pluto: Drop support for legacy PSK format.

Any line in ipsec.secrets starting with " or ' was treated as PSK
without ID selectors by pluto.  This prevented it from supporting DNs
like "C=CH, O=Linux strongSwan, OU=Sales, [email protected]" as
ID selectors.

PSKs defined in this legacy format can easily be updated by changing

"thisIsASecret"

into

: PSK "thisIsASecret"
This commit is contained in:
Tobias Brunner
2012-02-08 13:36:32 +01:00
parent e01751035e
commit 7efde9011e
+2 -15
View File
@@ -835,14 +835,7 @@ static void process_secret(secret_t *s, int whackfd)
err_t ugh = NULL;
s->kind = SECRET_PSK; /* default */
if (*tok == '"' || *tok == '\'')
{
log_psk("PSK", s);
/* old PSK format: just a string */
ugh = process_psk_secret(&s->u.preshared_secret);
}
else if (tokeqword("psk"))
if (tokeqword("psk"))
{
log_psk("PSK", s);
@@ -989,13 +982,7 @@ static void process_secret_records(int whackfd)
for (;;)
{
if (tok[0] == '"' || tok[0] == '\'')
{
/* found key part */
process_secret(s, whackfd);
break;
}
else if (tokeq(":"))
if (tokeq(":"))
{
/* found key part */
shift(); /* discard explicit separator */