ike-auth: Support exchange between IKE_SA_INIT and IKE_AUTH
This commit is contained in:
@@ -131,6 +131,11 @@ struct private_ike_auth_t {
|
|||||||
*/
|
*/
|
||||||
bool eap_acceptable;
|
bool eap_acceptable;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Whether we already handled the first IKE_AUTH message
|
||||||
|
*/
|
||||||
|
bool first_auth;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Gateway ID if redirected
|
* Gateway ID if redirected
|
||||||
*/
|
*/
|
||||||
@@ -588,10 +593,20 @@ METHOD(task_t, build_i, status_t,
|
|||||||
private_ike_auth_t *this, message_t *message)
|
private_ike_auth_t *this, message_t *message)
|
||||||
{
|
{
|
||||||
auth_cfg_t *cfg;
|
auth_cfg_t *cfg;
|
||||||
|
bool first_auth = FALSE;
|
||||||
|
|
||||||
if (message->get_exchange_type(message) == IKE_SA_INIT)
|
switch (message->get_exchange_type(message))
|
||||||
{
|
{
|
||||||
return collect_my_init_data(this, message);
|
case IKE_SA_INIT:
|
||||||
|
return collect_my_init_data(this, message);
|
||||||
|
case IKE_AUTH:
|
||||||
|
if (!this->first_auth)
|
||||||
|
{ /* some special handling for the first IKE_AUTH message below */
|
||||||
|
first_auth = this->first_auth = TRUE;
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
return NEED_MORE;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!this->peer_cfg)
|
if (!this->peer_cfg)
|
||||||
@@ -600,7 +615,7 @@ METHOD(task_t, build_i, status_t,
|
|||||||
this->peer_cfg->get_ref(this->peer_cfg);
|
this->peer_cfg->get_ref(this->peer_cfg);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (message->get_message_id(message) == 1)
|
if (first_auth)
|
||||||
{ /* in the first IKE_AUTH ... */
|
{ /* in the first IKE_AUTH ... */
|
||||||
if (this->ike_sa->supports_extension(this->ike_sa, EXT_MULTIPLE_AUTH))
|
if (this->ike_sa->supports_extension(this->ike_sa, EXT_MULTIPLE_AUTH))
|
||||||
{ /* indicate support for multiple authentication */
|
{ /* indicate support for multiple authentication */
|
||||||
@@ -668,8 +683,7 @@ METHOD(task_t, build_i, status_t,
|
|||||||
get_reserved_id_bytes(this, id_payload);
|
get_reserved_id_bytes(this, id_payload);
|
||||||
message->add_payload(message, (payload_t*)id_payload);
|
message->add_payload(message, (payload_t*)id_payload);
|
||||||
|
|
||||||
if (idr && !idr->contains_wildcards(idr) &&
|
if (idr && !idr->contains_wildcards(idr) && first_auth &&
|
||||||
message->get_message_id(message) == 1 &&
|
|
||||||
this->peer_cfg->get_unique_policy(this->peer_cfg) != UNIQUE_NEVER)
|
this->peer_cfg->get_unique_policy(this->peer_cfg) != UNIQUE_NEVER)
|
||||||
{
|
{
|
||||||
host_t *host;
|
host_t *host;
|
||||||
@@ -744,9 +758,14 @@ METHOD(task_t, process_r, status_t,
|
|||||||
id_payload_t *id_payload;
|
id_payload_t *id_payload;
|
||||||
identification_t *id;
|
identification_t *id;
|
||||||
|
|
||||||
if (message->get_exchange_type(message) == IKE_SA_INIT)
|
switch (message->get_exchange_type(message))
|
||||||
{
|
{
|
||||||
return collect_other_init_data(this, message);
|
case IKE_SA_INIT:
|
||||||
|
return collect_other_init_data(this, message);
|
||||||
|
case IKE_AUTH:
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
return NEED_MORE;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!this->my_auth && this->do_another_auth)
|
if (!this->my_auth && this->do_another_auth)
|
||||||
@@ -769,7 +788,7 @@ METHOD(task_t, process_r, status_t,
|
|||||||
return NEED_MORE;
|
return NEED_MORE;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (message->get_message_id(message) == 1)
|
if (!this->first_auth)
|
||||||
{ /* check for extensions in the first IKE_AUTH */
|
{ /* check for extensions in the first IKE_AUTH */
|
||||||
if (message->get_notify(message, MULTIPLE_AUTH_SUPPORTED))
|
if (message->get_notify(message, MULTIPLE_AUTH_SUPPORTED))
|
||||||
{
|
{
|
||||||
@@ -784,6 +803,7 @@ METHOD(task_t, process_r, status_t,
|
|||||||
{
|
{
|
||||||
this->initial_contact = TRUE;
|
this->initial_contact = TRUE;
|
||||||
}
|
}
|
||||||
|
this->first_auth = TRUE;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!this->other_auth)
|
if (!this->other_auth)
|
||||||
@@ -950,14 +970,19 @@ METHOD(task_t, build_r, status_t,
|
|||||||
identification_t *gateway;
|
identification_t *gateway;
|
||||||
auth_cfg_t *cfg;
|
auth_cfg_t *cfg;
|
||||||
|
|
||||||
if (message->get_exchange_type(message) == IKE_SA_INIT)
|
switch (message->get_exchange_type(message))
|
||||||
{
|
{
|
||||||
if (multiple_auth_enabled())
|
case IKE_SA_INIT:
|
||||||
{
|
if (multiple_auth_enabled())
|
||||||
message->add_notify(message, FALSE, MULTIPLE_AUTH_SUPPORTED,
|
{
|
||||||
chunk_empty);
|
message->add_notify(message, FALSE, MULTIPLE_AUTH_SUPPORTED,
|
||||||
}
|
chunk_empty);
|
||||||
return collect_my_init_data(this, message);
|
}
|
||||||
|
return collect_my_init_data(this, message);
|
||||||
|
case IKE_AUTH:
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
return NEED_MORE;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (this->authentication_failed || !this->peer_cfg)
|
if (this->authentication_failed || !this->peer_cfg)
|
||||||
@@ -1225,14 +1250,19 @@ METHOD(task_t, process_i, status_t,
|
|||||||
auth_cfg_t *cfg;
|
auth_cfg_t *cfg;
|
||||||
bool mutual_eap = FALSE, ppk_id_received = FALSE;
|
bool mutual_eap = FALSE, ppk_id_received = FALSE;
|
||||||
|
|
||||||
if (message->get_exchange_type(message) == IKE_SA_INIT)
|
switch (message->get_exchange_type(message))
|
||||||
{
|
{
|
||||||
if (message->get_notify(message, MULTIPLE_AUTH_SUPPORTED) &&
|
case IKE_SA_INIT:
|
||||||
multiple_auth_enabled())
|
if (message->get_notify(message, MULTIPLE_AUTH_SUPPORTED) &&
|
||||||
{
|
multiple_auth_enabled())
|
||||||
this->ike_sa->enable_extension(this->ike_sa, EXT_MULTIPLE_AUTH);
|
{
|
||||||
}
|
this->ike_sa->enable_extension(this->ike_sa, EXT_MULTIPLE_AUTH);
|
||||||
return collect_other_init_data(this, message);
|
}
|
||||||
|
return collect_other_init_data(this, message);
|
||||||
|
case IKE_AUTH:
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
return NEED_MORE;
|
||||||
}
|
}
|
||||||
|
|
||||||
enumerator = message->create_payload_enumerator(message);
|
enumerator = message->create_payload_enumerator(message);
|
||||||
@@ -1514,6 +1544,7 @@ METHOD(task_t, migrate, void,
|
|||||||
this->expect_another_auth = TRUE;
|
this->expect_another_auth = TRUE;
|
||||||
this->authentication_failed = FALSE;
|
this->authentication_failed = FALSE;
|
||||||
this->candidates = linked_list_create();
|
this->candidates = linked_list_create();
|
||||||
|
this->first_auth = FALSE;
|
||||||
}
|
}
|
||||||
|
|
||||||
METHOD(task_t, destroy, void,
|
METHOD(task_t, destroy, void,
|
||||||
|
|||||||
Reference in New Issue
Block a user