ikev1: Send and verify IPv6 addresses correctly

According to the mode-config draft there is no prefix sent for
IPv6 addresses in IKEv1.  We still accept 17 bytes long addresses for
backwards compatibility with older strongSwan releases.

Fixes #1304.
This commit is contained in:
Tobias Brunner
2016-03-03 17:32:03 +01:00
parent 2f3c08d268
commit 91d80298f9
2 changed files with 18 additions and 26 deletions
@@ -144,6 +144,13 @@ METHOD(payload_t, verify, status_t,
} }
break; break;
case INTERNAL_IP6_ADDRESS: case INTERNAL_IP6_ADDRESS:
if (this->type == PLV1_CONFIGURATION_ATTRIBUTE &&
this->length_or_value == 16)
{ /* 16 bytes are correct for IKEv1, but older releases sent a
* prefix byte so we still accept 0 or 17 as in IKEv2 */
break;
}
/* fall-through */
case INTERNAL_IP6_SUBNET: case INTERNAL_IP6_SUBNET:
if (this->length_or_value != 0 && this->length_or_value != 17) if (this->length_or_value != 0 && this->length_or_value != 17)
{ {
+11 -26
View File
@@ -76,35 +76,20 @@ typedef struct {
*/ */
static configuration_attribute_t *build_vip(host_t *vip) static configuration_attribute_t *build_vip(host_t *vip)
{ {
configuration_attribute_type_t type; configuration_attribute_type_t type = INTERNAL_IP4_ADDRESS;
chunk_t chunk, prefix; chunk_t chunk;
if (vip->get_family(vip) == AF_INET) if (vip->get_family(vip) == AF_INET6)
{ {
type = INTERNAL_IP4_ADDRESS; type = INTERNAL_IP6_ADDRESS;
if (vip->is_anyaddr(vip)) }
{ if (vip->is_anyaddr(vip))
chunk = chunk_empty; {
} chunk = chunk_empty;
else
{
chunk = vip->get_address(vip);
}
} }
else else
{ {
type = INTERNAL_IP6_ADDRESS; chunk = vip->get_address(vip);
if (vip->is_anyaddr(vip))
{
chunk = chunk_empty;
}
else
{
prefix = chunk_alloca(1);
*prefix.ptr = 64;
chunk = vip->get_address(vip);
chunk = chunk_cata("cc", chunk, prefix);
}
} }
return configuration_attribute_create_chunk(PLV1_CONFIGURATION_ATTRIBUTE, return configuration_attribute_create_chunk(PLV1_CONFIGURATION_ATTRIBUTE,
type, chunk); type, chunk);
@@ -165,8 +150,8 @@ static void process_attribute(private_mode_config_t *this,
} }
else else
{ {
/* skip prefix byte in IPv6 payload*/ /* skip prefix byte in IPv6 payload sent by older releases */
if (family == AF_INET6) if (family == AF_INET6 && addr.len == 17)
{ {
addr.len--; addr.len--;
} }