ike-cert-post: Make absolutely sure certificates are only added to IKE_AUTH
The AUTH payload check in build_certs() should be fine, but add some extra checks just to make really sure and also for clarification.
This commit is contained in:
@@ -255,8 +255,10 @@ static void build_certs(private_ike_cert_post_t *this, message_t *message)
|
|||||||
METHOD(task_t, build_i, status_t,
|
METHOD(task_t, build_i, status_t,
|
||||||
private_ike_cert_post_t *this, message_t *message)
|
private_ike_cert_post_t *this, message_t *message)
|
||||||
{
|
{
|
||||||
build_certs(this, message);
|
if (message->get_exchange_type(message) == IKE_AUTH)
|
||||||
|
{
|
||||||
|
build_certs(this, message);
|
||||||
|
}
|
||||||
return NEED_MORE;
|
return NEED_MORE;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -269,8 +271,10 @@ METHOD(task_t, process_r, status_t,
|
|||||||
METHOD(task_t, build_r, status_t,
|
METHOD(task_t, build_r, status_t,
|
||||||
private_ike_cert_post_t *this, message_t *message)
|
private_ike_cert_post_t *this, message_t *message)
|
||||||
{
|
{
|
||||||
build_certs(this, message);
|
if (message->get_exchange_type(message) == IKE_AUTH)
|
||||||
|
{
|
||||||
|
build_certs(this, message);
|
||||||
|
}
|
||||||
if (this->ike_sa->get_state(this->ike_sa) != IKE_ESTABLISHED)
|
if (this->ike_sa->get_state(this->ike_sa) != IKE_ESTABLISHED)
|
||||||
{ /* stay alive, we might have additional rounds with certs */
|
{ /* stay alive, we might have additional rounds with certs */
|
||||||
return NEED_MORE;
|
return NEED_MORE;
|
||||||
|
|||||||
Reference in New Issue
Block a user