Merge branch 'ikev1'
Conflicts: configure.in man/ipsec.conf.5.in src/libcharon/encoding/generator.c src/libcharon/encoding/payloads/notify_payload.c src/libcharon/encoding/payloads/notify_payload.h src/libcharon/encoding/payloads/payload.c src/libcharon/network/receiver.c src/libcharon/sa/authenticator.c src/libcharon/sa/authenticator.h src/libcharon/sa/ikev2/tasks/ike_init.c src/libcharon/sa/task_manager.c src/libstrongswan/credentials/auth_cfg.c
This commit is contained in:
@@ -23,11 +23,12 @@
|
||||
#include <eap/eap.h>
|
||||
#include <credentials/certificates/certificate.h>
|
||||
|
||||
ENUM(auth_class_names, AUTH_CLASS_ANY, AUTH_CLASS_EAP,
|
||||
ENUM(auth_class_names, AUTH_CLASS_ANY, AUTH_CLASS_XAUTH,
|
||||
"any",
|
||||
"public key",
|
||||
"pre-shared key",
|
||||
"EAP",
|
||||
"XAuth",
|
||||
);
|
||||
|
||||
ENUM(auth_rule_names, AUTH_RULE_IDENTITY, AUTH_HELPER_REVOCATION_CERT,
|
||||
@@ -37,6 +38,8 @@ ENUM(auth_rule_names, AUTH_RULE_IDENTITY, AUTH_HELPER_REVOCATION_CERT,
|
||||
"RULE_EAP_IDENTITY",
|
||||
"RULE_EAP_TYPE",
|
||||
"RULE_EAP_VENDOR",
|
||||
"RULE_XAUTH_BACKEND",
|
||||
"RULE_XAUTH_IDENTITY",
|
||||
"RULE_CA_CERT",
|
||||
"RULE_IM_CERT",
|
||||
"RULE_SUBJECT_CERT",
|
||||
@@ -68,6 +71,8 @@ static inline bool is_multi_value_rule(auth_rule_t type)
|
||||
case AUTH_RULE_IDENTITY:
|
||||
case AUTH_RULE_EAP_IDENTITY:
|
||||
case AUTH_RULE_AAA_IDENTITY:
|
||||
case AUTH_RULE_XAUTH_IDENTITY:
|
||||
case AUTH_RULE_XAUTH_BACKEND:
|
||||
case AUTH_RULE_SUBJECT_CERT:
|
||||
case AUTH_HELPER_SUBJECT_CERT:
|
||||
case AUTH_HELPER_SUBJECT_HASH_URL:
|
||||
@@ -203,6 +208,8 @@ static entry_t *entry_create(auth_rule_t type, va_list args)
|
||||
case AUTH_RULE_IDENTITY:
|
||||
case AUTH_RULE_EAP_IDENTITY:
|
||||
case AUTH_RULE_AAA_IDENTITY:
|
||||
case AUTH_RULE_XAUTH_BACKEND:
|
||||
case AUTH_RULE_XAUTH_IDENTITY:
|
||||
case AUTH_RULE_GROUP:
|
||||
case AUTH_RULE_CA_CERT:
|
||||
case AUTH_RULE_IM_CERT:
|
||||
@@ -261,6 +268,7 @@ static bool entry_equals(entry_t *e1, entry_t *e2)
|
||||
case AUTH_RULE_IDENTITY:
|
||||
case AUTH_RULE_EAP_IDENTITY:
|
||||
case AUTH_RULE_AAA_IDENTITY:
|
||||
case AUTH_RULE_XAUTH_IDENTITY:
|
||||
case AUTH_RULE_GROUP:
|
||||
{
|
||||
identification_t *id1, *id2;
|
||||
@@ -271,6 +279,7 @@ static bool entry_equals(entry_t *e1, entry_t *e2)
|
||||
return id1->equals(id1, id2);
|
||||
}
|
||||
case AUTH_RULE_CERT_POLICY:
|
||||
case AUTH_RULE_XAUTH_BACKEND:
|
||||
case AUTH_HELPER_IM_HASH_URL:
|
||||
case AUTH_HELPER_SUBJECT_HASH_URL:
|
||||
{
|
||||
@@ -293,6 +302,7 @@ static void destroy_entry_value(entry_t *entry)
|
||||
case AUTH_RULE_EAP_IDENTITY:
|
||||
case AUTH_RULE_AAA_IDENTITY:
|
||||
case AUTH_RULE_GROUP:
|
||||
case AUTH_RULE_XAUTH_IDENTITY:
|
||||
{
|
||||
identification_t *id = (identification_t*)entry->value;
|
||||
id->destroy(id);
|
||||
@@ -310,6 +320,7 @@ static void destroy_entry_value(entry_t *entry)
|
||||
break;
|
||||
}
|
||||
case AUTH_RULE_CERT_POLICY:
|
||||
case AUTH_RULE_XAUTH_BACKEND:
|
||||
case AUTH_HELPER_IM_HASH_URL:
|
||||
case AUTH_HELPER_SUBJECT_HASH_URL:
|
||||
{
|
||||
@@ -358,6 +369,8 @@ static void replace(private_auth_cfg_t *this, entry_enumerator_t *enumerator,
|
||||
case AUTH_RULE_IDENTITY:
|
||||
case AUTH_RULE_EAP_IDENTITY:
|
||||
case AUTH_RULE_AAA_IDENTITY:
|
||||
case AUTH_RULE_XAUTH_BACKEND:
|
||||
case AUTH_RULE_XAUTH_IDENTITY:
|
||||
case AUTH_RULE_GROUP:
|
||||
case AUTH_RULE_CA_CERT:
|
||||
case AUTH_RULE_IM_CERT:
|
||||
@@ -429,6 +442,8 @@ METHOD(auth_cfg_t, get, void*,
|
||||
case AUTH_RULE_IDENTITY:
|
||||
case AUTH_RULE_EAP_IDENTITY:
|
||||
case AUTH_RULE_AAA_IDENTITY:
|
||||
case AUTH_RULE_XAUTH_BACKEND:
|
||||
case AUTH_RULE_XAUTH_IDENTITY:
|
||||
case AUTH_RULE_GROUP:
|
||||
case AUTH_RULE_CA_CERT:
|
||||
case AUTH_RULE_IM_CERT:
|
||||
@@ -571,6 +586,7 @@ METHOD(auth_cfg_t, complies, bool,
|
||||
case AUTH_RULE_IDENTITY:
|
||||
case AUTH_RULE_EAP_IDENTITY:
|
||||
case AUTH_RULE_AAA_IDENTITY:
|
||||
case AUTH_RULE_XAUTH_IDENTITY:
|
||||
{
|
||||
identification_t *id1, *id2;
|
||||
|
||||
@@ -668,6 +684,7 @@ METHOD(auth_cfg_t, complies, bool,
|
||||
"public keys, but %d bit key used",
|
||||
(uintptr_t)value, strength);
|
||||
}
|
||||
break;
|
||||
}
|
||||
}
|
||||
else if (t2 == AUTH_RULE_RSA_STRENGTH)
|
||||
@@ -678,6 +695,7 @@ METHOD(auth_cfg_t, complies, bool,
|
||||
DBG1(DBG_CFG, "constraint requires %d bit ECDSA, "
|
||||
"but RSA used", (uintptr_t)value);
|
||||
}
|
||||
break;
|
||||
}
|
||||
else if (t2 == AUTH_RULE_ECDSA_STRENGTH)
|
||||
{
|
||||
@@ -687,6 +705,7 @@ METHOD(auth_cfg_t, complies, bool,
|
||||
DBG1(DBG_CFG, "constraint requires %d bit RSA, "
|
||||
"but ECDSA used", (uintptr_t)value);
|
||||
}
|
||||
break;
|
||||
}
|
||||
}
|
||||
e2->destroy(e2);
|
||||
@@ -714,6 +733,8 @@ METHOD(auth_cfg_t, complies, bool,
|
||||
}
|
||||
break;
|
||||
}
|
||||
case AUTH_RULE_XAUTH_BACKEND:
|
||||
/* not enforced, just a hint for local authentication */
|
||||
case AUTH_HELPER_IM_CERT:
|
||||
case AUTH_HELPER_SUBJECT_CERT:
|
||||
case AUTH_HELPER_IM_HASH_URL:
|
||||
@@ -789,12 +810,14 @@ static void merge(private_auth_cfg_t *this, private_auth_cfg_t *other, bool copy
|
||||
case AUTH_RULE_EAP_IDENTITY:
|
||||
case AUTH_RULE_AAA_IDENTITY:
|
||||
case AUTH_RULE_GROUP:
|
||||
case AUTH_RULE_XAUTH_IDENTITY:
|
||||
{
|
||||
identification_t *id = (identification_t*)value;
|
||||
|
||||
add(this, type, id->clone(id));
|
||||
break;
|
||||
}
|
||||
case AUTH_RULE_XAUTH_BACKEND:
|
||||
case AUTH_RULE_CERT_POLICY:
|
||||
case AUTH_HELPER_IM_HASH_URL:
|
||||
case AUTH_HELPER_SUBJECT_HASH_URL:
|
||||
@@ -904,6 +927,7 @@ METHOD(auth_cfg_t, clone_, auth_cfg_t*,
|
||||
case AUTH_RULE_EAP_IDENTITY:
|
||||
case AUTH_RULE_AAA_IDENTITY:
|
||||
case AUTH_RULE_GROUP:
|
||||
case AUTH_RULE_XAUTH_IDENTITY:
|
||||
{
|
||||
identification_t *id = (identification_t*)entry->value;
|
||||
clone->add(clone, entry->type, id->clone(id));
|
||||
@@ -920,6 +944,7 @@ METHOD(auth_cfg_t, clone_, auth_cfg_t*,
|
||||
clone->add(clone, entry->type, cert->get_ref(cert));
|
||||
break;
|
||||
}
|
||||
case AUTH_RULE_XAUTH_BACKEND:
|
||||
case AUTH_RULE_CERT_POLICY:
|
||||
case AUTH_HELPER_IM_HASH_URL:
|
||||
case AUTH_HELPER_SUBJECT_HASH_URL:
|
||||
|
||||
@@ -42,6 +42,8 @@ enum auth_class_t {
|
||||
AUTH_CLASS_PSK = 2,
|
||||
/** authentication using EAP */
|
||||
AUTH_CLASS_EAP = 3,
|
||||
/** authentication using IKEv1 XAUTH */
|
||||
AUTH_CLASS_XAUTH = 4,
|
||||
};
|
||||
|
||||
/**
|
||||
@@ -75,6 +77,10 @@ enum auth_rule_t {
|
||||
AUTH_RULE_EAP_TYPE,
|
||||
/** EAP vendor for vendor specific type, u_int32_t */
|
||||
AUTH_RULE_EAP_VENDOR,
|
||||
/** XAUTH backend name to use, char* */
|
||||
AUTH_RULE_XAUTH_BACKEND,
|
||||
/** XAuth identity to use or require, identification_t* */
|
||||
AUTH_RULE_XAUTH_IDENTITY,
|
||||
/** certificate authority, certificate_t* */
|
||||
AUTH_RULE_CA_CERT,
|
||||
/** intermediate certificate in trustchain, certificate_t* */
|
||||
|
||||
@@ -56,6 +56,8 @@ enum x509_flag_t {
|
||||
X509_IP_ADDR_BLOCKS = (1<<6),
|
||||
/** cert has CRL sign key usage */
|
||||
X509_CRL_SIGN = (1<<7),
|
||||
/** cert has iKEIntermediate key usage */
|
||||
X509_IKE_INTERMEDIATE = (1<<8),
|
||||
};
|
||||
|
||||
/**
|
||||
|
||||
@@ -52,6 +52,11 @@ struct private_credential_manager_t {
|
||||
*/
|
||||
thread_value_t *local_sets;
|
||||
|
||||
/**
|
||||
* Exclusive local sets, linked_list_t with credential_set_t
|
||||
*/
|
||||
thread_value_t *exclusive_local_sets;
|
||||
|
||||
/**
|
||||
* trust relationship and certificate cache
|
||||
*/
|
||||
@@ -117,12 +122,23 @@ typedef struct {
|
||||
enumerator_t *global;
|
||||
/** enumerator over local sets */
|
||||
enumerator_t *local;
|
||||
/** enumerator over exclusive local sets */
|
||||
enumerator_t *exclusive;
|
||||
} sets_enumerator_t;
|
||||
|
||||
|
||||
METHOD(enumerator_t, sets_enumerate, bool,
|
||||
sets_enumerator_t *this, credential_set_t **set)
|
||||
{
|
||||
if (this->exclusive)
|
||||
{
|
||||
if (this->exclusive->enumerate(this->exclusive, set))
|
||||
{ /* only enumerate last added */
|
||||
this->exclusive->destroy(this->exclusive);
|
||||
this->exclusive = NULL;
|
||||
return TRUE;
|
||||
}
|
||||
}
|
||||
if (this->global)
|
||||
{
|
||||
if (this->global->enumerate(this->global, set))
|
||||
@@ -145,6 +161,7 @@ METHOD(enumerator_t, sets_destroy, void,
|
||||
{
|
||||
DESTROY_IF(this->global);
|
||||
DESTROY_IF(this->local);
|
||||
DESTROY_IF(this->exclusive);
|
||||
free(this);
|
||||
}
|
||||
|
||||
@@ -154,19 +171,28 @@ METHOD(enumerator_t, sets_destroy, void,
|
||||
static enumerator_t *create_sets_enumerator(private_credential_manager_t *this)
|
||||
{
|
||||
sets_enumerator_t *enumerator;
|
||||
linked_list_t *local;
|
||||
linked_list_t *list;
|
||||
|
||||
INIT(enumerator,
|
||||
.public = {
|
||||
.enumerate = (void*)_sets_enumerate,
|
||||
.destroy = _sets_destroy,
|
||||
},
|
||||
.global = this->sets->create_enumerator(this->sets),
|
||||
);
|
||||
local = this->local_sets->get(this->local_sets);
|
||||
if (local)
|
||||
|
||||
list = this->exclusive_local_sets->get(this->exclusive_local_sets);
|
||||
if (list && list->get_count(list))
|
||||
{
|
||||
enumerator->local = local->create_enumerator(local);
|
||||
enumerator->exclusive = list->create_enumerator(list);
|
||||
}
|
||||
else
|
||||
{
|
||||
enumerator->global = this->sets->create_enumerator(this->sets);
|
||||
list = this->local_sets->get(this->local_sets);
|
||||
if (list)
|
||||
{
|
||||
enumerator->local = list->create_enumerator(list);
|
||||
}
|
||||
}
|
||||
return &enumerator->public;
|
||||
}
|
||||
@@ -373,26 +399,55 @@ METHOD(credential_manager_t, get_shared, shared_key_t*,
|
||||
}
|
||||
|
||||
METHOD(credential_manager_t, add_local_set, void,
|
||||
private_credential_manager_t *this, credential_set_t *set)
|
||||
private_credential_manager_t *this, credential_set_t *set, bool exclusive)
|
||||
{
|
||||
linked_list_t *sets;
|
||||
thread_value_t *tv;
|
||||
|
||||
sets = this->local_sets->get(this->local_sets);
|
||||
if (exclusive)
|
||||
{
|
||||
tv = this->exclusive_local_sets;
|
||||
}
|
||||
else
|
||||
{
|
||||
tv = this->local_sets;
|
||||
}
|
||||
sets = tv->get(tv);
|
||||
if (!sets)
|
||||
{ /* first invocation */
|
||||
{
|
||||
sets = linked_list_create();
|
||||
this->local_sets->set(this->local_sets, sets);
|
||||
tv->set(tv, sets);
|
||||
}
|
||||
if (exclusive)
|
||||
{
|
||||
sets->insert_first(sets, set);
|
||||
}
|
||||
else
|
||||
{
|
||||
sets->insert_last(sets, set);
|
||||
}
|
||||
sets->insert_last(sets, set);
|
||||
}
|
||||
|
||||
METHOD(credential_manager_t, remove_local_set, void,
|
||||
private_credential_manager_t *this, credential_set_t *set)
|
||||
{
|
||||
linked_list_t *sets;
|
||||
thread_value_t *tv;
|
||||
|
||||
sets = this->local_sets->get(this->local_sets);
|
||||
sets->remove(sets, set, NULL);
|
||||
tv = this->local_sets;
|
||||
sets = tv->get(tv);
|
||||
if (sets && sets->remove(sets, set, NULL) && sets->get_count(sets) == 0)
|
||||
{
|
||||
tv->set(tv, NULL);
|
||||
sets->destroy(sets);
|
||||
}
|
||||
tv = this->exclusive_local_sets;
|
||||
sets = tv->get(tv);
|
||||
if (sets && sets->remove(sets, set, NULL) && sets->get_count(sets) == 0)
|
||||
{
|
||||
tv->set(tv, NULL);
|
||||
sets->destroy(sets);
|
||||
}
|
||||
}
|
||||
|
||||
METHOD(credential_manager_t, cache_cert, void,
|
||||
@@ -859,7 +914,7 @@ METHOD(credential_manager_t, create_public_enumerator, enumerator_t*,
|
||||
if (auth)
|
||||
{
|
||||
enumerator->wrapper = auth_cfg_wrapper_create(auth);
|
||||
add_local_set(this, &enumerator->wrapper->set);
|
||||
add_local_set(this, &enumerator->wrapper->set, FALSE);
|
||||
}
|
||||
this->lock->read_lock(this->lock);
|
||||
return &enumerator->public;
|
||||
@@ -992,42 +1047,45 @@ METHOD(credential_manager_t, get_private, private_key_t*,
|
||||
}
|
||||
}
|
||||
|
||||
/* if a specific certificate is preferred, check for a matching key */
|
||||
cert = auth->get(auth, AUTH_RULE_SUBJECT_CERT);
|
||||
if (cert)
|
||||
if (auth)
|
||||
{
|
||||
private = get_private_by_cert(this, cert, type);
|
||||
if (private)
|
||||
/* if a specific certificate is preferred, check for a matching key */
|
||||
cert = auth->get(auth, AUTH_RULE_SUBJECT_CERT);
|
||||
if (cert)
|
||||
{
|
||||
trustchain = build_trustchain(this, cert, auth);
|
||||
if (trustchain)
|
||||
private = get_private_by_cert(this, cert, type);
|
||||
if (private)
|
||||
{
|
||||
auth->merge(auth, trustchain, FALSE);
|
||||
trustchain->destroy(trustchain);
|
||||
trustchain = build_trustchain(this, cert, auth);
|
||||
if (trustchain)
|
||||
{
|
||||
auth->merge(auth, trustchain, FALSE);
|
||||
trustchain->destroy(trustchain);
|
||||
}
|
||||
return private;
|
||||
}
|
||||
return private;
|
||||
}
|
||||
}
|
||||
|
||||
/* try to build a trust chain for each certificate found */
|
||||
enumerator = create_cert_enumerator(this, CERT_ANY, type, id, FALSE);
|
||||
while (enumerator->enumerate(enumerator, &cert))
|
||||
{
|
||||
private = get_private_by_cert(this, cert, type);
|
||||
if (private)
|
||||
/* try to build a trust chain for each certificate found */
|
||||
enumerator = create_cert_enumerator(this, CERT_ANY, type, id, FALSE);
|
||||
while (enumerator->enumerate(enumerator, &cert))
|
||||
{
|
||||
trustchain = build_trustchain(this, cert, auth);
|
||||
if (trustchain)
|
||||
private = get_private_by_cert(this, cert, type);
|
||||
if (private)
|
||||
{
|
||||
auth->merge(auth, trustchain, FALSE);
|
||||
trustchain->destroy(trustchain);
|
||||
break;
|
||||
trustchain = build_trustchain(this, cert, auth);
|
||||
if (trustchain)
|
||||
{
|
||||
auth->merge(auth, trustchain, FALSE);
|
||||
trustchain->destroy(trustchain);
|
||||
break;
|
||||
}
|
||||
private->destroy(private);
|
||||
private = NULL;
|
||||
}
|
||||
private->destroy(private);
|
||||
private = NULL;
|
||||
}
|
||||
enumerator->destroy(enumerator);
|
||||
}
|
||||
enumerator->destroy(enumerator);
|
||||
|
||||
/* if no valid trustchain was found, fall back to the first usable cert */
|
||||
if (!private)
|
||||
@@ -1038,7 +1096,10 @@ METHOD(credential_manager_t, get_private, private_key_t*,
|
||||
private = get_private_by_cert(this, cert, type);
|
||||
if (private)
|
||||
{
|
||||
auth->add(auth, AUTH_RULE_SUBJECT_CERT, cert->get_ref(cert));
|
||||
if (auth)
|
||||
{
|
||||
auth->add(auth, AUTH_RULE_SUBJECT_CERT, cert->get_ref(cert));
|
||||
}
|
||||
break;
|
||||
}
|
||||
}
|
||||
@@ -1100,6 +1161,7 @@ METHOD(credential_manager_t, destroy, void,
|
||||
this->sets->remove(this->sets, this->cache, NULL);
|
||||
this->sets->destroy(this->sets);
|
||||
this->local_sets->destroy(this->local_sets);
|
||||
this->exclusive_local_sets->destroy(this->exclusive_local_sets);
|
||||
this->cache->destroy(this->cache);
|
||||
this->validators->destroy(this->validators);
|
||||
this->lock->destroy(this->lock);
|
||||
@@ -1144,6 +1206,7 @@ credential_manager_t *credential_manager_create()
|
||||
);
|
||||
|
||||
this->local_sets = thread_value_create((thread_cleanup_t)this->sets->destroy);
|
||||
this->exclusive_local_sets = thread_value_create((thread_cleanup_t)this->sets->destroy);
|
||||
this->sets->insert_first(this->sets, this->cache);
|
||||
|
||||
return &this->public;
|
||||
|
||||
@@ -89,7 +89,7 @@ struct credential_manager_t {
|
||||
* @param type kind of requested shared key
|
||||
* @param first first subject between key is shared
|
||||
* @param second second subject between key is shared
|
||||
* @return enumerator over shared keys
|
||||
* @return enumerator over (shared_key_t*,id_match_t,id_match_t)
|
||||
*/
|
||||
enumerator_t *(*create_shared_enumerator)(credential_manager_t *this,
|
||||
shared_key_type_t type,
|
||||
@@ -230,10 +230,14 @@ struct credential_manager_t {
|
||||
* operation, sets may be added for the calling thread only. This
|
||||
* does not require a write lock and is therefore a much cheaper
|
||||
* operation.
|
||||
* The exclusive option allows to disable all other credential sets
|
||||
* until the set is deregistered.
|
||||
*
|
||||
* @param set set to register
|
||||
* @param exclusive TRUE to disable all other sets for this thread
|
||||
*/
|
||||
void (*add_local_set)(credential_manager_t *this, credential_set_t *set);
|
||||
void (*add_local_set)(credential_manager_t *this, credential_set_t *set,
|
||||
bool exclusive);
|
||||
|
||||
/**
|
||||
* Unregister a thread local credential set from the manager.
|
||||
|
||||
Reference in New Issue
Block a user