Add the ability to use a named pool for conftest configs
This commit is contained in:
+4
-3
@@ -98,9 +98,10 @@ The IKE_SA configuration uses the following options (as key/value pairs):
|
|||||||
src/libstrongswan/crypt/proposal/proposal_keywords.txt
|
src/libstrongswan/crypt/proposal/proposal_keywords.txt
|
||||||
fake_nat: Fake the NAT_DETECTION_*_IP payloads to simulate a NAT
|
fake_nat: Fake the NAT_DETECTION_*_IP payloads to simulate a NAT
|
||||||
scenario
|
scenario
|
||||||
rsa_strength: connection requires a trustchain with RSA keys of given bits
|
rsa_strength: Connection requires a trustchain with RSA keys of given bits
|
||||||
ecdsa_strength: connection requires a trustchain with ECDSA keys of given bits
|
ecdsa_strength: Connection requires a trustchain with ECDSA keys of given bits
|
||||||
cert_policy: connection requries a certificate with the given OID policy
|
cert_policy: Connection requries a certificate with the given OID policy
|
||||||
|
named_pool: Name of an IP pool defined e.g. in a database backend
|
||||||
|
|
||||||
The following CHILD_SA specific configuration options are supported:
|
The following CHILD_SA specific configuration options are supported:
|
||||||
|
|
||||||
|
|||||||
@@ -244,7 +244,7 @@ static peer_cfg_t *load_peer_config(private_config_t *this,
|
|||||||
child_cfg_t *child_cfg;
|
child_cfg_t *child_cfg;
|
||||||
enumerator_t *enumerator;
|
enumerator_t *enumerator;
|
||||||
identification_t *lid, *rid;
|
identification_t *lid, *rid;
|
||||||
char *child, *policy;
|
char *child, *policy, *pool;
|
||||||
uintptr_t strength;
|
uintptr_t strength;
|
||||||
|
|
||||||
ike_cfg = load_ike_config(this, settings, config);
|
ike_cfg = load_ike_config(this, settings, config);
|
||||||
@@ -280,6 +280,11 @@ static peer_cfg_t *load_peer_config(private_config_t *this,
|
|||||||
}
|
}
|
||||||
auth->add(auth, AUTH_RULE_IDENTITY, rid);
|
auth->add(auth, AUTH_RULE_IDENTITY, rid);
|
||||||
peer_cfg->add_auth_cfg(peer_cfg, auth, FALSE);
|
peer_cfg->add_auth_cfg(peer_cfg, auth, FALSE);
|
||||||
|
pool = settings->get_str(settings, "configs.%s.named_pool", NULL, config);
|
||||||
|
if (pool)
|
||||||
|
{
|
||||||
|
peer_cfg->add_pool(peer_cfg, pool);
|
||||||
|
}
|
||||||
|
|
||||||
DBG1(DBG_CFG, "loaded config %s: %Y - %Y", config, lid, rid);
|
DBG1(DBG_CFG, "loaded config %s: %Y - %Y", config, lid, rid);
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user