display selected IKE proposal in ipsec statusall

This commit is contained in:
Andreas Steffen
2008-06-22 11:24:33 +00:00
parent ff8d906b07
commit bc997f6583
4 changed files with 87 additions and 17 deletions
+26
View File
@@ -184,6 +184,11 @@ struct private_ike_sa_t {
*/
linked_list_t *child_sas;
/**
* String describing the selected IKE proposal
*/
char *selected_proposal;
/**
* crypter for inbound traffic
*/
@@ -1727,6 +1732,23 @@ static status_t derive_keys(private_ike_sa_t *this,
return SUCCESS;
}
/**
* Implementation of ike_sa_t.get_proposal.
*/
static char* get_proposal(private_ike_sa_t *this)
{
return this->selected_proposal;
}
/**
* Implementation of ike_sa_t.set_proposal.
*/
static void set_proposal(private_ike_sa_t *this, char *proposal)
{
free(this->selected_proposal);
this->selected_proposal = strdup(proposal);
}
/**
* Implementation of ike_sa_t.add_child_sa.
*/
@@ -2395,6 +2417,7 @@ static void destroy(private_ike_sa_t *this)
DESTROY_IF(this->child_prf);
chunk_free(&this->skp_verify);
chunk_free(&this->skp_build);
free(this->selected_proposal);
if (this->my_virtual_ip)
{
@@ -2495,6 +2518,8 @@ ike_sa_t * ike_sa_create(ike_sa_id_t *ike_sa_id)
this->public.get_skp_verify = (chunk_t (*)(ike_sa_t *)) get_skp_verify;
this->public.get_skp_build = (chunk_t (*)(ike_sa_t *)) get_skp_build;
this->public.derive_keys = (status_t (*)(ike_sa_t *,proposal_t*,chunk_t,chunk_t,chunk_t,bool,prf_t*,prf_t*)) derive_keys;
this->public.get_proposal = (char* (*)(ike_sa_t*)) get_proposal;
this->public.set_proposal = (void (*)(ike_sa_t*,char*)) set_proposal;
this->public.add_child_sa = (void (*)(ike_sa_t*,child_sa_t*)) add_child_sa;
this->public.get_child_sa = (child_sa_t* (*)(ike_sa_t*,protocol_id_t,u_int32_t,bool)) get_child_sa;
this->public.create_child_sa_iterator = (iterator_t* (*)(ike_sa_t*)) create_child_sa_iterator;
@@ -2534,6 +2559,7 @@ ike_sa_t * ike_sa_create(ike_sa_id_t *ike_sa_id)
this->other_id = identification_create_from_encoding(ID_ANY, chunk_empty);
this->extensions = 0;
this->conditions = 0;
this->selected_proposal = NULL;
this->crypter_in = NULL;
this->crypter_out = NULL;
this->signer_in = NULL;
+15
View File
@@ -703,6 +703,21 @@ struct ike_sa_t {
chunk_t nonce_i, chunk_t nonce_r,
bool initiator, prf_t *child_prf, prf_t *old_prf);
/**
* Get the selected IKE proposal string
*
* @return string describing the selected IKE proposal
*/
char* (*get_proposal)(ike_sa_t *this);
/**
* Set the selected IKE proposal string for status information purposes
* (the "%P" printf format handler is used)
*
* @param proposal string describing the selected IKE proposal
*/
void (*set_proposal)(ike_sa_t *this, char *proposal);
/**
* Get a multi purpose prf for the negotiated PRF function.
*
+20 -4
View File
@@ -424,9 +424,16 @@ static status_t build_r(private_ike_init_t *this, message_t *message)
message->add_notify(message, TRUE, NO_PROPOSAL_CHOSEN, chunk_empty);
return FAILED;
}
build_payloads(this, message);
/* Keep the selected IKE proposal for status information purposes */
{
char buf[BUF_LEN];
snprintf(buf, BUF_LEN, "%P", this->proposal);
this->ike_sa->set_proposal(this->ike_sa, buf+4);
}
build_payloads(this, message);
return SUCCESS;
}
@@ -508,7 +515,7 @@ static status_t process_i(private_ike_init_t *this, message_t *message)
if (this->proposal == NULL ||
this->other_nonce.len == 0 || this->my_nonce.len == 0)
{
SIG(IKE_UP_FAILED, "peers proposal selection invalid");
SIG(IKE_UP_FAILED, "peer's proposal selection invalid");
return FAILED;
}
@@ -516,7 +523,7 @@ static status_t process_i(private_ike_init_t *this, message_t *message)
!this->proposal->has_dh_group(this->proposal, this->dh_group) ||
this->dh->get_shared_secret(this->dh, &secret) != SUCCESS)
{
SIG(IKE_UP_FAILED, "peers DH group selection invalid");
SIG(IKE_UP_FAILED, "peer's DH group selection invalid");
return FAILED;
}
@@ -548,6 +555,15 @@ static status_t process_i(private_ike_init_t *this, message_t *message)
SIG(IKE_UP_FAILED, "key derivation failed");
return FAILED;
}
/* Keep the selected IKE proposal for status information purposes */
{
char buf[BUF_LEN];
snprintf(buf, BUF_LEN, "%P", this->proposal);
this->ike_sa->set_proposal(this->ike_sa, buf+4);
}
return SUCCESS;
}