ikev2: Add task that verifies a peer's certificate

On failure the SA is deleted and reestablished as configured.  The task
is activated after the REAUTH_COMPLETE task so a make-before-break reauth
is completed before the new SA might get torn down.
This commit is contained in:
Tobias Brunner
2016-03-10 11:07:15 +01:00
parent 034a462901
commit 8ce78e43a4
7 changed files with 183 additions and 2 deletions
+5
View File
@@ -527,6 +527,11 @@ METHOD(task_manager_t, initiate, status_t,
exchange = INFORMATIONAL;
break;
}
if (activate_task(this, TASK_IKE_VERIFY_PEER_CERT))
{
exchange = INFORMATIONAL;
break;
}
case IKE_REKEYING:
if (activate_task(this, TASK_IKE_DELETE))
{