Support different authentication schemes for PT-TLS

This commit is contained in:
Martin Willi
2013-02-28 16:46:08 +01:00
parent 807f2facd0
commit 61f1693df1
5 changed files with 71 additions and 6 deletions
+38 -2
View File
@@ -14,7 +14,6 @@
*/
#include "pt_tls_server.h"
#include "pt_tls.h"
#include <sasl/sasl_mechanism.h>
@@ -37,6 +36,11 @@ struct private_pt_tls_server_t {
*/
tls_socket_t *tls;
/**
* Client authentication requirements
*/
pt_tls_auth_t auth;
enum {
/* expecting version negotiation */
PT_TLS_SERVER_VERSION,
@@ -305,6 +309,37 @@ static bool do_sasl(private_pt_tls_server_t *this)
sasl_mechanism_t *sasl;
status_t status;
switch (this->auth)
{
case PT_TLS_AUTH_NONE:
return TRUE;
case PT_TLS_AUTH_TLS:
if (this->tls->get_peer_id(this->tls))
{
return TRUE;
}
DBG1(DBG_TNC, "requiring TLS certificate client authentication");
return FALSE;
case PT_TLS_AUTH_SASL:
break;
case PT_TLS_AUTH_TLS_OR_SASL:
if (this->tls->get_peer_id(this->tls))
{
DBG1(DBG_TNC, "skipping SASL, client authenticated with TLS "
"certificate");
return TRUE;
}
break;
case PT_TLS_AUTH_TLS_AND_SASL:
default:
if (!this->tls->get_peer_id(this->tls))
{
DBG1(DBG_TNC, "requiring TLS certificate client authentication");
return FALSE;
}
break;
}
if (!send_sasl_mechs(this))
{
return FALSE;
@@ -482,7 +517,7 @@ METHOD(pt_tls_server_t, destroy, void,
* See header
*/
pt_tls_server_t *pt_tls_server_create(identification_t *server, int fd,
tnccs_t *tnccs)
pt_tls_auth_t auth, tnccs_t *tnccs)
{
private_pt_tls_server_t *this;
@@ -495,6 +530,7 @@ pt_tls_server_t *pt_tls_server_create(identification_t *server, int fd,
.state = PT_TLS_SERVER_VERSION,
.tls = tls_socket_create(TRUE, server, NULL, fd, NULL),
.tnccs = (tls_t*)tnccs,
.auth = auth,
);
if (!this->tls)