Authenticate ISA using certificates
The authentication of the ISA is now done using the certificate provided by the peer.
This commit is contained in:
committed by
Tobias Brunner
parent
49b1fdb24a
commit
832488b14a
@@ -202,9 +202,19 @@ METHOD(listener_t, authorize, bool,
|
|||||||
*success = FALSE;
|
*success = FALSE;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const chunk_t * const other_init_msg = keymat->get_peer_init_msg(keymat);
|
||||||
|
if (!other_init_msg->ptr)
|
||||||
|
{
|
||||||
|
DBG1(DBG_IKE, "no peer init message available");
|
||||||
|
*success = FALSE;
|
||||||
|
}
|
||||||
|
|
||||||
signature_type signature;
|
signature_type signature;
|
||||||
chunk_to_sequence(auth, &signature, sizeof(signature_type));
|
chunk_to_sequence(auth, &signature, sizeof(signature_type));
|
||||||
if (ike_isa_auth_psk(isa_id, signature) != TKM_OK)
|
init_message_type init_msg;
|
||||||
|
chunk_to_sequence(other_init_msg, &init_msg, sizeof(init_message_type));
|
||||||
|
|
||||||
|
if (ike_isa_auth(isa_id, cc_id, init_msg, signature) != TKM_OK)
|
||||||
{
|
{
|
||||||
DBG1(DBG_IKE, "TKM based authentication failed"
|
DBG1(DBG_IKE, "TKM based authentication failed"
|
||||||
" for ISA context %llu", isa_id);
|
" for ISA context %llu", isa_id);
|
||||||
|
|||||||
Reference in New Issue
Block a user