child-sa: Add a new state to track rekeyed IKEv1 CHILD_SAs
This is needed to handle DELETEs properly, which was previously done via
CHILD_REKEYING, which we don't use anymore since 5c6a62ceb6 as it prevents
reauthentication.
This commit is contained in:
@@ -323,7 +323,8 @@ static void log_child_sa(FILE *out, child_sa_t *child_sa, bool all)
|
|||||||
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
else if (child_sa->get_state(child_sa) == CHILD_REKEYING)
|
else if (child_sa->get_state(child_sa) == CHILD_REKEYING ||
|
||||||
|
child_sa->get_state(child_sa) == CHILD_REKEYED)
|
||||||
{
|
{
|
||||||
rekey = child_sa->get_lifetime(child_sa, TRUE);
|
rekey = child_sa->get_lifetime(child_sa, TRUE);
|
||||||
fprintf(out, ", expires in %V", &now, &rekey);
|
fprintf(out, ", expires in %V", &now, &rekey);
|
||||||
|
|||||||
@@ -68,7 +68,8 @@ static void list_child(private_vici_query_t *this, vici_builder_t *b,
|
|||||||
b->add_kv(b, "state", "%N", child_sa_state_names, child->get_state(child));
|
b->add_kv(b, "state", "%N", child_sa_state_names, child->get_state(child));
|
||||||
b->add_kv(b, "mode", "%N", ipsec_mode_names, child->get_mode(child));
|
b->add_kv(b, "mode", "%N", ipsec_mode_names, child->get_mode(child));
|
||||||
if (child->get_state(child) == CHILD_INSTALLED ||
|
if (child->get_state(child) == CHILD_INSTALLED ||
|
||||||
child->get_state(child) == CHILD_REKEYING)
|
child->get_state(child) == CHILD_REKEYING ||
|
||||||
|
child->get_state(child) == CHILD_REKEYED)
|
||||||
{
|
{
|
||||||
b->add_kv(b, "protocol", "%N", protocol_id_names,
|
b->add_kv(b, "protocol", "%N", protocol_id_names,
|
||||||
child->get_protocol(child));
|
child->get_protocol(child));
|
||||||
|
|||||||
@@ -67,7 +67,8 @@ static u_int32_t get_retry_delay(ike_sa_t *ike_sa)
|
|||||||
enumerator = ike_sa->create_child_sa_enumerator(ike_sa);
|
enumerator = ike_sa->create_child_sa_enumerator(ike_sa);
|
||||||
while (enumerator->enumerate(enumerator, &child_sa))
|
while (enumerator->enumerate(enumerator, &child_sa))
|
||||||
{
|
{
|
||||||
if (child_sa->get_state(child_sa) != CHILD_INSTALLED)
|
if (child_sa->get_state(child_sa) != CHILD_INSTALLED &&
|
||||||
|
child_sa->get_state(child_sa) != CHILD_REKEYED)
|
||||||
{
|
{
|
||||||
retry = RETRY_INTERVAL - (random() % RETRY_JITTER);
|
retry = RETRY_INTERVAL - (random() % RETRY_JITTER);
|
||||||
DBG1(DBG_IKE, "unable to reauthenticate in CHILD_SA %N state, "
|
DBG1(DBG_IKE, "unable to reauthenticate in CHILD_SA %N state, "
|
||||||
|
|||||||
@@ -34,6 +34,7 @@ ENUM(child_sa_state_names, CHILD_CREATED, CHILD_DESTROYING,
|
|||||||
"INSTALLED",
|
"INSTALLED",
|
||||||
"UPDATING",
|
"UPDATING",
|
||||||
"REKEYING",
|
"REKEYING",
|
||||||
|
"REKEYED",
|
||||||
"RETRYING",
|
"RETRYING",
|
||||||
"DELETING",
|
"DELETING",
|
||||||
"DESTROYING",
|
"DESTROYING",
|
||||||
|
|||||||
@@ -67,6 +67,11 @@ enum child_sa_state_t {
|
|||||||
*/
|
*/
|
||||||
CHILD_REKEYING,
|
CHILD_REKEYING,
|
||||||
|
|
||||||
|
/**
|
||||||
|
* CHILD_SA that was rekeyed, but stays installed
|
||||||
|
*/
|
||||||
|
CHILD_REKEYED,
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* CHILD_SA negotiation failed, but gets retried
|
* CHILD_SA negotiation failed, but gets retried
|
||||||
*/
|
*/
|
||||||
|
|||||||
@@ -105,7 +105,7 @@ static bool delete_child(private_quick_delete_t *this, protocol_id_t protocol,
|
|||||||
this->spi = spi = child_sa->get_spi(child_sa, TRUE);
|
this->spi = spi = child_sa->get_spi(child_sa, TRUE);
|
||||||
}
|
}
|
||||||
|
|
||||||
rekeyed = child_sa->get_state(child_sa) == CHILD_REKEYING;
|
rekeyed = child_sa->get_state(child_sa) == CHILD_REKEYED;
|
||||||
child_sa->set_state(child_sa, CHILD_DELETING);
|
child_sa->set_state(child_sa, CHILD_DELETING);
|
||||||
|
|
||||||
my_ts = linked_list_create_from_enumerator(
|
my_ts = linked_list_create_from_enumerator(
|
||||||
|
|||||||
@@ -402,7 +402,7 @@ static bool install(private_quick_mode_t *this)
|
|||||||
{
|
{
|
||||||
charon->bus->child_rekey(charon->bus, old, this->child_sa);
|
charon->bus->child_rekey(charon->bus, old, this->child_sa);
|
||||||
/* rekeyed CHILD_SAs stay installed until they expire */
|
/* rekeyed CHILD_SAs stay installed until they expire */
|
||||||
old->set_state(old, CHILD_INSTALLED);
|
old->set_state(old, CHILD_REKEYED);
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
@@ -988,6 +988,7 @@ static void check_for_rekeyed_child(private_quick_mode_t *this)
|
|||||||
{
|
{
|
||||||
case CHILD_INSTALLED:
|
case CHILD_INSTALLED:
|
||||||
case CHILD_REKEYING:
|
case CHILD_REKEYING:
|
||||||
|
case CHILD_REKEYED:
|
||||||
policies = child_sa->create_policy_enumerator(child_sa);
|
policies = child_sa->create_policy_enumerator(child_sa);
|
||||||
if (policies->enumerate(policies, &local, &remote) &&
|
if (policies->enumerate(policies, &local, &remote) &&
|
||||||
local->equals(local, this->tsr) &&
|
local->equals(local, this->tsr) &&
|
||||||
|
|||||||
Reference in New Issue
Block a user