||
max_msg_len = get_uint_attribute(this, conn_id, TNC_ATTRIBUTEID_MAX_MESSAGE_SIZE);
|
||||
ar_identities = get_identity_attribute(this, conn_id, TNC_ATTRIBUTEID_AR_IDENTITIES);
|
||||
has_long = get_bool_attribute(this, conn_id,
|
||||
TNC_ATTRIBUTEID_HAS_LONG_TYPES);
|
||||
has_excl = get_bool_attribute(this, conn_id,
|
||||
TNC_ATTRIBUTEID_HAS_EXCLUSIVE);
|
||||
has_soh = get_bool_attribute(this, conn_id,
|
||||
TNC_ATTRIBUTEID_HAS_SOH);
|
||||
tnccs_p = get_str_attribute(this, conn_id,
|
||||
TNC_ATTRIBUTEID_IFTNCCS_PROTOCOL);
|
||||
tnccs_v = get_str_attribute(this, conn_id,
|
||||
TNC_ATTRIBUTEID_IFTNCCS_VERSION);
|
||||
t_p = get_str_attribute(this, conn_id,
|
||||
TNC_ATTRIBUTEID_IFT_PROTOCOL);
|
||||
t_v = get_str_attribute(this, conn_id,
|
||||
TNC_ATTRIBUTEID_IFT_VERSION);
|
||||
max_msg_len = get_uint_attribute(this, conn_id,
|
||||
TNC_ATTRIBUTEID_MAX_MESSAGE_SIZE);
|
||||
ar_identities = get_identity_attribute(this, conn_id,
|
||||
TNC_ATTRIBUTEID_AR_IDENTITIES);
|
||||
|
||||
state->set_flags(state, has_long, has_excl);
|
||||
state->set_max_msg_len(state, max_msg_len);
|
||||
@@ -451,48 +456,9 @@ METHOD(imv_agent_t, create_state, TNC_Result,
|
||||
DBG2(DBG_IMV, " over %s %s with maximum PA-TNC message size of %u bytes",
|
||||
t_p ? t_p:"?", t_v ? t_v :"?", max_msg_len);
|
||||
|
||||
enumerator = ar_identities->create_enumerator(ar_identities);
|
||||
while (enumerator->enumerate(enumerator, &tnc_id))
|
||||
{
|
||||
pen_type_t id_type, subject_type, auth_type;
|
||||
uint32_t tcg_id_type, tcg_subject_type, tcg_auth_type;
|
||||
chunk_t id_value;
|
||||
|
||||
id_type = tnc_id->get_identity_type(tnc_id);
|
||||
id_value = tnc_id->get_identity_value(tnc_id);
|
||||
subject_type = tnc_id->get_subject_type(tnc_id);
|
||||
auth_type = tnc_id->get_auth_type(tnc_id);
|
||||
|
||||
tcg_id_type = (id_type.vendor_id == PEN_TCG) ?
|
||||
id_type.type : TNC_ID_UNKNOWN;
|
||||
tcg_subject_type = (subject_type.vendor_id == PEN_TCG) ?
|
||||
subject_type.type : TNC_SUBJECT_UNKNOWN;
|
||||
tcg_auth_type = (auth_type.vendor_id == PEN_TCG) ?
|
||||
auth_type.type : TNC_AUTH_UNKNOWN;
|
||||
|
||||
|
||||
DBG2(DBG_IMV, " %N AR identity '%.*s' authenticated by %N",
|
||||
TNC_Subject_names, tcg_subject_type,
|
||||
id_value.len, id_value.ptr,
|
||||
TNC_Authentication_names, tcg_auth_type);
|
||||
|
||||
/* keep the first access requestor ID */
|
||||
if (first)
|
||||
{
|
||||
ar_id_type = tcg_id_type;
|
||||
ar_id_value = id_value;
|
||||
first = FALSE;
|
||||
}
|
||||
}
|
||||
enumerator->destroy(enumerator);
|
||||
|
||||
session = imcv_sessions->add_session(imcv_sessions, conn_id,
|
||||
ar_id_type, ar_id_value);
|
||||
session = imcv_sessions->add_session(imcv_sessions, conn_id, ar_identities);
|
||||
state->set_session(state, session);
|
||||
|
||||
/* clean up temporary variables */
|
||||
ar_identities->destroy_offset(ar_identities,
|
||||
offsetof(tncif_identity_t, destroy));
|
||||
free(tnccs_p);
|
||||
free(tnccs_v);
|
||||
free(t_p);
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2013-2014 Andreas Steffen
|
||||
* Copyright (C) 2013-2015 Andreas Steffen
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
@@ -22,6 +22,8 @@
|
||||
|
||||
#include "imv_database.h"
|
||||
|
||||
#include <tncif_identity.h>
|
||||
|
||||
#include <utils/debug.h>
|
||||
#include <threading/mutex.h>
|
||||
|
||||
@@ -60,41 +62,14 @@ METHOD(imv_database_t, get_database, database_t*,
|
||||
*/
|
||||
static bool create_session(private_imv_database_t *this, imv_session_t *session)
|
||||
{
|
||||
enumerator_t *e;
|
||||
enumerator_t *enumerator, *e;
|
||||
imv_os_info_t *os_info;
|
||||
chunk_t device_id, ar_id_value;
|
||||
chunk_t device_id;
|
||||
tncif_identity_t *tnc_id;
|
||||
TNC_ConnectionID conn_id;
|
||||
uint32_t ar_id_type;
|
||||
char *product, *device;
|
||||
int session_id = 0, ar_id = 0, pid = 0, did = 0, trusted = 0, created;
|
||||
|
||||
ar_id_value = session->get_ar_id(session, &ar_id_type);
|
||||
if (ar_id_value.len)
|
||||
{
|
||||
/* get primary key of AR identity if it exists */
|
||||
e = this->db->query(this->db,
|
||||
"SELECT id FROM identities WHERE type = ? AND value = ?",
|
||||
DB_INT, ar_id_type, DB_BLOB, ar_id_value, DB_INT);
|
||||
if (e)
|
||||
{
|
||||
e->enumerate(e, &ar_id);
|
||||
e->destroy(e);
|
||||
}
|
||||
|
||||
/* if AR identity has not been found - register it */
|
||||
if (!ar_id)
|
||||
{
|
||||
this->db->execute(this->db, &ar_id,
|
||||
"INSERT INTO identities (type, value) VALUES (?, ?)",
|
||||
DB_INT, ar_id_type, DB_BLOB, ar_id_value);
|
||||
}
|
||||
|
||||
if (!ar_id)
|
||||
{
|
||||
DBG1(DBG_IMV, "imv_db: registering access requestor failed");
|
||||
return FALSE;
|
||||
}
|
||||
}
|
||||
int session_id = 0, pid = 0, did = 0, trusted = 0, created;
|
||||
bool first = TRUE, success = TRUE;
|
||||
|
||||
/* get product info string */
|
||||
os_info = session->get_os_info(session);
|
||||
@@ -170,10 +145,9 @@ static bool create_session(private_imv_database_t *this, imv_session_t *session)
|
||||
created = session->get_creation_time(session);
|
||||
conn_id = session->get_connection_id(session);
|
||||
this->db->execute(this->db, &session_id,
|
||||
"INSERT INTO sessions (time, connection, identity, product, device) "
|
||||
"VALUES (?, ?, ?, ?, ?)",
|
||||
DB_INT, created, DB_INT, conn_id, DB_INT, ar_id,
|
||||
DB_INT, pid, DB_INT, did);
|
||||
"INSERT INTO sessions (time, connection, product, device) "
|
||||
"VALUES (?, ?, ?, ?)",
|
||||
DB_INT, created, DB_INT, conn_id, DB_INT, pid, DB_INT, did);
|
||||
|
||||
if (session_id)
|
||||
{
|
||||
@@ -187,7 +161,68 @@ static bool create_session(private_imv_database_t *this, imv_session_t *session)
|
||||
}
|
||||
session->set_session_id(session, session_id, pid, did);
|
||||
|
||||
return TRUE;
|
||||
enumerator = session->create_ar_identities_enumerator(session);
|
||||
while (enumerator->enumerate(enumerator, &tnc_id))
|
||||
{
|
||||
pen_type_t ar_id_type;
|
||||
chunk_t ar_id_value;
|
||||
int ar_id = 0, si_id = 0;
|
||||
|
||||
ar_id_type = tnc_id->get_identity_type(tnc_id);
|
||||
ar_id_value = tnc_id->get_identity_value(tnc_id);
|
||||
|
||||
if (ar_id_type.vendor_id != PEN_TCG || ar_id_value.len == 0)
|
||||
{
|
||||
continue;
|
||||
}
|
||||
|
||||
/* get primary key of AR identity if it exists */
|
||||
e = this->db->query(this->db,
|
||||
"SELECT id FROM identities WHERE type = ? AND value = ?",
|
||||
DB_INT, ar_id_type.type, DB_BLOB, ar_id_value, DB_INT);
|
||||
if (e)
|
||||
{
|
||||
e->enumerate(e, &ar_id);
|
||||
e->destroy(e);
|
||||
}
|
||||
|
||||
/* if AR identity has not been found - register it */
|
||||
if (!ar_id)
|
||||
{
|
||||
this->db->execute(this->db, &ar_id,
|
||||
"INSERT INTO identities (type, value) VALUES (?, ?)",
|
||||
DB_INT, ar_id_type.type, DB_BLOB, ar_id_value);
|
||||
}
|
||||
if (!ar_id)
|
||||
{
|
||||
DBG1(DBG_IMV, "imv_db: registering access requestor failed");
|
||||
success = FALSE;
|
||||
break;
|
||||
}
|
||||
|
||||
this->db->execute(this->db, &si_id,
|
||||
"INSERT INTO sessions_identities (session_id, identity_id) "
|
||||
"VALUES (?, ?)",
|
||||
DB_INT, session_id, DB_INT, ar_id);
|
||||
|
||||
if (!si_id)
|
||||
{
|
||||
DBG1(DBG_IMV, "imv_db: assigning identity to session failed");
|
||||
success = FALSE;
|
||||
break;
|
||||
}
|
||||
|
||||
if (first)
|
||||
{
|
||||
this->db->execute(this->db, NULL,
|
||||
"UPDATE sessions SET identity = ? WHERE id = ?",
|
||||
DB_INT, ar_id, DB_INT, session_id);
|
||||
first = FALSE;
|
||||
}
|
||||
}
|
||||
enumerator->destroy(enumerator);
|
||||
|
||||
return success;
|
||||
}
|
||||
|
||||
static bool add_workitems(private_imv_database_t *this, imv_session_t *session)
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2013 Andreas Steffen
|
||||
* Copyright (C) 2013-2015 Andreas Steffen
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
@@ -19,6 +19,8 @@
|
||||
#include <library.h>
|
||||
#include <utils/debug.h>
|
||||
|
||||
#include <tncif_names.h>
|
||||
|
||||
#include <stdlib.h>
|
||||
#include <stdio.h>
|
||||
#include <time.h>
|
||||
@@ -251,9 +253,12 @@ static bool policy_start(database_t *db, int session_id)
|
||||
static bool policy_stop(database_t *db, int session_id)
|
||||
{
|
||||
enumerator_t *e;
|
||||
int rec, policy;
|
||||
char *result;
|
||||
int rec, policy, final_rec, id_type;
|
||||
chunk_t id_value;
|
||||
char *result, *ip_address = NULL;
|
||||
bool success = TRUE;
|
||||
|
||||
/* store all workitem results for this session in the results table */
|
||||
e = db->query(db,
|
||||
"SELECT w.rec_final, w.result, e.policy FROM workitems AS w "
|
||||
"JOIN enforcements AS e ON w.enforcement = e.id "
|
||||
@@ -270,9 +275,68 @@ static bool policy_stop(database_t *db, int session_id)
|
||||
}
|
||||
e->destroy(e);
|
||||
}
|
||||
return db->execute(db, NULL,
|
||||
"DELETE FROM workitems WHERE session = ?",
|
||||
DB_UINT, session_id) >= 0;
|
||||
else
|
||||
{
|
||||
success = FALSE;
|
||||
}
|
||||
|
||||
/* delete all workitems for this session from the database */
|
||||
if (db->execute(db, NULL,
|
||||
"DELETE FROM workitems WHERE session = ?",
|
||||
DB_UINT, session_id) < 0)
|
||||
{
|
||||
success = FALSE;
|
||||
}
|
||||
|
||||
final_rec = TNC_IMV_ACTION_RECOMMENDATION_NO_RECOMMENDATION;
|
||||
|
||||
/* retrieve the final recommendation for this session */
|
||||
e = db->query(db,
|
||||
"SELECT rec FROM sessions WHERE id = ?",
|
||||
DB_INT, session_id, DB_INT);
|
||||
if (e)
|
||||
{
|
||||
if (!e->enumerate(e, &final_rec))
|
||||
{
|
||||
success = FALSE;
|
||||
}
|
||||
e->destroy(e);
|
||||
}
|
||||
else
|
||||
{
|
||||
success = FALSE;
|
||||
}
|
||||
|
||||
/* retrieve client IP address for this session */
|
||||
e = db->query(db,
|
||||
"SELECT i.type, i.value FROM identities AS i "
|
||||
"JOIN sessions_identities AS si ON si.identity_id = i.id "
|
||||
"WHERE si.session_id = ? AND (i.type = ? OR i.type = ?)",
|
||||
DB_INT, session_id, DB_INT, TNC_ID_IPV4_ADDR, DB_INT,
|
||||
TNC_ID_IPV6_ADDR, DB_INT, DB_BLOB);
|
||||
if (e)
|
||||
{
|
||||
if (e->enumerate(e, &id_type, &id_value))
|
||||
{
|
||||
ip_address = strndup(id_value.ptr, id_value.len);
|
||||
}
|
||||
else
|
||||
{
|
||||
success = FALSE;
|
||||
}
|
||||
e->destroy(e);
|
||||
}
|
||||
else
|
||||
{
|
||||
success = FALSE;
|
||||
}
|
||||
|
||||
fprintf(stderr, "recommendation for access requestor %s is %N\n",
|
||||
ip_address ? ip_address : "0.0.0.0",
|
||||
TNC_IMV_Action_Recommendation_names, final_rec);
|
||||
free(ip_address);
|
||||
|
||||
return success;
|
||||
}
|
||||
|
||||
int main(int argc, char *argv[])
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2013 Andreas Steffen
|
||||
* Copyright (C) 2013-2015 Andreas Steffen
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
@@ -15,6 +15,8 @@
|
||||
|
||||
#include "imv_session.h"
|
||||
|
||||
#include <tncif_identity.h>
|
||||
|
||||
#include <utils/debug.h>
|
||||
|
||||
typedef struct private_imv_session_t private_imv_session_t;
|
||||
@@ -55,14 +57,9 @@ struct private_imv_session_t {
|
||||
time_t created;
|
||||
|
||||
/**
|
||||
* Access Requestor ID type
|
||||
* List of Access Requestor identities
|
||||
*/
|
||||
uint32_t ar_id_type;
|
||||
|
||||
/**
|
||||
* Access Requestor ID value
|
||||
*/
|
||||
chunk_t ar_id_value;
|
||||
linked_list_t *ar_identities;
|
||||
|
||||
/**
|
||||
* OS information
|
||||
@@ -130,14 +127,10 @@ METHOD(imv_session_t, get_creation_time, time_t,
|
||||
return this->created;
|
||||
}
|
||||
|
||||
METHOD(imv_session_t, get_ar_id, chunk_t,
|
||||
private_imv_session_t *this, uint32_t *ar_id_type)
|
||||
METHOD(imv_session_t, create_ar_identities_enumerator, enumerator_t*,
|
||||
private_imv_session_t *this)
|
||||
{
|
||||
if (ar_id_type)
|
||||
{
|
||||
*ar_id_type = this->ar_id_type;
|
||||
}
|
||||
return this->ar_id_value;
|
||||
return this->ar_identities->create_enumerator(this->ar_identities);
|
||||
}
|
||||
|
||||
METHOD(imv_session_t, get_os_info, imv_os_info_t*,
|
||||
@@ -256,7 +249,8 @@ METHOD(imv_session_t, destroy, void,
|
||||
this->workitems->destroy_offset(this->workitems,
|
||||
offsetof(imv_workitem_t, destroy));
|
||||
this->os_info->destroy(this->os_info);
|
||||
free(this->ar_id_value.ptr);
|
||||
this->ar_identities->destroy_offset(this->ar_identities,
|
||||
offsetof(tncif_identity_t, destroy));
|
||||
free(this->device_id.ptr);
|
||||
free(this);
|
||||
}
|
||||
@@ -266,7 +260,7 @@ METHOD(imv_session_t, destroy, void,
|
||||
* See header
|
||||
*/
|
||||
imv_session_t *imv_session_create(TNC_ConnectionID conn_id, time_t created,
|
||||
uint32_t ar_id_type, chunk_t ar_id_value)
|
||||
linked_list_t *ar_identities)
|
||||
{
|
||||
private_imv_session_t *this;
|
||||
|
||||
@@ -276,7 +270,7 @@ imv_session_t *imv_session_create(TNC_ConnectionID conn_id, time_t created,
|
||||
.get_session_id = _get_session_id,
|
||||
.get_connection_id = _get_connection_id,
|
||||
.get_creation_time = _get_creation_time,
|
||||
.get_ar_id = _get_ar_id,
|
||||
.create_ar_identities_enumerator = _create_ar_identities_enumerator,
|
||||
.get_os_info = _get_os_info,
|
||||
.set_device_id = _set_device_id,
|
||||
.get_device_id = _get_device_id,
|
||||
@@ -293,8 +287,7 @@ imv_session_t *imv_session_create(TNC_ConnectionID conn_id, time_t created,
|
||||
},
|
||||
.conn_id = conn_id,
|
||||
.created = created,
|
||||
.ar_id_type = ar_id_type,
|
||||
.ar_id_value = chunk_clone(ar_id_value),
|
||||
.ar_identities = ar_identities,
|
||||
.os_info = imv_os_info_create(),
|
||||
.workitems = linked_list_create(),
|
||||
.ref = 1,
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2013-2014 Andreas Steffen
|
||||
* Copyright (C) 2013-2015 Andreas Steffen
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
@@ -70,12 +70,11 @@ struct imv_session_t {
|
||||
time_t (*get_creation_time)(imv_session_t *this);
|
||||
|
||||
/**
|
||||
* Get Access Requestor ID
|
||||
* Get list of Access Requestor identities
|
||||
*
|
||||
* @param id_type Access Requestor TCG Standard ID Type
|
||||
* @return Access Requestor TCG Standard ID Value
|
||||
* @return List of Access Requestor identities
|
||||
*/
|
||||
chunk_t (*get_ar_id)(imv_session_t *this, uint32_t *id_type);
|
||||
enumerator_t* (*create_ar_identities_enumerator)(imv_session_t *this);
|
||||
|
||||
/**
|
||||
* Get OS Information
|
||||
@@ -172,10 +171,9 @@ struct imv_session_t {
|
||||
*
|
||||
* @param id Associated Connection ID
|
||||
* @param created Session creation time
|
||||
* @param ar_id_type Access Requestor ID type
|
||||
* @param ar_id_value Access Requestor ID value
|
||||
* @param ar_identities List of Access Requestor identities
|
||||
*/
|
||||
imv_session_t* imv_session_create(TNC_ConnectionID id, time_t created,
|
||||
uint32_t ar_id_type, chunk_t ar_id_value);
|
||||
linked_list_t *ar_identities);
|
||||
|
||||
#endif /** IMV_SESSION_H_ @}*/
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2014 Andreas Steffen
|
||||
* Copyright (C) 2014-2015 Andreas Steffen
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
@@ -15,6 +15,9 @@
|
||||
|
||||
#include "imv_session_manager.h"
|
||||
|
||||
#include <tncif_names.h>
|
||||
#include <tncif_identity.h>
|
||||
|
||||
#include <threading/mutex.h>
|
||||
|
||||
typedef struct private_imv_session_manager_t private_imv_session_manager_t;
|
||||
@@ -43,9 +46,10 @@ struct private_imv_session_manager_t {
|
||||
|
||||
METHOD(imv_session_manager_t, add_session, imv_session_t*,
|
||||
private_imv_session_manager_t *this, TNC_ConnectionID conn_id,
|
||||
uint32_t ar_id_type, chunk_t ar_id_value)
|
||||
linked_list_t *ar_identities)
|
||||
{
|
||||
enumerator_t *enumerator;
|
||||
tncif_identity_t *tnc_id;
|
||||
imv_session_t *current, *session = NULL;
|
||||
time_t created;
|
||||
|
||||
@@ -66,13 +70,43 @@ METHOD(imv_session_manager_t, add_session, imv_session_t*,
|
||||
/* session already exists */
|
||||
if (session)
|
||||
{
|
||||
ar_identities->destroy_offset(ar_identities,
|
||||
offsetof(tncif_identity_t, destroy));
|
||||
this->mutex->unlock(this->mutex);
|
||||
return session->get_ref(session);
|
||||
}
|
||||
|
||||
/* Output list of Access Requestor identities */
|
||||
enumerator = ar_identities->create_enumerator(ar_identities);
|
||||
while (enumerator->enumerate(enumerator, &tnc_id))
|
||||
{
|
||||
pen_type_t id_type, subject_type, auth_type;
|
||||
uint32_t tcg_id_type, tcg_subject_type, tcg_auth_type;
|
||||
chunk_t id_value;
|
||||
|
||||
id_type = tnc_id->get_identity_type(tnc_id);
|
||||
id_value = tnc_id->get_identity_value(tnc_id);
|
||||
subject_type = tnc_id->get_subject_type(tnc_id);
|
||||
auth_type = tnc_id->get_auth_type(tnc_id);
|
||||
|
||||
tcg_id_type = (subject_type.vendor_id == PEN_TCG) ?
|
||||
id_type.type : TNC_SUBJECT_UNKNOWN;
|
||||
tcg_subject_type = (subject_type.vendor_id == PEN_TCG) ?
|
||||
subject_type.type : TNC_SUBJECT_UNKNOWN;
|
||||
tcg_auth_type = (auth_type.vendor_id == PEN_TCG) ?
|
||||
auth_type.type : TNC_AUTH_UNKNOWN;
|
||||
|
||||
DBG2(DBG_IMV, " %N AR identity '%.*s' of type %N authenticated by %N",
|
||||
TNC_Subject_names, tcg_subject_type,
|
||||
id_value.len, id_value.ptr,
|
||||
TNC_Identity_names, tcg_id_type,
|
||||
TNC_Authentication_names, tcg_auth_type);
|
||||
}
|
||||
enumerator->destroy(enumerator);
|
||||
|
||||
/* create a new session entry */
|
||||
created = time(NULL);
|
||||
session = imv_session_create(conn_id, created, ar_id_type, ar_id_value);
|
||||
session = imv_session_create(conn_id, created, ar_identities);
|
||||
this->sessions->insert_last(this->sessions, session);
|
||||
|
||||
this->mutex->unlock(this->mutex);
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright (C) 2014 Andreas Steffen
|
||||
* Copyright (C) 2014-2015 Andreas Steffen
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
@@ -39,13 +39,12 @@ struct imv_session_manager_t {
|
||||
* Create or get a session associated with a TNCCS connection
|
||||
*
|
||||
* @param conn_id TNCCS Connection ID
|
||||
* @param ar_id_type Access Requestor identity type
|
||||
* @param ar_id_value Access Requestor identity value
|
||||
* @param ar_identities List of Access Requestor identities
|
||||
* @return Session associated with TNCCS Connection
|
||||
*/
|
||||
imv_session_t* (*add_session)(imv_session_manager_t *this,
|
||||
TNC_ConnectionID conn_id,
|
||||
uint32_t ar_id_type, chunk_t ar_id_value);
|
||||
linked_list_t *ar_identities);
|
||||
|
||||
/**
|
||||
* Remove a session
|
||||
|
||||
@@ -99,6 +99,14 @@ CREATE TABLE `sessions` (
|
||||
`rec` INTEGER DEFAULT 3
|
||||
);
|
||||
|
||||
DROP TABLE IF EXISTS `sessions_identities`;
|
||||
CREATE TABLE `sessions_identities` (
|
||||
`id` INTEGER NOT NULL PRIMARY KEY AUTO_INCREMENT,
|
||||
`session_id` INTEGER NOT NULL REFERENCES `sessions`(`id`),
|
||||
`identity_id` INTEGER NOT NULL REFERENCES `identities`(`id`),
|
||||
UNIQUE (`session_id`, `identity_id`)
|
||||
);
|
||||
|
||||
DROP TABLE IF EXISTS `workitems`;
|
||||
CREATE TABLE `workitems` (
|
||||
`id` INTEGER NOT NULL PRIMARY KEY AUTO_INCREMENT,
|
||||
|
||||
@@ -104,6 +104,14 @@ CREATE TABLE sessions (
|
||||
rec INTEGER DEFAULT 3
|
||||
);
|
||||
|
||||
DROP TABLE IF EXISTS sessions_identities;
|
||||
CREATE TABLE sessions_identities (
|
||||
id INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT,
|
||||
session_id INTEGER NOT NULL REFERENCES sessions(id),
|
||||
identity_id INTEGER NOT NULL REFERENCES identities(id),
|
||||
UNIQUE (session_id, identity_id)
|
||||
);
|
||||
|
||||
DROP TABLE IF EXISTS workitems;
|
||||
CREATE TABLE workitems (
|
||||
id INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT,
|
||||
|
||||
Reference in New Issue
Block a user