Handle invalid IKEv1 hashes more specifically.
This commit is contained in:
@@ -1942,7 +1942,7 @@ METHOD(message_t, parse_body, status_t,
|
||||
DBG1(DBG_ENC, "our hash does not match received %B",
|
||||
&other_hash);
|
||||
chunk_free(&hash);
|
||||
return VERIFY_ERROR;
|
||||
return FAILED;
|
||||
}
|
||||
DBG2(DBG_ENC, "verified IKEv1 message with hash %B", &hash);
|
||||
chunk_free(&hash);
|
||||
|
||||
@@ -51,6 +51,8 @@ enum notify_type_t {
|
||||
/* IKEv1 only */
|
||||
PAYLOAD_MALFORMED = 16,
|
||||
INVALID_KE_PAYLOAD = 17,
|
||||
/* IKEv1 only */
|
||||
INVALID_HASH_INFORMATION = 23,
|
||||
AUTHENTICATION_FAILED = 24,
|
||||
SINGLE_PAIR_REQUIRED = 34,
|
||||
NO_ADDITIONAL_SAS = 35,
|
||||
|
||||
@@ -717,7 +717,7 @@ static status_t parse_message(private_task_manager_t *this, message_t *msg)
|
||||
case FAILED:
|
||||
DBG1(DBG_IKE, "integrity check failed");
|
||||
send_notify_response(this, msg,
|
||||
PAYLOAD_MALFORMED, chunk_empty);
|
||||
INVALID_HASH_INFORMATION, chunk_empty);
|
||||
break;
|
||||
case INVALID_STATE:
|
||||
DBG1(DBG_IKE, "found encrypted message, but no keys available");
|
||||
|
||||
Reference in New Issue
Block a user