IKEv1 XAuth: Added a "NULL" XAuth plugin which sends a hardcoded user/pass, and blindly accepts whatever user/pass is sent it. Changed the xauth_request task to use this new plugin. Add --enable-xauth-null to your configure line to build with the new plugin.

This commit is contained in:
Clavister OpenSource
2012-03-20 17:31:11 +01:00
parent 9c5366446a
commit 4394d96844
10 changed files with 363 additions and 23 deletions
@@ -0,0 +1,16 @@
INCLUDES = -I$(top_srcdir)/src/libstrongswan -I$(top_srcdir)/src/libhydra \
-I$(top_srcdir)/src/libcharon
AM_CFLAGS = -rdynamic
if MONOLITHIC
noinst_LTLIBRARIES = libstrongswan-xauth-null.la
else
plugin_LTLIBRARIES = libstrongswan-xauth-null.la
endif
libstrongswan_xauth_null_la_SOURCES = \
xauth_null_plugin.h xauth_null_plugin.c xauth_null.h xauth_null.c
libstrongswan_xauth_null_la_LDFLAGS = -module -avoid-version
@@ -0,0 +1,132 @@
/*
* Copyright (C) 2007-2008 Martin Willi
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#include "xauth_null.h"
#include <daemon.h>
#include <library.h>
typedef struct private_xauth_null_t private_xauth_null_t;
/**
* Private data of an xauth_null_t object.
*/
struct private_xauth_null_t {
/**
* Public authenticator_t interface.
*/
xauth_null_t public;
/**
* ID of the peer
*/
identification_t *peer;
};
METHOD(xauth_method_t, process_peer, status_t,
private_xauth_null_t *this, cp_payload_t *in, cp_payload_t **out)
{
chunk_t user_name = chunk_from_chars('j', 'o', 's', 't');
chunk_t user_pass = chunk_from_chars('j', 'o', 's', 't');
cp_payload_t *cp;
/* TODO-IKEv1: Fetch the user/pass from an authenticator */
cp = cp_payload_create_type(CONFIGURATION_V1, CFG_REPLY);
cp->add_attribute(cp, configuration_attribute_create_chunk(
CONFIGURATION_ATTRIBUTE_V1, XAUTH_USER_NAME, user_name));
cp->add_attribute(cp, configuration_attribute_create_chunk(
CONFIGURATION_ATTRIBUTE_V1, XAUTH_USER_PASSWORD, user_pass));
*out = cp;
return NEED_MORE;
}
METHOD(xauth_method_t, initiate_peer, status_t,
private_xauth_null_t *this, cp_payload_t **out)
{
/* peer never initiates */
return FAILED;
}
METHOD(xauth_method_t, process_server, status_t,
private_xauth_null_t *this, cp_payload_t *in, cp_payload_t **out)
{
return SUCCESS;
}
METHOD(xauth_method_t, initiate_server, status_t,
private_xauth_null_t *this, cp_payload_t **out)
{
return NEED_MORE;
}
METHOD(xauth_method_t, get_type, xauth_type_t,
private_xauth_null_t *this, u_int32_t *vendor)
{
return XAUTH_NULL;
}
METHOD(xauth_method_t, destroy, void,
private_xauth_null_t *this)
{
this->peer->destroy(this->peer);
free(this);
}
/*
* Described in header.
*/
xauth_null_t *xauth_null_create_peer(identification_t *server,
identification_t *peer)
{
private_xauth_null_t *this;
INIT(this,
.public = {
.xauth_method = {
.initiate = _initiate_peer,
.process = _process_peer,
.get_type = _get_type,
.destroy = _destroy,
},
},
.peer = peer->clone(peer),
);
return &this->public;
}
/*
* Described in header.
*/
xauth_null_t *xauth_null_create_server(identification_t *server,
identification_t *peer)
{
private_xauth_null_t *this;
INIT(this,
.public = {
.xauth_method = {
.initiate = _initiate_server,
.process = _process_server,
.get_type = _get_type,
.destroy = _destroy,
},
},
.peer = peer->clone(peer),
);
return &this->public;
}
@@ -0,0 +1,59 @@
/*
* Copyright (C) 2008 Martin Willi
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup xauth_null_i xauth_null
* @{ @ingroup xauth_null
*/
#ifndef XAUTH_NULL_H_
#define XAUTH_NULL_H_
typedef struct xauth_null_t xauth_null_t;
#include <sa/authenticators/xauth/xauth_method.h>
/**
* Implementation of the xauth_method_t providing no actual identity verification.
*/
struct xauth_null_t {
/**
* Implemented xauth_method_t interface.
*/
xauth_method_t xauth_method;
};
/**
* Creates the XAuth method XAuth NULL, acting as server.
*
* @param server ID of the XAuth server
* @param peer ID of the XAuth client
* @return xauth_null_t object
*/
xauth_null_t *xauth_null_create_server(identification_t *server,
identification_t *peer);
/**
* Creates the XAuth method XAuth NULL, acting as peer.
*
* @param server ID of the XAuth server
* @param peer ID of the XAuth client
* @return xauth_null_t object
*/
xauth_null_t *xauth_null_create_peer(identification_t *server,
identification_t *peer);
#endif /** XAUTH_NULL_H_ @}*/
@@ -0,0 +1,62 @@
/*
* Copyright (C) 2008 Martin Willi
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#include "xauth_null_plugin.h"
#include "xauth_null.h"
#include <daemon.h>
METHOD(plugin_t, get_name, char*,
xauth_null_plugin_t *this)
{
return "xauth-null";
}
METHOD(plugin_t, get_features, int,
xauth_null_plugin_t *this, plugin_feature_t *features[])
{
static plugin_feature_t f[] = {
PLUGIN_CALLBACK(xauth_method_register, xauth_null_create_server),
PLUGIN_PROVIDE(XAUTH_SERVER, XAUTH_NULL),
PLUGIN_CALLBACK(xauth_method_register, xauth_null_create_peer),
PLUGIN_PROVIDE(XAUTH_PEER, XAUTH_NULL),
};
*features = f;
return countof(f);
}
METHOD(plugin_t, destroy, void,
xauth_null_plugin_t *this)
{
free(this);
}
/*
* see header file
*/
plugin_t *xauth_null_plugin_create()
{
xauth_null_plugin_t *this;
INIT(this,
.plugin = {
.get_name = _get_name,
.get_features = _get_features,
.destroy = _destroy,
},
);
return &this->plugin;
}
@@ -0,0 +1,42 @@
/*
* Copyright (C) 2008 Martin Willi
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup xauth_null xauth_null
* @ingroup cplugins
*
* @defgroup xauth_null_plugin xauth_null_plugin
* @{ @ingroup xauth_null
*/
#ifndef XAUTH_NULL_PLUGIN_H_
#define XAUTH_NULL_PLUGIN_H_
#include <plugins/plugin.h>
typedef struct xauth_null_plugin_t xauth_null_plugin_t;
/**
* XAUTH Null plugin.
*/
struct xauth_null_plugin_t {
/**
* implements plugin interface
*/
plugin_t plugin;
};
#endif /** XAUTH_NULL_PLUGIN_H_ @}*/