Support different authentication schemes for PT-TLS

This commit is contained in:
Martin Willi
2013-02-28 16:46:08 +01:00
parent 807f2facd0
commit 61f1693df1
5 changed files with 71 additions and 6 deletions
+17
View File
@@ -37,6 +37,7 @@
typedef enum pt_tls_message_type_t pt_tls_message_type_t; typedef enum pt_tls_message_type_t pt_tls_message_type_t;
typedef enum pt_tls_sasl_result_t pt_tls_sasl_result_t; typedef enum pt_tls_sasl_result_t pt_tls_sasl_result_t;
typedef enum pt_tls_auth_t pt_tls_auth_t;
/** /**
* Message types, as defined by NEA PT-TLS * Message types, as defined by NEA PT-TLS
@@ -63,6 +64,22 @@ enum pt_tls_sasl_result_t {
PT_TLS_SASL_RESULT_MECH_FAILURE = 3, PT_TLS_SASL_RESULT_MECH_FAILURE = 3,
}; };
/**
* Client authentication to require as PT-TLS server.
*/
enum pt_tls_auth_t {
/** don't require TLS client certificate or request SASL authentication */
PT_TLS_AUTH_NONE,
/** require TLS certificate authentication, no SASL */
PT_TLS_AUTH_TLS,
/** do SASL regardless of TLS certificate authentication */
PT_TLS_AUTH_SASL,
/* if client does not authenticate with a TLS certificate, request SASL */
PT_TLS_AUTH_TLS_OR_SASL,
/* require both, TLS certificate authentication and SASL */
PT_TLS_AUTH_TLS_AND_SASL,
};
/** /**
* Read a PT-TLS message, create reader over Message Value. * Read a PT-TLS message, create reader over Message Value.
* *
+8 -2
View File
@@ -41,6 +41,11 @@ struct private_pt_tls_dispatcher_t {
*/ */
int fd; int fd;
/**
* Client authentication requirements
*/
pt_tls_auth_t auth;
/** /**
* Server identity * Server identity
*/ */
@@ -141,7 +146,7 @@ METHOD(pt_tls_dispatcher_t, dispatch, void,
close(fd); close(fd);
continue; continue;
} }
connection = pt_tls_server_create(this->server, fd, tnccs); connection = pt_tls_server_create(this->server, fd, this->auth, tnccs);
if (!connection) if (!connection)
{ {
close(fd); close(fd);
@@ -171,7 +176,7 @@ METHOD(pt_tls_dispatcher_t, destroy, void,
* See header * See header
*/ */
pt_tls_dispatcher_t *pt_tls_dispatcher_create(host_t *address, pt_tls_dispatcher_t *pt_tls_dispatcher_create(host_t *address,
identification_t *id) identification_t *id, pt_tls_auth_t auth)
{ {
private_pt_tls_dispatcher_t *this; private_pt_tls_dispatcher_t *this;
@@ -184,6 +189,7 @@ pt_tls_dispatcher_t *pt_tls_dispatcher_create(host_t *address,
/* we currently don't authenticate the peer, use %any identity */ /* we currently don't authenticate the peer, use %any identity */
.peer = identification_create_from_encoding(ID_ANY, chunk_empty), .peer = identification_create_from_encoding(ID_ANY, chunk_empty),
.fd = -1, .fd = -1,
.auth = auth,
); );
if (!open_socket(this, address)) if (!open_socket(this, address))
+4 -1
View File
@@ -26,6 +26,8 @@
#include <tnc/tnccs/tnccs.h> #include <tnc/tnccs/tnccs.h>
#include "pt_tls.h"
typedef struct pt_tls_dispatcher_t pt_tls_dispatcher_t; typedef struct pt_tls_dispatcher_t pt_tls_dispatcher_t;
/** /**
@@ -64,9 +66,10 @@ struct pt_tls_dispatcher_t {
* *
* @param address server address with port to listen on, gets owned * @param address server address with port to listen on, gets owned
* @param id TLS server identity, gets owned * @param id TLS server identity, gets owned
* @param auth client authentication to perform
* @return dispatcher service * @return dispatcher service
*/ */
pt_tls_dispatcher_t *pt_tls_dispatcher_create(host_t *address, pt_tls_dispatcher_t *pt_tls_dispatcher_create(host_t *address,
identification_t *id); identification_t *id, pt_tls_auth_t auth);
#endif /** PT_TLS_DISPATCHER_H_ @}*/ #endif /** PT_TLS_DISPATCHER_H_ @}*/
+38 -2
View File
@@ -14,7 +14,6 @@
*/ */
#include "pt_tls_server.h" #include "pt_tls_server.h"
#include "pt_tls.h"
#include <sasl/sasl_mechanism.h> #include <sasl/sasl_mechanism.h>
@@ -37,6 +36,11 @@ struct private_pt_tls_server_t {
*/ */
tls_socket_t *tls; tls_socket_t *tls;
/**
* Client authentication requirements
*/
pt_tls_auth_t auth;
enum { enum {
/* expecting version negotiation */ /* expecting version negotiation */
PT_TLS_SERVER_VERSION, PT_TLS_SERVER_VERSION,
@@ -305,6 +309,37 @@ static bool do_sasl(private_pt_tls_server_t *this)
sasl_mechanism_t *sasl; sasl_mechanism_t *sasl;
status_t status; status_t status;
switch (this->auth)
{
case PT_TLS_AUTH_NONE:
return TRUE;
case PT_TLS_AUTH_TLS:
if (this->tls->get_peer_id(this->tls))
{
return TRUE;
}
DBG1(DBG_TNC, "requiring TLS certificate client authentication");
return FALSE;
case PT_TLS_AUTH_SASL:
break;
case PT_TLS_AUTH_TLS_OR_SASL:
if (this->tls->get_peer_id(this->tls))
{
DBG1(DBG_TNC, "skipping SASL, client authenticated with TLS "
"certificate");
return TRUE;
}
break;
case PT_TLS_AUTH_TLS_AND_SASL:
default:
if (!this->tls->get_peer_id(this->tls))
{
DBG1(DBG_TNC, "requiring TLS certificate client authentication");
return FALSE;
}
break;
}
if (!send_sasl_mechs(this)) if (!send_sasl_mechs(this))
{ {
return FALSE; return FALSE;
@@ -482,7 +517,7 @@ METHOD(pt_tls_server_t, destroy, void,
* See header * See header
*/ */
pt_tls_server_t *pt_tls_server_create(identification_t *server, int fd, pt_tls_server_t *pt_tls_server_create(identification_t *server, int fd,
tnccs_t *tnccs) pt_tls_auth_t auth, tnccs_t *tnccs)
{ {
private_pt_tls_server_t *this; private_pt_tls_server_t *this;
@@ -495,6 +530,7 @@ pt_tls_server_t *pt_tls_server_create(identification_t *server, int fd,
.state = PT_TLS_SERVER_VERSION, .state = PT_TLS_SERVER_VERSION,
.tls = tls_socket_create(TRUE, server, NULL, fd, NULL), .tls = tls_socket_create(TRUE, server, NULL, fd, NULL),
.tnccs = (tls_t*)tnccs, .tnccs = (tls_t*)tnccs,
.auth = auth,
); );
if (!this->tls) if (!this->tls)
+4 -1
View File
@@ -25,6 +25,8 @@
#include <tnc/tnccs/tnccs.h> #include <tnc/tnccs/tnccs.h>
#include "pt_tls.h"
typedef struct pt_tls_server_t pt_tls_server_t; typedef struct pt_tls_server_t pt_tls_server_t;
/** /**
@@ -60,10 +62,11 @@ struct pt_tls_server_t {
* *
* @param server TLS server identity * @param server TLS server identity
* @param fd client connection socket * @param fd client connection socket
* @param auth client authentication requirements
* @param tnccs inner TNCCS protocol handler to use for this connection * @param tnccs inner TNCCS protocol handler to use for this connection
* @return PT-TLS server * @return PT-TLS server
*/ */
pt_tls_server_t *pt_tls_server_create(identification_t *server, int fd, pt_tls_server_t *pt_tls_server_create(identification_t *server, int fd,
tnccs_t *tnccs); pt_tls_auth_t auth, tnccs_t *tnccs);
#endif /** PT_TLS_SERVER_H_ @}*/ #endif /** PT_TLS_SERVER_H_ @}*/