Group membership constraint is fulfilled if subject is member in one of the groups
This commit is contained in:
@@ -308,7 +308,7 @@ static bool complies(private_auth_cfg_t *this, auth_cfg_t *constraints,
|
|||||||
bool log_error)
|
bool log_error)
|
||||||
{
|
{
|
||||||
enumerator_t *e1, *e2;
|
enumerator_t *e1, *e2;
|
||||||
bool success = TRUE;
|
bool success = TRUE, has_group = FALSE, group_match = FALSE;
|
||||||
auth_rule_t t1, t2;
|
auth_rule_t t1, t2;
|
||||||
void *value;
|
void *value;
|
||||||
|
|
||||||
@@ -463,17 +463,18 @@ static bool complies(private_auth_cfg_t *this, auth_cfg_t *constraints,
|
|||||||
{
|
{
|
||||||
identification_t *id1, *id2;
|
identification_t *id1, *id2;
|
||||||
|
|
||||||
|
/* for groups, a match of a single group is sufficient */
|
||||||
|
has_group = TRUE;
|
||||||
id1 = (identification_t*)value;
|
id1 = (identification_t*)value;
|
||||||
id2 = get(this, t1);
|
e2 = create_enumerator(this);
|
||||||
if (!id2 || !id2->matches(id2, id1))
|
while (e2->enumerate(e2, &t2, &id2))
|
||||||
{
|
{
|
||||||
success = FALSE;
|
if (t2 == AUTH_RULE_GROUP && id2->matches(id2, id1))
|
||||||
if (log_error)
|
|
||||||
{
|
{
|
||||||
DBG1(DBG_CFG, "constraint check failed: membership to "
|
group_match = TRUE;
|
||||||
"group '%Y' required", id1);
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
e2->destroy(e2);
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
case AUTH_HELPER_IM_CERT:
|
case AUTH_HELPER_IM_CERT:
|
||||||
@@ -489,6 +490,15 @@ static bool complies(private_auth_cfg_t *this, auth_cfg_t *constraints,
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
e1->destroy(e1);
|
e1->destroy(e1);
|
||||||
|
|
||||||
|
if (has_group && !group_match)
|
||||||
|
{
|
||||||
|
if (log_error)
|
||||||
|
{
|
||||||
|
DBG1(DBG_CFG, "constraint check failed: group membership required");
|
||||||
|
}
|
||||||
|
return FALSE;
|
||||||
|
}
|
||||||
return success;
|
return success;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -62,7 +62,9 @@ enum auth_rule_t {
|
|||||||
AUTH_RULE_CRL_VALIDATION,
|
AUTH_RULE_CRL_VALIDATION,
|
||||||
/** result of a OCSP validation, cert_validation_t */
|
/** result of a OCSP validation, cert_validation_t */
|
||||||
AUTH_RULE_OCSP_VALIDATION,
|
AUTH_RULE_OCSP_VALIDATION,
|
||||||
/** subject is member of a group, identification_t* */
|
/** subject is member of a group, identification_t*
|
||||||
|
* The group membership constraint is fulfilled if the subject is member of
|
||||||
|
* one group defined in the constraints. */
|
||||||
AUTH_RULE_GROUP,
|
AUTH_RULE_GROUP,
|
||||||
|
|
||||||
/** intermediate certificate, certificate_t* */
|
/** intermediate certificate, certificate_t* */
|
||||||
|
|||||||
Reference in New Issue
Block a user