ikev1: Use actual local identity as initiator or aggressive mode responder

If none is configured, there is a fallback to the IP address, which is
not stored on the static auth config, but is set on the IKE_SA.

Fixes #3394.
This commit is contained in:
Tobias Brunner
2020-05-07 15:05:55 +02:00
parent b8f02fc42d
commit 1665a4e050
+2 -6
View File
@@ -143,11 +143,10 @@ static shared_key_t *lookup_shared_key(private_phase1_t *this,
if (peer_cfg) if (peer_cfg)
{ /* as initiator or aggressive responder, use identities */ { /* as initiator or aggressive responder, use identities */
my_auth = get_auth_cfg(peer_cfg, TRUE);
other_auth = get_auth_cfg(peer_cfg, FALSE); other_auth = get_auth_cfg(peer_cfg, FALSE);
if (my_auth && other_auth) if (other_auth)
{ {
my_id = my_auth->get(my_auth, AUTH_RULE_IDENTITY); my_id = this->ike_sa->get_my_id(this->ike_sa);
if (peer_cfg->use_aggressive(peer_cfg)) if (peer_cfg->use_aggressive(peer_cfg))
{ {
other_id = this->ike_sa->get_other_id(this->ike_sa); other_id = this->ike_sa->get_other_id(this->ike_sa);
@@ -156,12 +155,9 @@ static shared_key_t *lookup_shared_key(private_phase1_t *this,
{ {
other_id = other_auth->get(other_auth, AUTH_RULE_IDENTITY); other_id = other_auth->get(other_auth, AUTH_RULE_IDENTITY);
} }
if (my_id)
{
shared_key = find_shared_key(my_id, me, other_id, other); shared_key = find_shared_key(my_id, me, other_id, other);
} }
} }
}
else else
{ /* as responder, we try to find a config by IP addresses and use the { /* as responder, we try to find a config by IP addresses and use the
* configured identities to find the PSK */ * configured identities to find the PSK */