From a88aae3df6de7dc905f8950b43edf49c1f2d7b82 Mon Sep 17 00:00:00 2001 From: Martin Willi Date: Mon, 25 Aug 2008 07:50:21 +0000 Subject: [PATCH] enforce DN of configured gateway certificate --- .../properties/nm-strongswan-dialog.glade | 86 +++++++++---------- src/charon/plugins/nm/nm_service.c | 16 ++-- 2 files changed, 54 insertions(+), 48 deletions(-) diff --git a/src/charon/plugins/nm/gnome/properties/nm-strongswan-dialog.glade b/src/charon/plugins/nm/gnome/properties/nm-strongswan-dialog.glade index bffc88e66..5a1b176da 100644 --- a/src/charon/plugins/nm/gnome/properties/nm-strongswan-dialog.glade +++ b/src/charon/plugins/nm/gnome/properties/nm-strongswan-dialog.glade @@ -37,28 +37,14 @@ 6 6 - - True - Gateway or CA certificate to use for gateway authentication. - - - 1 - 2 - 1 - 2 - - - - + True 0 - _Certificate: + _Address: True - certificate-button + address-entry - 1 - 2 GTK_FILL @@ -77,18 +63,32 @@ - + True 0 - _Address: + _Certificate: True - address-entry + certificate-button + 1 + 2 GTK_FILL + + + True + Gateway certificate to use for gateway authentication. + + + 1 + 2 + 1 + 2 + + @@ -129,14 +129,29 @@ 6 6 - + True - 0 - _Username: - True - user-entry + True + True + The username (identity) to use for authentication against the gateway. + 1 + 2 + + + + + + True + 0 + _Method: + True + method-combo + + + 1 + 2 GTK_FILL @@ -156,33 +171,18 @@ - + True 0 - _Method: + _Username: True - method-combo + user-entry - 1 - 2 GTK_FILL - - - True - True - True - The username (identity) to use for authentication against the gateway. - - - 1 - 2 - - - diff --git a/src/charon/plugins/nm/nm_service.c b/src/charon/plugins/nm/nm_service.c index 9f617b860..37db6e045 100644 --- a/src/charon/plugins/nm/nm_service.c +++ b/src/charon/plugins/nm/nm_service.c @@ -163,7 +163,7 @@ static gboolean connect_(NMVPNPlugin *plugin, NMConnection *connection, { nm_creds_t *creds; NMSettingVPN *settings; - identification_t *user = NULL; + identification_t *user = NULL, *gateway; char *address, *str; bool virtual, encap, ipcomp; ike_cfg_t *ike_cfg; @@ -173,6 +173,7 @@ static gboolean connect_(NMVPNPlugin *plugin, NMConnection *connection, ike_sa_t *ike_sa; auth_info_t *auth; auth_class_t auth_class = AUTH_CLASS_EAP; + certificate_t *cert = NULL; /** * Read parameters @@ -229,12 +230,17 @@ static gboolean connect_(NMVPNPlugin *plugin, NMConnection *connection, str = g_hash_table_lookup(settings->data, "certificate"); if (str) { - certificate_t *cert; - cert = lib->creds->create(lib->creds, CRED_CERTIFICATE, CERT_X509, BUILD_FROM_FILE, str, BUILD_END); creds->set_certificate(creds, cert); } + if (!cert) + { + g_set_error(err, NM_VPN_PLUGIN_ERROR, NM_VPN_PLUGIN_ERROR_BAD_ARGUMENTS, + "Loading certificate failed."); + return FALSE; + } + gateway = cert->get_subject(cert); str = g_hash_table_lookup(settings->data, "password"); if (str) { @@ -246,8 +252,8 @@ static gboolean connect_(NMVPNPlugin *plugin, NMConnection *connection, */ ike_cfg = ike_cfg_create(TRUE, encap, "0.0.0.0", address); ike_cfg->add_proposal(ike_cfg, proposal_create_default(PROTO_IKE)); - peer_cfg = peer_cfg_create(CONFIG_NAME, 2, ike_cfg, user, - identification_create_from_encoding(ID_ANY, chunk_empty), + peer_cfg = peer_cfg_create(CONFIG_NAME, 2, ike_cfg, + user, gateway->clone(gateway), CERT_SEND_IF_ASKED, UNIQUE_REPLACE, 1, /* keyingtries */ 18000, 0, /* rekey 5h, reauth none */ 600, 600, /* jitter, over 10min */