Add a return value to radius_message_t.sign()

This commit is contained in:
Martin Willi
2012-07-16 14:53:33 +02:00
parent 264e702109
commit 5fb719e0de
5 changed files with 26 additions and 15 deletions
@@ -184,11 +184,16 @@ static void send_response(private_eap_radius_dae_t *this,
response = radius_message_create(code); response = radius_message_create(code);
response->set_identifier(response, request->get_identifier(request)); response->set_identifier(response, request->get_identifier(request));
response->sign(response, request->get_authenticator(request), if (response->sign(response, request->get_authenticator(request),
this->secret, this->hasher, this->signer, NULL, FALSE); this->secret, this->hasher, this->signer, NULL, FALSE))
{
send_message(this, response, client); send_message(this, response, client);
save_retransmit(this, response, client); save_retransmit(this, response, client);
}
else
{
response->destroy(response);
}
} }
/** /**
+7 -6
View File
@@ -293,12 +293,13 @@ static void send_response(private_tnc_pdp_t *this, radius_message_t *request,
chunk_free(&data); chunk_free(&data);
} }
response->set_identifier(response, request->get_identifier(request)); response->set_identifier(response, request->get_identifier(request));
response->sign(response, request->get_authenticator(request), if (response->sign(response, request->get_authenticator(request),
this->secret, this->hasher, this->signer, NULL, TRUE); this->secret, this->hasher, this->signer, NULL, TRUE))
{
DBG1(DBG_CFG, "sending RADIUS %N to client '%H'", radius_message_code_names, DBG1(DBG_CFG, "sending RADIUS %N to client '%H'",
code, client); radius_message_code_names, code, client);
send_message(this, response, client); send_message(this, response, client);
}
response->destroy(response); response->destroy(response);
} }
+2 -1
View File
@@ -286,7 +286,7 @@ METHOD(radius_message_t, add, void,
this->msg->length = htons(ntohs(this->msg->length) + attribute->length); this->msg->length = htons(ntohs(this->msg->length) + attribute->length);
} }
METHOD(radius_message_t, sign, void, METHOD(radius_message_t, sign, bool,
private_radius_message_t *this, u_int8_t *req_auth, chunk_t secret, private_radius_message_t *this, u_int8_t *req_auth, chunk_t secret,
hasher_t *hasher, signer_t *signer, rng_t *rng, bool msg_auth) hasher_t *hasher, signer_t *signer, rng_t *rng, bool msg_auth)
{ {
@@ -329,6 +329,7 @@ METHOD(radius_message_t, sign, void,
hasher->get_hash(hasher, msg, NULL); hasher->get_hash(hasher, msg, NULL);
hasher->get_hash(hasher, secret, this->msg->authenticator); hasher->get_hash(hasher, secret, this->msg->authenticator);
} }
return TRUE;
} }
METHOD(radius_message_t, verify, bool, METHOD(radius_message_t, verify, bool,
+2 -1
View File
@@ -257,8 +257,9 @@ struct radius_message_t {
* @param hasher MD5 hasher * @param hasher MD5 hasher
* @param rng RNG to create Request-Authenticator, NULL to omit * @param rng RNG to create Request-Authenticator, NULL to omit
* @param msg_auth calculate and add Message-Authenticator * @param msg_auth calculate and add Message-Authenticator
* @return TRUE if signed successfully
*/ */
void (*sign)(radius_message_t *this, u_int8_t *req_auth, chunk_t secret, bool (*sign)(radius_message_t *this, u_int8_t *req_auth, chunk_t secret,
hasher_t *hasher, signer_t *signer, rng_t *rng, bool msg_auth); hasher_t *hasher, signer_t *signer, rng_t *rng, bool msg_auth);
/** /**
+5 -2
View File
@@ -148,8 +148,11 @@ METHOD(radius_socket_t, request, radius_message_t*,
/* set Message Identifier */ /* set Message Identifier */
request->set_identifier(request, this->identifier++); request->set_identifier(request, this->identifier++);
/* sign the request */ /* sign the request */
request->sign(request, NULL, this->secret, this->hasher, this->signer, if (!request->sign(request, NULL, this->secret, this->hasher, this->signer,
rng, rng != NULL); rng, rng != NULL))
{
return NULL;
}
if (!check_connection(this, fd, port)) if (!check_connection(this, fd, port))
{ {