vici: Support of raw public keys
This commit is contained in:
@@ -1,5 +1,6 @@
|
|||||||
AM_CPPFLAGS = \
|
AM_CPPFLAGS = \
|
||||||
-I$(top_srcdir)/src/libstrongswan \
|
-I$(top_srcdir)/src/libstrongswan \
|
||||||
|
-I$(top_srcdir)/src/libstrongswan/plugins/pubkey \
|
||||||
-I$(top_srcdir)/src/libhydra \
|
-I$(top_srcdir)/src/libhydra \
|
||||||
-I$(top_srcdir)/src/libcharon \
|
-I$(top_srcdir)/src/libcharon \
|
||||||
-DIPSEC_PIDDIR=\"${piddir}\"
|
-DIPSEC_PIDDIR=\"${piddir}\"
|
||||||
|
|||||||
@@ -48,6 +48,8 @@
|
|||||||
#include <collections/array.h>
|
#include <collections/array.h>
|
||||||
#include <collections/linked_list.h>
|
#include <collections/linked_list.h>
|
||||||
|
|
||||||
|
#include <pubkey_cert.h>
|
||||||
|
|
||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -97,6 +99,11 @@ struct private_vici_config_t {
|
|||||||
*/
|
*/
|
||||||
rwlock_t *lock;
|
rwlock_t *lock;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Credential backend managed by VICI used for our certificates
|
||||||
|
*/
|
||||||
|
vici_cred_t *cred;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Auxiliary certification authority information
|
* Auxiliary certification authority information
|
||||||
*/
|
*/
|
||||||
@@ -1057,6 +1064,7 @@ CALLBACK(parse_group, bool,
|
|||||||
static bool parse_cert(auth_data_t *auth, auth_rule_t rule, chunk_t v)
|
static bool parse_cert(auth_data_t *auth, auth_rule_t rule, chunk_t v)
|
||||||
{
|
{
|
||||||
vici_authority_t *authority;
|
vici_authority_t *authority;
|
||||||
|
vici_cred_t *cred;
|
||||||
certificate_t *cert;
|
certificate_t *cert;
|
||||||
|
|
||||||
cert = lib->creds->create(lib->creds, CRED_CERTIFICATE, CERT_X509,
|
cert = lib->creds->create(lib->creds, CRED_CERTIFICATE, CERT_X509,
|
||||||
@@ -1068,6 +1076,8 @@ static bool parse_cert(auth_data_t *auth, auth_rule_t rule, chunk_t v)
|
|||||||
authority = auth->request->this->authority;
|
authority = auth->request->this->authority;
|
||||||
authority->check_for_hash_and_url(authority, cert);
|
authority->check_for_hash_and_url(authority, cert);
|
||||||
}
|
}
|
||||||
|
cred = auth->request->this->cred;
|
||||||
|
cert = cred->add_cert(cred, cert);
|
||||||
auth->cfg->add(auth->cfg, rule, cert);
|
auth->cfg->add(auth->cfg, rule, cert);
|
||||||
return TRUE;
|
return TRUE;
|
||||||
}
|
}
|
||||||
@@ -1092,6 +1102,27 @@ CALLBACK(parse_cacerts, bool,
|
|||||||
return parse_cert(auth, AUTH_RULE_CA_CERT, v);
|
return parse_cert(auth, AUTH_RULE_CA_CERT, v);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Parse raw public keys
|
||||||
|
*/
|
||||||
|
CALLBACK(parse_pubkeys, bool,
|
||||||
|
auth_data_t *auth, chunk_t v)
|
||||||
|
{
|
||||||
|
vici_cred_t *cred;
|
||||||
|
certificate_t *cert;
|
||||||
|
|
||||||
|
cert = lib->creds->create(lib->creds, CRED_CERTIFICATE, CERT_TRUSTED_PUBKEY,
|
||||||
|
BUILD_BLOB_PEM, v, BUILD_END);
|
||||||
|
if (cert)
|
||||||
|
{
|
||||||
|
cred = auth->request->this->cred;
|
||||||
|
cert = cred->add_cert(cred, cert);
|
||||||
|
auth->cfg->add(auth->cfg, AUTH_RULE_SUBJECT_CERT, cert);
|
||||||
|
return TRUE;
|
||||||
|
}
|
||||||
|
return FALSE;
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Parse revocation status
|
* Parse revocation status
|
||||||
*/
|
*/
|
||||||
@@ -1287,6 +1318,7 @@ CALLBACK(auth_li, bool,
|
|||||||
{ "groups", parse_group, auth->cfg },
|
{ "groups", parse_group, auth->cfg },
|
||||||
{ "certs", parse_certs, auth },
|
{ "certs", parse_certs, auth },
|
||||||
{ "cacerts", parse_cacerts, auth },
|
{ "cacerts", parse_cacerts, auth },
|
||||||
|
{ "pubkeys", parse_pubkeys, auth },
|
||||||
};
|
};
|
||||||
|
|
||||||
return parse_rules(rules, countof(rules), name, value,
|
return parse_rules(rules, countof(rules), name, value,
|
||||||
@@ -1510,20 +1542,32 @@ CALLBACK(peer_sn, bool,
|
|||||||
.request = peer->request,
|
.request = peer->request,
|
||||||
.cfg = auth_cfg_create(),
|
.cfg = auth_cfg_create(),
|
||||||
};
|
};
|
||||||
|
certificate_t *cert;
|
||||||
|
identification_t *id;
|
||||||
|
|
||||||
if (!message->parse(message, ctx, NULL, auth_kv, auth_li, &auth))
|
if (!message->parse(message, ctx, NULL, auth_kv, auth_li, &auth))
|
||||||
{
|
{
|
||||||
auth.cfg->destroy(auth.cfg);
|
auth.cfg->destroy(auth.cfg);
|
||||||
return FALSE;
|
return FALSE;
|
||||||
}
|
}
|
||||||
|
cert = auth.cfg->get(auth.cfg, AUTH_RULE_SUBJECT_CERT);
|
||||||
|
id = auth.cfg->get(auth.cfg, AUTH_RULE_IDENTITY);
|
||||||
|
|
||||||
if (!auth.cfg->get(auth.cfg, AUTH_RULE_IDENTITY))
|
if (cert)
|
||||||
{
|
{
|
||||||
identification_t *id;
|
if (id)
|
||||||
certificate_t *cert;
|
{
|
||||||
|
if (cert->get_type(cert) == CERT_TRUSTED_PUBKEY &&
|
||||||
|
id->get_type != ID_ANY)
|
||||||
|
{
|
||||||
|
pubkey_cert_t *pubkey_cert;
|
||||||
|
|
||||||
cert = auth.cfg->get(auth.cfg, AUTH_RULE_SUBJECT_CERT);
|
/* the id is set for informational purposes, only */
|
||||||
if (cert)
|
pubkey_cert = (pubkey_cert_t*)cert;
|
||||||
|
pubkey_cert->set_subject(pubkey_cert, id);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
else
|
||||||
{
|
{
|
||||||
id = cert->get_subject(cert);
|
id = cert->get_subject(cert);
|
||||||
DBG1(DBG_CFG, " id not specified, defaulting to cert id '%Y'",
|
DBG1(DBG_CFG, " id not specified, defaulting to cert id '%Y'",
|
||||||
@@ -2121,7 +2165,8 @@ METHOD(vici_config_t, destroy, void,
|
|||||||
* See header
|
* See header
|
||||||
*/
|
*/
|
||||||
vici_config_t *vici_config_create(vici_dispatcher_t *dispatcher,
|
vici_config_t *vici_config_create(vici_dispatcher_t *dispatcher,
|
||||||
vici_authority_t *authority)
|
vici_authority_t *authority,
|
||||||
|
vici_cred_t *cred)
|
||||||
{
|
{
|
||||||
private_vici_config_t *this;
|
private_vici_config_t *this;
|
||||||
|
|
||||||
@@ -2138,6 +2183,7 @@ vici_config_t *vici_config_create(vici_dispatcher_t *dispatcher,
|
|||||||
.conns = linked_list_create(),
|
.conns = linked_list_create(),
|
||||||
.lock = rwlock_create(RWLOCK_TYPE_DEFAULT),
|
.lock = rwlock_create(RWLOCK_TYPE_DEFAULT),
|
||||||
.authority = authority,
|
.authority = authority,
|
||||||
|
.cred = cred,
|
||||||
);
|
);
|
||||||
|
|
||||||
manage_commands(this, TRUE);
|
manage_commands(this, TRUE);
|
||||||
|
|||||||
@@ -26,6 +26,7 @@
|
|||||||
|
|
||||||
#include "vici_dispatcher.h"
|
#include "vici_dispatcher.h"
|
||||||
#include "vici_authority.h"
|
#include "vici_authority.h"
|
||||||
|
#include "vici_cred.h"
|
||||||
|
|
||||||
#include <config/backend.h>
|
#include <config/backend.h>
|
||||||
|
|
||||||
@@ -51,9 +52,11 @@ struct vici_config_t {
|
|||||||
*
|
*
|
||||||
* @param dispatcher dispatcher to receive requests from
|
* @param dispatcher dispatcher to receive requests from
|
||||||
* @param authority Auxiliary certification authority information
|
* @param authority Auxiliary certification authority information
|
||||||
|
* @param cred in-memory credential backend managed by VICI
|
||||||
* @return config backend
|
* @return config backend
|
||||||
*/
|
*/
|
||||||
vici_config_t *vici_config_create(vici_dispatcher_t *dispatcher,
|
vici_config_t *vici_config_create(vici_dispatcher_t *dispatcher,
|
||||||
vici_authority_t *authority);
|
vici_authority_t *authority,
|
||||||
|
vici_cred_t *cred);
|
||||||
|
|
||||||
#endif /** VICI_CONFIG_H_ @}*/
|
#endif /** VICI_CONFIG_H_ @}*/
|
||||||
|
|||||||
@@ -308,7 +308,7 @@ static void manage_commands(private_vici_cred_t *this, bool reg)
|
|||||||
METHOD(vici_cred_t, add_cert, certificate_t*,
|
METHOD(vici_cred_t, add_cert, certificate_t*,
|
||||||
private_vici_cred_t *this, certificate_t *cert)
|
private_vici_cred_t *this, certificate_t *cert)
|
||||||
{
|
{
|
||||||
return this->creds->get_cert_ref(this->creds, cert);
|
return this->creds->add_cert_ref(this->creds, TRUE, cert);
|
||||||
}
|
}
|
||||||
|
|
||||||
METHOD(vici_cred_t, destroy, void,
|
METHOD(vici_cred_t, destroy, void,
|
||||||
|
|||||||
@@ -131,7 +131,8 @@ static bool register_vici(private_vici_plugin_t *this,
|
|||||||
this->authority = vici_authority_create(this->dispatcher,
|
this->authority = vici_authority_create(this->dispatcher,
|
||||||
this->cred);
|
this->cred);
|
||||||
lib->credmgr->add_set(lib->credmgr, &this->authority->set);
|
lib->credmgr->add_set(lib->credmgr, &this->authority->set);
|
||||||
this->config = vici_config_create(this->dispatcher, this->authority);
|
this->config = vici_config_create(this->dispatcher, this->authority,
|
||||||
|
this->cred);
|
||||||
this->attrs = vici_attribute_create(this->dispatcher);
|
this->attrs = vici_attribute_create(this->dispatcher);
|
||||||
this->logger = vici_logger_create(this->dispatcher);
|
this->logger = vici_logger_create(this->dispatcher);
|
||||||
|
|
||||||
|
|||||||
@@ -196,6 +196,13 @@ METHOD(certificate_t, destroy, void,
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
METHOD(pubkey_cert_t, set_subject, void,
|
||||||
|
private_pubkey_cert_t *this, identification_t *subject)
|
||||||
|
{
|
||||||
|
DESTROY_IF(this->subject);
|
||||||
|
this->subject = subject->clone(subject);
|
||||||
|
}
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* see header file
|
* see header file
|
||||||
*/
|
*/
|
||||||
@@ -222,6 +229,7 @@ static pubkey_cert_t *pubkey_cert_create(public_key_t *key,
|
|||||||
.get_ref = _get_ref,
|
.get_ref = _get_ref,
|
||||||
.destroy = _destroy,
|
.destroy = _destroy,
|
||||||
},
|
},
|
||||||
|
.set_subject = _set_subject,
|
||||||
},
|
},
|
||||||
.ref = 1,
|
.ref = 1,
|
||||||
.key = key,
|
.key = key,
|
||||||
|
|||||||
@@ -35,6 +35,13 @@ struct pubkey_cert_t {
|
|||||||
* Implements certificate_t.
|
* Implements certificate_t.
|
||||||
*/
|
*/
|
||||||
certificate_t interface;
|
certificate_t interface;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Set the subject of the trusted public key.
|
||||||
|
*
|
||||||
|
* @param subject subject to be set
|
||||||
|
*/
|
||||||
|
void (*set_subject)(pubkey_cert_t *this, identification_t *subject);
|
||||||
};
|
};
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -59,6 +59,7 @@ static bool is_file_list_key(char *key)
|
|||||||
char *keys[] = {
|
char *keys[] = {
|
||||||
"certs",
|
"certs",
|
||||||
"cacerts",
|
"cacerts",
|
||||||
|
"pubkeys"
|
||||||
};
|
};
|
||||||
int i;
|
int i;
|
||||||
|
|
||||||
@@ -112,12 +113,18 @@ static bool add_file_list_key(vici_req_t *req, char *key, char *value)
|
|||||||
SWANCTL_X509DIR, DIRECTORY_SEPARATOR, token);
|
SWANCTL_X509DIR, DIRECTORY_SEPARATOR, token);
|
||||||
token = buf;
|
token = buf;
|
||||||
}
|
}
|
||||||
if (streq(key, "cacerts"))
|
else if (streq(key, "cacerts"))
|
||||||
{
|
{
|
||||||
snprintf(buf, sizeof(buf), "%s%s%s",
|
snprintf(buf, sizeof(buf), "%s%s%s",
|
||||||
SWANCTL_X509CADIR, DIRECTORY_SEPARATOR, token);
|
SWANCTL_X509CADIR, DIRECTORY_SEPARATOR, token);
|
||||||
token = buf;
|
token = buf;
|
||||||
}
|
}
|
||||||
|
else if (streq(key, "pubkeys"))
|
||||||
|
{
|
||||||
|
snprintf(buf, sizeof(buf), "%s%s%s",
|
||||||
|
SWANCTL_PUBKEYDIR, DIRECTORY_SEPARATOR, token);
|
||||||
|
token = buf;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
map = chunk_map(token, FALSE);
|
map = chunk_map(token, FALSE);
|
||||||
|
|||||||
+27
-10
@@ -273,12 +273,22 @@ connections.<conn>.local<suffix>.certs =
|
|||||||
|
|
||||||
Comma separated list of certificate candidates to use for authentication.
|
Comma separated list of certificate candidates to use for authentication.
|
||||||
The certificates may use a relative path from the **swanctl** _x509_
|
The certificates may use a relative path from the **swanctl** _x509_
|
||||||
directory, or an absolute path.
|
directory or an absolute path.
|
||||||
|
|
||||||
The certificate used for authentication is selected based on the received
|
The certificate used for authentication is selected based on the received
|
||||||
certificate request payloads. If no appropriate CA can be located, the
|
certificate request payloads. If no appropriate CA can be located, the
|
||||||
first certificate is used.
|
first certificate is used.
|
||||||
|
|
||||||
|
connections.<conn>.local<suffix>.pubkeys =
|
||||||
|
Comma separated list of raw public key candidates to use for authentication.
|
||||||
|
|
||||||
|
Comma separated list of raw public key candidates to use for authentication.
|
||||||
|
The public keys may use a relative path from the **swanctl** _pubkey_
|
||||||
|
directory or an absolute path.
|
||||||
|
|
||||||
|
Even though multiple local public keys could be defined in principle, only
|
||||||
|
the first public key in the list is used for authentication.
|
||||||
|
|
||||||
connections.<conn>.local<suffix>.auth = pubkey
|
connections.<conn>.local<suffix>.auth = pubkey
|
||||||
Authentication to perform locally (_pubkey_, _psk_, _xauth[-backend]_ or
|
Authentication to perform locally (_pubkey_, _psk_, _xauth[-backend]_ or
|
||||||
_eap[-method]_).
|
_eap[-method]_).
|
||||||
@@ -370,14 +380,21 @@ connections.<conn>.remote<suffix>.certs =
|
|||||||
|
|
||||||
Comma separated list of certificates to accept for authentication.
|
Comma separated list of certificates to accept for authentication.
|
||||||
The certificates may use a relative path from the **swanctl** _x509_
|
The certificates may use a relative path from the **swanctl** _x509_
|
||||||
directory, or an absolute path.
|
directory or an absolute path.
|
||||||
|
|
||||||
connections.<conn>.remote<suffix>.cacerts =
|
connections.<conn>.remote<suffix>.cacerts =
|
||||||
Comma separated list of CA certificates to accept for authentication.
|
Comma separated list of CA certificates to accept for authentication.
|
||||||
|
|
||||||
Comma separated list of CA certificates to accept for authentication.
|
Comma separated list of CA certificates to accept for authentication.
|
||||||
The certificates may use a relative path from the **swanctl** _x509ca_
|
The certificates may use a relative path from the **swanctl** _x509ca_
|
||||||
directory, or an absolute path.
|
directory or an absolute path.
|
||||||
|
|
||||||
|
connections.<conn>.remote<suffix>.pubkeys =
|
||||||
|
Comma separated list of raw public keys to accept for authentication.
|
||||||
|
|
||||||
|
Comma separated list of raw public keys to accept for authentication.
|
||||||
|
The public keys may use a relative path from the **swanctl** _x509_
|
||||||
|
directory or an absolute path.
|
||||||
|
|
||||||
connections.<conn>.remote<suffix>.revocation = relaxed
|
connections.<conn>.remote<suffix>.revocation = relaxed
|
||||||
Certificate revocation policy, (_strict_, _ifuri_ or _relaxed_).
|
Certificate revocation policy, (_strict_, _ifuri_ or _relaxed_).
|
||||||
@@ -587,8 +604,8 @@ connections.<conn>.children.<child>.mode = tunnel
|
|||||||
Both _transport_ and _beet_ modes are subject to mode negotiation; _tunnel_
|
Both _transport_ and _beet_ modes are subject to mode negotiation; _tunnel_
|
||||||
mode is negotiated if the preferred mode is not available.
|
mode is negotiated if the preferred mode is not available.
|
||||||
|
|
||||||
_pass_ and _drop_ are used to install shunt policies, which explicitly
|
_pass_ and _drop_ are used to install shunt policies which explicitly
|
||||||
bypass the defined traffic from IPsec processing, or drop it, respectively.
|
bypass the defined traffic from IPsec processing or drop it, respectively.
|
||||||
|
|
||||||
connections.<conn>.children.<child>.policies = yes
|
connections.<conn>.children.<child>.policies = yes
|
||||||
Whether to install IPsec policies or not.
|
Whether to install IPsec policies or not.
|
||||||
@@ -704,7 +721,7 @@ secrets { # }
|
|||||||
|
|
||||||
It is not recommended to define any private key decryption passphrases,
|
It is not recommended to define any private key decryption passphrases,
|
||||||
as then there is no real security benefit in having encrypted keys. Either
|
as then there is no real security benefit in having encrypted keys. Either
|
||||||
store the key unencrypted, or enter the keys manually when loading
|
store the key unencrypted or enter the keys manually when loading
|
||||||
credentials.
|
credentials.
|
||||||
|
|
||||||
secrets.eap<suffix> { # }
|
secrets.eap<suffix> { # }
|
||||||
@@ -725,7 +742,7 @@ secrets.eap<suffix>.secret =
|
|||||||
Value of the EAP/XAuth secret.
|
Value of the EAP/XAuth secret.
|
||||||
|
|
||||||
Value of the EAP/XAuth secret. It may either be an ASCII string, a hex
|
Value of the EAP/XAuth secret. It may either be an ASCII string, a hex
|
||||||
encoded string if it has a _0x_ prefix, or a Base64 encoded string if it
|
encoded string if it has a _0x_ prefix or a Base64 encoded string if it
|
||||||
has a _0s_ prefix in its value.
|
has a _0s_ prefix in its value.
|
||||||
|
|
||||||
secrets.eap<suffix>.id<suffix> =
|
secrets.eap<suffix>.id<suffix> =
|
||||||
@@ -745,7 +762,7 @@ secrets.ike<suffix>.secret =
|
|||||||
Value of the IKE preshared secret.
|
Value of the IKE preshared secret.
|
||||||
|
|
||||||
Value of the IKE preshared secret. It may either be an ASCII string,
|
Value of the IKE preshared secret. It may either be an ASCII string,
|
||||||
a hex encoded string if it has a _0x_ prefix, or a Base64 encoded string if
|
a hex encoded string if it has a _0x_ prefix or a Base64 encoded string if
|
||||||
it has a _0s_ prefix in its value.
|
it has a _0s_ prefix in its value.
|
||||||
|
|
||||||
secrets.ike<suffix>.id<suffix> =
|
secrets.ike<suffix>.id<suffix> =
|
||||||
@@ -805,7 +822,7 @@ pools.<name>.addrs =
|
|||||||
Addresses allocated in pool.
|
Addresses allocated in pool.
|
||||||
|
|
||||||
Subnet or range defining addresses allocated in pool. Accepts a single CIDR
|
Subnet or range defining addresses allocated in pool. Accepts a single CIDR
|
||||||
subnet defining the pool to allocate addresses from, or an address range
|
subnet defining the pool to allocate addresses from or an address range
|
||||||
(<from>-<to>). Pools must be unique and non-overlapping.
|
(<from>-<to>). Pools must be unique and non-overlapping.
|
||||||
|
|
||||||
pools.<name>.<attr> =
|
pools.<name>.<attr> =
|
||||||
@@ -828,7 +845,7 @@ authorities.<name>.cacert =
|
|||||||
CA certificate belonging to the certification authority.
|
CA certificate belonging to the certification authority.
|
||||||
|
|
||||||
The certificates may use a relative path from the **swanctl** _x509ca_
|
The certificates may use a relative path from the **swanctl** _x509ca_
|
||||||
directory, or an absolute path.
|
directory or an absolute path.
|
||||||
|
|
||||||
authorities.<name>.crl_uris =
|
authorities.<name>.crl_uris =
|
||||||
Comma-separated list of CRL distribution points
|
Comma-separated list of CRL distribution points
|
||||||
|
|||||||
Reference in New Issue
Block a user