Handle INFORMATIONAL_V1 messages when no keys have been derived yet.

This allows to gracefully process the INFORMATIONAL_V1 message rules which
require the payloads to be encrypted and thus the exchange to be
authenticated with a HASH payload.  If such an exchange is now initiated
before the ISAKMP_SA is established, the message is simply sent unencrypted
and without HASH payload.
This commit is contained in:
Tobias Brunner
2012-03-20 17:31:08 +01:00
parent e6732003f4
commit 983e852af8
2 changed files with 8 additions and 2 deletions
+3 -2
View File
@@ -1419,8 +1419,8 @@ METHOD(message_t, generate, status_t,
chunk_free(&hash);
}
/* if at least one payload requires encryption, encrypt the message */
/* TODO-IKEV1: set is_encrypted externally instead of this check? */
/* if at least one payload requires encryption, encrypt the message.
* if we have no key material available, the flag will be reset below */
enumerator = this->payloads->create_enumerator(this->payloads);
while (enumerator->enumerate(enumerator, (void**)&payload))
{
@@ -1447,6 +1447,7 @@ METHOD(message_t, generate, status_t,
else
{
DBG2(DBG_ENC, "not encrypting payloads");
this->is_encrypted = FALSE;
}
ike_header = ike_header_create_version(this->major_version,
+5
View File
@@ -759,6 +759,11 @@ METHOD(keymat_v1_t, get_hash_phase2, chunk_t,
bool add_message = TRUE;
char *name = "Hash";
if (!this->prf)
{ /* no keys derived yet */
return hash;
}
/* Hashes are simple for most exchanges in Phase 2:
* Hash = prf(SKEYID_a, M-ID | Complete message after HASH payload)
* For Quick Mode there are three hashes: