Added an option to prefer types sent by peer in eap-dynamic plugin

This commit is contained in:
Tobias Brunner
2012-08-31 11:42:03 +02:00
parent 3dde55e67b
commit 333c3b6228
+42 -14
View File
@@ -50,6 +50,11 @@ struct private_eap_dynamic_t {
*/ */
linked_list_t *other_types; linked_list_t *other_types;
/**
* Prefer types sent by peer
*/
bool prefer_peer;
/** /**
* The proxied EAP method * The proxied EAP method
*/ */
@@ -90,41 +95,60 @@ static eap_method_t *load_method(private_eap_dynamic_t *this,
} }
/** /**
* Select the first method we can instantiate and is (optionally) supported * Select the first method we can instantiate and is supported by both peers.
* by the client.
*/ */
static void select_method(private_eap_dynamic_t *this) static void select_method(private_eap_dynamic_t *this)
{ {
eap_vendor_type_t *entry; eap_vendor_type_t *entry;
linked_list_t *outer = this->types, *inner = this->other_types;
char *who = "peer";
while (this->types->remove_first(this->types, (void*)&entry) == SUCCESS) if (this->other_types && this->prefer_peer)
{ {
if (this->other_types) outer = this->other_types;
inner = this->types;
who = "us";
}
while (outer->remove_first(outer, (void*)&entry) == SUCCESS)
{
if (inner)
{ {
if (this->other_types->find_first(this->other_types, if (inner->find_first(inner, (void*)entry_matches,
(void*)entry_matches, NULL, entry) != SUCCESS) NULL, entry) != SUCCESS)
{ {
if (entry->vendor) if (entry->vendor)
{ {
DBG2(DBG_IKE, "skip vendor specific EAP method %d-%d not " DBG2(DBG_IKE, "proposed vendor specific EAP method %d-%d "
"supported by peer", entry->type, entry->vendor); "not supported by %s, skipped", entry->type,
entry->vendor, who);
} }
else else
{ {
DBG2(DBG_IKE, "skip %N method not supported by peer", DBG2(DBG_IKE, "proposed %N method not supported by %s, "
eap_type_names, entry->type); "skipped", eap_type_names, entry->type, who);
} }
free(entry); free(entry);
continue; continue;
} }
} }
this->method = load_method(this, entry->type, entry->vendor); this->method = load_method(this, entry->type, entry->vendor);
free(entry);
if (this->method) if (this->method)
{ {
if (entry->vendor)
{
DBG1(DBG_IKE, "vendor specific EAP method %d-%d selected",
entry->type, entry->vendor);
}
else
{
DBG1(DBG_IKE, "%N method selected", eap_type_names,
entry->type);
}
free(entry);
break; break;
} }
free(entry);
} }
} }
@@ -154,7 +178,9 @@ METHOD(eap_method_t, process, status_t,
{ {
enumerator_t *enumerator; enumerator_t *enumerator;
DBG1(DBG_IKE, "received %N", eap_type_names, EAP_NAK); DBG1(DBG_IKE, "received %N, selecting a different EAP method",
eap_type_names, EAP_NAK);
if (this->other_types) if (this->other_types)
{ /* we already received a Nak or a proper response before */ { /* we already received a Nak or a proper response before */
DBG1(DBG_IKE, "%N is not supported in this state", eap_type_names, DBG1(DBG_IKE, "%N is not supported in this state", eap_type_names,
@@ -350,13 +376,15 @@ eap_dynamic_t *eap_dynamic_create(identification_t *server,
.peer = peer->clone(peer), .peer = peer->clone(peer),
.server = server->clone(server), .server = server->clone(server),
.types = linked_list_create(), .types = linked_list_create(),
.prefer_peer = lib->settings->get_bool(lib->settings,
"%s.plugins.eap-dynamic.prefer_peer", FALSE, charon->name),
); );
/* get all supported EAP methods */ /* get all supported EAP methods */
get_supported_eap_types(this); get_supported_eap_types(this);
/* move preferred methods to the front */ /* move preferred methods to the front */
preferred = lib->settings->get_str(lib->settings, preferred = lib->settings->get_str(lib->settings,
"%s.plugins.eap-dynamic.preferred", NULL, charon->name); "%s.plugins.eap-dynamic.preferred", NULL, charon->name);
if (preferred) if (preferred)
{ {
handle_preferred_eap_types(this, preferred); handle_preferred_eap_types(this, preferred);