credential-manager: Make online revocation checks optional for public key enumerator

This commit is contained in:
Tobias Brunner
2016-03-10 11:07:14 +01:00
parent 819da83fcc
commit 5452e3d66e
6 changed files with 14 additions and 7 deletions
@@ -173,7 +173,7 @@ METHOD(authenticator_t, process, status_t,
sig = sig_payload->get_hash(sig_payload); sig = sig_payload->get_hash(sig_payload);
auth = this->ike_sa->get_auth_cfg(this->ike_sa, FALSE); auth = this->ike_sa->get_auth_cfg(this->ike_sa, FALSE);
enumerator = lib->credmgr->create_public_enumerator(lib->credmgr, this->type, enumerator = lib->credmgr->create_public_enumerator(lib->credmgr, this->type,
id, auth); id, auth, TRUE);
while (enumerator->enumerate(enumerator, &public, &current_auth)) while (enumerator->enumerate(enumerator, &public, &current_auth))
{ {
if (public->verify(public, scheme, hash, sig)) if (public->verify(public, scheme, hash, sig))
@@ -409,7 +409,7 @@ METHOD(authenticator_t, process, status_t,
} }
auth = this->ike_sa->get_auth_cfg(this->ike_sa, FALSE); auth = this->ike_sa->get_auth_cfg(this->ike_sa, FALSE);
enumerator = lib->credmgr->create_public_enumerator(lib->credmgr, enumerator = lib->credmgr->create_public_enumerator(lib->credmgr,
key_type, id, auth); key_type, id, auth, TRUE);
while (enumerator->enumerate(enumerator, &public, &current_auth)) while (enumerator->enumerate(enumerator, &public, &current_auth))
{ {
if (public->verify(public, scheme, octets, auth_data)) if (public->verify(public, scheme, octets, auth_data))
@@ -1,4 +1,5 @@
/* /*
* Copyright (C) 2015 Tobias Brunner
* Copyright (C) 2007 Martin Willi * Copyright (C) 2007 Martin Willi
* Hochschule fuer Technik Rapperswil * Hochschule fuer Technik Rapperswil
* *
@@ -993,7 +994,7 @@ METHOD(enumerator_t, public_destroy, void,
METHOD(credential_manager_t, create_public_enumerator, enumerator_t*, METHOD(credential_manager_t, create_public_enumerator, enumerator_t*,
private_credential_manager_t *this, key_type_t type, identification_t *id, private_credential_manager_t *this, key_type_t type, identification_t *id,
auth_cfg_t *auth) auth_cfg_t *auth, bool online)
{ {
public_enumerator_t *enumerator; public_enumerator_t *enumerator;
@@ -1002,7 +1003,7 @@ METHOD(credential_manager_t, create_public_enumerator, enumerator_t*,
.enumerate = (void*)_public_enumerate, .enumerate = (void*)_public_enumerate,
.destroy = _public_destroy, .destroy = _public_destroy,
}, },
.inner = create_trusted_enumerator(this, type, id, TRUE), .inner = create_trusted_enumerator(this, type, id, online),
.this = this, .this = this,
); );
if (auth) if (auth)
@@ -1,4 +1,5 @@
/* /*
* Copyright (C) 2015 Tobias Brunner
* Copyright (C) 2007-2009 Martin Willi * Copyright (C) 2007-2009 Martin Willi
* Hochschule fuer Technik Rapperswil * Hochschule fuer Technik Rapperswil
* *
@@ -202,14 +203,18 @@ struct credential_manager_t {
* where the auth config helper contains rules for constraint checks. * where the auth config helper contains rules for constraint checks.
* This function is very similar to create_trusted_enumerator(), but * This function is very similar to create_trusted_enumerator(), but
* gets public keys directly. * gets public keys directly.
* If online is set, revocations are checked online for the whole
* trustchain.
* *
* @param type type of the key to get * @param type type of the key to get
* @param id owner of the key, signer of the signature * @param id owner of the key, signer of the signature
* @param auth authentication infos * @param auth authentication infos
* @param online whether revocations should be checked online
* @return enumerator * @return enumerator
*/ */
enumerator_t* (*create_public_enumerator)(credential_manager_t *this, enumerator_t* (*create_public_enumerator)(credential_manager_t *this,
key_type_t type, identification_t *id, auth_cfg_t *auth); key_type_t type, identification_t *id, auth_cfg_t *auth,
bool online);
/** /**
* Cache a certificate by invoking cache_cert() on all registered sets. * Cache a certificate by invoking cache_cert() on all registered sets.
+2 -1
View File
@@ -320,7 +320,8 @@ static public_key_t *find_public_key(private_tls_peer_t *this)
if (cert) if (cert)
{ {
enumerator = lib->credmgr->create_public_enumerator(lib->credmgr, enumerator = lib->credmgr->create_public_enumerator(lib->credmgr,
KEY_ANY, cert->get_subject(cert), this->server_auth); KEY_ANY, cert->get_subject(cert),
this->server_auth, TRUE);
while (enumerator->enumerate(enumerator, &current, &auth)) while (enumerator->enumerate(enumerator, &current, &auth))
{ {
found = auth->get(auth, AUTH_RULE_SUBJECT_CERT); found = auth->get(auth, AUTH_RULE_SUBJECT_CERT);
+1 -1
View File
@@ -548,7 +548,7 @@ static status_t process_cert_verify(private_tls_server_t *this,
bio_reader_t *sig; bio_reader_t *sig;
enumerator = lib->credmgr->create_public_enumerator(lib->credmgr, enumerator = lib->credmgr->create_public_enumerator(lib->credmgr,
KEY_ANY, this->peer, this->peer_auth); KEY_ANY, this->peer, this->peer_auth, TRUE);
while (enumerator->enumerate(enumerator, &public, &auth)) while (enumerator->enumerate(enumerator, &public, &auth))
{ {
sig = bio_reader_create(reader->peek(reader)); sig = bio_reader_create(reader->peek(reader));