ike-auth: Support exchange between IKE_SA_INIT and IKE_AUTH

This commit is contained in:
Tobias Brunner
2022-06-29 10:28:50 +02:00
parent 09a4aed3a2
commit 28b33d7cac
+53 -22
View File
@@ -131,6 +131,11 @@ struct private_ike_auth_t {
*/ */
bool eap_acceptable; bool eap_acceptable;
/**
* Whether we already handled the first IKE_AUTH message
*/
bool first_auth;
/** /**
* Gateway ID if redirected * Gateway ID if redirected
*/ */
@@ -588,10 +593,20 @@ METHOD(task_t, build_i, status_t,
private_ike_auth_t *this, message_t *message) private_ike_auth_t *this, message_t *message)
{ {
auth_cfg_t *cfg; auth_cfg_t *cfg;
bool first_auth = FALSE;
if (message->get_exchange_type(message) == IKE_SA_INIT) switch (message->get_exchange_type(message))
{ {
return collect_my_init_data(this, message); case IKE_SA_INIT:
return collect_my_init_data(this, message);
case IKE_AUTH:
if (!this->first_auth)
{ /* some special handling for the first IKE_AUTH message below */
first_auth = this->first_auth = TRUE;
}
break;
default:
return NEED_MORE;
} }
if (!this->peer_cfg) if (!this->peer_cfg)
@@ -600,7 +615,7 @@ METHOD(task_t, build_i, status_t,
this->peer_cfg->get_ref(this->peer_cfg); this->peer_cfg->get_ref(this->peer_cfg);
} }
if (message->get_message_id(message) == 1) if (first_auth)
{ /* in the first IKE_AUTH ... */ { /* in the first IKE_AUTH ... */
if (this->ike_sa->supports_extension(this->ike_sa, EXT_MULTIPLE_AUTH)) if (this->ike_sa->supports_extension(this->ike_sa, EXT_MULTIPLE_AUTH))
{ /* indicate support for multiple authentication */ { /* indicate support for multiple authentication */
@@ -668,8 +683,7 @@ METHOD(task_t, build_i, status_t,
get_reserved_id_bytes(this, id_payload); get_reserved_id_bytes(this, id_payload);
message->add_payload(message, (payload_t*)id_payload); message->add_payload(message, (payload_t*)id_payload);
if (idr && !idr->contains_wildcards(idr) && if (idr && !idr->contains_wildcards(idr) && first_auth &&
message->get_message_id(message) == 1 &&
this->peer_cfg->get_unique_policy(this->peer_cfg) != UNIQUE_NEVER) this->peer_cfg->get_unique_policy(this->peer_cfg) != UNIQUE_NEVER)
{ {
host_t *host; host_t *host;
@@ -744,9 +758,14 @@ METHOD(task_t, process_r, status_t,
id_payload_t *id_payload; id_payload_t *id_payload;
identification_t *id; identification_t *id;
if (message->get_exchange_type(message) == IKE_SA_INIT) switch (message->get_exchange_type(message))
{ {
return collect_other_init_data(this, message); case IKE_SA_INIT:
return collect_other_init_data(this, message);
case IKE_AUTH:
break;
default:
return NEED_MORE;
} }
if (!this->my_auth && this->do_another_auth) if (!this->my_auth && this->do_another_auth)
@@ -769,7 +788,7 @@ METHOD(task_t, process_r, status_t,
return NEED_MORE; return NEED_MORE;
} }
if (message->get_message_id(message) == 1) if (!this->first_auth)
{ /* check for extensions in the first IKE_AUTH */ { /* check for extensions in the first IKE_AUTH */
if (message->get_notify(message, MULTIPLE_AUTH_SUPPORTED)) if (message->get_notify(message, MULTIPLE_AUTH_SUPPORTED))
{ {
@@ -784,6 +803,7 @@ METHOD(task_t, process_r, status_t,
{ {
this->initial_contact = TRUE; this->initial_contact = TRUE;
} }
this->first_auth = TRUE;
} }
if (!this->other_auth) if (!this->other_auth)
@@ -950,14 +970,19 @@ METHOD(task_t, build_r, status_t,
identification_t *gateway; identification_t *gateway;
auth_cfg_t *cfg; auth_cfg_t *cfg;
if (message->get_exchange_type(message) == IKE_SA_INIT) switch (message->get_exchange_type(message))
{ {
if (multiple_auth_enabled()) case IKE_SA_INIT:
{ if (multiple_auth_enabled())
message->add_notify(message, FALSE, MULTIPLE_AUTH_SUPPORTED, {
chunk_empty); message->add_notify(message, FALSE, MULTIPLE_AUTH_SUPPORTED,
} chunk_empty);
return collect_my_init_data(this, message); }
return collect_my_init_data(this, message);
case IKE_AUTH:
break;
default:
return NEED_MORE;
} }
if (this->authentication_failed || !this->peer_cfg) if (this->authentication_failed || !this->peer_cfg)
@@ -1225,14 +1250,19 @@ METHOD(task_t, process_i, status_t,
auth_cfg_t *cfg; auth_cfg_t *cfg;
bool mutual_eap = FALSE, ppk_id_received = FALSE; bool mutual_eap = FALSE, ppk_id_received = FALSE;
if (message->get_exchange_type(message) == IKE_SA_INIT) switch (message->get_exchange_type(message))
{ {
if (message->get_notify(message, MULTIPLE_AUTH_SUPPORTED) && case IKE_SA_INIT:
multiple_auth_enabled()) if (message->get_notify(message, MULTIPLE_AUTH_SUPPORTED) &&
{ multiple_auth_enabled())
this->ike_sa->enable_extension(this->ike_sa, EXT_MULTIPLE_AUTH); {
} this->ike_sa->enable_extension(this->ike_sa, EXT_MULTIPLE_AUTH);
return collect_other_init_data(this, message); }
return collect_other_init_data(this, message);
case IKE_AUTH:
break;
default:
return NEED_MORE;
} }
enumerator = message->create_payload_enumerator(message); enumerator = message->create_payload_enumerator(message);
@@ -1514,6 +1544,7 @@ METHOD(task_t, migrate, void,
this->expect_another_auth = TRUE; this->expect_another_auth = TRUE;
this->authentication_failed = FALSE; this->authentication_failed = FALSE;
this->candidates = linked_list_create(); this->candidates = linked_list_create();
this->first_auth = FALSE;
} }
METHOD(task_t, destroy, void, METHOD(task_t, destroy, void,