- code cleaned up
This commit is contained in:
+78
-39
@@ -285,7 +285,8 @@ static status_t process_message (private_ike_sa_t *this, message_t *message)
|
||||
is_request = message->get_request(message);
|
||||
exchange_type = message->get_exchange_type(message);
|
||||
|
||||
this->logger->log(this->logger, CONTROL, "Process %s message of exchange type %s",(is_request) ? "REQUEST" : "RESPONSE",mapping_find(exchange_type_m,exchange_type));
|
||||
this->logger->log(this->logger, CONTROL, "Process %s message of exchange type %s",
|
||||
(is_request) ? "REQUEST" : "RESPONSE",mapping_find(exchange_type_m,exchange_type));
|
||||
|
||||
message_id = message->get_message_id(message);
|
||||
|
||||
@@ -305,7 +306,9 @@ static status_t process_message (private_ike_sa_t *this, message_t *message)
|
||||
/* In a request, the message has to be this->message_id_in (other case is already handled) */
|
||||
if (message_id != this->message_id_in)
|
||||
{
|
||||
this->logger->log(this->logger, ERROR | LEVEL1, "Message request with message id %d received, but %d expected",message_id,this->message_id_in);
|
||||
this->logger->log(this->logger, ERROR | LEVEL1,
|
||||
"Message request with message id %d received, but %d expected",
|
||||
message_id,this->message_id_in);
|
||||
return FAILED;
|
||||
}
|
||||
}
|
||||
@@ -314,7 +317,9 @@ static status_t process_message (private_ike_sa_t *this, message_t *message)
|
||||
/* In a reply, the message has to be this->message_id_out -1 cause it is the reply to the last sent message*/
|
||||
if (message_id != (this->message_id_out - 1))
|
||||
{
|
||||
this->logger->log(this->logger, ERROR | LEVEL1, "Message reply with message id %d received, but %d expected",message_id,this->message_id_in);
|
||||
this->logger->log(this->logger, ERROR | LEVEL1,
|
||||
"Message reply with message id %d received, but %d expected",
|
||||
message_id,this->message_id_in);
|
||||
return FAILED;
|
||||
}
|
||||
}
|
||||
@@ -379,7 +384,10 @@ static ike_sa_id_t* get_id(private_ike_sa_t *this)
|
||||
/**
|
||||
* Implementation of protected_ike_sa_t.compute_secrets.
|
||||
*/
|
||||
static void compute_secrets(private_ike_sa_t *this,chunk_t dh_shared_secret,chunk_t initiator_nonce, chunk_t responder_nonce)
|
||||
static void compute_secrets(private_ike_sa_t *this,
|
||||
chunk_t dh_shared_secret,
|
||||
chunk_t initiator_nonce,
|
||||
chunk_t responder_nonce)
|
||||
{
|
||||
u_int8_t ei_buffer[this->crypter_initiator->get_block_size(this->crypter_initiator)];
|
||||
chunk_t ei_key = {ptr: ei_buffer, len: sizeof(ei_buffer)};
|
||||
@@ -454,10 +462,14 @@ static void compute_secrets(private_ike_sa_t *this,chunk_t dh_shared_secret,chun
|
||||
this->logger->log_chunk(this->logger, PRIVATE, "Sk_er secret", &(er_key));
|
||||
this->crypter_responder->set_key(this->crypter_responder,er_key);
|
||||
|
||||
prf_plus->allocate_bytes(prf_plus,this->crypter_responder->get_block_size(this->crypter_responder),&(this->secrets.pi_key));
|
||||
prf_plus->allocate_bytes(prf_plus,
|
||||
this->crypter_responder->get_block_size(this->crypter_responder),
|
||||
&(this->secrets.pi_key));
|
||||
this->logger->log_chunk(this->logger, PRIVATE, "Sk_pi secret", &(this->secrets.pi_key));
|
||||
|
||||
prf_plus->allocate_bytes(prf_plus,this->crypter_responder->get_block_size(this->crypter_responder),&(this->secrets.pr_key));
|
||||
prf_plus->allocate_bytes(prf_plus,
|
||||
this->crypter_responder->get_block_size(this->crypter_responder),
|
||||
&(this->secrets.pr_key));
|
||||
this->logger->log_chunk(this->logger, PRIVATE, "Sk_pr secret", &(this->secrets.pr_key));
|
||||
|
||||
prf_plus->destroy(prf_plus);
|
||||
@@ -619,11 +631,17 @@ static chunk_t get_key_pi (private_ike_sa_t *this)
|
||||
*/
|
||||
static status_t create_transforms_from_proposal (private_ike_sa_t *this,ike_proposal_t *proposal)
|
||||
{
|
||||
this->logger->log(this->logger, CONTROL|LEVEL1, "Going to create transform objects for proposal");
|
||||
this->logger->log(this->logger, CONTROL|LEVEL2, "Going to create transform objects for proposal");
|
||||
|
||||
this->logger->log(this->logger, CONTROL|LEVEL1, "Encryption algorithm: %s with keylength %d",mapping_find(encryption_algorithm_m,proposal->encryption_algorithm),proposal->encryption_algorithm_key_length);
|
||||
this->logger->log(this->logger, CONTROL|LEVEL1, "integrity algorithm: %s with keylength %d",mapping_find(integrity_algorithm_m,proposal->integrity_algorithm),proposal->integrity_algorithm_key_length);
|
||||
this->logger->log(this->logger, CONTROL|LEVEL1, "prf: %s with keylength %d",mapping_find(pseudo_random_function_m,proposal->pseudo_random_function),proposal->pseudo_random_function_key_length);
|
||||
this->logger->log(this->logger, CONTROL|LEVEL2, "Encryption algorithm: %s with keylength %d",
|
||||
mapping_find(encryption_algorithm_m,proposal->encryption_algorithm),
|
||||
proposal->encryption_algorithm_key_length);
|
||||
this->logger->log(this->logger, CONTROL|LEVEL2, "Integrity algorithm: %s with keylength %d",
|
||||
mapping_find(integrity_algorithm_m,proposal->integrity_algorithm),
|
||||
proposal->integrity_algorithm_key_length);
|
||||
this->logger->log(this->logger, CONTROL|LEVEL2, "PRF: %s with keylength %d",
|
||||
mapping_find(pseudo_random_function_m,proposal->pseudo_random_function),
|
||||
proposal->pseudo_random_function_key_length);
|
||||
|
||||
if (this->prf != NULL)
|
||||
{
|
||||
@@ -632,7 +650,8 @@ static status_t create_transforms_from_proposal (private_ike_sa_t *this,ike_prop
|
||||
this->prf = prf_create(proposal->pseudo_random_function);
|
||||
if (this->prf == NULL)
|
||||
{
|
||||
this->logger->log(this->logger, ERROR|LEVEL1, "prf not supported!");
|
||||
this->logger->log(this->logger, ERROR|LEVEL1, "PRF %s not supported!",
|
||||
mapping_find(pseudo_random_function_m,proposal->pseudo_random_function));
|
||||
return FAILED;
|
||||
}
|
||||
|
||||
@@ -640,10 +659,11 @@ static status_t create_transforms_from_proposal (private_ike_sa_t *this,ike_prop
|
||||
{
|
||||
this->crypter_initiator->destroy(this->crypter_initiator);
|
||||
}
|
||||
this->crypter_initiator = crypter_create(proposal->encryption_algorithm,proposal->encryption_algorithm_key_length);
|
||||
this->crypter_initiator = crypter_create(proposal->encryption_algorithm,
|
||||
proposal->encryption_algorithm_key_length);
|
||||
if (this->crypter_initiator == NULL)
|
||||
{
|
||||
this->logger->log(this->logger, ERROR|LEVEL1, "encryption algorithm %s not supported!",
|
||||
this->logger->log(this->logger, ERROR|LEVEL1, "Encryption algorithm %s not supported!",
|
||||
mapping_find(encryption_algorithm_m,proposal->encryption_algorithm));
|
||||
return FAILED;
|
||||
}
|
||||
@@ -652,7 +672,8 @@ static status_t create_transforms_from_proposal (private_ike_sa_t *this,ike_prop
|
||||
{
|
||||
this->crypter_responder->destroy(this->crypter_responder);
|
||||
}
|
||||
this->crypter_responder = crypter_create(proposal->encryption_algorithm,proposal->encryption_algorithm_key_length);
|
||||
this->crypter_responder = crypter_create(proposal->encryption_algorithm,
|
||||
proposal->encryption_algorithm_key_length);
|
||||
/* check must not be done again */
|
||||
|
||||
if (this->signer_initiator != NULL)
|
||||
@@ -662,7 +683,8 @@ static status_t create_transforms_from_proposal (private_ike_sa_t *this,ike_prop
|
||||
this->signer_initiator = signer_create(proposal->integrity_algorithm);
|
||||
if (this->signer_initiator == NULL)
|
||||
{
|
||||
this->logger->log(this->logger, ERROR|LEVEL1, "integrity algorithm not supported!");
|
||||
this->logger->log(this->logger, ERROR|LEVEL1, "Integrity algorithm %s not supported!",
|
||||
mapping_find(integrity_algorithm_m,proposal->integrity_algorithm));
|
||||
return FAILED;
|
||||
}
|
||||
|
||||
@@ -742,7 +764,9 @@ static status_t send_request (private_ike_sa_t *this,message_t * message)
|
||||
return FAILED;
|
||||
}
|
||||
|
||||
this->logger->log(this->logger, CONTROL|LEVEL2, "Add packet to global send queue");
|
||||
this->logger->log(this->logger, CONTROL|LEVEL3,
|
||||
"Add request packet with message id %d to global send queue",
|
||||
this->message_id_out);
|
||||
charon->send_queue->add(charon->send_queue, packet);
|
||||
|
||||
if (this->last_requested_message != NULL)
|
||||
@@ -751,12 +775,13 @@ static status_t send_request (private_ike_sa_t *this,message_t * message)
|
||||
this->last_requested_message->destroy(this->last_requested_message);
|
||||
}
|
||||
|
||||
this->logger->log(this->logger, CONTROL|LEVEL2, "replace last requested message with new one");
|
||||
this->logger->log(this->logger, CONTROL|LEVEL3, "Replace last requested message with new one");
|
||||
this->last_requested_message = message;
|
||||
|
||||
retransmit_job = retransmit_request_job_create(this->message_id_out,this->ike_sa_id);
|
||||
|
||||
status = charon->configuration_manager->get_retransmit_timeout (charon->configuration_manager,retransmit_job->get_retransmit_count(retransmit_job),&timeout);
|
||||
status = charon->configuration_manager->get_retransmit_timeout (charon->configuration_manager,
|
||||
retransmit_job->get_retransmit_count(retransmit_job),&timeout);
|
||||
|
||||
if (status != SUCCESS)
|
||||
{
|
||||
@@ -770,7 +795,9 @@ static status_t send_request (private_ike_sa_t *this,message_t * message)
|
||||
}
|
||||
|
||||
/* message counter can now be increased */
|
||||
this->logger->log(this->logger, CONTROL|LEVEL2, "Increase message counter for outgoing messages from %d",this->message_id_out);
|
||||
this->logger->log(this->logger, CONTROL|LEVEL3,
|
||||
"Increase message counter for outgoing messages from %d",
|
||||
this->message_id_out);
|
||||
this->message_id_out++;
|
||||
return SUCCESS;
|
||||
}
|
||||
@@ -785,7 +812,7 @@ static status_t send_response (private_ike_sa_t *this,message_t * message)
|
||||
|
||||
if (message->get_message_id(message) != this->message_id_in)
|
||||
{
|
||||
this->logger->log(this->logger, CONTROL|LEVEL2, "Message could not be sent cause id was not as expected");
|
||||
this->logger->log(this->logger, ERROR, "Message could not be sent cause id was not as expected");
|
||||
return FAILED;
|
||||
}
|
||||
|
||||
@@ -796,7 +823,9 @@ static status_t send_response (private_ike_sa_t *this,message_t * message)
|
||||
return FAILED;
|
||||
}
|
||||
|
||||
this->logger->log(this->logger, CONTROL|LEVEL2, "Add packet to global send queue");
|
||||
this->logger->log(this->logger, CONTROL|LEVEL3,
|
||||
"Add response packet with message id %d to global send queue",
|
||||
this->message_id_in);
|
||||
charon->send_queue->add(charon->send_queue, packet);
|
||||
|
||||
if (this->last_responded_message != NULL)
|
||||
@@ -805,11 +834,11 @@ static status_t send_response (private_ike_sa_t *this,message_t * message)
|
||||
this->last_responded_message->destroy(this->last_responded_message);
|
||||
}
|
||||
|
||||
this->logger->log(this->logger, CONTROL|LEVEL2, "replace last responded message with new one");
|
||||
this->logger->log(this->logger, CONTROL|LEVEL3, "Replace last responded message with new one");
|
||||
this->last_responded_message = message;
|
||||
|
||||
/* message counter can now be increased */
|
||||
this->logger->log(this->logger, CONTROL|LEVEL2, "Increase message counter for incoming messages");
|
||||
this->logger->log(this->logger, CONTROL|LEVEL3, "Increase message counter for incoming messages");
|
||||
this->message_id_in++;
|
||||
|
||||
return SUCCESS;
|
||||
@@ -839,6 +868,9 @@ static message_t * get_last_requested_message (private_ike_sa_t *this)
|
||||
return this->last_requested_message;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of protected_ike_sa_t.get_state.
|
||||
*/
|
||||
static ike_sa_state_t get_state (private_ike_sa_t *this)
|
||||
{
|
||||
return this->current_state->get_state(this->current_state);
|
||||
@@ -869,11 +901,16 @@ static void reset_message_buffers (private_ike_sa_t *this)
|
||||
this->last_replied_message_id = -1;
|
||||
}
|
||||
|
||||
/**
|
||||
* Implementation of protected_ike_sa_t.create_delete_established_ike_sa_job.
|
||||
*/
|
||||
static void create_delete_established_ike_sa_job (private_ike_sa_t *this,u_int32_t timeout)
|
||||
{
|
||||
job_t *delete_job;
|
||||
|
||||
this->logger->log(this->logger, CONTROL | LEVEL1, "Going to create job to delete established IKE_SA in %d ms", timeout);
|
||||
this->logger->log(this->logger, CONTROL | LEVEL1,
|
||||
"Going to create job to delete established IKE_SA in %d ms",
|
||||
timeout);
|
||||
|
||||
delete_job = (job_t *) delete_established_ike_sa_job_create(this->ike_sa_id);
|
||||
charon->event_queue->add_relative(charon->event_queue,delete_job, timeout);
|
||||
@@ -890,7 +927,7 @@ static void destroy (private_ike_sa_t *this)
|
||||
this->ike_sa_id->is_initiator(this->ike_sa_id) ? "initiator" : "responder");
|
||||
|
||||
/* destroy child sa's */
|
||||
this->logger->log(this->logger, CONTROL | LEVEL2, "Destroy all child_sa's");
|
||||
this->logger->log(this->logger, CONTROL | LEVEL3, "Destroy all child_sa's");
|
||||
while (this->child_sas->get_count(this->child_sas) > 0)
|
||||
{
|
||||
void *child_sa;
|
||||
@@ -902,86 +939,86 @@ static void destroy (private_ike_sa_t *this)
|
||||
}
|
||||
this->child_sas->destroy(this->child_sas);
|
||||
|
||||
this->logger->log(this->logger, CONTROL | LEVEL2, "Destroy secrets");
|
||||
this->logger->log(this->logger, CONTROL | LEVEL3, "Destroy secrets");
|
||||
allocator_free(this->secrets.d_key.ptr);
|
||||
allocator_free(this->secrets.pi_key.ptr);
|
||||
allocator_free(this->secrets.pr_key.ptr);
|
||||
|
||||
if (this->crypter_initiator != NULL)
|
||||
{
|
||||
this->logger->log(this->logger, CONTROL | LEVEL2, "Destroy initiator crypter_t object");
|
||||
this->logger->log(this->logger, CONTROL | LEVEL3, "Destroy initiator crypter_t object");
|
||||
this->crypter_initiator->destroy(this->crypter_initiator);
|
||||
}
|
||||
|
||||
if (this->crypter_responder != NULL)
|
||||
{
|
||||
this->logger->log(this->logger, CONTROL | LEVEL2, "Destroy responder crypter_t object");
|
||||
this->logger->log(this->logger, CONTROL | LEVEL3, "Destroy responder crypter_t object");
|
||||
this->crypter_responder->destroy(this->crypter_responder);
|
||||
}
|
||||
|
||||
if (this->signer_initiator != NULL)
|
||||
{
|
||||
this->logger->log(this->logger, CONTROL | LEVEL2, "Destroy initiator signer_t object");
|
||||
this->logger->log(this->logger, CONTROL | LEVEL3, "Destroy initiator signer_t object");
|
||||
this->signer_initiator->destroy(this->signer_initiator);
|
||||
}
|
||||
|
||||
if (this->signer_responder != NULL)
|
||||
{
|
||||
this->logger->log(this->logger, CONTROL | LEVEL2, "Destroy responder signer_t object");
|
||||
this->logger->log(this->logger, CONTROL | LEVEL3, "Destroy responder signer_t object");
|
||||
this->signer_responder->destroy(this->signer_responder);
|
||||
}
|
||||
|
||||
if (this->prf != NULL)
|
||||
{
|
||||
this->logger->log(this->logger, CONTROL | LEVEL2, "Destroy prf_t object");
|
||||
this->logger->log(this->logger, CONTROL | LEVEL3, "Destroy prf_t object");
|
||||
this->prf->destroy(this->prf);
|
||||
}
|
||||
|
||||
/* destroy ike_sa_id */
|
||||
this->logger->log(this->logger, CONTROL | LEVEL2, "Destroy ike_sa_id object");
|
||||
this->logger->log(this->logger, CONTROL | LEVEL3, "Destroy ike_sa_id object");
|
||||
this->ike_sa_id->destroy(this->ike_sa_id);
|
||||
|
||||
/* destroy stored requested message */
|
||||
if (this->last_requested_message != NULL)
|
||||
{
|
||||
this->logger->log(this->logger, CONTROL | LEVEL2, "Destroy last requested message");
|
||||
this->logger->log(this->logger, CONTROL | LEVEL3, "Destroy last requested message");
|
||||
this->last_requested_message->destroy(this->last_requested_message);
|
||||
}
|
||||
|
||||
/* destroy stored responded messages */
|
||||
if (this->last_responded_message != NULL)
|
||||
{
|
||||
this->logger->log(this->logger, CONTROL | LEVEL2, "Destroy last responded message");
|
||||
this->logger->log(this->logger, CONTROL | LEVEL3, "Destroy last responded message");
|
||||
this->last_responded_message->destroy(this->last_responded_message);
|
||||
}
|
||||
|
||||
/* destroy stored host_t objects */
|
||||
if (this->me.host != NULL)
|
||||
{
|
||||
this->logger->log(this->logger, CONTROL | LEVEL2, "Destroy my host_t object");
|
||||
this->logger->log(this->logger, CONTROL | LEVEL3, "Destroy my host_t object");
|
||||
this->me.host->destroy(this->me.host);
|
||||
}
|
||||
|
||||
/* destroy stored host_t objects */
|
||||
if (this->other.host != NULL)
|
||||
{
|
||||
this->logger->log(this->logger, CONTROL | LEVEL2, "Destroy other host_t object");
|
||||
this->logger->log(this->logger, CONTROL | LEVEL3, "Destroy other host_t object");
|
||||
this->other.host->destroy(this->other.host);
|
||||
}
|
||||
|
||||
this->randomizer->destroy(this->randomizer);
|
||||
|
||||
this->logger->log(this->logger, CONTROL | LEVEL2, "Destroy current state object");
|
||||
this->logger->log(this->logger, CONTROL | LEVEL3, "Destroy current state object");
|
||||
this->current_state->destroy(this->current_state);
|
||||
|
||||
this->logger->log(this->logger, CONTROL | LEVEL2, "Destroy logger of IKE_SA");
|
||||
this->logger->log(this->logger, CONTROL | LEVEL3, "Destroy logger of IKE_SA");
|
||||
charon->logger_manager->destroy_logger(charon->logger_manager, this->logger);
|
||||
|
||||
allocator_free(this);
|
||||
}
|
||||
|
||||
/*
|
||||
* Described in Header
|
||||
* Described in header.
|
||||
*/
|
||||
ike_sa_t * ike_sa_create(ike_sa_id_t *ike_sa_id)
|
||||
{
|
||||
@@ -1057,10 +1094,12 @@ ike_sa_t * ike_sa_create(ike_sa_id_t *ike_sa_id)
|
||||
/* at creation time, IKE_SA is in a initiator state */
|
||||
if (ike_sa_id->is_initiator(ike_sa_id))
|
||||
{
|
||||
this->logger->log(this->logger, CONTROL | LEVEL2, "Create first state_t object of type INITIATOR_INIT");
|
||||
this->current_state = (state_t *) initiator_init_create(&(this->protected));
|
||||
}
|
||||
else
|
||||
{
|
||||
this->logger->log(this->logger, CONTROL | LEVEL2, "Create first state_t object of type RESPONDER_INIT");
|
||||
this->current_state = (state_t *) responder_init_create(&(this->protected));
|
||||
}
|
||||
return &(this->protected.public);
|
||||
|
||||
Reference in New Issue
Block a user