proposal: Don't return a default IKE proposal without encryption/AEAD algs

This commit is contained in:
Martin Willi
2014-05-16 16:51:19 +02:00
parent 8d74ec9e80
commit 2f893f278d
+23 -3
View File
@@ -627,7 +627,7 @@ proposal_t *proposal_create(protocol_id_t protocol, u_int number)
/** /**
* Add supported IKE algorithms to proposal * Add supported IKE algorithms to proposal
*/ */
static void proposal_add_supported_ike(private_proposal_t *this, bool aead) static bool proposal_add_supported_ike(private_proposal_t *this, bool aead)
{ {
enumerator_t *enumerator; enumerator_t *enumerator;
encryption_algorithm_t encryption; encryption_algorithm_t encryption;
@@ -662,6 +662,11 @@ static void proposal_add_supported_ike(private_proposal_t *this, bool aead)
} }
} }
enumerator->destroy(enumerator); enumerator->destroy(enumerator);
if (!array_count(this->transforms))
{
return FALSE;
}
} }
else else
{ {
@@ -691,6 +696,11 @@ static void proposal_add_supported_ike(private_proposal_t *this, bool aead)
} }
enumerator->destroy(enumerator); enumerator->destroy(enumerator);
if (!array_count(this->transforms))
{
return FALSE;
}
enumerator = lib->crypto->create_signer_enumerator(lib->crypto); enumerator = lib->crypto->create_signer_enumerator(lib->crypto);
while (enumerator->enumerate(enumerator, &integrity, &plugin_name)) while (enumerator->enumerate(enumerator, &integrity, &plugin_name))
{ {
@@ -772,6 +782,8 @@ static void proposal_add_supported_ike(private_proposal_t *this, bool aead)
} }
} }
enumerator->destroy(enumerator); enumerator->destroy(enumerator);
return TRUE;
} }
/* /*
@@ -784,7 +796,11 @@ proposal_t *proposal_create_default(protocol_id_t protocol)
switch (protocol) switch (protocol)
{ {
case PROTO_IKE: case PROTO_IKE:
proposal_add_supported_ike(this, FALSE); if (!proposal_add_supported_ike(this, FALSE))
{
destroy(this);
return NULL;
}
break; break;
case PROTO_ESP: case PROTO_ESP:
add_algorithm(this, ENCRYPTION_ALGORITHM, ENCR_AES_CBC, 128); add_algorithm(this, ENCRYPTION_ALGORITHM, ENCR_AES_CBC, 128);
@@ -820,7 +836,11 @@ proposal_t *proposal_create_default_aead(protocol_id_t protocol)
{ {
case PROTO_IKE: case PROTO_IKE:
this = (private_proposal_t*)proposal_create(protocol, 0); this = (private_proposal_t*)proposal_create(protocol, 0);
proposal_add_supported_ike(this, TRUE); if (!proposal_add_supported_ike(this, TRUE))
{
destroy(this);
return NULL;
}
return &this->public; return &this->public;
case PROTO_ESP: case PROTO_ESP:
/* we currently don't include any AEAD proposal for ESP, as we /* we currently don't include any AEAD proposal for ESP, as we