Indicate and dected support for EAP-only authentication

This commit is contained in:
Martin Willi
2010-01-07 14:30:28 +01:00
parent cdad91de49
commit 12fca6cc9f
2 changed files with 28 additions and 7 deletions
+5
View File
@@ -91,6 +91,11 @@ enum ike_extension_t {
* peer uses strongSwan, accept private use extensions * peer uses strongSwan, accept private use extensions
*/ */
EXT_STRONGSWAN = (1<<4), EXT_STRONGSWAN = (1<<4),
/**
* peer supports EAP-only authentication, draft-eronen-ipsec-ikev2-eap-auth
*/
EXT_EAP_ONLY_AUTHENTICATION = (1<<5),
}; };
/** /**
+23 -7
View File
@@ -347,10 +347,16 @@ static status_t build_i(private_ike_auth_t *this, message_t *message)
this->peer_cfg->get_ref(this->peer_cfg); this->peer_cfg->get_ref(this->peer_cfg);
} }
if (message->get_message_id(message) == 1 && if (message->get_message_id(message) == 1)
this->ike_sa->supports_extension(this->ike_sa, EXT_MULTIPLE_AUTH)) { /* in the first IKE_AUTH ... */
{ /* in the first IKE_AUTH, indicate support for multiple authentication */ if (this->ike_sa->supports_extension(this->ike_sa, EXT_MULTIPLE_AUTH))
message->add_notify(message, FALSE, MULTIPLE_AUTH_SUPPORTED, chunk_empty); { /* indicate support for multiple authentication */
message->add_notify(message, FALSE, MULTIPLE_AUTH_SUPPORTED,
chunk_empty);
}
/* indicate support for EAP-only authentication */
message->add_notify(message, FALSE, EAP_ONLY_AUTHENTICATION,
chunk_empty);
} }
if (!this->do_another_auth && !this->my_auth) if (!this->do_another_auth && !this->my_auth)
@@ -468,9 +474,19 @@ static status_t process_r(private_ike_auth_t *this, message_t *message)
{ {
return NEED_MORE; return NEED_MORE;
} }
if (message->get_notify(message, MULTIPLE_AUTH_SUPPORTED))
{ if (message->get_message_id(message) == 1)
this->ike_sa->enable_extension(this->ike_sa, EXT_MULTIPLE_AUTH); { /* check for extensions in the first IKE_AUTH */
if (message->get_notify(message, MULTIPLE_AUTH_SUPPORTED))
{
this->ike_sa->enable_extension(this->ike_sa, EXT_MULTIPLE_AUTH);
}
if (this->ike_sa->supports_extension(this->ike_sa, EXT_STRONGSWAN) &&
message->get_notify(message, EAP_ONLY_AUTHENTICATION))
{ /* EAP-only has no official notify, accept only from strongSwan */
this->ike_sa->enable_extension(this->ike_sa,
EXT_EAP_ONLY_AUTHENTICATION);
}
} }
if (this->other_auth == NULL) if (this->other_auth == NULL)