kernel: Use structs to pass information to the kernel-ipsec interface
This commit is contained in:
committed by
Andreas Steffen
parent
ea3a4d3f72
commit
89da06ace9
@@ -1,6 +1,7 @@
|
||||
/*
|
||||
* Copyright (C) 2008-2015 Tobias Brunner
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
* Copyright (C) 2008-2016 Tobias Brunner
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* Copyright (C) 2010 Martin Willi
|
||||
* Copyright (C) 2010 revosec AG
|
||||
*
|
||||
@@ -415,59 +416,48 @@ METHOD(kernel_interface_t, release_reqid, status_t,
|
||||
}
|
||||
|
||||
METHOD(kernel_interface_t, add_sa, status_t,
|
||||
private_kernel_interface_t *this, host_t *src, host_t *dst,
|
||||
uint32_t spi, uint8_t protocol, uint32_t reqid, mark_t mark,
|
||||
uint32_t tfc, lifetime_cfg_t *lifetime, uint16_t enc_alg, chunk_t enc_key,
|
||||
uint16_t int_alg, chunk_t int_key, ipsec_mode_t mode,
|
||||
uint16_t ipcomp, uint16_t cpi, uint32_t replay_window,
|
||||
bool initiator, bool encap, bool esn, bool inbound, bool update,
|
||||
linked_list_t *src_ts, linked_list_t *dst_ts)
|
||||
private_kernel_interface_t *this, kernel_ipsec_sa_id_t *id,
|
||||
kernel_ipsec_add_sa_t *data)
|
||||
{
|
||||
if (!this->ipsec)
|
||||
{
|
||||
return NOT_SUPPORTED;
|
||||
}
|
||||
return this->ipsec->add_sa(this->ipsec, src, dst, spi, protocol, reqid,
|
||||
mark, tfc, lifetime, enc_alg, enc_key, int_alg, int_key, mode,
|
||||
ipcomp, cpi, replay_window, initiator, encap, esn, inbound,
|
||||
update, src_ts, dst_ts);
|
||||
return this->ipsec->add_sa(this->ipsec, id, data);
|
||||
}
|
||||
|
||||
METHOD(kernel_interface_t, update_sa, status_t,
|
||||
private_kernel_interface_t *this, uint32_t spi, uint8_t protocol,
|
||||
uint16_t cpi, host_t *src, host_t *dst, host_t *new_src, host_t *new_dst,
|
||||
bool encap, bool new_encap, mark_t mark)
|
||||
private_kernel_interface_t *this, kernel_ipsec_sa_id_t *id,
|
||||
kernel_ipsec_update_sa_t *data)
|
||||
{
|
||||
if (!this->ipsec)
|
||||
{
|
||||
return NOT_SUPPORTED;
|
||||
}
|
||||
return this->ipsec->update_sa(this->ipsec, spi, protocol, cpi, src, dst,
|
||||
new_src, new_dst, encap, new_encap, mark);
|
||||
return this->ipsec->update_sa(this->ipsec, id, data);
|
||||
}
|
||||
|
||||
METHOD(kernel_interface_t, query_sa, status_t,
|
||||
private_kernel_interface_t *this, host_t *src, host_t *dst,
|
||||
uint32_t spi, uint8_t protocol, mark_t mark,
|
||||
uint64_t *bytes, uint64_t *packets, time_t *time)
|
||||
private_kernel_interface_t *this, kernel_ipsec_sa_id_t *id,
|
||||
kernel_ipsec_query_sa_t *data, uint64_t *bytes, uint64_t *packets,
|
||||
time_t *time)
|
||||
{
|
||||
if (!this->ipsec)
|
||||
{
|
||||
return NOT_SUPPORTED;
|
||||
}
|
||||
return this->ipsec->query_sa(this->ipsec, src, dst, spi, protocol, mark,
|
||||
bytes, packets, time);
|
||||
return this->ipsec->query_sa(this->ipsec, id, data, bytes, packets, time);
|
||||
}
|
||||
|
||||
METHOD(kernel_interface_t, del_sa, status_t,
|
||||
private_kernel_interface_t *this, host_t *src, host_t *dst, uint32_t spi,
|
||||
uint8_t protocol, uint16_t cpi, mark_t mark)
|
||||
private_kernel_interface_t *this, kernel_ipsec_sa_id_t *id,
|
||||
kernel_ipsec_del_sa_t *data)
|
||||
{
|
||||
if (!this->ipsec)
|
||||
{
|
||||
return NOT_SUPPORTED;
|
||||
}
|
||||
return this->ipsec->del_sa(this->ipsec, src, dst, spi, protocol, cpi, mark);
|
||||
return this->ipsec->del_sa(this->ipsec, id, data);
|
||||
}
|
||||
|
||||
METHOD(kernel_interface_t, flush_sas, status_t,
|
||||
@@ -481,44 +471,36 @@ METHOD(kernel_interface_t, flush_sas, status_t,
|
||||
}
|
||||
|
||||
METHOD(kernel_interface_t, add_policy, status_t,
|
||||
private_kernel_interface_t *this, host_t *src, host_t *dst,
|
||||
traffic_selector_t *src_ts, traffic_selector_t *dst_ts,
|
||||
policy_dir_t direction, policy_type_t type, ipsec_sa_cfg_t *sa,
|
||||
mark_t mark, policy_priority_t priority)
|
||||
private_kernel_interface_t *this, kernel_ipsec_policy_id_t *id,
|
||||
kernel_ipsec_manage_policy_t *data)
|
||||
{
|
||||
if (!this->ipsec)
|
||||
{
|
||||
return NOT_SUPPORTED;
|
||||
}
|
||||
return this->ipsec->add_policy(this->ipsec, src, dst, src_ts, dst_ts,
|
||||
direction, type, sa, mark, priority);
|
||||
return this->ipsec->add_policy(this->ipsec, id, data);
|
||||
}
|
||||
|
||||
METHOD(kernel_interface_t, query_policy, status_t,
|
||||
private_kernel_interface_t *this, traffic_selector_t *src_ts,
|
||||
traffic_selector_t *dst_ts, policy_dir_t direction, mark_t mark,
|
||||
time_t *use_time)
|
||||
private_kernel_interface_t *this, kernel_ipsec_policy_id_t *id,
|
||||
kernel_ipsec_query_policy_t *data, time_t *use_time)
|
||||
{
|
||||
if (!this->ipsec)
|
||||
{
|
||||
return NOT_SUPPORTED;
|
||||
}
|
||||
return this->ipsec->query_policy(this->ipsec, src_ts, dst_ts,
|
||||
direction, mark, use_time);
|
||||
return this->ipsec->query_policy(this->ipsec, id, data, use_time);
|
||||
}
|
||||
|
||||
METHOD(kernel_interface_t, del_policy, status_t,
|
||||
private_kernel_interface_t *this, host_t *src, host_t *dst,
|
||||
traffic_selector_t *src_ts, traffic_selector_t *dst_ts,
|
||||
policy_dir_t direction, policy_type_t type, ipsec_sa_cfg_t *sa,
|
||||
mark_t mark, policy_priority_t priority)
|
||||
private_kernel_interface_t *this, kernel_ipsec_policy_id_t *id,
|
||||
kernel_ipsec_manage_policy_t *data)
|
||||
{
|
||||
if (!this->ipsec)
|
||||
{
|
||||
return NOT_SUPPORTED;
|
||||
}
|
||||
return this->ipsec->del_policy(this->ipsec, src, dst, src_ts, dst_ts,
|
||||
direction, type, sa, mark, priority);
|
||||
return this->ipsec->del_policy(this->ipsec, id, data);
|
||||
}
|
||||
|
||||
METHOD(kernel_interface_t, flush_policies, status_t,
|
||||
|
||||
@@ -1,9 +1,9 @@
|
||||
/*
|
||||
* Copyright (C) 2006-2015 Tobias Brunner
|
||||
* Copyright (C) 2006-2016 Tobias Brunner
|
||||
* Copyright (C) 2006 Daniel Roethlisberger
|
||||
* Copyright (C) 2005-2006 Martin Willi
|
||||
* Copyright (C) 2005 Jan Hutter
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
@@ -160,41 +160,12 @@ struct kernel_interface_t {
|
||||
* This function does install a single SA for a single protocol in one
|
||||
* direction.
|
||||
*
|
||||
* @param src source address for this SA
|
||||
* @param dst destination address for this SA
|
||||
* @param spi SPI allocated by us or remote peer
|
||||
* @param protocol protocol for this SA (ESP/AH)
|
||||
* @param reqid reqid for this SA
|
||||
* @param mark optional mark for this SA
|
||||
* @param tfc Traffic Flow Confidentiality padding for this SA
|
||||
* @param lifetime lifetime_cfg_t for this SA
|
||||
* @param enc_alg Algorithm to use for encryption (ESP only)
|
||||
* @param enc_key key to use for encryption
|
||||
* @param int_alg Algorithm to use for integrity protection
|
||||
* @param int_key key to use for integrity protection
|
||||
* @param mode mode of the SA (tunnel, transport)
|
||||
* @param ipcomp IPComp transform to use
|
||||
* @param cpi CPI for IPComp
|
||||
* @param replay_window anti-replay window size
|
||||
* @param initiator TRUE if initiator of the exchange creating this SA
|
||||
* @param encap enable UDP encapsulation for NAT traversal
|
||||
* @param esn TRUE to use Extended Sequence Numbers
|
||||
* @param inbound TRUE if this is an inbound SA
|
||||
* @param update TRUE if an SPI has already been allocated for SA
|
||||
* @param src_ts list of source traffic selectors
|
||||
* @param dst_ts list of destination traffic selectors
|
||||
* @param id data identifying this SA
|
||||
* @param data data for this SA
|
||||
* @return SUCCESS if operation completed
|
||||
*/
|
||||
status_t (*add_sa) (kernel_interface_t *this,
|
||||
host_t *src, host_t *dst, uint32_t spi,
|
||||
uint8_t protocol, uint32_t reqid, mark_t mark,
|
||||
uint32_t tfc, lifetime_cfg_t *lifetime,
|
||||
uint16_t enc_alg, chunk_t enc_key,
|
||||
uint16_t int_alg, chunk_t int_key,
|
||||
ipsec_mode_t mode, uint16_t ipcomp, uint16_t cpi,
|
||||
uint32_t replay_window, bool initiator, bool encap,
|
||||
bool esn, bool inbound, bool update,
|
||||
linked_list_t *src_ts, linked_list_t *dst_ts);
|
||||
status_t (*add_sa)(kernel_interface_t *this, kernel_ipsec_sa_id_t *id,
|
||||
kernel_ipsec_add_sa_t *data);
|
||||
|
||||
/**
|
||||
* Update the hosts on an installed SA.
|
||||
@@ -204,85 +175,55 @@ struct kernel_interface_t {
|
||||
* to identify SAs. Therefore if the destination address changed we
|
||||
* create a new SA and delete the old one.
|
||||
*
|
||||
* @param spi SPI of the SA
|
||||
* @param protocol protocol for this SA (ESP/AH)
|
||||
* @param cpi CPI for IPComp, 0 if no IPComp is used
|
||||
* @param src current source address
|
||||
* @param dst current destination address
|
||||
* @param new_src new source address
|
||||
* @param new_dst new destination address
|
||||
* @param encap current use of UDP encapsulation
|
||||
* @param new_encap new use of UDP encapsulation
|
||||
* @param mark optional mark for this SA
|
||||
* @param id data identifying this SA
|
||||
* @param data updated data for this SA
|
||||
* @return SUCCESS if operation completed, NOT_SUPPORTED if
|
||||
* the kernel interface can't update the SA
|
||||
* the kernel interface can't update the SA
|
||||
*/
|
||||
status_t (*update_sa)(kernel_interface_t *this,
|
||||
uint32_t spi, uint8_t protocol, uint16_t cpi,
|
||||
host_t *src, host_t *dst,
|
||||
host_t *new_src, host_t *new_dst,
|
||||
bool encap, bool new_encap, mark_t mark);
|
||||
status_t (*update_sa)(kernel_interface_t *this, kernel_ipsec_sa_id_t *id,
|
||||
kernel_ipsec_update_sa_t *data);
|
||||
|
||||
/**
|
||||
* Query the number of bytes processed by an SA from the SAD.
|
||||
*
|
||||
* @param src source address for this SA
|
||||
* @param dst destination address for this SA
|
||||
* @param spi SPI allocated by us or remote peer
|
||||
* @param protocol protocol for this SA (ESP/AH)
|
||||
* @param mark optional mark for this SA
|
||||
* @param id data identifying this SA
|
||||
* @param data data to query the SA
|
||||
* @param[out] bytes the number of bytes processed by SA
|
||||
* @param[out] packets number of packets processed by SA
|
||||
* @param[out] time last (monotonic) time of SA use
|
||||
* @return SUCCESS if operation completed
|
||||
*/
|
||||
status_t (*query_sa) (kernel_interface_t *this, host_t *src, host_t *dst,
|
||||
uint32_t spi, uint8_t protocol, mark_t mark,
|
||||
uint64_t *bytes, uint64_t *packets, time_t *time);
|
||||
status_t (*query_sa)(kernel_interface_t *this, kernel_ipsec_sa_id_t *id,
|
||||
kernel_ipsec_query_sa_t *data, uint64_t *bytes,
|
||||
uint64_t *packets, time_t *time);
|
||||
|
||||
/**
|
||||
* Delete a previously installed SA from the SAD.
|
||||
*
|
||||
* @param src source address for this SA
|
||||
* @param dst destination address for this SA
|
||||
* @param spi SPI allocated by us or remote peer
|
||||
* @param protocol protocol for this SA (ESP/AH)
|
||||
* @param cpi CPI for IPComp or 0
|
||||
* @param mark optional mark for this SA
|
||||
* @param id data identifying this SA
|
||||
* @param data data to delete the SA
|
||||
* @return SUCCESS if operation completed
|
||||
*/
|
||||
status_t (*del_sa) (kernel_interface_t *this, host_t *src, host_t *dst,
|
||||
uint32_t spi, uint8_t protocol, uint16_t cpi,
|
||||
mark_t mark);
|
||||
status_t (*del_sa)(kernel_interface_t *this, kernel_ipsec_sa_id_t *id,
|
||||
kernel_ipsec_del_sa_t *data);
|
||||
|
||||
/**
|
||||
* Flush all SAs from the SAD.
|
||||
*
|
||||
* @return SUCCESS if operation completed
|
||||
*/
|
||||
status_t (*flush_sas) (kernel_interface_t *this);
|
||||
status_t (*flush_sas)(kernel_interface_t *this);
|
||||
|
||||
/**
|
||||
* Add a policy to the SPD.
|
||||
*
|
||||
* @param src source address of SA
|
||||
* @param dst dest address of SA
|
||||
* @param src_ts traffic selector to match traffic source
|
||||
* @param dst_ts traffic selector to match traffic dest
|
||||
* @param direction direction of traffic, POLICY_(IN|OUT|FWD)
|
||||
* @param type type of policy, POLICY_(IPSEC|PASS|DROP)
|
||||
* @param sa details about the SA(s) tied to this policy
|
||||
* @param mark mark for this policy
|
||||
* @param priority priority of this policy
|
||||
* @param id data identifying this policy
|
||||
* @param data data for this policy
|
||||
* @return SUCCESS if operation completed
|
||||
*/
|
||||
status_t (*add_policy) (kernel_interface_t *this,
|
||||
host_t *src, host_t *dst,
|
||||
traffic_selector_t *src_ts,
|
||||
traffic_selector_t *dst_ts,
|
||||
policy_dir_t direction, policy_type_t type,
|
||||
ipsec_sa_cfg_t *sa, mark_t mark,
|
||||
policy_priority_t priority);
|
||||
status_t (*add_policy)(kernel_interface_t *this,
|
||||
kernel_ipsec_policy_id_t *id,
|
||||
kernel_ipsec_manage_policy_t *data);
|
||||
|
||||
/**
|
||||
* Query the use time of a policy.
|
||||
@@ -290,47 +231,33 @@ struct kernel_interface_t {
|
||||
* The use time of a policy is the time the policy was used
|
||||
* for the last time.
|
||||
*
|
||||
* @param src_ts traffic selector to match traffic source
|
||||
* @param dst_ts traffic selector to match traffic dest
|
||||
* @param direction direction of traffic, POLICY_(IN|OUT|FWD)
|
||||
* @param mark optional mark
|
||||
* @param[out] use_time the (monotonic) time of this SA's last use
|
||||
* @param id data identifying this policy
|
||||
* @param data data to query the policy
|
||||
* @param[out] use_time the monotonic timestamp of this SA's last use
|
||||
* @return SUCCESS if operation completed
|
||||
*/
|
||||
status_t (*query_policy) (kernel_interface_t *this,
|
||||
traffic_selector_t *src_ts,
|
||||
traffic_selector_t *dst_ts,
|
||||
policy_dir_t direction, mark_t mark,
|
||||
time_t *use_time);
|
||||
status_t (*query_policy)(kernel_interface_t *this,
|
||||
kernel_ipsec_policy_id_t *id,
|
||||
kernel_ipsec_query_policy_t *data,
|
||||
time_t *use_time);
|
||||
|
||||
/**
|
||||
* Remove a policy from the SPD.
|
||||
*
|
||||
* @param src source address of SA
|
||||
* @param dst dest address of SA
|
||||
* @param src_ts traffic selector to match traffic source
|
||||
* @param dst_ts traffic selector to match traffic dest
|
||||
* @param direction direction of traffic, POLICY_(IN|OUT|FWD)
|
||||
* @param type type of policy, POLICY_(IPSEC|PASS|DROP)
|
||||
* @param sa details about the SA(s) tied to this policy
|
||||
* @param mark mark for this policy
|
||||
* @param priority priority of the policy
|
||||
* @param id data identifying this policy
|
||||
* @param data data for this policy
|
||||
* @return SUCCESS if operation completed
|
||||
*/
|
||||
status_t (*del_policy) (kernel_interface_t *this,
|
||||
host_t *src, host_t *dst,
|
||||
traffic_selector_t *src_ts,
|
||||
traffic_selector_t *dst_ts,
|
||||
policy_dir_t direction, policy_type_t type,
|
||||
ipsec_sa_cfg_t *sa, mark_t mark,
|
||||
policy_priority_t priority);
|
||||
status_t (*del_policy)(kernel_interface_t *this,
|
||||
kernel_ipsec_policy_id_t *id,
|
||||
kernel_ipsec_manage_policy_t *data);
|
||||
|
||||
/**
|
||||
* Flush all policies from the SPD.
|
||||
*
|
||||
* @return SUCCESS if operation completed
|
||||
*/
|
||||
status_t (*flush_policies) (kernel_interface_t *this);
|
||||
status_t (*flush_policies)(kernel_interface_t *this);
|
||||
|
||||
/**
|
||||
* Get our outgoing source address for a destination.
|
||||
|
||||
+173
-113
@@ -1,9 +1,9 @@
|
||||
/*
|
||||
* Copyright (C) 2006-2015 Tobias Brunner
|
||||
* Copyright (C) 2006-2016 Tobias Brunner
|
||||
* Copyright (C) 2006 Daniel Roethlisberger
|
||||
* Copyright (C) 2005-2006 Martin Willi
|
||||
* Copyright (C) 2005 Jan Hutter
|
||||
* Hochschule fuer Technik Rapperswil
|
||||
* HSR Hochschule fuer Technik Rapperswil
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
@@ -25,6 +25,14 @@
|
||||
#define KERNEL_IPSEC_H_
|
||||
|
||||
typedef struct kernel_ipsec_t kernel_ipsec_t;
|
||||
typedef struct kernel_ipsec_sa_id_t kernel_ipsec_sa_id_t;
|
||||
typedef struct kernel_ipsec_add_sa_t kernel_ipsec_add_sa_t;
|
||||
typedef struct kernel_ipsec_update_sa_t kernel_ipsec_update_sa_t;
|
||||
typedef struct kernel_ipsec_query_sa_t kernel_ipsec_query_sa_t;
|
||||
typedef struct kernel_ipsec_del_sa_t kernel_ipsec_del_sa_t;
|
||||
typedef struct kernel_ipsec_policy_id_t kernel_ipsec_policy_id_t;
|
||||
typedef struct kernel_ipsec_manage_policy_t kernel_ipsec_manage_policy_t;
|
||||
typedef struct kernel_ipsec_query_policy_t kernel_ipsec_query_policy_t;
|
||||
|
||||
#include <networking/host.h>
|
||||
#include <ipsec/ipsec_types.h>
|
||||
@@ -32,6 +40,131 @@ typedef struct kernel_ipsec_t kernel_ipsec_t;
|
||||
#include <plugins/plugin.h>
|
||||
#include <kernel/kernel_interface.h>
|
||||
|
||||
/**
|
||||
* Data required to identify an SA in the kernel
|
||||
*/
|
||||
struct kernel_ipsec_sa_id_t {
|
||||
/** Source address */
|
||||
host_t *src;
|
||||
/** Destination address */
|
||||
host_t *dst;
|
||||
/** SPI */
|
||||
uint32_t spi;
|
||||
/** Protocol (ESP/AH) */
|
||||
uint8_t proto;
|
||||
/** Optional mark */
|
||||
mark_t mark;
|
||||
};
|
||||
|
||||
/**
|
||||
* Data required to add an SA to the kernel
|
||||
*/
|
||||
struct kernel_ipsec_add_sa_t {
|
||||
/** Reqid */
|
||||
uint32_t reqid;
|
||||
/** Mode (tunnel, transport...) */
|
||||
ipsec_mode_t mode;
|
||||
/** List of source traffic selectors */
|
||||
linked_list_t *src_ts;
|
||||
/** List of destination traffic selectors */
|
||||
linked_list_t *dst_ts;
|
||||
/** Lifetime configuration */
|
||||
lifetime_cfg_t *lifetime;
|
||||
/** Encryption algorithm */
|
||||
uint16_t enc_alg;
|
||||
/** Encryption key */
|
||||
chunk_t enc_key;
|
||||
/** Integrity protection algorithm */
|
||||
uint16_t int_alg;
|
||||
/** Integrity protection key */
|
||||
chunk_t int_key;
|
||||
/** Anti-replay window size */
|
||||
uint32_t replay_window;
|
||||
/** Traffic Flow Confidentiality padding */
|
||||
uint32_t tfc;
|
||||
/** IPComp transform */
|
||||
uint16_t ipcomp;
|
||||
/** CPI for IPComp */
|
||||
uint16_t cpi;
|
||||
/** TRUE to enable UDP encapsulation for NAT traversal */
|
||||
bool encap;
|
||||
/** TRUE to use Extended Sequence Numbers */
|
||||
bool esn;
|
||||
/** TRUE if initiator of the exchange creating the SA */
|
||||
bool initiator;
|
||||
/** TRUE if this is an inbound SA */
|
||||
bool inbound;
|
||||
/** TRUE if an SPI has already been allocated for this SA */
|
||||
bool update;
|
||||
};
|
||||
|
||||
/**
|
||||
* Data required to update the hosts of an SA in the kernel
|
||||
*/
|
||||
struct kernel_ipsec_update_sa_t {
|
||||
/** CPI in case IPComp is used */
|
||||
uint16_t cpi;
|
||||
/** New source address */
|
||||
host_t *new_src;
|
||||
/** New destination address */
|
||||
host_t *new_dst;
|
||||
/** TRUE if UDP encapsulation is currently enabled */
|
||||
bool encap;
|
||||
/** TRUE to enable UDP encapsulation */
|
||||
bool new_encap;
|
||||
};
|
||||
|
||||
/**
|
||||
* Data required to query an SA in the kernel
|
||||
*/
|
||||
struct kernel_ipsec_query_sa_t {
|
||||
uint16_t cpi;
|
||||
};
|
||||
|
||||
/**
|
||||
* Data required to delete an SA in the kernel
|
||||
*/
|
||||
struct kernel_ipsec_del_sa_t {
|
||||
/** CPI in case IPComp is used */
|
||||
uint16_t cpi;
|
||||
};
|
||||
|
||||
/**
|
||||
* Data identifying a policy in the kernel
|
||||
*/
|
||||
struct kernel_ipsec_policy_id_t {
|
||||
/** Direction of traffic */
|
||||
policy_dir_t dir;
|
||||
/** Source traffic selector */
|
||||
traffic_selector_t *src_ts;
|
||||
/** Destination traffic selector */
|
||||
traffic_selector_t *dst_ts;
|
||||
/** Optional mark */
|
||||
mark_t mark;
|
||||
};
|
||||
|
||||
/**
|
||||
* Data required to add/delete a policy to/from the kernel
|
||||
*/
|
||||
struct kernel_ipsec_manage_policy_t {
|
||||
/** Type of policy */
|
||||
policy_type_t type;
|
||||
/** Priority class */
|
||||
policy_priority_t prio;
|
||||
/** Source address of the SA(s) tied to this policy */
|
||||
host_t *src;
|
||||
/** Destination address of the SA(s) tied to this policy */
|
||||
host_t *dst;
|
||||
/** Details about the SA(s) tied to this policy */
|
||||
ipsec_sa_cfg_t *sa;
|
||||
};
|
||||
|
||||
/**
|
||||
* Data required to query a policy in the kernel
|
||||
*/
|
||||
struct kernel_ipsec_query_policy_t {
|
||||
};
|
||||
|
||||
/**
|
||||
* Interface to the ipsec subsystem of the kernel.
|
||||
*
|
||||
@@ -81,41 +214,12 @@ struct kernel_ipsec_t {
|
||||
* This function does install a single SA for a single protocol in one
|
||||
* direction.
|
||||
*
|
||||
* @param src source address for this SA
|
||||
* @param dst destination address for this SA
|
||||
* @param spi SPI allocated by us or remote peer
|
||||
* @param protocol protocol for this SA (ESP/AH)
|
||||
* @param reqid unique ID for this SA
|
||||
* @param mark mark for this SA
|
||||
* @param tfc Traffic Flow Confidentiality padding for this SA
|
||||
* @param lifetime lifetime_cfg_t for this SA
|
||||
* @param enc_alg Algorithm to use for encryption (ESP only)
|
||||
* @param enc_key key to use for encryption
|
||||
* @param int_alg Algorithm to use for integrity protection
|
||||
* @param int_key key to use for integrity protection
|
||||
* @param mode mode of the SA (tunnel, transport)
|
||||
* @param ipcomp IPComp transform to use
|
||||
* @param cpi CPI for IPComp
|
||||
* @param replay_window anti-replay window size
|
||||
* @param initiator TRUE if initiator of the exchange creating this SA
|
||||
* @param encap enable UDP encapsulation for NAT traversal
|
||||
* @param esn TRUE to use Extended Sequence Numbers
|
||||
* @param inbound TRUE if this is an inbound SA
|
||||
* @param update TRUE if an SPI has already been allocated for SA
|
||||
* @param src_ts list of source traffic selectors
|
||||
* @param dst_ts list of destination traffic selectors
|
||||
* @param id data identifying this SA
|
||||
* @param data data for this SA
|
||||
* @return SUCCESS if operation completed
|
||||
*/
|
||||
status_t (*add_sa) (kernel_ipsec_t *this,
|
||||
host_t *src, host_t *dst, uint32_t spi,
|
||||
uint8_t protocol, uint32_t reqid,
|
||||
mark_t mark, uint32_t tfc, lifetime_cfg_t *lifetime,
|
||||
uint16_t enc_alg, chunk_t enc_key,
|
||||
uint16_t int_alg, chunk_t int_key,
|
||||
ipsec_mode_t mode, uint16_t ipcomp, uint16_t cpi,
|
||||
uint32_t replay_window, bool initiator, bool encap,
|
||||
bool esn, bool inbound, bool update,
|
||||
linked_list_t *src_ts, linked_list_t *dst_ts);
|
||||
status_t (*add_sa)(kernel_ipsec_t *this, kernel_ipsec_sa_id_t *id,
|
||||
kernel_ipsec_add_sa_t *data);
|
||||
|
||||
/**
|
||||
* Update the hosts on an installed SA.
|
||||
@@ -125,85 +229,55 @@ struct kernel_ipsec_t {
|
||||
* to identify SAs. Therefore if the destination address changed we
|
||||
* create a new SA and delete the old one.
|
||||
*
|
||||
* @param spi SPI of the SA
|
||||
* @param protocol protocol for this SA (ESP/AH)
|
||||
* @param cpi CPI for IPComp, 0 if no IPComp is used
|
||||
* @param src current source address
|
||||
* @param dst current destination address
|
||||
* @param new_src new source address
|
||||
* @param new_dst new destination address
|
||||
* @param encap current use of UDP encapsulation
|
||||
* @param new_encap new use of UDP encapsulation
|
||||
* @param mark optional mark for this SA
|
||||
* @param id data identifying this SA
|
||||
* @param data updated data for this SA
|
||||
* @return SUCCESS if operation completed, NOT_SUPPORTED if
|
||||
* the kernel interface can't update the SA
|
||||
* the kernel interface can't update the SA
|
||||
*/
|
||||
status_t (*update_sa)(kernel_ipsec_t *this,
|
||||
uint32_t spi, uint8_t protocol, uint16_t cpi,
|
||||
host_t *src, host_t *dst,
|
||||
host_t *new_src, host_t *new_dst,
|
||||
bool encap, bool new_encap, mark_t mark);
|
||||
status_t (*update_sa)(kernel_ipsec_t *this, kernel_ipsec_sa_id_t *id,
|
||||
kernel_ipsec_update_sa_t *data);
|
||||
|
||||
/**
|
||||
* Query the number of bytes processed by an SA from the SAD.
|
||||
*
|
||||
* @param src source address for this SA
|
||||
* @param dst destination address for this SA
|
||||
* @param spi SPI allocated by us or remote peer
|
||||
* @param protocol protocol for this SA (ESP/AH)
|
||||
* @param mark optional mark for this SA
|
||||
* @param id data identifying this SA
|
||||
* @param data data to query the SA
|
||||
* @param[out] bytes the number of bytes processed by SA
|
||||
* @param[out] packets number of packets processed by SA
|
||||
* @param[out] time last (monotonic) time of SA use
|
||||
* @return SUCCESS if operation completed
|
||||
*/
|
||||
status_t (*query_sa) (kernel_ipsec_t *this, host_t *src, host_t *dst,
|
||||
uint32_t spi, uint8_t protocol, mark_t mark,
|
||||
uint64_t *bytes, uint64_t *packets, time_t *time);
|
||||
status_t (*query_sa)(kernel_ipsec_t *this, kernel_ipsec_sa_id_t *id,
|
||||
kernel_ipsec_query_sa_t *data, uint64_t *bytes,
|
||||
uint64_t *packets, time_t *time);
|
||||
|
||||
/**
|
||||
* Delete a previusly installed SA from the SAD.
|
||||
* Delete a previously installed SA from the SAD.
|
||||
*
|
||||
* @param src source address for this SA
|
||||
* @param dst destination address for this SA
|
||||
* @param spi SPI allocated by us or remote peer
|
||||
* @param protocol protocol for this SA (ESP/AH)
|
||||
* @param cpi CPI for IPComp or 0
|
||||
* @param mark optional mark for this SA
|
||||
* @param id data identifying this SA
|
||||
* @param data data to delete the SA
|
||||
* @return SUCCESS if operation completed
|
||||
*/
|
||||
status_t (*del_sa) (kernel_ipsec_t *this, host_t *src, host_t *dst,
|
||||
uint32_t spi, uint8_t protocol, uint16_t cpi,
|
||||
mark_t mark);
|
||||
status_t (*del_sa)(kernel_ipsec_t *this, kernel_ipsec_sa_id_t *id,
|
||||
kernel_ipsec_del_sa_t *data);
|
||||
|
||||
/**
|
||||
* Flush all SAs from the SAD.
|
||||
*
|
||||
* @return SUCCESS if operation completed
|
||||
*/
|
||||
status_t (*flush_sas) (kernel_ipsec_t *this);
|
||||
status_t (*flush_sas)(kernel_ipsec_t *this);
|
||||
|
||||
/**
|
||||
* Add a policy to the SPD.
|
||||
*
|
||||
* @param src source address of SA
|
||||
* @param dst dest address of SA
|
||||
* @param src_ts traffic selector to match traffic source
|
||||
* @param dst_ts traffic selector to match traffic dest
|
||||
* @param direction direction of traffic, POLICY_(IN|OUT|FWD)
|
||||
* @param type type of policy, POLICY_(IPSEC|PASS|DROP)
|
||||
* @param sa details about the SA(s) tied to this policy
|
||||
* @param mark mark for this policy
|
||||
* @param priority priority of this policy
|
||||
* @param id data identifying this policy
|
||||
* @param data data for this policy
|
||||
* @return SUCCESS if operation completed
|
||||
*/
|
||||
status_t (*add_policy) (kernel_ipsec_t *this,
|
||||
host_t *src, host_t *dst,
|
||||
traffic_selector_t *src_ts,
|
||||
traffic_selector_t *dst_ts,
|
||||
policy_dir_t direction, policy_type_t type,
|
||||
ipsec_sa_cfg_t *sa, mark_t mark,
|
||||
policy_priority_t priority);
|
||||
status_t (*add_policy)(kernel_ipsec_t *this,
|
||||
kernel_ipsec_policy_id_t *id,
|
||||
kernel_ipsec_manage_policy_t *data);
|
||||
|
||||
/**
|
||||
* Query the use time of a policy.
|
||||
@@ -212,47 +286,33 @@ struct kernel_ipsec_t {
|
||||
* time. It is not the system time, but a monotonic timestamp as returned
|
||||
* by time_monotonic.
|
||||
*
|
||||
* @param src_ts traffic selector to match traffic source
|
||||
* @param dst_ts traffic selector to match traffic dest
|
||||
* @param direction direction of traffic, POLICY_(IN|OUT|FWD)
|
||||
* @param mark optional mark
|
||||
* @param id data identifying this policy
|
||||
* @param data data to query the policy
|
||||
* @param[out] use_time the monotonic timestamp of this SA's last use
|
||||
* @return SUCCESS if operation completed
|
||||
*/
|
||||
status_t (*query_policy) (kernel_ipsec_t *this,
|
||||
traffic_selector_t *src_ts,
|
||||
traffic_selector_t *dst_ts,
|
||||
policy_dir_t direction, mark_t mark,
|
||||
time_t *use_time);
|
||||
status_t (*query_policy)(kernel_ipsec_t *this,
|
||||
kernel_ipsec_policy_id_t *id,
|
||||
kernel_ipsec_query_policy_t *data,
|
||||
time_t *use_time);
|
||||
|
||||
/**
|
||||
* Remove a policy from the SPD.
|
||||
*
|
||||
* @param src source address of SA
|
||||
* @param dst dest address of SA
|
||||
* @param src_ts traffic selector to match traffic source
|
||||
* @param dst_ts traffic selector to match traffic dest
|
||||
* @param direction direction of traffic, POLICY_(IN|OUT|FWD)
|
||||
* @param type type of policy, POLICY_(IPSEC|PASS|DROP)
|
||||
* @param sa details about the SA(s) tied to this policy
|
||||
* @param mark mark for this policy
|
||||
* @param priority priority of the policy
|
||||
* @param id data identifying this policy
|
||||
* @param data data for this policy
|
||||
* @return SUCCESS if operation completed
|
||||
*/
|
||||
status_t (*del_policy) (kernel_ipsec_t *this,
|
||||
host_t *src, host_t *dst,
|
||||
traffic_selector_t *src_ts,
|
||||
traffic_selector_t *dst_ts,
|
||||
policy_dir_t direction, policy_type_t type,
|
||||
ipsec_sa_cfg_t *sa, mark_t mark,
|
||||
policy_priority_t priority);
|
||||
status_t (*del_policy)(kernel_ipsec_t *this,
|
||||
kernel_ipsec_policy_id_t *id,
|
||||
kernel_ipsec_manage_policy_t *data);
|
||||
|
||||
/**
|
||||
* Flush all policies from the SPD.
|
||||
*
|
||||
* @return SUCCESS if operation completed
|
||||
*/
|
||||
status_t (*flush_policies) (kernel_ipsec_t *this);
|
||||
status_t (*flush_policies)(kernel_ipsec_t *this);
|
||||
|
||||
/**
|
||||
* Install a bypass policy for the given socket.
|
||||
@@ -277,7 +337,7 @@ struct kernel_ipsec_t {
|
||||
/**
|
||||
* Destroy the implementation.
|
||||
*/
|
||||
void (*destroy) (kernel_ipsec_t *this);
|
||||
void (*destroy)(kernel_ipsec_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
|
||||
Reference in New Issue
Block a user