respecting ipsec.conf cachecrls= option

This commit is contained in:
Martin Willi
2008-04-17 15:01:57 +00:00
parent 58126dd295
commit b360e3933d
10 changed files with 86 additions and 51 deletions
-13
View File
@@ -456,9 +456,6 @@ static void usage(const char *msg)
fprintf(stderr, "Usage: charon\n"
" [--help]\n"
" [--version]\n"
" [--strictcrlpolicy]\n"
" [--cachecrls]\n"
" [--crlcheckinterval <interval>]\n"
" [--use-syslog]\n"
" [--debug-<type> <level>]\n"
" <type>: log context type (dmn|mgr|ike|chd|job|cfg|knl|net|enc|lib)\n"
@@ -474,8 +471,6 @@ static void usage(const char *msg)
*/
int main(int argc, char *argv[])
{
u_int crl_check_interval = 0;
bool cache_crls = FALSE;
bool use_syslog = FALSE;
private_daemon_t *private_charon;
@@ -512,8 +507,6 @@ int main(int argc, char *argv[])
{ "help", no_argument, NULL, 'h' },
{ "version", no_argument, NULL, 'v' },
{ "use-syslog", no_argument, NULL, 'l' },
{ "cachecrls", no_argument, NULL, 'C' },
{ "crlcheckinterval", required_argument, NULL, 'x' },
/* TODO: handle "debug-all" */
{ "debug-dmn", required_argument, &signal, DBG_DMN },
{ "debug-mgr", required_argument, &signal, DBG_MGR },
@@ -542,12 +535,6 @@ int main(int argc, char *argv[])
case 'l':
use_syslog = TRUE;
continue;
case 'C':
cache_crls = TRUE;
continue;
case 'x':
crl_check_interval = atoi(optarg);
continue;
case 0:
/* option is in signal */
levels[signal] = atoi(optarg);
+20 -1
View File
@@ -73,6 +73,11 @@ struct private_stroke_cred_t {
* mutex to lock lists above
*/
mutex_t *mutex;
/**
* cache CRLs to disk?
*/
bool cachecrl;
};
/**
@@ -527,7 +532,7 @@ static void load_certdir(private_stroke_cred_t *this, char *path,
*/
static void cache_cert(private_stroke_cred_t *this, certificate_t *cert)
{
if (cert->get_type(cert) == CERT_X509_CRL)
if (cert->get_type(cert) == CERT_X509_CRL && this->cachecrl)
{
/* CRLs get cached to /etc/ipsec.d/crls/authkeyId.der */
crl_t *crl = (crl_t*)cert;
@@ -560,6 +565,17 @@ static void cache_cert(private_stroke_cred_t *this, certificate_t *cert)
}
}
/**
* Implementation of stroke_cred_t.cachecrl.
*/
static void cachecrl(private_stroke_cred_t *this, bool enabled)
{
DBG1(DBG_CFG, "crl caching to %s %s",
CRL_DIR, enabled ? "enabled" : "disabled");
this->cachecrl = enabled;
}
/**
* Convert a string of characters into a binary secret
* A string between single or double quotes is treated as ASCII characters
@@ -912,6 +928,7 @@ stroke_cred_t *stroke_cred_create()
this->public.reread = (void(*)(stroke_cred_t*, stroke_msg_t *msg))reread;
this->public.load_ca = (certificate_t*(*)(stroke_cred_t*, char *filename))load_ca;
this->public.load_peer = (certificate_t*(*)(stroke_cred_t*, char *filename))load_peer;
this->public.cachecrl = (void(*)(stroke_cred_t*, bool enabled))cachecrl;
this->public.destroy = (void(*)(stroke_cred_t*))destroy;
this->certs = linked_list_create();
@@ -922,6 +939,8 @@ stroke_cred_t *stroke_cred_create()
load_certs(this);
load_secrets(this);
this->cachecrl = FALSE;
return &this->public;
}
+7
View File
@@ -62,6 +62,13 @@ struct stroke_cred_t {
*/
certificate_t* (*load_peer)(stroke_cred_t *this, char *filename);
/**
* Enable/Disable CRL caching to disk.
*
* @param enabled TRUE to enable, FALSE to disable
*/
void (*cachecrl)(stroke_cred_t *this, bool enabled);
/**
* Destroy a stroke_cred instance.
*/
+10
View File
@@ -355,6 +355,13 @@ static void stroke_loglevel(private_stroke_socket_t *this, stroke_msg_t *msg, FI
charon->syslog->set_level(charon->syslog, signal, msg->loglevel.level);
}
/**
* set various config options
*/
static void stroke_config(private_stroke_socket_t *this, stroke_msg_t *msg, FILE *out)
{
this->cred->cachecrl(this->cred, msg->config.cachecrl);
}
/**
* destroy a job context
@@ -448,6 +455,9 @@ static job_requeue_t process(stroke_job_context_t *ctx)
case STR_LOGLEVEL:
stroke_loglevel(this, msg, out);
break;
case STR_CONFIG:
stroke_config(this, msg, out);
break;
case STR_LIST:
stroke_list(this, msg, out);
break;