medsrv/medcli: Remove prototypical medsrv web application and plugins
This was from a student project that has never been developed further. And similar to the manager web application it lacks all sorts of modern standards. So just remove it and the two plugins it relied on. The test scenario is renamed to avoid confusion (neither of the two p2pnat scenarios uses medsrv/medcli).
This commit is contained in:
@@ -1,20 +0,0 @@
|
||||
AM_CPPFLAGS = \
|
||||
-I$(top_srcdir)/src/libstrongswan \
|
||||
-I$(top_srcdir)/src/libcharon
|
||||
|
||||
AM_CFLAGS = \
|
||||
$(PLUGIN_CFLAGS)
|
||||
|
||||
if MONOLITHIC
|
||||
noinst_LTLIBRARIES = libstrongswan-medcli.la
|
||||
else
|
||||
plugin_LTLIBRARIES = libstrongswan-medcli.la
|
||||
endif
|
||||
|
||||
libstrongswan_medcli_la_SOURCES = \
|
||||
medcli_plugin.h medcli_plugin.c \
|
||||
medcli_creds.h medcli_creds.c \
|
||||
medcli_config.h medcli_config.c \
|
||||
medcli_listener.h medcli_listener.c
|
||||
|
||||
libstrongswan_medcli_la_LDFLAGS = -module -avoid-version
|
||||
@@ -1,434 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#define _GNU_SOURCE
|
||||
#include <string.h>
|
||||
|
||||
#include "medcli_config.h"
|
||||
|
||||
#include <daemon.h>
|
||||
#include <processing/jobs/callback_job.h>
|
||||
|
||||
typedef struct private_medcli_config_t private_medcli_config_t;
|
||||
|
||||
/**
|
||||
* Name of the mediation connection
|
||||
*/
|
||||
#define MEDIATION_CONN_NAME "medcli-mediation"
|
||||
|
||||
/**
|
||||
* Private data of an medcli_config_t object
|
||||
*/
|
||||
struct private_medcli_config_t {
|
||||
|
||||
/**
|
||||
* Public part
|
||||
*/
|
||||
medcli_config_t public;
|
||||
|
||||
/**
|
||||
* database connection
|
||||
*/
|
||||
database_t *db;
|
||||
|
||||
/**
|
||||
* rekey time
|
||||
*/
|
||||
int rekey;
|
||||
|
||||
/**
|
||||
* dpd delay
|
||||
*/
|
||||
int dpd;
|
||||
|
||||
/**
|
||||
* default ike config
|
||||
*/
|
||||
ike_cfg_t *ike;
|
||||
};
|
||||
|
||||
/**
|
||||
* create a traffic selector from a CIDR notation string
|
||||
*/
|
||||
static traffic_selector_t *ts_from_string(char *str)
|
||||
{
|
||||
if (str)
|
||||
{
|
||||
traffic_selector_t *ts;
|
||||
|
||||
ts = traffic_selector_create_from_cidr(str, 0, 0, 65535);
|
||||
if (ts)
|
||||
{
|
||||
return ts;
|
||||
}
|
||||
}
|
||||
return traffic_selector_create_dynamic(0, 0, 65535);
|
||||
}
|
||||
|
||||
/**
|
||||
* Build a mediation config
|
||||
*/
|
||||
static peer_cfg_t *build_mediation_config(private_medcli_config_t *this,
|
||||
peer_cfg_create_t *defaults)
|
||||
{
|
||||
enumerator_t *e;
|
||||
auth_cfg_t *auth;
|
||||
ike_cfg_t *ike_cfg;
|
||||
peer_cfg_t *med_cfg;
|
||||
ike_cfg_create_t ike = {
|
||||
.version = IKEV2,
|
||||
.local = "0.0.0.0",
|
||||
.local_port = charon->socket->get_port(charon->socket, FALSE),
|
||||
.remote_port = IKEV2_UDP_PORT,
|
||||
.no_certreq = TRUE,
|
||||
};
|
||||
peer_cfg_create_t peer = *defaults;
|
||||
chunk_t me, other;
|
||||
|
||||
/* query mediation server config:
|
||||
* - build ike_cfg/peer_cfg for mediation connection on-the-fly
|
||||
*/
|
||||
e = this->db->query(this->db,
|
||||
"SELECT Address, ClientConfig.KeyId, MediationServerConfig.KeyId "
|
||||
"FROM MediationServerConfig JOIN ClientConfig",
|
||||
DB_TEXT, DB_BLOB, DB_BLOB);
|
||||
if (!e || !e->enumerate(e, &ike.remote, &me, &other))
|
||||
{
|
||||
DESTROY_IF(e);
|
||||
return NULL;
|
||||
}
|
||||
ike_cfg = ike_cfg_create(&ike);
|
||||
ike_cfg->add_proposal(ike_cfg, proposal_create_default(PROTO_IKE));
|
||||
ike_cfg->add_proposal(ike_cfg, proposal_create_default_aead(PROTO_IKE));
|
||||
|
||||
peer.mediation = TRUE;
|
||||
med_cfg = peer_cfg_create(MEDIATION_CONN_NAME, ike_cfg, &peer);
|
||||
e->destroy(e);
|
||||
|
||||
auth = auth_cfg_create();
|
||||
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY);
|
||||
auth->add(auth, AUTH_RULE_IDENTITY,
|
||||
identification_create_from_encoding(ID_KEY_ID, me));
|
||||
med_cfg->add_auth_cfg(med_cfg, auth, TRUE);
|
||||
auth = auth_cfg_create();
|
||||
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY);
|
||||
auth->add(auth, AUTH_RULE_IDENTITY,
|
||||
identification_create_from_encoding(ID_KEY_ID, other));
|
||||
med_cfg->add_auth_cfg(med_cfg, auth, FALSE);
|
||||
return med_cfg;
|
||||
}
|
||||
|
||||
METHOD(backend_t, get_peer_cfg_by_name, peer_cfg_t*,
|
||||
private_medcli_config_t *this, char *name)
|
||||
{
|
||||
enumerator_t *e;
|
||||
auth_cfg_t *auth;
|
||||
peer_cfg_t *peer_cfg;
|
||||
child_cfg_t *child_cfg;
|
||||
chunk_t me, other;
|
||||
char *local_net, *remote_net;
|
||||
peer_cfg_create_t peer = {
|
||||
.cert_policy = CERT_NEVER_SEND,
|
||||
.unique = UNIQUE_REPLACE,
|
||||
.keyingtries = 1,
|
||||
.rekey_time = this->rekey * 60,
|
||||
.jitter_time = this->rekey * 5,
|
||||
.over_time = this->rekey * 3,
|
||||
.dpd = this->dpd,
|
||||
};
|
||||
child_cfg_create_t child = {
|
||||
.lifetime = {
|
||||
.time = {
|
||||
.life = this->rekey * 60 + this->rekey,
|
||||
.rekey = this->rekey,
|
||||
.jitter = this->rekey
|
||||
},
|
||||
},
|
||||
.mode = MODE_TUNNEL,
|
||||
};
|
||||
|
||||
if (streq(name, "medcli-mediation"))
|
||||
{
|
||||
return build_mediation_config(this, &peer);
|
||||
}
|
||||
|
||||
/* query mediated config:
|
||||
* - use any-any ike_cfg
|
||||
* - build peer_cfg on-the-fly using med_cfg
|
||||
* - add a child_cfg
|
||||
*/
|
||||
e = this->db->query(this->db,
|
||||
"SELECT ClientConfig.KeyId, Connection.KeyId, "
|
||||
"Connection.LocalSubnet, Connection.RemoteSubnet "
|
||||
"FROM ClientConfig JOIN Connection "
|
||||
"WHERE Active AND Alias = ?", DB_TEXT, name,
|
||||
DB_BLOB, DB_BLOB, DB_TEXT, DB_TEXT);
|
||||
if (!e || !e->enumerate(e, &me, &other, &local_net, &remote_net))
|
||||
{
|
||||
DESTROY_IF(e);
|
||||
return NULL;
|
||||
}
|
||||
peer.mediated_by = MEDIATION_CONN_NAME;
|
||||
peer.peer_id = identification_create_from_encoding(ID_KEY_ID, other);
|
||||
peer_cfg = peer_cfg_create(name, this->ike->get_ref(this->ike), &peer);
|
||||
|
||||
auth = auth_cfg_create();
|
||||
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY);
|
||||
auth->add(auth, AUTH_RULE_IDENTITY,
|
||||
identification_create_from_encoding(ID_KEY_ID, me));
|
||||
peer_cfg->add_auth_cfg(peer_cfg, auth, TRUE);
|
||||
auth = auth_cfg_create();
|
||||
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY);
|
||||
auth->add(auth, AUTH_RULE_IDENTITY,
|
||||
identification_create_from_encoding(ID_KEY_ID, other));
|
||||
peer_cfg->add_auth_cfg(peer_cfg, auth, FALSE);
|
||||
|
||||
child_cfg = child_cfg_create(name, &child);
|
||||
child_cfg->add_proposal(child_cfg, proposal_create_default_aead(PROTO_ESP));
|
||||
child_cfg->add_proposal(child_cfg, proposal_create_default(PROTO_ESP));
|
||||
child_cfg->add_traffic_selector(child_cfg, TRUE, ts_from_string(local_net));
|
||||
child_cfg->add_traffic_selector(child_cfg, FALSE, ts_from_string(remote_net));
|
||||
peer_cfg->add_child_cfg(peer_cfg, child_cfg);
|
||||
e->destroy(e);
|
||||
return peer_cfg;
|
||||
}
|
||||
|
||||
METHOD(backend_t, create_ike_cfg_enumerator, enumerator_t*,
|
||||
private_medcli_config_t *this, host_t *me, host_t *other)
|
||||
{
|
||||
return enumerator_create_single(this->ike, NULL);
|
||||
}
|
||||
|
||||
typedef struct {
|
||||
/** implements enumerator */
|
||||
enumerator_t public;
|
||||
/** inner SQL enumerator */
|
||||
enumerator_t *inner;
|
||||
/** currently enumerated peer config */
|
||||
peer_cfg_t *current;
|
||||
/** ike cfg to use in peer cfg */
|
||||
ike_cfg_t *ike;
|
||||
/** rekey time */
|
||||
int rekey;
|
||||
/** dpd time */
|
||||
int dpd;
|
||||
} peer_enumerator_t;
|
||||
|
||||
METHOD(enumerator_t, peer_enumerator_enumerate, bool,
|
||||
peer_enumerator_t *this, va_list args)
|
||||
{
|
||||
char *name, *local_net, *remote_net;
|
||||
chunk_t me, other;
|
||||
peer_cfg_t **cfg;
|
||||
child_cfg_t *child_cfg;
|
||||
auth_cfg_t *auth;
|
||||
peer_cfg_create_t peer = {
|
||||
.cert_policy = CERT_NEVER_SEND,
|
||||
.unique = UNIQUE_REPLACE,
|
||||
.keyingtries = 1,
|
||||
.rekey_time = this->rekey * 60,
|
||||
.jitter_time = this->rekey * 5,
|
||||
.over_time = this->rekey * 3,
|
||||
.dpd = this->dpd,
|
||||
};
|
||||
child_cfg_create_t child = {
|
||||
.lifetime = {
|
||||
.time = {
|
||||
.life = this->rekey * 60 + this->rekey,
|
||||
.rekey = this->rekey,
|
||||
.jitter = this->rekey
|
||||
},
|
||||
},
|
||||
.mode = MODE_TUNNEL,
|
||||
};
|
||||
|
||||
VA_ARGS_VGET(args, cfg);
|
||||
|
||||
DESTROY_IF(this->current);
|
||||
if (!this->inner->enumerate(this->inner, &name, &me, &other,
|
||||
&local_net, &remote_net))
|
||||
{
|
||||
this->current = NULL;
|
||||
return FALSE;
|
||||
}
|
||||
this->current = peer_cfg_create(name, this->ike->get_ref(this->ike), &peer);
|
||||
|
||||
auth = auth_cfg_create();
|
||||
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY);
|
||||
auth->add(auth, AUTH_RULE_IDENTITY,
|
||||
identification_create_from_encoding(ID_KEY_ID, me));
|
||||
this->current->add_auth_cfg(this->current, auth, TRUE);
|
||||
auth = auth_cfg_create();
|
||||
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY);
|
||||
auth->add(auth, AUTH_RULE_IDENTITY,
|
||||
identification_create_from_encoding(ID_KEY_ID, other));
|
||||
this->current->add_auth_cfg(this->current, auth, FALSE);
|
||||
|
||||
child_cfg = child_cfg_create(name, &child);
|
||||
child_cfg->add_proposal(child_cfg, proposal_create_default_aead(PROTO_ESP));
|
||||
child_cfg->add_proposal(child_cfg, proposal_create_default(PROTO_ESP));
|
||||
child_cfg->add_traffic_selector(child_cfg, TRUE, ts_from_string(local_net));
|
||||
child_cfg->add_traffic_selector(child_cfg, FALSE, ts_from_string(remote_net));
|
||||
this->current->add_child_cfg(this->current, child_cfg);
|
||||
*cfg = this->current;
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(enumerator_t, peer_enumerator_destroy, void,
|
||||
peer_enumerator_t *this)
|
||||
{
|
||||
DESTROY_IF(this->current);
|
||||
this->inner->destroy(this->inner);
|
||||
free(this);
|
||||
}
|
||||
|
||||
METHOD(backend_t, create_peer_cfg_enumerator, enumerator_t*,
|
||||
private_medcli_config_t *this, identification_t *me,
|
||||
identification_t *other)
|
||||
{
|
||||
peer_enumerator_t *e;
|
||||
|
||||
INIT(e,
|
||||
.public = {
|
||||
.enumerate = enumerator_enumerate_default,
|
||||
.venumerate = _peer_enumerator_enumerate,
|
||||
.destroy = _peer_enumerator_destroy,
|
||||
},
|
||||
.ike = this->ike,
|
||||
.rekey = this->rekey,
|
||||
.dpd = this->dpd,
|
||||
);
|
||||
|
||||
/* filter on IDs: NULL or ANY or matching KEY_ID */
|
||||
e->inner = this->db->query(this->db,
|
||||
"SELECT Alias, ClientConfig.KeyId, Connection.KeyId, "
|
||||
"Connection.LocalSubnet, Connection.RemoteSubnet "
|
||||
"FROM ClientConfig JOIN Connection "
|
||||
"WHERE Active AND "
|
||||
"(? OR ClientConfig.KeyId = ?) AND (? OR Connection.KeyId = ?)",
|
||||
DB_INT, me == NULL || me->get_type(me) == ID_ANY,
|
||||
DB_BLOB, me && me->get_type(me) == ID_KEY_ID ?
|
||||
me->get_encoding(me) : chunk_empty,
|
||||
DB_INT, other == NULL || other->get_type(other) == ID_ANY,
|
||||
DB_BLOB, other && other->get_type(other) == ID_KEY_ID ?
|
||||
other->get_encoding(other) : chunk_empty,
|
||||
DB_TEXT, DB_BLOB, DB_BLOB, DB_TEXT, DB_TEXT);
|
||||
if (!e->inner)
|
||||
{
|
||||
free(e);
|
||||
return NULL;
|
||||
}
|
||||
return &e->public;
|
||||
}
|
||||
|
||||
/**
|
||||
* initiate a peer config
|
||||
*/
|
||||
static job_requeue_t initiate_config(peer_cfg_t *peer_cfg)
|
||||
{
|
||||
enumerator_t *enumerator;
|
||||
child_cfg_t *child_cfg = NULL;
|
||||
|
||||
enumerator = peer_cfg->create_child_cfg_enumerator(peer_cfg);
|
||||
enumerator->enumerate(enumerator, &child_cfg);
|
||||
if (child_cfg)
|
||||
{
|
||||
child_cfg->get_ref(child_cfg);
|
||||
peer_cfg->get_ref(peer_cfg);
|
||||
enumerator->destroy(enumerator);
|
||||
charon->controller->initiate(charon->controller, peer_cfg, child_cfg,
|
||||
NULL, NULL, 0, 0, FALSE);
|
||||
}
|
||||
else
|
||||
{
|
||||
enumerator->destroy(enumerator);
|
||||
}
|
||||
return JOB_REQUEUE_NONE;
|
||||
}
|
||||
|
||||
/**
|
||||
* schedule initiation of all "active" connections
|
||||
*/
|
||||
static void schedule_autoinit(private_medcli_config_t *this)
|
||||
{
|
||||
enumerator_t *e;
|
||||
char *name;
|
||||
|
||||
e = this->db->query(this->db, "SELECT Alias FROM Connection WHERE Active",
|
||||
DB_TEXT);
|
||||
if (e)
|
||||
{
|
||||
while (e->enumerate(e, &name))
|
||||
{
|
||||
peer_cfg_t *peer_cfg;
|
||||
|
||||
peer_cfg = get_peer_cfg_by_name(this, name);
|
||||
if (peer_cfg)
|
||||
{
|
||||
/* schedule asynchronous initiation job */
|
||||
lib->processor->queue_job(lib->processor,
|
||||
(job_t*)callback_job_create(
|
||||
(callback_job_cb_t)initiate_config,
|
||||
peer_cfg, (void*)peer_cfg->destroy, NULL));
|
||||
}
|
||||
}
|
||||
e->destroy(e);
|
||||
}
|
||||
}
|
||||
|
||||
METHOD(medcli_config_t, destroy, void,
|
||||
private_medcli_config_t *this)
|
||||
{
|
||||
this->ike->destroy(this->ike);
|
||||
free(this);
|
||||
}
|
||||
|
||||
/**
|
||||
* Described in header.
|
||||
*/
|
||||
medcli_config_t *medcli_config_create(database_t *db)
|
||||
{
|
||||
private_medcli_config_t *this;
|
||||
ike_cfg_create_t ike = {
|
||||
.version = IKEV2,
|
||||
.local = "0.0.0.0",
|
||||
.local_port = charon->socket->get_port(charon->socket, FALSE),
|
||||
.remote = "0.0.0.0",
|
||||
.remote_port = IKEV2_UDP_PORT,
|
||||
.no_certreq = TRUE,
|
||||
};
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.backend = {
|
||||
.create_peer_cfg_enumerator = _create_peer_cfg_enumerator,
|
||||
.create_ike_cfg_enumerator = _create_ike_cfg_enumerator,
|
||||
.get_peer_cfg_by_name = _get_peer_cfg_by_name,
|
||||
},
|
||||
.destroy = _destroy,
|
||||
},
|
||||
.db = db,
|
||||
.rekey = lib->settings->get_time(lib->settings, "medcli.rekey", 1200),
|
||||
.dpd = lib->settings->get_time(lib->settings, "medcli.dpd", 300),
|
||||
.ike = ike_cfg_create(&ike),
|
||||
);
|
||||
this->ike->add_proposal(this->ike, proposal_create_default(PROTO_IKE));
|
||||
this->ike->add_proposal(this->ike, proposal_create_default_aead(PROTO_IKE));
|
||||
|
||||
schedule_autoinit(this);
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
@@ -1,54 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup medcli_config_i medcli_config
|
||||
* @{ @ingroup medcli
|
||||
*/
|
||||
|
||||
#ifndef MEDCLI_CONFIG_H_
|
||||
#define MEDCLI_CONFIG_H_
|
||||
|
||||
#include <config/backend.h>
|
||||
#include <database/database.h>
|
||||
|
||||
typedef struct medcli_config_t medcli_config_t;
|
||||
|
||||
/**
|
||||
* Mediation client configuration backend.
|
||||
*/
|
||||
struct medcli_config_t {
|
||||
|
||||
/**
|
||||
* Implements backend_t interface
|
||||
*/
|
||||
backend_t backend;
|
||||
|
||||
/**
|
||||
* Destroy the backend.
|
||||
*/
|
||||
void (*destroy)(medcli_config_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Create a medcli_config backend instance.
|
||||
*
|
||||
* @param db underlying database
|
||||
* @return backend instance
|
||||
*/
|
||||
medcli_config_t *medcli_config_create(database_t *db);
|
||||
|
||||
#endif /** MEDCLI_CONFIG_H_ @}*/
|
||||
@@ -1,242 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "medcli_creds.h"
|
||||
|
||||
#include <daemon.h>
|
||||
#include <library.h>
|
||||
#include <collections/enumerator.h>
|
||||
|
||||
typedef struct private_medcli_creds_t private_medcli_creds_t;
|
||||
|
||||
/**
|
||||
* Private data of an medcli_creds_t object
|
||||
*/
|
||||
struct private_medcli_creds_t {
|
||||
|
||||
/**
|
||||
* Public part
|
||||
*/
|
||||
medcli_creds_t public;
|
||||
|
||||
/**
|
||||
* underlying database handle
|
||||
*/
|
||||
database_t *db;
|
||||
};
|
||||
|
||||
/**
|
||||
* enumerator over private keys
|
||||
*/
|
||||
typedef struct {
|
||||
/** implements enumerator */
|
||||
enumerator_t public;
|
||||
/** inner SQL enumerator */
|
||||
enumerator_t *inner;
|
||||
/** currently enumerated private key */
|
||||
private_key_t *current;
|
||||
} private_enumerator_t;
|
||||
|
||||
METHOD(enumerator_t, private_enumerator_enumerate, bool,
|
||||
private_enumerator_t *this, va_list args)
|
||||
{
|
||||
private_key_t **key;
|
||||
chunk_t chunk;
|
||||
|
||||
VA_ARGS_VGET(args, key);
|
||||
|
||||
DESTROY_IF(this->current);
|
||||
while (this->inner->enumerate(this->inner, &chunk))
|
||||
{
|
||||
this->current = lib->creds->create(lib->creds, CRED_PRIVATE_KEY, KEY_RSA,
|
||||
BUILD_BLOB_ASN1_DER, chunk,
|
||||
BUILD_END);
|
||||
if (this->current)
|
||||
{
|
||||
*key = this->current;
|
||||
return TRUE;
|
||||
}
|
||||
}
|
||||
this->current = NULL;
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
METHOD(enumerator_t, private_enumerator_destroy, void,
|
||||
private_enumerator_t *this)
|
||||
{
|
||||
DESTROY_IF(this->current);
|
||||
this->inner->destroy(this->inner);
|
||||
free(this);
|
||||
}
|
||||
|
||||
METHOD(credential_set_t, create_private_enumerator, enumerator_t*,
|
||||
private_medcli_creds_t *this, key_type_t type, identification_t *id)
|
||||
{
|
||||
private_enumerator_t *e;
|
||||
|
||||
if ((type != KEY_RSA && type != KEY_ANY) ||
|
||||
id == NULL || id->get_type(id) != ID_KEY_ID)
|
||||
{
|
||||
DBG1(DBG_CFG, "%N - %Y", key_type_names, type, id);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
INIT(e,
|
||||
.public = {
|
||||
.enumerate = enumerator_enumerate_default,
|
||||
.venumerate = _private_enumerator_enumerate,
|
||||
.destroy = _private_enumerator_destroy,
|
||||
},
|
||||
);
|
||||
e->inner = this->db->query(this->db,
|
||||
"SELECT PrivateKey FROM ClientConfig WHERE KeyId = ?",
|
||||
DB_BLOB, id->get_encoding(id),
|
||||
DB_BLOB);
|
||||
if (!e->inner)
|
||||
{
|
||||
free(e);
|
||||
return NULL;
|
||||
}
|
||||
return &e->public;
|
||||
}
|
||||
|
||||
/**
|
||||
* enumerator over certificates
|
||||
*/
|
||||
typedef struct {
|
||||
/** implements enumerator */
|
||||
enumerator_t public;
|
||||
/** inner SQL enumerator */
|
||||
enumerator_t *inner;
|
||||
/** currently enumerated cert */
|
||||
certificate_t *current;
|
||||
/** type of requested key */
|
||||
key_type_t type;
|
||||
} cert_enumerator_t;
|
||||
|
||||
METHOD(enumerator_t, cert_enumerator_enumerate, bool,
|
||||
cert_enumerator_t *this, va_list args)
|
||||
{
|
||||
certificate_t **cert;
|
||||
public_key_t *public;
|
||||
chunk_t chunk;
|
||||
|
||||
VA_ARGS_VGET(args, cert);
|
||||
|
||||
DESTROY_IF(this->current);
|
||||
while (this->inner->enumerate(this->inner, &chunk))
|
||||
{
|
||||
public = lib->creds->create(lib->creds, CRED_PUBLIC_KEY, KEY_ANY,
|
||||
BUILD_BLOB_ASN1_DER, chunk,
|
||||
BUILD_END);
|
||||
if (public)
|
||||
{
|
||||
if (this->type == KEY_ANY || this->type == public->get_type(public))
|
||||
{
|
||||
this->current = lib->creds->create(lib->creds,
|
||||
CRED_CERTIFICATE, CERT_TRUSTED_PUBKEY,
|
||||
BUILD_PUBLIC_KEY, public, BUILD_END);
|
||||
public->destroy(public);
|
||||
if (this->current)
|
||||
{
|
||||
*cert = this->current;
|
||||
return TRUE;
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
public->destroy(public);
|
||||
}
|
||||
}
|
||||
}
|
||||
this->current = NULL;
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
METHOD(enumerator_t, cert_enumerator_destroy, void,
|
||||
cert_enumerator_t *this)
|
||||
{
|
||||
DESTROY_IF(this->current);
|
||||
this->inner->destroy(this->inner);
|
||||
free(this);
|
||||
}
|
||||
|
||||
METHOD(credential_set_t, create_cert_enumerator, enumerator_t*,
|
||||
private_medcli_creds_t *this, certificate_type_t cert, key_type_t key,
|
||||
identification_t *id, bool trusted)
|
||||
{
|
||||
cert_enumerator_t *e;
|
||||
|
||||
if ((cert != CERT_TRUSTED_PUBKEY && cert != CERT_ANY) ||
|
||||
id == NULL || id->get_type(id) != ID_KEY_ID)
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
|
||||
INIT(e,
|
||||
.public = {
|
||||
.enumerate = enumerator_enumerate_default,
|
||||
.venumerate = _cert_enumerator_enumerate,
|
||||
.destroy = _cert_enumerator_destroy,
|
||||
},
|
||||
.type = key,
|
||||
);
|
||||
e->inner = this->db->query(this->db,
|
||||
"SELECT PublicKey FROM ClientConfig WHERE KeyId = ? UNION "
|
||||
"SELECT PublicKey FROM MediationServerConfig WHERE KeyId = ? UNION "
|
||||
"SELECT PublicKey FROM Connection WHERE KeyId = ?",
|
||||
DB_BLOB, id->get_encoding(id),
|
||||
DB_BLOB, id->get_encoding(id),
|
||||
DB_BLOB, id->get_encoding(id),
|
||||
DB_BLOB);
|
||||
if (!e->inner)
|
||||
{
|
||||
free(e);
|
||||
return NULL;
|
||||
}
|
||||
return &e->public;
|
||||
}
|
||||
|
||||
METHOD(medcli_creds_t, destroy, void,
|
||||
private_medcli_creds_t *this)
|
||||
{
|
||||
free(this);
|
||||
}
|
||||
|
||||
/**
|
||||
* Described in header.
|
||||
*/
|
||||
medcli_creds_t *medcli_creds_create(database_t *db)
|
||||
{
|
||||
private_medcli_creds_t *this;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.set = {
|
||||
.create_private_enumerator = _create_private_enumerator,
|
||||
.create_cert_enumerator = _create_cert_enumerator,
|
||||
.create_shared_enumerator = (void*)return_null,
|
||||
.create_cdp_enumerator = (void*)return_null,
|
||||
.cache_cert = (void*)nop,
|
||||
},
|
||||
.destroy = _destroy,
|
||||
},
|
||||
.db = db,
|
||||
);
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
|
||||
@@ -1,54 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup medcli_creds_i medcli_creds
|
||||
* @{ @ingroup medcli
|
||||
*/
|
||||
|
||||
#ifndef MEDCLI_CREDS_H_
|
||||
#define MEDCLI_CREDS_H_
|
||||
|
||||
#include <credentials/credential_set.h>
|
||||
#include <database/database.h>
|
||||
|
||||
typedef struct medcli_creds_t medcli_creds_t;
|
||||
|
||||
/**
|
||||
* Mediation client credentials database.
|
||||
*/
|
||||
struct medcli_creds_t {
|
||||
|
||||
/**
|
||||
* Implements credential_set_t interface
|
||||
*/
|
||||
credential_set_t set;
|
||||
|
||||
/**
|
||||
* Destroy the credentials database.
|
||||
*/
|
||||
void (*destroy)(medcli_creds_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Create the medcli credential set.
|
||||
*
|
||||
* @param database underlying database
|
||||
* @return credential set implementation on that database
|
||||
*/
|
||||
medcli_creds_t *medcli_creds_create(database_t *database);
|
||||
|
||||
#endif /** MEDCLI_CREDS_H_ @}*/
|
||||
@@ -1,132 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "medcli_listener.h"
|
||||
|
||||
#include <daemon.h>
|
||||
#include <library.h>
|
||||
|
||||
typedef struct private_medcli_listener_t private_medcli_listener_t;
|
||||
typedef enum mediated_state_t mediated_state_t;
|
||||
|
||||
/**
|
||||
* state of a mediated connection
|
||||
*/
|
||||
enum mediated_state_t {
|
||||
STATE_DOWN = 1,
|
||||
STATE_CONNECTING = 2,
|
||||
STATE_UP = 3,
|
||||
};
|
||||
|
||||
/**
|
||||
* Private data of an medcli_listener_t object
|
||||
*/
|
||||
struct private_medcli_listener_t {
|
||||
|
||||
/**
|
||||
* Public part
|
||||
*/
|
||||
medcli_listener_t public;
|
||||
|
||||
/**
|
||||
* underlying database handle
|
||||
*/
|
||||
database_t *db;
|
||||
};
|
||||
|
||||
/**
|
||||
* Update connection status in the database
|
||||
*/
|
||||
static void set_state(private_medcli_listener_t *this, char *alias,
|
||||
mediated_state_t state)
|
||||
{
|
||||
this->db->execute(this->db, NULL,
|
||||
"UPDATE Connection SET Status = ? WHERE Alias = ?",
|
||||
DB_UINT, state, DB_TEXT, alias);
|
||||
}
|
||||
|
||||
METHOD(listener_t, ike_state_change, bool,
|
||||
private_medcli_listener_t *this, ike_sa_t *ike_sa, ike_sa_state_t state)
|
||||
{
|
||||
if (ike_sa)
|
||||
{
|
||||
switch (state)
|
||||
{
|
||||
case IKE_CONNECTING:
|
||||
set_state(this, ike_sa->get_name(ike_sa), STATE_CONNECTING);
|
||||
break;
|
||||
case IKE_DESTROYING:
|
||||
set_state(this, ike_sa->get_name(ike_sa), STATE_DOWN);
|
||||
default:
|
||||
break;
|
||||
}
|
||||
}
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(listener_t, child_state_change, bool,
|
||||
private_medcli_listener_t *this, ike_sa_t *ike_sa, child_sa_t *child_sa,
|
||||
child_sa_state_t state)
|
||||
{
|
||||
if (ike_sa && child_sa)
|
||||
{
|
||||
switch (state)
|
||||
{
|
||||
case CHILD_INSTALLED:
|
||||
set_state(this, child_sa->get_name(child_sa), STATE_UP);
|
||||
break;
|
||||
case CHILD_DESTROYING:
|
||||
set_state(this, child_sa->get_name(child_sa), STATE_DOWN);
|
||||
break;
|
||||
default:
|
||||
break;
|
||||
}
|
||||
}
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(medcli_listener_t, destroy, void,
|
||||
private_medcli_listener_t *this)
|
||||
{
|
||||
this->db->execute(this->db, NULL, "UPDATE Connection SET Status = ?",
|
||||
DB_UINT, STATE_DOWN);
|
||||
free(this);
|
||||
}
|
||||
|
||||
/**
|
||||
* Described in header.
|
||||
*/
|
||||
medcli_listener_t *medcli_listener_create(database_t *db)
|
||||
{
|
||||
private_medcli_listener_t *this;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.listener = {
|
||||
.ike_state_change = _ike_state_change,
|
||||
.child_state_change = _child_state_change,
|
||||
},
|
||||
.destroy = _destroy,
|
||||
},
|
||||
.db = db,
|
||||
);
|
||||
|
||||
db->execute(db, NULL, "UPDATE Connection SET Status = ?",
|
||||
DB_UINT, STATE_DOWN);
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
|
||||
@@ -1,54 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup medcli_listener_i medcli_listener
|
||||
* @{ @ingroup medcli
|
||||
*/
|
||||
|
||||
#ifndef MEDCLI_LISTENER_H_
|
||||
#define MEDCLI_LISTENER_H_
|
||||
|
||||
#include <bus/bus.h>
|
||||
#include <database/database.h>
|
||||
|
||||
typedef struct medcli_listener_t medcli_listener_t;
|
||||
|
||||
/**
|
||||
* Mediation client listener, writes connection status to database
|
||||
*/
|
||||
struct medcli_listener_t {
|
||||
|
||||
/**
|
||||
* Implements bus_listener_t interface
|
||||
*/
|
||||
listener_t listener;
|
||||
|
||||
/**
|
||||
* Destroy the credentials database.
|
||||
*/
|
||||
void (*destroy)(medcli_listener_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Create the medcli credential set.
|
||||
*
|
||||
* @param database underlying database
|
||||
* @return listener
|
||||
*/
|
||||
medcli_listener_t *medcli_listener_create(database_t *database);
|
||||
|
||||
#endif /** MEDCLI_LISTENER_H_ @}*/
|
||||
@@ -1,147 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2013 Tobias Brunner
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "medcli_plugin.h"
|
||||
|
||||
#include "medcli_creds.h"
|
||||
#include "medcli_config.h"
|
||||
#include "medcli_listener.h"
|
||||
|
||||
#include <daemon.h>
|
||||
|
||||
typedef struct private_medcli_plugin_t private_medcli_plugin_t;
|
||||
|
||||
/**
|
||||
* private data of medcli plugin
|
||||
*/
|
||||
struct private_medcli_plugin_t {
|
||||
|
||||
/**
|
||||
* implements plugin interface
|
||||
*/
|
||||
medcli_plugin_t public;
|
||||
|
||||
/**
|
||||
* database connection instance
|
||||
*/
|
||||
database_t *db;
|
||||
|
||||
/**
|
||||
* medcli credential set instance
|
||||
*/
|
||||
medcli_creds_t *creds;
|
||||
|
||||
/**
|
||||
* medcli config database
|
||||
*/
|
||||
medcli_config_t *config;
|
||||
|
||||
/**
|
||||
* Listener to update database connection state
|
||||
*/
|
||||
medcli_listener_t *listener;
|
||||
};
|
||||
|
||||
METHOD(plugin_t, get_name, char*,
|
||||
private_medcli_plugin_t *this)
|
||||
{
|
||||
return "medcli";
|
||||
}
|
||||
|
||||
/**
|
||||
* Connect to database
|
||||
*/
|
||||
static bool open_database(private_medcli_plugin_t *this,
|
||||
plugin_feature_t *feature, bool reg, void *cb_data)
|
||||
{
|
||||
if (reg)
|
||||
{
|
||||
char *uri;
|
||||
|
||||
uri = lib->settings->get_str(lib->settings,
|
||||
"medcli.database", NULL);
|
||||
if (!uri)
|
||||
{
|
||||
DBG1(DBG_CFG, "mediation client database URI not defined, skipped");
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
this->db = lib->db->create(lib->db, uri);
|
||||
if (this->db == NULL)
|
||||
{
|
||||
DBG1(DBG_CFG, "opening mediation client database failed");
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
this->creds = medcli_creds_create(this->db);
|
||||
this->config = medcli_config_create(this->db);
|
||||
this->listener = medcli_listener_create(this->db);
|
||||
|
||||
lib->credmgr->add_set(lib->credmgr, &this->creds->set);
|
||||
charon->backends->add_backend(charon->backends, &this->config->backend);
|
||||
charon->bus->add_listener(charon->bus, &this->listener->listener);
|
||||
}
|
||||
else
|
||||
{
|
||||
charon->bus->remove_listener(charon->bus, &this->listener->listener);
|
||||
charon->backends->remove_backend(charon->backends, &this->config->backend);
|
||||
lib->credmgr->remove_set(lib->credmgr, &this->creds->set);
|
||||
this->listener->destroy(this->listener);
|
||||
this->config->destroy(this->config);
|
||||
this->creds->destroy(this->creds);
|
||||
this->db->destroy(this->db);
|
||||
}
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(plugin_t, get_features, int,
|
||||
private_medcli_plugin_t *this, plugin_feature_t *features[])
|
||||
{
|
||||
static plugin_feature_t f[] = {
|
||||
PLUGIN_CALLBACK((plugin_feature_callback_t)open_database, NULL),
|
||||
PLUGIN_PROVIDE(CUSTOM, "medcli"),
|
||||
PLUGIN_DEPENDS(DATABASE, DB_ANY),
|
||||
};
|
||||
*features = f;
|
||||
return countof(f);
|
||||
}
|
||||
|
||||
METHOD(plugin_t, destroy, void,
|
||||
private_medcli_plugin_t *this)
|
||||
{
|
||||
free(this);
|
||||
}
|
||||
|
||||
/*
|
||||
* see header file
|
||||
*/
|
||||
PLUGIN_DEFINE(medcli)
|
||||
{
|
||||
private_medcli_plugin_t *this;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.plugin = {
|
||||
.get_name = _get_name,
|
||||
.get_features = _get_features,
|
||||
.destroy = _destroy,
|
||||
},
|
||||
},
|
||||
);
|
||||
|
||||
return &this->public.plugin;
|
||||
}
|
||||
@@ -1,43 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup medcli medcli
|
||||
* @ingroup cplugins
|
||||
*
|
||||
* @defgroup medcli_plugin medcli_plugin
|
||||
* @{ @ingroup medcli
|
||||
*/
|
||||
|
||||
#ifndef MEDCLI_PLUGIN_H_
|
||||
#define MEDCLI_PLUGIN_H_
|
||||
|
||||
#include <plugins/plugin.h>
|
||||
|
||||
typedef struct medcli_plugin_t medcli_plugin_t;
|
||||
|
||||
/**
|
||||
* Mediation client database plugin.
|
||||
*/
|
||||
struct medcli_plugin_t {
|
||||
|
||||
/**
|
||||
* implements plugin interface
|
||||
*/
|
||||
plugin_t plugin;
|
||||
};
|
||||
|
||||
#endif /** MEDCLI_PLUGIN_H_ @}*/
|
||||
@@ -1,32 +0,0 @@
|
||||
|
||||
CREATE TABLE `ClientConfig` (
|
||||
`IdClientConfig` int(11) NOT NULL,
|
||||
`KeyId` varbinary(20) NOT NULL,
|
||||
`PublicKey` blob NOT NULL,
|
||||
`PrivateKey` blob NOT NULL,
|
||||
PRIMARY KEY (`IdClientConfig`)
|
||||
);
|
||||
|
||||
|
||||
CREATE TABLE `MediationServerConfig` (
|
||||
`IdMediationServerConfig` int(11) NOT NULL,
|
||||
`Address` varchar(200) NOT NULL,
|
||||
`KeyId` varbinary(20) NOT NULL,
|
||||
`PublicKey` blob NOT NULL,
|
||||
PRIMARY KEY (`IdMediationServerConfig`)
|
||||
);
|
||||
|
||||
|
||||
CREATE TABLE `Connection` (
|
||||
`IdConnection` int(11) NOT NULL auto_increment,
|
||||
`Active` tinyint(1) NOT NULL,
|
||||
`Alias` varchar(50) NOT NULL,
|
||||
`KeyId` varbinary(20) NOT NULL,
|
||||
`PublicKey` blob NOT NULL,
|
||||
`LocalSubnet` varchar(20),
|
||||
`RemoteSubnet` varchar(20),
|
||||
`Status` int(11) NOT NULL,
|
||||
PRIMARY KEY (`IdConnection`),
|
||||
UNIQUE (`Alias`),
|
||||
UNIQUE (`KeyId`)
|
||||
);
|
||||
@@ -1,19 +0,0 @@
|
||||
AM_CPPFLAGS = \
|
||||
-I$(top_srcdir)/src/libstrongswan \
|
||||
-I$(top_srcdir)/src/libcharon
|
||||
|
||||
AM_CFLAGS = \
|
||||
$(PLUGIN_CFLAGS)
|
||||
|
||||
if MONOLITHIC
|
||||
noinst_LTLIBRARIES = libstrongswan-medsrv.la
|
||||
else
|
||||
plugin_LTLIBRARIES = libstrongswan-medsrv.la
|
||||
endif
|
||||
|
||||
libstrongswan_medsrv_la_SOURCES = \
|
||||
medsrv_plugin.h medsrv_plugin.c \
|
||||
medsrv_creds.h medsrv_creds.c \
|
||||
medsrv_config.h medsrv_config.c
|
||||
|
||||
libstrongswan_medsrv_la_LDFLAGS = -module -avoid-version
|
||||
@@ -1,161 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include <string.h>
|
||||
|
||||
#include "medsrv_config.h"
|
||||
|
||||
#include <daemon.h>
|
||||
|
||||
typedef struct private_medsrv_config_t private_medsrv_config_t;
|
||||
|
||||
/**
|
||||
* Private data of an medsrv_config_t object
|
||||
*/
|
||||
struct private_medsrv_config_t {
|
||||
|
||||
/**
|
||||
* Public part
|
||||
*/
|
||||
medsrv_config_t public;
|
||||
|
||||
/**
|
||||
* database connection
|
||||
*/
|
||||
database_t *db;
|
||||
|
||||
/**
|
||||
* rekey time
|
||||
*/
|
||||
int rekey;
|
||||
|
||||
/**
|
||||
* dpd delay
|
||||
*/
|
||||
int dpd;
|
||||
|
||||
/**
|
||||
* default ike config
|
||||
*/
|
||||
ike_cfg_t *ike;
|
||||
};
|
||||
|
||||
METHOD(backend_t, get_peer_cfg_by_name, peer_cfg_t*,
|
||||
private_medsrv_config_t *this, char *name)
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
|
||||
METHOD(backend_t, create_ike_cfg_enumerator, enumerator_t*,
|
||||
private_medsrv_config_t *this, host_t *me, host_t *other)
|
||||
{
|
||||
return enumerator_create_single(this->ike, NULL);
|
||||
}
|
||||
|
||||
METHOD(backend_t, create_peer_cfg_enumerator, enumerator_t*,
|
||||
private_medsrv_config_t *this, identification_t *me,
|
||||
identification_t *other)
|
||||
{
|
||||
enumerator_t *e;
|
||||
|
||||
if (!me || !other || other->get_type(other) != ID_KEY_ID)
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
e = this->db->query(this->db,
|
||||
"SELECT CONCAT(peer.alias, CONCAT('@', user.login)) FROM "
|
||||
"peer JOIN user ON peer.user = user.id "
|
||||
"WHERE peer.keyid = ?", DB_BLOB, other->get_encoding(other),
|
||||
DB_TEXT);
|
||||
if (e)
|
||||
{
|
||||
peer_cfg_t *peer_cfg;
|
||||
auth_cfg_t *auth;
|
||||
char *name;
|
||||
|
||||
if (e->enumerate(e, &name))
|
||||
{
|
||||
peer_cfg_create_t peer = {
|
||||
.cert_policy = CERT_NEVER_SEND,
|
||||
.unique = UNIQUE_REPLACE,
|
||||
.keyingtries = 1,
|
||||
.rekey_time = this->rekey * 60,
|
||||
.jitter_time = this->rekey * 5,
|
||||
.over_time = this->rekey * 3,
|
||||
.dpd = this->dpd,
|
||||
.mediation = TRUE,
|
||||
};
|
||||
peer_cfg = peer_cfg_create(name, this->ike->get_ref(this->ike),
|
||||
&peer);
|
||||
e->destroy(e);
|
||||
|
||||
auth = auth_cfg_create();
|
||||
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY);
|
||||
auth->add(auth, AUTH_RULE_IDENTITY, me->clone(me));
|
||||
peer_cfg->add_auth_cfg(peer_cfg, auth, TRUE);
|
||||
auth = auth_cfg_create();
|
||||
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY);
|
||||
auth->add(auth, AUTH_RULE_IDENTITY, other->clone(other));
|
||||
peer_cfg->add_auth_cfg(peer_cfg, auth, FALSE);
|
||||
|
||||
return enumerator_create_single(peer_cfg, (void*)peer_cfg->destroy);
|
||||
}
|
||||
e->destroy(e);
|
||||
}
|
||||
return NULL;
|
||||
}
|
||||
|
||||
METHOD(medsrv_config_t, destroy, void,
|
||||
private_medsrv_config_t *this)
|
||||
{
|
||||
this->ike->destroy(this->ike);
|
||||
free(this);
|
||||
}
|
||||
|
||||
/**
|
||||
* Described in header.
|
||||
*/
|
||||
medsrv_config_t *medsrv_config_create(database_t *db)
|
||||
{
|
||||
private_medsrv_config_t *this;
|
||||
ike_cfg_create_t ike = {
|
||||
.version = IKEV2,
|
||||
.local = "0.0.0.0",
|
||||
.local_port = charon->socket->get_port(charon->socket, FALSE),
|
||||
.remote = "0.0.0.0",
|
||||
.remote_port = IKEV2_UDP_PORT,
|
||||
.no_certreq = TRUE,
|
||||
};
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.backend = {
|
||||
.create_peer_cfg_enumerator = _create_peer_cfg_enumerator,
|
||||
.create_ike_cfg_enumerator = _create_ike_cfg_enumerator,
|
||||
.get_peer_cfg_by_name = _get_peer_cfg_by_name,
|
||||
},
|
||||
.destroy = _destroy,
|
||||
},
|
||||
.db = db,
|
||||
.rekey = lib->settings->get_time(lib->settings, "medsrv.rekey", 1200),
|
||||
.dpd = lib->settings->get_time(lib->settings, "medsrv.dpd", 300),
|
||||
.ike = ike_cfg_create(&ike),
|
||||
);
|
||||
this->ike->add_proposal(this->ike, proposal_create_default(PROTO_IKE));
|
||||
this->ike->add_proposal(this->ike, proposal_create_default_aead(PROTO_IKE));
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
@@ -1,54 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup medsrv_config_i medsrv_config
|
||||
* @{ @ingroup medsrv_p
|
||||
*/
|
||||
|
||||
#ifndef MEDSRV_CONFIG_H_
|
||||
#define MEDSRV_CONFIG_H_
|
||||
|
||||
#include <config/backend.h>
|
||||
#include <database/database.h>
|
||||
|
||||
typedef struct medsrv_config_t medsrv_config_t;
|
||||
|
||||
/**
|
||||
* Mediation server configuration backend.
|
||||
*/
|
||||
struct medsrv_config_t {
|
||||
|
||||
/**
|
||||
* Implements backend_t interface
|
||||
*/
|
||||
backend_t backend;
|
||||
|
||||
/**
|
||||
* Destroy the backend.
|
||||
*/
|
||||
void (*destroy)(medsrv_config_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Create a medsrv_config backend instance.
|
||||
*
|
||||
* @param db underlying database
|
||||
* @return backend instance
|
||||
*/
|
||||
medsrv_config_t *medsrv_config_create(database_t *db);
|
||||
|
||||
#endif /** MEDSRV_CONFIG_H_ @}*/
|
||||
@@ -1,163 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "medsrv_creds.h"
|
||||
|
||||
#include <daemon.h>
|
||||
#include <library.h>
|
||||
#include <collections/enumerator.h>
|
||||
|
||||
typedef struct private_medsrv_creds_t private_medsrv_creds_t;
|
||||
|
||||
/**
|
||||
* Private data of an medsrv_creds_t object
|
||||
*/
|
||||
struct private_medsrv_creds_t {
|
||||
|
||||
/**
|
||||
* Public part
|
||||
*/
|
||||
medsrv_creds_t public;
|
||||
|
||||
/**
|
||||
* underlying database handle
|
||||
*/
|
||||
database_t *db;
|
||||
};
|
||||
|
||||
/**
|
||||
* enumerator over certificates
|
||||
*/
|
||||
typedef struct {
|
||||
/** implements enumerator */
|
||||
enumerator_t public;
|
||||
/** inner SQL enumerator */
|
||||
enumerator_t *inner;
|
||||
/** currently enumerated cert */
|
||||
certificate_t *current;
|
||||
/** type of requested key */
|
||||
key_type_t type;
|
||||
} cert_enumerator_t;
|
||||
|
||||
METHOD(enumerator_t, cert_enumerator_enumerate, bool,
|
||||
cert_enumerator_t *this, va_list args)
|
||||
{
|
||||
certificate_t *trusted, **cert;
|
||||
public_key_t *public;
|
||||
chunk_t chunk;
|
||||
|
||||
VA_ARGS_VGET(args, cert);
|
||||
|
||||
DESTROY_IF(this->current);
|
||||
while (this->inner->enumerate(this->inner, &chunk))
|
||||
{
|
||||
public = lib->creds->create(lib->creds, CRED_PUBLIC_KEY, KEY_ANY,
|
||||
BUILD_BLOB_ASN1_DER, chunk,
|
||||
BUILD_END);
|
||||
if (public)
|
||||
{
|
||||
if (this->type == KEY_ANY || this->type == public->get_type(public))
|
||||
{
|
||||
trusted = lib->creds->create(lib->creds,
|
||||
CRED_CERTIFICATE, CERT_TRUSTED_PUBKEY,
|
||||
BUILD_PUBLIC_KEY, public, BUILD_END);
|
||||
public->destroy(public);
|
||||
if (trusted)
|
||||
{
|
||||
*cert = this->current = trusted;
|
||||
return TRUE;
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
public->destroy(public);
|
||||
}
|
||||
}
|
||||
}
|
||||
this->current = NULL;
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
METHOD(enumerator_t, cert_enumerator_destroy, void,
|
||||
cert_enumerator_t *this)
|
||||
{
|
||||
DESTROY_IF(this->current);
|
||||
this->inner->destroy(this->inner);
|
||||
free(this);
|
||||
}
|
||||
|
||||
METHOD(credential_set_t, create_cert_enumerator, enumerator_t*,
|
||||
private_medsrv_creds_t *this, certificate_type_t cert, key_type_t key,
|
||||
identification_t *id, bool trusted)
|
||||
{
|
||||
cert_enumerator_t *e;
|
||||
|
||||
if ((cert != CERT_TRUSTED_PUBKEY && cert != CERT_ANY) ||
|
||||
id == NULL || id->get_type(id) != ID_KEY_ID)
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
|
||||
INIT(e,
|
||||
.public = {
|
||||
.enumerate = enumerator_enumerate_default,
|
||||
.venumerate = _cert_enumerator_enumerate,
|
||||
.destroy = _cert_enumerator_destroy,
|
||||
},
|
||||
.type = key,
|
||||
.inner = this->db->query(this->db,
|
||||
"SELECT public_key FROM peer WHERE keyid = ?",
|
||||
DB_BLOB, id->get_encoding(id),
|
||||
DB_BLOB),
|
||||
);
|
||||
if (!e->inner)
|
||||
{
|
||||
free(e);
|
||||
return NULL;
|
||||
}
|
||||
return &e->public;
|
||||
}
|
||||
|
||||
METHOD(medsrv_creds_t, destroy, void,
|
||||
private_medsrv_creds_t *this)
|
||||
{
|
||||
free(this);
|
||||
}
|
||||
|
||||
/**
|
||||
* Described in header.
|
||||
*/
|
||||
medsrv_creds_t *medsrv_creds_create(database_t *db)
|
||||
{
|
||||
private_medsrv_creds_t *this;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.set = {
|
||||
.create_private_enumerator = (void*)return_null,
|
||||
.create_cert_enumerator = _create_cert_enumerator,
|
||||
.create_shared_enumerator = (void*)return_null,
|
||||
.create_cdp_enumerator = (void*)return_null,
|
||||
.cache_cert = (void*)nop,
|
||||
},
|
||||
.destroy = _destroy,
|
||||
},
|
||||
.db = db,
|
||||
);
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
|
||||
@@ -1,54 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2007-2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup medsrv_creds_i medsrv_creds
|
||||
* @{ @ingroup medsrv_p
|
||||
*/
|
||||
|
||||
#ifndef MEDSRV_CREDS_H_
|
||||
#define MEDSRV_CREDS_H_
|
||||
|
||||
#include <credentials/credential_set.h>
|
||||
#include <database/database.h>
|
||||
|
||||
typedef struct medsrv_creds_t medsrv_creds_t;
|
||||
|
||||
/**
|
||||
* Mediation credentials database.
|
||||
*/
|
||||
struct medsrv_creds_t {
|
||||
|
||||
/**
|
||||
* Implements credential_set_t interface
|
||||
*/
|
||||
credential_set_t set;
|
||||
|
||||
/**
|
||||
* Destroy the credentials database.
|
||||
*/
|
||||
void (*destroy)(medsrv_creds_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Create the medsrv credentials db.
|
||||
*
|
||||
* @param database underlying database
|
||||
* @return credential set implementation on that database
|
||||
*/
|
||||
medsrv_creds_t *medsrv_creds_create(database_t *database);
|
||||
|
||||
#endif /** MEDSRV_CREDS_H_ @}*/
|
||||
@@ -1,137 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2013 Tobias Brunner
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "medsrv_plugin.h"
|
||||
|
||||
#include "medsrv_creds.h"
|
||||
#include "medsrv_config.h"
|
||||
|
||||
#include <daemon.h>
|
||||
|
||||
typedef struct private_medsrv_plugin_t private_medsrv_plugin_t;
|
||||
|
||||
/**
|
||||
* private data of medsrv plugin
|
||||
*/
|
||||
struct private_medsrv_plugin_t {
|
||||
|
||||
/**
|
||||
* implements plugin interface
|
||||
*/
|
||||
medsrv_plugin_t public;
|
||||
|
||||
/**
|
||||
* database connection instance
|
||||
*/
|
||||
database_t *db;
|
||||
|
||||
/**
|
||||
* medsrv credential set instance
|
||||
*/
|
||||
medsrv_creds_t *creds;
|
||||
|
||||
/**
|
||||
* medsrv config database
|
||||
*/
|
||||
medsrv_config_t *config;
|
||||
};
|
||||
|
||||
METHOD(plugin_t, get_name, char*,
|
||||
private_medsrv_plugin_t *this)
|
||||
{
|
||||
return "medsrv";
|
||||
}
|
||||
|
||||
/**
|
||||
* Connect to database
|
||||
*/
|
||||
static bool open_database(private_medsrv_plugin_t *this,
|
||||
plugin_feature_t *feature, bool reg, void *cb_data)
|
||||
{
|
||||
if (reg)
|
||||
{
|
||||
char *uri;
|
||||
|
||||
uri = lib->settings->get_str(lib->settings,
|
||||
"medsrv.database", NULL);
|
||||
if (!uri)
|
||||
{
|
||||
DBG1(DBG_CFG, "mediation database URI not defined, skipped");
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
this->db = lib->db->create(lib->db, uri);
|
||||
if (this->db == NULL)
|
||||
{
|
||||
DBG1(DBG_CFG, "opening mediation server database failed");
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
this->creds = medsrv_creds_create(this->db);
|
||||
this->config = medsrv_config_create(this->db);
|
||||
|
||||
lib->credmgr->add_set(lib->credmgr, &this->creds->set);
|
||||
charon->backends->add_backend(charon->backends, &this->config->backend);
|
||||
}
|
||||
else
|
||||
{
|
||||
charon->backends->remove_backend(charon->backends, &this->config->backend);
|
||||
lib->credmgr->remove_set(lib->credmgr, &this->creds->set);
|
||||
this->config->destroy(this->config);
|
||||
this->creds->destroy(this->creds);
|
||||
this->db->destroy(this->db);
|
||||
}
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(plugin_t, get_features, int,
|
||||
private_medsrv_plugin_t *this, plugin_feature_t *features[])
|
||||
{
|
||||
static plugin_feature_t f[] = {
|
||||
PLUGIN_CALLBACK((plugin_feature_callback_t)open_database, NULL),
|
||||
PLUGIN_PROVIDE(CUSTOM, "medsrv"),
|
||||
PLUGIN_DEPENDS(DATABASE, DB_ANY),
|
||||
};
|
||||
*features = f;
|
||||
return countof(f);
|
||||
}
|
||||
|
||||
METHOD(plugin_t, destroy, void,
|
||||
private_medsrv_plugin_t *this)
|
||||
{
|
||||
free(this);
|
||||
}
|
||||
|
||||
/*
|
||||
* see header file
|
||||
*/
|
||||
PLUGIN_DEFINE(medsrv)
|
||||
{
|
||||
private_medsrv_plugin_t *this;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.plugin = {
|
||||
.get_name = _get_name,
|
||||
.get_features = _get_features,
|
||||
.destroy = _destroy,
|
||||
},
|
||||
},
|
||||
);
|
||||
|
||||
return &this->public.plugin;
|
||||
}
|
||||
@@ -1,43 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup medsrv_p medsrv
|
||||
* @ingroup cplugins
|
||||
*
|
||||
* @defgroup medsrv_plugin medsrv_plugin
|
||||
* @{ @ingroup medsrv_p
|
||||
*/
|
||||
|
||||
#ifndef MEDSRV_PLUGIN_H_
|
||||
#define MEDSRV_PLUGIN_H_
|
||||
|
||||
#include <plugins/plugin.h>
|
||||
|
||||
typedef struct medsrv_plugin_t medsrv_plugin_t;
|
||||
|
||||
/**
|
||||
* Mediation server database plugin.
|
||||
*/
|
||||
struct medsrv_plugin_t {
|
||||
|
||||
/**
|
||||
* implements plugin interface
|
||||
*/
|
||||
plugin_t plugin;
|
||||
};
|
||||
|
||||
#endif /** MEDSRV_PLUGIN_H_ @}*/
|
||||
@@ -1,21 +0,0 @@
|
||||
|
||||
CREATE TABLE IF NOT EXISTS `peer` (
|
||||
`id` int(10) unsigned NOT NULL auto_increment,
|
||||
`user` int(10) unsigned NOT NULL,
|
||||
`alias` varchar(30) NOT NULL,
|
||||
`keyid` varbinary(20) NOT NULL,
|
||||
`public_key` blob,
|
||||
PRIMARY KEY (`id`),
|
||||
UNIQUE KEY (`user`,`alias`),
|
||||
UNIQUE KEY (`keyid`),
|
||||
KEY (`user`)
|
||||
) ENGINE=MyISAM DEFAULT CHARSET=utf8 COLLATE=utf8_unicode_ci;
|
||||
|
||||
CREATE TABLE IF NOT EXISTS `user` (
|
||||
`id` int(10) unsigned NOT NULL auto_increment,
|
||||
`login` varchar(30) NOT NULL,
|
||||
`password` varbinary(20) NOT NULL,
|
||||
PRIMARY KEY (`id`),
|
||||
UNIQUE KEY (`login`)
|
||||
) ENGINE=MyISAM DEFAULT CHARSET=utf8 COLLATE=utf8_unicode_ci;
|
||||
|
||||
@@ -1,9 +0,0 @@
|
||||
|
||||
INSERT INTO `Peer` (
|
||||
`IdPeer`, `IdUser`, `Alias`, `KeyId`, `PublicKey`
|
||||
) VALUES (
|
||||
1, 0, 'sidv150',
|
||||
X'ed90e64feca21f4b6897992422e0de21b9d62629',
|
||||
X'30820122300d06092a864886f70d01010105000382010f003082010a0282010100cd946c229f7d52b21da1cb5384e7dcaf6529f760534a56355efd49e87a9c6f1ddd5ff303bd7eb49c23de03adc487456f41eb5f92947bdc8ff8dbe443f8d112e0da2c98145e7c4d1cd15cddd08577f4d4f3d0a2e1da3c08c94cd819758751931e7a9724cc43d73a11b8e176a268b4cdbbf3995cb09723abc9bfc477c25e714a4661a84c078be7404d8986be55f20437e3a6b278a3cc89aec085941f1a1aafaf4b22ae146fe4684d5567dc30658a32087d01b98515070cb1653311cb6102f82a83c638c2a79985dbb9600752e9cbc272014a5c547b4ab59130c3a948658bff794b6f202cf95939ffa73b10521f05c060cecb15f8597ed95d72b9e405ee31f1b5d90203010001'
|
||||
);
|
||||
|
||||
Reference in New Issue
Block a user