implemented the RFC 5792 PA-TNC protocol and an example IMC/IMV pair
This commit is contained in:
@@ -0,0 +1,313 @@
|
||||
/*
|
||||
* Copyright (C) 2011 Andreas Steffen, HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "imc_agent.h"
|
||||
|
||||
#include <debug.h>
|
||||
#include <utils/linked_list.h>
|
||||
#include <threading/rwlock.h>
|
||||
|
||||
typedef struct private_imc_agent_t private_imc_agent_t;
|
||||
|
||||
/**
|
||||
* Private data of an imc_agent_t object.
|
||||
*/
|
||||
struct private_imc_agent_t {
|
||||
|
||||
/**
|
||||
* Public members of imc_agent_t
|
||||
*/
|
||||
imc_agent_t public;
|
||||
|
||||
/**
|
||||
* name of IMC
|
||||
*/
|
||||
const char *name;
|
||||
|
||||
/**
|
||||
* message type of IMC
|
||||
*/
|
||||
TNC_MessageType type;
|
||||
|
||||
/**
|
||||
* ID of IMC as assigned by TNCC
|
||||
*/
|
||||
TNC_IMCID id;
|
||||
|
||||
/**
|
||||
* list of TNCC connection entries
|
||||
*/
|
||||
linked_list_t *connections;
|
||||
|
||||
/**
|
||||
* rwlock to lock TNCS connection entries
|
||||
*/
|
||||
rwlock_t *connection_lock;
|
||||
|
||||
/**
|
||||
* Inform a TNCS about the set of message types the IMC is able to receive
|
||||
*
|
||||
* @param imc_id IMC ID assigned by TNCC
|
||||
* @param supported_types list of supported message types
|
||||
* @param type_count number of list elements
|
||||
* @return TNC result code
|
||||
*/
|
||||
TNC_Result (*report_message_types)(TNC_IMCID imc_id,
|
||||
TNC_MessageTypeList supported_types,
|
||||
TNC_UInt32 type_count);
|
||||
|
||||
/**
|
||||
* Call when an IMC-IMC message is to be sent
|
||||
*
|
||||
* @param imc_id IMC ID assigned by TNCC
|
||||
* @param connection_id network connection ID assigned by TNCC
|
||||
* @param msg message to send
|
||||
* @param msg_len message length in bytes
|
||||
* @param msg_type message type
|
||||
* @return TNC result code
|
||||
*/
|
||||
TNC_Result (*send_message)(TNC_IMCID imc_id,
|
||||
TNC_ConnectionID connection_id,
|
||||
TNC_BufferReference msg,
|
||||
TNC_UInt32 msg_len,
|
||||
TNC_MessageType msg_type);
|
||||
};
|
||||
|
||||
METHOD(imc_agent_t, bind_functions, TNC_Result,
|
||||
private_imc_agent_t *this, TNC_TNCC_BindFunctionPointer bind_function)
|
||||
{
|
||||
if (!bind_function)
|
||||
{
|
||||
DBG1(DBG_IMC, "TNC client failed to provide bind function");
|
||||
return TNC_RESULT_INVALID_PARAMETER;
|
||||
}
|
||||
if (bind_function(this->id, "TNC_TNCC_ReportMessageTypes",
|
||||
(void**)&this->report_message_types) != TNC_RESULT_SUCCESS)
|
||||
{
|
||||
this->report_message_types = NULL;
|
||||
}
|
||||
if (bind_function(this->id, "TNC_TNCC_RequestHandshakeRetry",
|
||||
(void**)&this->public.request_handshake_retry) != TNC_RESULT_SUCCESS)
|
||||
{
|
||||
this->public.request_handshake_retry = NULL;
|
||||
}
|
||||
if (bind_function(this->id, "TNC_TNCC_SendMessage",
|
||||
(void**)&this->send_message) != TNC_RESULT_SUCCESS)
|
||||
{
|
||||
this->send_message = NULL;
|
||||
}
|
||||
DBG2(DBG_IMC, "IMC %u \"%s\" provided with bind function",
|
||||
this->id, this->name);
|
||||
|
||||
if (this->report_message_types)
|
||||
{
|
||||
this->report_message_types(this->id, &this->type, 1);
|
||||
}
|
||||
return TNC_RESULT_SUCCESS;
|
||||
}
|
||||
|
||||
/**
|
||||
* finds a connection state based on its Connection ID
|
||||
*/
|
||||
static imc_state_t* find_connection(private_imc_agent_t *this,
|
||||
TNC_ConnectionID id)
|
||||
{
|
||||
enumerator_t *enumerator;
|
||||
imc_state_t *state, *found = NULL;
|
||||
|
||||
this->connection_lock->read_lock(this->connection_lock);
|
||||
enumerator = this->connections->create_enumerator(this->connections);
|
||||
while (enumerator->enumerate(enumerator, &state))
|
||||
{
|
||||
if (id == state->get_connection_id(state))
|
||||
{
|
||||
found = state;
|
||||
break;
|
||||
}
|
||||
}
|
||||
enumerator->destroy(enumerator);
|
||||
this->connection_lock->unlock(this->connection_lock);
|
||||
|
||||
return found;
|
||||
}
|
||||
|
||||
/**
|
||||
* delete a connection state with a given Connection ID
|
||||
*/
|
||||
static bool delete_connection(private_imc_agent_t *this, TNC_ConnectionID id)
|
||||
{
|
||||
enumerator_t *enumerator;
|
||||
imc_state_t *state;
|
||||
bool found = FALSE;
|
||||
|
||||
this->connection_lock->write_lock(this->connection_lock);
|
||||
enumerator = this->connections->create_enumerator(this->connections);
|
||||
while (enumerator->enumerate(enumerator, &state))
|
||||
{
|
||||
if (id == state->get_connection_id(state))
|
||||
{
|
||||
found = TRUE;
|
||||
state->destroy(state);
|
||||
this->connections->remove_at(this->connections, enumerator);
|
||||
break;
|
||||
}
|
||||
}
|
||||
enumerator->destroy(enumerator);
|
||||
this->connection_lock->unlock(this->connection_lock);
|
||||
|
||||
return found;
|
||||
}
|
||||
|
||||
METHOD(imc_agent_t, create_state, TNC_Result,
|
||||
private_imc_agent_t *this, imc_state_t *state)
|
||||
{
|
||||
TNC_ConnectionID connection_id;
|
||||
|
||||
connection_id = state->get_connection_id(state);
|
||||
if (find_connection(this, connection_id))
|
||||
{
|
||||
DBG1(DBG_IMC, "IMC %u \"%s\" already created a state for Connection ID %u",
|
||||
this->id, this->name, connection_id);
|
||||
state->destroy(state);
|
||||
return TNC_RESULT_OTHER;
|
||||
}
|
||||
this->connection_lock->write_lock(this->connection_lock);
|
||||
this->connections->insert_last(this->connections, state);
|
||||
this->connection_lock->unlock(this->connection_lock);
|
||||
DBG2(DBG_IMC, "IMC %u \"%s\" created a state for Connection ID %u",
|
||||
this->id, this->name, connection_id);
|
||||
return TNC_RESULT_SUCCESS;
|
||||
}
|
||||
|
||||
METHOD(imc_agent_t, delete_state, TNC_Result,
|
||||
private_imc_agent_t *this, TNC_ConnectionID connection_id)
|
||||
{
|
||||
if (!delete_connection(this, connection_id))
|
||||
{
|
||||
DBG1(DBG_IMC, "IMC %u \"%s\" has no state for Connection ID %u",
|
||||
this->id, this->name, connection_id);
|
||||
return TNC_RESULT_FATAL;
|
||||
}
|
||||
DBG2(DBG_IMC, "IMC %u \"%s\" deleted the state of Connection ID %u",
|
||||
this->id, this->name, connection_id);
|
||||
return TNC_RESULT_SUCCESS;
|
||||
}
|
||||
|
||||
METHOD(imc_agent_t, change_state, TNC_Result,
|
||||
private_imc_agent_t *this, TNC_ConnectionID connection_id,
|
||||
TNC_ConnectionState new_state)
|
||||
{
|
||||
imc_state_t *state;
|
||||
|
||||
switch (new_state)
|
||||
{
|
||||
case TNC_CONNECTION_STATE_HANDSHAKE:
|
||||
case TNC_CONNECTION_STATE_ACCESS_ALLOWED:
|
||||
case TNC_CONNECTION_STATE_ACCESS_ISOLATED:
|
||||
case TNC_CONNECTION_STATE_ACCESS_NONE:
|
||||
state = find_connection(this, connection_id);
|
||||
if (!state)
|
||||
{
|
||||
DBG1(DBG_IMC, "IMC %u \"%s\" has no state for Connection ID %u",
|
||||
this->id, this->name, connection_id);
|
||||
return TNC_RESULT_FATAL;
|
||||
}
|
||||
state->change_state(state, new_state);
|
||||
DBG2(DBG_IMC, "IMC %u \"%s\" changed state of Connection ID %u to '%N'",
|
||||
this->id, this->name, connection_id,
|
||||
TNC_Connection_State_names, new_state);
|
||||
break;
|
||||
case TNC_CONNECTION_STATE_CREATE:
|
||||
DBG1(DBG_IMC, "state '%N' should be handled by create_state()",
|
||||
TNC_Connection_State_names, new_state);
|
||||
return TNC_RESULT_FATAL;
|
||||
case TNC_CONNECTION_STATE_DELETE:
|
||||
DBG1(DBG_IMC, "state '%N' should be handled by delete_state()",
|
||||
TNC_Connection_State_names, new_state);
|
||||
return TNC_RESULT_FATAL;
|
||||
default:
|
||||
DBG1(DBG_IMC, "IMC %u \"%s\" was notified of unknown state %u "
|
||||
"for Connection ID %u",
|
||||
this->id, this->name, new_state, connection_id);
|
||||
return TNC_RESULT_INVALID_PARAMETER;
|
||||
}
|
||||
return TNC_RESULT_SUCCESS;
|
||||
}
|
||||
|
||||
METHOD(imc_agent_t, get_state, bool,
|
||||
private_imc_agent_t *this, TNC_ConnectionID connection_id,
|
||||
imc_state_t **state)
|
||||
{
|
||||
*state = find_connection(this, connection_id);
|
||||
if (!*state)
|
||||
{
|
||||
DBG1(DBG_IMC, "IMC %u \"%s\" has no state for Connection ID %u",
|
||||
this->id, this->name, connection_id);
|
||||
return FALSE;
|
||||
}
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(imc_agent_t, send_message, TNC_Result,
|
||||
private_imc_agent_t *this, TNC_ConnectionID connection_id, chunk_t msg)
|
||||
{
|
||||
if (!this->send_message)
|
||||
{
|
||||
return TNC_RESULT_FATAL;
|
||||
}
|
||||
return this->send_message(this->id, connection_id, msg.ptr, msg.len,
|
||||
this->type);
|
||||
}
|
||||
|
||||
METHOD(imc_agent_t, destroy, void,
|
||||
private_imc_agent_t *this)
|
||||
{
|
||||
DBG1(DBG_IMC, "IMC %u \"%s\" terminated", this->id, this->name);
|
||||
this->connections->destroy_function(this->connections, free);
|
||||
this->connection_lock->destroy(this->connection_lock);
|
||||
free(this);
|
||||
}
|
||||
|
||||
/**
|
||||
* Described in header.
|
||||
*/
|
||||
imc_agent_t *imc_agent_create(const char *name,
|
||||
pen_t vendor_id, u_int32_t subtype,
|
||||
TNC_IMCID id, TNC_Version *actual_version)
|
||||
{
|
||||
private_imc_agent_t *this;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.bind_functions = _bind_functions,
|
||||
.create_state = _create_state,
|
||||
.delete_state = _delete_state,
|
||||
.change_state = _change_state,
|
||||
.get_state = _get_state,
|
||||
.send_message = _send_message,
|
||||
.destroy = _destroy,
|
||||
},
|
||||
.name = name,
|
||||
.type = (vendor_id << 8) | (subtype && 0xff),
|
||||
.id = id,
|
||||
.connections = linked_list_create(),
|
||||
.connection_lock = rwlock_create(RWLOCK_TYPE_DEFAULT),
|
||||
);
|
||||
|
||||
*actual_version = TNC_IFIMC_VERSION_1;
|
||||
DBG1(DBG_IMC, "IMC %u \"%s\" initialized", this->id, this->name);
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
|
||||
@@ -0,0 +1,127 @@
|
||||
/*
|
||||
* Copyright (C) 2011 Andreas Steffen, HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
*
|
||||
* @defgroup imc_agent_t imc_agent
|
||||
* @{ @ingroup imc_agent
|
||||
*/
|
||||
|
||||
#ifndef IMC_AGENT_H_
|
||||
#define IMC_AGENT_H_
|
||||
|
||||
#include "imc_state.h"
|
||||
|
||||
#include <tnc/tncifimc.h>
|
||||
#include <tnc/pen/pen.h>
|
||||
#include <library.h>
|
||||
|
||||
typedef struct imc_agent_t imc_agent_t;
|
||||
|
||||
/**
|
||||
* Core functions of an Integrity Measurement Verifier (IMC)
|
||||
*/
|
||||
struct imc_agent_t {
|
||||
|
||||
/**
|
||||
* Ask a TNCC to retry an Integrity Check Handshake
|
||||
*
|
||||
* @param imc_id IMC ID assigned by TNCC
|
||||
* @param connection_id network connection ID assigned by TNCC
|
||||
* @param reason IMC retry reason
|
||||
* @return TNC result code
|
||||
*/
|
||||
TNC_Result (*request_handshake_retry)(TNC_IMCID imc_id,
|
||||
TNC_ConnectionID connection_id,
|
||||
TNC_RetryReason reason);
|
||||
|
||||
/**
|
||||
* Bind TNCC functions
|
||||
*
|
||||
* @param bind_function function offered by the TNCC
|
||||
* @return TNC result code
|
||||
*/
|
||||
TNC_Result (*bind_functions)(imc_agent_t *this,
|
||||
TNC_TNCC_BindFunctionPointer bind_function);
|
||||
|
||||
/**
|
||||
* Create the IMC state for a TNCCS connection instance
|
||||
*
|
||||
* @param state internal IMC state instance
|
||||
* @return TNC result code
|
||||
*/
|
||||
TNC_Result (*create_state)(imc_agent_t *this, imc_state_t *state);
|
||||
|
||||
/**
|
||||
* Delete the IMC state for a TNCCS connection instance
|
||||
*
|
||||
* @param connection_id network connection ID assigned by TNCS
|
||||
* @return TNC result code
|
||||
*/
|
||||
TNC_Result (*delete_state)(imc_agent_t *this,
|
||||
TNC_ConnectionID connection_id);
|
||||
|
||||
/**
|
||||
* Change the current state of a TNCCS connection
|
||||
*
|
||||
* @param connection_id network connection ID assigned by TNCS
|
||||
* @param new_state new state of TNCCS connection
|
||||
* @return TNC result code
|
||||
*/
|
||||
TNC_Result (*change_state)(imc_agent_t *this,
|
||||
TNC_ConnectionID connection_id,
|
||||
TNC_ConnectionState new_state);
|
||||
|
||||
/**
|
||||
* Get the IMC state for a TNCCS connection instance
|
||||
*
|
||||
* @param connection_id network connection ID assigned by TNCS
|
||||
* @param state internal IMC state instance
|
||||
* @return TRUE if the state was found
|
||||
*/
|
||||
bool (*get_state)(imc_agent_t *this,
|
||||
TNC_ConnectionID connection_id, imc_state_t **state);
|
||||
|
||||
/**
|
||||
* Call when an IMC-IMV message is to be sent
|
||||
*
|
||||
* @param connection_id network connection ID assigned by TNCC
|
||||
* @param msg message to send
|
||||
* @return TNC result code
|
||||
*/
|
||||
TNC_Result (*send_message)(imc_agent_t *this,
|
||||
TNC_ConnectionID connection_id,
|
||||
chunk_t msg);
|
||||
|
||||
/**
|
||||
* Destroys an imc_agent_t object
|
||||
*/
|
||||
void (*destroy)(imc_agent_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Create an imc_agent_t object
|
||||
*
|
||||
* @param name name of the IMC
|
||||
* @param vendor_id vendor ID of the IMC
|
||||
* @param subtype message subtype of the IMC
|
||||
* @param id ID of the IMC as assigned by the TNCS
|
||||
* @param actual_version actual version of the IF-IMC API
|
||||
*
|
||||
*/
|
||||
imc_agent_t *imc_agent_create(const char *name,
|
||||
pen_t vendor_id, u_int32_t subtype,
|
||||
TNC_IMCID id, TNC_Version *actual_version);
|
||||
|
||||
#endif /** IMC_AGENT_H_ @}*/
|
||||
@@ -0,0 +1,54 @@
|
||||
/*
|
||||
* Copyright (C) 2011 Andreas Steffen, HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
*
|
||||
* @defgroup imc_state_t imc_state
|
||||
* @{ @ingroup imc_state
|
||||
*/
|
||||
|
||||
#ifndef IMC_STATE_H_
|
||||
#define IMC_STATE_H_
|
||||
|
||||
#include <tnc/tncif.h>
|
||||
#include <library.h>
|
||||
|
||||
typedef struct imc_state_t imc_state_t;
|
||||
|
||||
/**
|
||||
* Internal state of an IMC connection instance
|
||||
*/
|
||||
struct imc_state_t {
|
||||
|
||||
/**
|
||||
* Get the TNCS connection ID attached to the state
|
||||
*
|
||||
* @return TNCS connection ID of the state
|
||||
*/
|
||||
TNC_ConnectionID (*get_connection_id)(imc_state_t *this);
|
||||
|
||||
/**
|
||||
* Change the connection state
|
||||
*
|
||||
* @param new_state new connection state
|
||||
*/
|
||||
void (*change_state)(imc_state_t *this, TNC_ConnectionState new_state);
|
||||
|
||||
/**
|
||||
* Destroys an imc_state_t object
|
||||
*/
|
||||
void (*destroy)(imc_state_t *this);
|
||||
};
|
||||
|
||||
#endif /** IMC_STATE_H_ @}*/
|
||||
Reference in New Issue
Block a user