vici: Match identity with wildcards against remote ID in redirect command

This commit is contained in:
Tobias Brunner
2016-03-04 16:02:59 +01:00
parent e92364db66
commit bef4518de7
3 changed files with 10 additions and 6 deletions
+2 -1
View File
@@ -298,7 +298,8 @@ supported by the peer.
ike = <redirect an IKE_SA by configuration name>
ike-id = <redirect an IKE_SA by its unique id>
peer-ip = <redirect an IKE_SA with matching peer IP>
peer-id = <redirect an IKE_SA with matching peer identity>
peer-id = <redirect an IKE_SA with matching peer identity, may contain
wildcards>
} => {
success = <yes or no>
errmsg = <error string on failure>
+7 -4
View File
@@ -366,7 +366,7 @@ CALLBACK(redirect, vici_message_t*,
enumerator_t *sas;
char *ike, *peer_ip, *peer_id, *gw, *errmsg = NULL;
u_int ike_id, current, found = 0;
identification_t *gateway, *identity = NULL;
identification_t *gateway, *identity = NULL, *other_id;
host_t *address = NULL;
ike_sa_t *ike_sa;
vici_builder_t *builder;
@@ -445,10 +445,13 @@ CALLBACK(redirect, vici_message_t*,
{
continue;
}
if (identity &&
!identity->equals(identity, ike_sa->get_other_eap_id(ike_sa)))
if (identity)
{
continue;
other_id = ike_sa->get_other_eap_id(ike_sa);
if (!other_id->matches(other_id, identity))
{
continue;
}
}
lib->processor->queue_job(lib->processor,
(job_t*)redirect_job_create(ike_sa->get_id(ike_sa), gateway));