experimental P2P-NAT-T for IKEv2 merged back from branch

This commit is contained in:
Tobias Brunner
2007-10-03 15:10:41 +00:00
parent 99670c3714
commit d5cc175833
41 changed files with 5114 additions and 31 deletions
File diff suppressed because it is too large Load Diff
+131
View File
@@ -0,0 +1,131 @@
/**
* @file connect_manager.h
*
* @brief Interface of connect_manager_t.
*
*/
/*
* Copyright (C) 2007 Tobias Brunner
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#ifndef CONNECT_MANAGER_H_
#define CONNECT_MANAGER_H_
typedef struct connect_manager_t connect_manager_t;
#include <encoding/message.h>
#include <config/child_cfg.h>
#include <sa/ike_sa_id.h>
#include <utils/identification.h>
/**
* @brief The connection manager is responsible for establishing a direct
* connection with another peer.
*
* @b Constructors:
* - connect_manager_create()
*
* @ingroup sa
*/
struct connect_manager_t {
/**
* @brief Checks if a there is already a mediated connection registered
* between two peers.
*
* @param this the manager object
* @param id my id
* @param peer_id the other peer's id
* @param mediated_sa the IKE_SA ID of the mediated connection
* @param child the CHILD_SA config of the mediated connection
* @returns
* - TRUE, if there was already a mediated connection registered
* - FALSE, otherwise
*/
bool (*check_and_register) (connect_manager_t *this,
identification_t *id, identification_t *peer_id,
ike_sa_id_t *mediated_sa, child_cfg_t *child);
/**
* @brief Checks if there are waiting connections with a specific peer.
* If so, reinitiate them.
*
* @param this the manager object
* @param id my id
* @param peer_id the other peer's id
*/
void (*check_and_initiate) (connect_manager_t *this, ike_sa_id_t *mediation_sa,
identification_t *id, identification_t *peer_id);
/**
* @brief Creates a checklist and sets the initiator's data.
*
* @param this the manager object
* @param initiator ID of the initiator
* @param responder ID of the responder
* @param session_id the session ID provided by the initiator
* @param key the initiator's key
* @param endpoints the initiator's endpoints
* @param is_initiator TRUE, if the caller of this method is the initiator
* FALSE, otherwise
* @returns
* SUCCESS
*/
status_t (*set_initiator_data) (connect_manager_t *this,
identification_t *initiator, identification_t *responder,
chunk_t session_id, chunk_t key, linked_list_t *endpoints, bool is_initiator);
/**
* @brief Updates a checklist and sets the responder's data. The checklist's
* state is advanced to WAITING which means that checks will be sent.
*
* @param this the manager object
* @param session_id the session ID
* @param chunk_t the responder's key
* @param endpoints the responder's endpoints
* @returns
* - NOT_FOUND, if the checklist has not been found
* - SUCCESS, otherwise
*/
status_t (*set_responder_data) (connect_manager_t *this,
chunk_t session_id, chunk_t key, linked_list_t *endpoints);
/**
* @brief Processes a connectivity check
*
* @param this the manager object
* @param message the received message
*/
void (*process_check) (connect_manager_t *this, message_t *message);
/**
* @brief Destroys the manager with all data.
*
* @param this the manager object
*/
void (*destroy) (connect_manager_t *this);
};
/**
* @brief Create a manager.
*
* @returns connect_manager_t object
*
* @ingroup sa
*/
connect_manager_t *connect_manager_create(void);
#endif /*CONNECT_MANAGER_H_*/
+155 -8
View File
@@ -6,7 +6,8 @@
*/
/*
* Copyright (C) 2006 Tobias Brunner, Daniel Roethlisberger
* Copyright (C) 2006-2007 Tobias Brunner
* Copyright (C) 2006 Daniel Roethlisberger
* Copyright (C) 2005-2006 Martin Willi
* Copyright (C) 2005 Jan Hutter
* Hochschule fuer Technik Rapperswil
@@ -65,6 +66,9 @@
#include <processing/jobs/send_keepalive_job.h>
#include <processing/jobs/rekey_ike_sa_job.h>
#ifdef P2P
#include <sa/tasks/ike_p2p.h>
#endif
#ifndef RESOLV_CONF
#define RESOLV_CONF "/etc/resolv.conf"
@@ -130,6 +134,13 @@ struct private_ike_sa_t {
*/
host_t *other_host;
#ifdef P2P
/**
* Server reflexive host
*/
host_t *server_reflexive_host;
#endif /* P2P */
/**
* Identification used for us
*/
@@ -855,6 +866,92 @@ static void send_notify_response(private_ike_sa_t *this, message_t *request,
response->destroy(response);
}
#ifdef P2P
/**
* Implementation of ike_sa_t.get_server_reflexive_host.
*/
static host_t *get_server_reflexive_host(private_ike_sa_t *this)
{
return this->server_reflexive_host;
}
/**
* Implementation of ike_sa_t.set_server_reflexive_host.
*/
static void set_server_reflexive_host(private_ike_sa_t *this, host_t *host)
{
DESTROY_IF(this->server_reflexive_host);
this->server_reflexive_host = host;
}
/**
* Implementation of ike_sa_t.respond
*/
static status_t respond(private_ike_sa_t *this, identification_t *peer_id,
chunk_t session_id)
{
ike_p2p_t *task = ike_p2p_create(&this->public, TRUE);
task->respond(task, peer_id, session_id);
this->task_manager->queue_task(this->task_manager, (task_t*)task);
return this->task_manager->initiate(this->task_manager);
}
/**
* Implementation of ike_sa_t.callback
*/
static status_t callback(private_ike_sa_t *this, identification_t *peer_id)
{
ike_p2p_t *task = ike_p2p_create(&this->public, TRUE);
task->callback(task, peer_id);
this->task_manager->queue_task(this->task_manager, (task_t*)task);
return this->task_manager->initiate(this->task_manager);
}
/**
* Implementation of ike_sa_t.relay
*/
static status_t relay(private_ike_sa_t *this, identification_t *requester,
chunk_t session_id, chunk_t session_key, linked_list_t *endpoints, bool response)
{
ike_p2p_t *task = ike_p2p_create(&this->public, TRUE);
task->relay(task, requester, session_id, session_key, endpoints, response);
this->task_manager->queue_task(this->task_manager, (task_t*)task);
return this->task_manager->initiate(this->task_manager);
}
/**
* Implementation of ike_sa_t.initiate_mediation
*/
static status_t initiate_mediation(private_ike_sa_t *this, peer_cfg_t *mediated_cfg)
{
ike_p2p_t *task = ike_p2p_create(&this->public, TRUE);
task->connect(task, mediated_cfg->get_peer_id(mediated_cfg));
this->task_manager->queue_task(this->task_manager, (task_t*)task);
return this->task_manager->initiate(this->task_manager);
}
/**
* Implementation of ike_sa_t.initiate_mediated
*/
static status_t initiate_mediated(private_ike_sa_t *this, host_t *me, host_t *other,
linked_list_t *childs)
{
this->my_host = me->clone(me);
this->other_host = other->clone(other);
task_t *task;
child_cfg_t *child_cfg;
iterator_t *iterator = childs->create_iterator(childs, TRUE);
while (iterator->iterate(iterator, (void**)&child_cfg))
{
task = (task_t*)child_create_create(&this->public, child_cfg);
this->task_manager->queue_task(this->task_manager, task);
}
iterator->destroy(iterator);
return this->task_manager->initiate(this->task_manager);
}
#endif /* P2P */
/**
* Implementation of ike_sa_t.initiate.
*/
@@ -864,7 +961,11 @@ static status_t initiate(private_ike_sa_t *this, child_cfg_t *child_cfg)
if (this->state == IKE_CREATED)
{
if (this->other_host->is_anyaddr(this->other_host))
if (this->other_host->is_anyaddr(this->other_host)
#ifdef P2P
&& !this->peer_cfg->get_mediated_by(this->peer_cfg)
#endif /* P2P */
)
{
child_cfg->destroy(child_cfg);
SIG(IKE_UP_START, "initiating IKE_SA");
@@ -887,11 +988,36 @@ static status_t initiate(private_ike_sa_t *this, child_cfg_t *child_cfg)
task = (task_t*)ike_mobike_create(&this->public, TRUE);
this->task_manager->queue_task(this->task_manager, task);
}
#ifdef P2P
task = (task_t*)ike_p2p_create(&this->public, TRUE);
this->task_manager->queue_task(this->task_manager, task);
#endif /* P2P */
}
#ifdef P2P
if (this->peer_cfg->get_mediated_by(this->peer_cfg))
{
// mediated connection, initiate mediation process
job_t *job = (job_t*)initiate_mediation_job_create(this->ike_sa_id, child_cfg);
child_cfg->destroy(child_cfg);
charon->processor->queue_job(charon->processor, job);
return SUCCESS;
}
else if (this->peer_cfg->is_mediation(this->peer_cfg))
{
if (this->state == IKE_ESTABLISHED)
{// FIXME: we should try to find a better solution to this
SIG(CHILD_UP_SUCCESS, "mediation connection is already up and running");
}
}
else
#endif /* P2P */
{
// normal IKE_SA with CHILD_SA
task = (task_t*)child_create_create(&this->public, child_cfg);
child_cfg->destroy(child_cfg);
this->task_manager->queue_task(this->task_manager, task);
}
task = (task_t*)child_create_create(&this->public, child_cfg);
child_cfg->destroy(child_cfg);
this->task_manager->queue_task(this->task_manager, task);
return this->task_manager->initiate(this->task_manager);
}
@@ -900,7 +1026,7 @@ static status_t initiate(private_ike_sa_t *this, child_cfg_t *child_cfg)
* Implementation of ike_sa_t.acquire.
*/
static status_t acquire(private_ike_sa_t *this, u_int32_t reqid)
{
{// FIXME: P2P-NAT-T
child_cfg_t *child_cfg;
iterator_t *iterator;
child_sa_t *current, *child_sa = NULL;
@@ -1224,7 +1350,7 @@ static status_t process_message(private_ike_sa_t *this, message_t *message)
* Implementation of ike_sa_t.retransmit.
*/
static status_t retransmit(private_ike_sa_t *this, u_int32_t message_id)
{
{// FIXME: P2P-NAT-T
this->time.outbound = time(NULL);
if (this->task_manager->retransmit(this->task_manager, message_id) != SUCCESS)
{
@@ -2047,6 +2173,15 @@ static void destroy(private_ike_sa_t *this)
offsetof(host_t, destroy));
this->additional_addresses->destroy_offset(this->additional_addresses,
offsetof(host_t, destroy));
#ifdef P2P
if (this->peer_cfg && this->peer_cfg->is_mediation(this->peer_cfg) &&
!this->ike_sa_id->is_initiator(this->ike_sa_id))
{
// mediation server
charon->mediation_manager->remove(charon->mediation_manager, this->ike_sa_id);
}
DESTROY_IF(this->server_reflexive_host);
#endif /* P2P */
DESTROY_IF(this->my_host);
DESTROY_IF(this->other_host);
@@ -2129,6 +2264,15 @@ ike_sa_t * ike_sa_create(ike_sa_id_t *ike_sa_id)
this->public.set_virtual_ip = (void (*)(ike_sa_t*,bool,host_t*))set_virtual_ip;
this->public.get_virtual_ip = (host_t* (*)(ike_sa_t*,bool))get_virtual_ip;
this->public.add_dns_server = (void (*)(ike_sa_t*,host_t*))add_dns_server;
#ifdef P2P
this->public.get_server_reflexive_host = (host_t* (*)(ike_sa_t*)) get_server_reflexive_host;
this->public.set_server_reflexive_host = (void (*)(ike_sa_t*,host_t*)) set_server_reflexive_host;
this->public.initiate_mediation = (status_t (*)(ike_sa_t*,peer_cfg_t*)) initiate_mediation;
this->public.initiate_mediated = (status_t (*)(ike_sa_t*,host_t*,host_t*,linked_list_t*)) initiate_mediated;
this->public.relay = (status_t (*)(ike_sa_t*,identification_t*,chunk_t,chunk_t,linked_list_t*,bool)) relay;
this->public.callback = (status_t (*)(ike_sa_t*,identification_t*)) callback;
this->public.respond = (status_t (*)(ike_sa_t*,identification_t*,chunk_t)) respond;
#endif /* P2P */
/* initialize private fields */
this->ike_sa_id = ike_sa_id->clone(ike_sa_id);
@@ -2163,6 +2307,9 @@ ike_sa_t * ike_sa_create(ike_sa_id_t *ike_sa_id)
this->additional_addresses = linked_list_create();
this->pending_updates = 0;
this->keyingtry = 0;
#ifdef P2P
this->server_reflexive_host = NULL;
#endif /* P2P */
return &this->public;
}
+92 -1
View File
@@ -6,7 +6,8 @@
*/
/*
* Copyright (C) 2006 Tobias Brunner, Daniel Roethlisberger
* Copyright (C) 2006-2007 Tobias Brunner
* Copyright (C) 2006 Daniel Roethlisberger
* Copyright (C) 2005-2006 Martin Willi
* Copyright (C) 2005 Jan Hutter
* Hochschule fuer Technik Rapperswil
@@ -452,6 +453,96 @@ struct ike_sa_t {
* @param updates number of pending updates
*/
void (*set_pending_updates)(ike_sa_t *this, u_int32_t updates);
#ifdef P2P
/**
* @brief Get the server reflexive host.
*
* @param this calling object
* @return server reflexive host
*/
host_t* (*get_server_reflexive_host) (ike_sa_t *this);
/**
* @brief Set the server reflexive host.
*
* @param this calling object
* @param host server reflexive host
*/
void (*set_server_reflexive_host) (ike_sa_t *this, host_t *host);
/**
* @brief Initiate the mediation of a mediated connection (i.e. initiate a
* P2P_CONNECT exchange).
*
* @param this calling object
* @param mediated_cfg peer_cfg of the mediated connection
* @return
* - SUCCESS if initialization started
* - DESTROY_ME if initialization failed
*/
status_t (*initiate_mediation) (ike_sa_t *this, peer_cfg_t *mediated_cfg);
/**
* @brief Initiate the mediated connection
*
* @param this calling object
* @param me local endpoint (gets cloned)
* @param other remote endpoint (gets cloned)
* @param childs linked list of child_cfg_t of CHILD_SAs (gets cloned)
* @return
* - SUCCESS if initialization started
* - DESTROY_ME if initialization failed
*/
status_t (*initiate_mediated) (ike_sa_t *this, host_t *me, host_t *other,
linked_list_t *childs);
/**
* @brief Relay data from one peer to another (i.e. initiate a
* P2P_CONNECT exchange).
*
* Data is cloned.
*
* @param this calling object
* @param requester ID of the requesting peer
* @param session_id data of the P2P_SESSIONID payload
* @param session_key data of the P2P_SESSIONKEY payload
* @param endpoints endpoints
* @param response TRUE if this is a response
* @return
* - SUCCESS if relay started
* - DESTROY_ME if relay failed
*/
status_t (*relay) (ike_sa_t *this, identification_t *requester, chunk_t session_id,
chunk_t session_key, linked_list_t *endpoints, bool response);
/**
* @brief Send a callback to a peer.
*
* Data is cloned.
*
* @param this calling object
* @param peer_id ID of the other peer
* @return
* - SUCCESS if response started
* - DESTROY_ME if response failed
*/
status_t (*callback) (ike_sa_t *this, identification_t *peer_id);
/**
* @brief Respond to a P2P_CONNECT request.
*
* Data is cloned.
*
* @param this calling object
* @param peer_id ID of the other peer
* @param session_id the session ID supplied by the initiator
* @return
* - SUCCESS if response started
* - DESTROY_ME if response failed
*/
status_t (*respond) (ike_sa_t *this, identification_t *peer_id, chunk_t session_id);
#endif /* P2P */
/**
* @brief Initiate a new connection.
+343
View File
@@ -0,0 +1,343 @@
/**
* @file mediation_manager.c
*
* @brief Implementation of mediation_manager_t.
*
*/
/*
* Copyright (C) 2007 Tobias Brunner
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#include "mediation_manager.h"
#include <pthread.h>
#include <daemon.h>
#include <utils/linked_list.h>
#include <processing/jobs/mediation_job.h>
typedef struct peer_t peer_t;
/**
* An entry in the linked list.
*/
struct peer_t {
/** id of the peer */
identification_t *id;
/** sa id of the peer, NULL if offline */
ike_sa_id_t *ike_sa_id;
/** list of peer ids that reuested this peer */
linked_list_t *requested_by;
};
/**
* Implementation of peer_t.destroy.
*/
static void peer_destroy(peer_t *this)
{
DESTROY_IF(this->id);
DESTROY_IF(this->ike_sa_id);
this->requested_by->destroy_offset(this->requested_by, offsetof(identification_t, destroy));
free(this);
}
/**
* Creates a new entry for the list.
*/
static peer_t *peer_create(identification_t *id, ike_sa_id_t* ike_sa_id)
{
peer_t *this = malloc_thing(peer_t);
/* clone everything */
this->id = id->clone(id);
this->ike_sa_id = ike_sa_id ? ike_sa_id->clone(ike_sa_id) : NULL;
this->requested_by = linked_list_create();
return this;
}
typedef struct private_mediation_manager_t private_mediation_manager_t;
/**
* Additional private members of mediation_manager_t.
*/
struct private_mediation_manager_t {
/**
* Public interface of mediation_manager_t.
*/
mediation_manager_t public;
/**
* Lock for exclusivly accessing the manager.
*/
pthread_mutex_t mutex;
/**
* Linked list with state entries.
*/
linked_list_t *peers;
};
/**
* Registers a peer's ID at another peer, if it is not yet registered
*/
static void register_peer(peer_t *peer, identification_t *peer_id)
{
iterator_t *iterator;
identification_t *current;
iterator = peer->requested_by->create_iterator(peer->requested_by, TRUE);
while (iterator->iterate(iterator, (void**)&current))
{
if (peer_id->equals(peer_id, current))
{
iterator->destroy(iterator);
return;
}
}
iterator->destroy(iterator);
peer->requested_by->insert_last(peer->requested_by, peer_id->clone(peer_id));
}
/**
* Get a peer_t object by a peer's id
*/
static status_t get_peer_by_id(private_mediation_manager_t *this,
identification_t *id, peer_t **peer)
{
iterator_t *iterator;
peer_t *current;
status_t status = NOT_FOUND;
iterator = this->peers->create_iterator(this->peers, TRUE);
while (iterator->iterate(iterator, (void**)&current))
{
if (id->equals(id, current->id))
{
if (peer)
{
*peer = current;
}
status = SUCCESS;
break;
}
}
iterator->destroy(iterator);
return status;
}
/**
* Check if a given peer is registered at other peers. If so, remove it there
* and then remove peers completely that are not online and have no registered
* peers.
*/
static void unregister_peer(private_mediation_manager_t *this, identification_t *peer_id)
{
iterator_t *iterator, *iterator_r;
peer_t *peer;
identification_t *registered;
iterator = this->peers->create_iterator(this->peers, TRUE);
while (iterator->iterate(iterator, (void**)&peer))
{
iterator_r = peer->requested_by->create_iterator(peer->requested_by, TRUE);
while (iterator_r->iterate(iterator_r, (void**)&registered))
{
if (peer_id->equals(peer_id, registered))
{
iterator_r->remove(iterator_r);
registered->destroy(registered);
break;
}
}
iterator_r->destroy(iterator_r);
if (!peer->ike_sa_id && !peer->requested_by->get_count(peer->requested_by))
{
iterator->remove(iterator);
peer_destroy(peer);
break;
}
}
iterator->destroy(iterator);
}
/**
* Implementation of mediation_manager_t.remove
*/
static void remove_sa(private_mediation_manager_t *this, ike_sa_id_t *ike_sa_id)
{
iterator_t *iterator;
peer_t *peer;
pthread_mutex_lock(&(this->mutex));
iterator = this->peers->create_iterator(this->peers, TRUE);
while (iterator->iterate(iterator, (void**)&peer))
{
if (ike_sa_id->equals(ike_sa_id, peer->ike_sa_id))
{
iterator->remove(iterator);
unregister_peer(this, peer->id);
peer_destroy(peer);
break;
}
}
iterator->destroy(iterator);
pthread_mutex_unlock(&(this->mutex));
}
/**
* Implementation of mediation_manager_t.update_sa_id
*/
static void update_sa_id(private_mediation_manager_t *this, identification_t *peer_id, ike_sa_id_t *ike_sa_id)
{
iterator_t *iterator;
peer_t *peer;
bool found = FALSE;
pthread_mutex_lock(&(this->mutex));
iterator = this->peers->create_iterator(this->peers, TRUE);
while (iterator->iterate(iterator, (void**)&peer))
{
if (peer_id->equals(peer_id, peer->id))
{
DESTROY_IF(peer->ike_sa_id);
found = TRUE;
break;
}
}
iterator->destroy(iterator);
if (!found)
{
DBG2(DBG_IKE, "adding peer '%D'", peer_id);
peer = peer_create(peer_id, NULL);
this->peers->insert_last(this->peers, peer);
}
DBG2(DBG_IKE, "changing registered IKE_SA ID of peer '%D'", peer_id);
peer->ike_sa_id = ike_sa_id ? ike_sa_id->clone(ike_sa_id) : NULL;
// send callbacks to registered peers
identification_t *requester;
while(peer->requested_by->remove_last(peer->requested_by, (void**)&requester) == SUCCESS)
{
job_t *job = (job_t*)mediation_callback_job_create(requester, peer_id);
charon->processor->queue_job(charon->processor, job);
}
pthread_mutex_unlock(&(this->mutex));
}
/**
* Implementation of mediation_manager_t.check.
*/
static ike_sa_id_t *check(private_mediation_manager_t *this,
identification_t *peer_id)
{
peer_t *peer;
ike_sa_id_t *ike_sa_id;
pthread_mutex_lock(&(this->mutex));
if (get_peer_by_id(this, peer_id, &peer) != SUCCESS)
{
pthread_mutex_unlock(&(this->mutex));
return NULL;
}
ike_sa_id = peer->ike_sa_id;
pthread_mutex_unlock(&(this->mutex));
return ike_sa_id;
}
/**
* Implementation of mediation_manager_t.check_and_register.
*/
static ike_sa_id_t *check_and_register(private_mediation_manager_t *this,
identification_t *peer_id, identification_t *requester)
{
peer_t *peer;
ike_sa_id_t *ike_sa_id;
pthread_mutex_lock(&(this->mutex));
if (get_peer_by_id(this, peer_id, &peer) != SUCCESS)
{
DBG2(DBG_IKE, "adding peer %D", peer_id);
peer = peer_create(peer_id, NULL);
this->peers->insert_last(this->peers, peer);
}
if (!peer->ike_sa_id)
{
// the peer is not online
DBG2(DBG_IKE, "requested peer '%D' is offline, registering peer '%D'", peer_id, requester);
register_peer(peer, requester);
pthread_mutex_unlock(&(this->mutex));
return NULL;
}
ike_sa_id = peer->ike_sa_id;
pthread_mutex_unlock(&(this->mutex));
return ike_sa_id;
}
/**
* Implementation of mediation_manager_t.destroy.
*/
static void destroy(private_mediation_manager_t *this)
{
pthread_mutex_lock(&(this->mutex));
this->peers->destroy_function(this->peers, (void*)peer_destroy);
pthread_mutex_unlock(&(this->mutex));
pthread_mutex_destroy(&(this->mutex));
free(this);
}
/*
* Described in header.
*/
mediation_manager_t *mediation_manager_create()
{
private_mediation_manager_t *this = malloc_thing(private_mediation_manager_t);
this->public.destroy = (void(*)(mediation_manager_t*))destroy;
this->public.remove = (void(*)(mediation_manager_t*,ike_sa_id_t*))remove_sa;
this->public.update_sa_id = (void(*)(mediation_manager_t*,identification_t*,ike_sa_id_t*))update_sa_id;
this->public.check = (ike_sa_id_t*(*)(mediation_manager_t*,identification_t*))check;
this->public.check_and_register = (ike_sa_id_t*(*)(mediation_manager_t*,identification_t*,identification_t*))check_and_register;
this->peers = linked_list_create();
pthread_mutex_init(&(this->mutex), NULL);
return (mediation_manager_t*)this;
}
+104
View File
@@ -0,0 +1,104 @@
/**
* @file mediation_manager.h
*
* @brief Interface of mediation_manager_t.
*
*/
/*
* Copyright (C) 2007 Tobias Brunner
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#ifndef MEDIATION_MANAGER_H_
#define MEDIATION_MANAGER_H_
typedef struct mediation_manager_t mediation_manager_t;
#include <sa/ike_sa_id.h>
#include <utils/identification.h>
/**
* @brief The mediation manager is responsible for managing currently online
* peers and registered requests for offline peers on the mediation server.
*
* @b Constructors:
* - mediation_manager_create()
*
* @ingroup sa
*/
struct mediation_manager_t {
/**
* @brief Remove the IKE_SA of a peer.
*
* @param this the manager object
* @param ike_sa_id the IKE_SA ID of the peer's SA
*/
void (*remove) (mediation_manager_t* this, ike_sa_id_t *ike_sa_id);
/**
* @brief Update the ike_sa_id that is assigned to a peer's ID. If the peer
* is new, it gets a new record assigned.
*
* @param this the manager object
* @param peer_id the peer's ID
* @param ike_sa_id the IKE_SA ID of the peer's SA
*/
void (*update_sa_id) (mediation_manager_t* this, identification_t *peer_id,
ike_sa_id_t *ike_sa_id);
/**
* @brief Checks if a specific peer is online.
*
* @param this the manager object
* @param peer_id the peer's ID
* @returns
* - IKE_SA ID of the peer's SA.
* - NULL, if the peer is not online.
*/
ike_sa_id_t* (*check) (mediation_manager_t* this,
identification_t *peer_id);
/**
* @brief Checks if a specific peer is online and registers the requesting
* peer if it is not.
*
* @param this the manager object
* @param peer_id the peer's ID
* @param requester the requesters ID
* @returns
* - IKE_SA ID of the peer's SA.
* - NULL, if the peer is not online.
*/
ike_sa_id_t* (*check_and_register) (mediation_manager_t* this,
identification_t *peer_id, identification_t *requester);
/**
* @brief Destroys the manager with all data.
*
* @param this the manager object
*/
void (*destroy) (mediation_manager_t *this);
};
/**
* @brief Create a manager.
*
* @returns mediation_manager_t object
*
* @ingroup sa
*/
mediation_manager_t *mediation_manager_create(void);
#endif /*MEDIATION_MANAGER_H_*/
+31 -1
View File
@@ -6,6 +6,7 @@
*/
/*
* Copyright (C) 2007 Tobias Brunner
* Copyright (C) 2007 Martin Willi
* Hochschule fuer Technik Rapperswil
*
@@ -40,6 +41,10 @@
#include <encoding/payloads/delete_payload.h>
#include <processing/jobs/retransmit_job.h>
#ifdef P2P
#include <sa/tasks/ike_p2p.h>
#endif
typedef struct exchange_t exchange_t;
/**
@@ -323,6 +328,13 @@ static status_t build_request(private_task_manager_t *this)
exchange = IKE_SA_INIT;
activate_task(this, IKE_NATD);
activate_task(this, IKE_CERT);
#ifdef P2P
/* this task has to be activated before the IKE_AUTHENTICATE
* task, because that task pregenerates the packet after
* which no payloads can be added to the message anymore.
*/
activate_task(this, IKE_P2P);
#endif /* P2P */
activate_task(this, IKE_AUTHENTICATE);
activate_task(this, IKE_CONFIG);
activate_task(this, CHILD_CREATE);
@@ -370,6 +382,13 @@ static status_t build_request(private_task_manager_t *this)
exchange = INFORMATIONAL;
break;
}
#ifdef P2P
if (activate_task(this, IKE_P2P))
{
exchange = P2P_CONNECT;
break;
}
#endif /* P2P */
case IKE_REKEYING:
if (activate_task(this, IKE_DELETE))
{
@@ -668,6 +687,10 @@ static status_t process_request(private_task_manager_t *this,
this->passive_tasks->insert_last(this->passive_tasks, task);
task = (task_t*)ike_cert_create(this->ike_sa, FALSE);
this->passive_tasks->insert_last(this->passive_tasks, task);
#ifdef P2P
task = (task_t*)ike_p2p_create(this->ike_sa, FALSE);
this->passive_tasks->insert_last(this->passive_tasks, task);
#endif /* P2P */
task = (task_t*)ike_auth_create(this->ike_sa, FALSE);
this->passive_tasks->insert_last(this->passive_tasks, task);
task = (task_t*)ike_config_create(this->ike_sa, FALSE);
@@ -679,7 +702,7 @@ static status_t process_request(private_task_manager_t *this,
break;
}
case CREATE_CHILD_SA:
{
{//FIXME: we should prevent this on mediation connections
bool notify_found = FALSE, ts_found = FALSE;
iterator = message->get_payload_iterator(message);
while (iterator->iterate(iterator, (void**)&payload))
@@ -787,6 +810,13 @@ static status_t process_request(private_task_manager_t *this,
this->passive_tasks->insert_last(this->passive_tasks, task);
break;
}
#ifdef P2P
case P2P_CONNECT:
{
task = (task_t*)ike_p2p_create(this->ike_sa, FALSE);
this->passive_tasks->insert_last(this->passive_tasks, task);
}
#endif /* P2P */
default:
break;
}
+17 -2
View File
@@ -91,7 +91,7 @@ static chunk_t generate_natd_hash(private_ike_natd_t *this,
u_int64_t spi_i, spi_r;
u_int16_t port;
/* prepare all requred chunks */
/* prepare all required chunks */
spi_i = ike_sa_id->get_initiator_spi(ike_sa_id);
spi_r = ike_sa_id->get_responder_spi(ike_sa_id);
spi_i_chunk.ptr = (void*)&spi_i;
@@ -258,8 +258,23 @@ static status_t process_i(private_ike_natd_t *this, message_t *message)
if (message->get_exchange_type(message) == IKE_SA_INIT)
{
peer_cfg_t *peer_cfg = this->ike_sa->get_peer_cfg(this->ike_sa);
#ifdef P2P
/* if we are on a mediated connection we have already switched to
* port 4500 and the correct destination port is already configured,
* therefore we must not switch again */
if (peer_cfg->get_mediated_by(peer_cfg))
{
return SUCCESS;
}
#endif /* P2P */
if (this->ike_sa->has_condition(this->ike_sa, COND_NAT_ANY) ||
#ifdef P2P
/* if we are on a mediation connection we swith to port 4500 even
* if no NAT is detected. */
peer_cfg->is_mediation(peer_cfg) ||
#endif /* P2P */
/* if peer supports NAT-T, we switch to port 4500 even
* if no NAT is detected. MOBIKE requires this. */
(peer_cfg->use_mobike(peer_cfg) &&
+851
View File
@@ -0,0 +1,851 @@
/**
* @file ike_p2p.c
*
* @brief Implementation of the ike_p2p task.
*
*/
/*
* Copyright (C) 2007 Tobias Brunner
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#include "ike_p2p.h"
#include <string.h>
#include <daemon.h>
#include <config/peer_cfg.h>
#include <encoding/payloads/id_payload.h>
#include <encoding/payloads/notify_payload.h>
#include <encoding/payloads/endpoint_notify.h>
#include <processing/jobs/mediation_job.h>
#define P2P_SESSIONID_LEN 8
#define P2P_SESSIONKEY_LEN 16
// FIXME: proposed values
#define P2P_SESSIONID_MIN_LEN 4
#define P2P_SESSIONID_MAX_LEN 16
#define P2P_SESSIONKEY_MIN_LEN 8
#define P2P_SESSIONKEY_MAX_LEN 64
typedef struct private_ike_p2p_t private_ike_p2p_t;
/**
* Private members of a ike_p2p_t task.
*/
struct private_ike_p2p_t {
/**
* Public methods and task_t interface.
*/
ike_p2p_t public;
/**
* Assigned IKE_SA.
*/
ike_sa_t *ike_sa;
/**
* Are we the initiator?
*/
bool initiator;
/**
* Is this a mediation connection?
*/
bool mediation;
/**
* Is this the response from another peer?
*/
bool response;
/**
* Gathered endpoints
*/
linked_list_t *local_endpoints;
/**
* Parsed endpoints
*/
linked_list_t *remote_endpoints;
/**
* Did the peer request a callback?
*/
bool callback;
/**
* Did the connect fail?
*/
bool failed;
/**
* Was there anything wrong with the payloads?
*/
bool invalid_syntax;
/**
* The requested peer
*/
identification_t *peer_id;
/**
* Received ID used for connectivity checks
*/
chunk_t session_id;
/**
* Received key used for connectivity checks
*/
chunk_t session_key;
/**
* Peer config of the mediated connection
*/
peer_cfg_t *mediated_cfg;
};
// -----------------------------------------------------------------------------
/**
* Adds a list of endpoints as notifies to a given message
*/
static void add_endpoints_to_message(message_t *message, linked_list_t *endpoints)
{
iterator_t *iterator;
endpoint_notify_t *endpoint;
iterator = endpoints->create_iterator(endpoints, TRUE);
while (iterator->iterate(iterator, (void**)&endpoint))
{
message->add_payload(message, (payload_t*)endpoint->build_notify(endpoint));
}
iterator->destroy(iterator);
}
/**
* Gathers endpoints and adds them to the current message
*/
static void gather_and_add_endpoints(private_ike_p2p_t *this, message_t *message)
{
iterator_t *iterator;
host_t *addr, *host;
u_int16_t port;
// get the port that is used to communicate with the ms
host = this->ike_sa->get_my_host(this->ike_sa);
port = host->get_port(host);
iterator = charon->kernel_interface->create_address_iterator(
charon->kernel_interface);
while (iterator->iterate(iterator, (void**)&addr))
{
host = addr->clone(addr);
host->set_port(host, port);
this->local_endpoints->insert_last(this->local_endpoints,
endpoint_notify_create_from_host(HOST, host, NULL));
host->destroy(host);
}
iterator->destroy(iterator);
host = this->ike_sa->get_server_reflexive_host(this->ike_sa);
if (host)
{
this->local_endpoints->insert_last(this->local_endpoints,
endpoint_notify_create_from_host(SERVER_REFLEXIVE, host,
this->ike_sa->get_my_host(this->ike_sa)));
}
add_endpoints_to_message(message, this->local_endpoints);
}
/**
* read notifys from message and evaluate them
*/
static void process_payloads(private_ike_p2p_t *this, message_t *message)
{
iterator_t *iterator;
payload_t *payload;
iterator = message->get_payload_iterator(message);
while (iterator->iterate(iterator, (void**)&payload))
{
if (payload->get_type(payload) != NOTIFY)
{
continue;
}
notify_payload_t *notify = (notify_payload_t*)payload;
switch (notify->get_notify_type(notify))
{
case P2P_CONNECT_FAILED:
{
DBG2(DBG_IKE, "received P2P_CONNECT_FAILED notify");
this->failed = TRUE;
break;
}
case P2P_MEDIATION:
{
DBG2(DBG_IKE, "received P2P_MEDIATION notify");
this->mediation = TRUE;
break;
}
case P2P_ENDPOINT:
{
endpoint_notify_t *endpoint = endpoint_notify_create_from_payload(notify);
if (!endpoint)
{
DBG1(DBG_IKE, "received invalid P2P_ENDPOINT notify");
break;
}
DBG2(DBG_IKE, "received P2P_ENDPOINT notify");
this->remote_endpoints->insert_last(this->remote_endpoints, endpoint);
break;
}
case P2P_CALLBACK:
{
DBG2(DBG_IKE, "received P2P_CALLBACK notify");
this->callback = TRUE;
break;
}
case P2P_SESSIONID:
{
chunk_free(&this->session_id);
this->session_id = chunk_clone(notify->get_notification_data(notify));
DBG3(DBG_IKE, "received p2p_sessionid %B", &this->session_id);
break;
}
case P2P_SESSIONKEY:
{
chunk_free(&this->session_key);
this->session_key = chunk_clone(notify->get_notification_data(notify));
DBG4(DBG_IKE, "received p2p_sessionkey %B", &this->session_key);
break;
}
case P2P_RESPONSE:
{
DBG2(DBG_IKE, "received P2P_RESPONSE notify");
this->response = TRUE;
break;
}
default:
break;
}
}
iterator->destroy(iterator);
}
// -----------------------------------------------------------------------------
/**
* Implementation of task_t.process for initiator
*/
static status_t build_i(private_ike_p2p_t *this, message_t *message)
{
switch(message->get_exchange_type(message))
{
case IKE_SA_INIT:
{
peer_cfg_t *peer_cfg = this->ike_sa->get_peer_cfg(this->ike_sa);
if (peer_cfg->is_mediation(peer_cfg))
{
DBG2(DBG_IKE, "adding P2P_MEDIATION");
message->add_notify(message, FALSE, P2P_MEDIATION, chunk_empty);
}
else
{
return SUCCESS;
}
break;
}
case IKE_AUTH:
{
if (this->ike_sa->has_condition(this->ike_sa, COND_NAT_HERE))
{
endpoint_notify_t *endpoint = endpoint_notify_create_from_host(SERVER_REFLEXIVE, NULL, NULL);
message->add_payload(message, (payload_t*)endpoint->build_notify(endpoint));
endpoint->destroy(endpoint);
}
break;
}
case P2P_CONNECT:
{
id_payload_t *id_payload;
randomizer_t *rand = randomizer_create();
id_payload = id_payload_create_from_identification(ID_PEER, this->peer_id);
message->add_payload(message, (payload_t*)id_payload);
if (!this->response)
{
// only the initiator creates a session ID. the responder returns
// the session ID that it received from the initiator
if (rand->allocate_pseudo_random_bytes(rand,
P2P_SESSIONID_LEN, &this->session_id) != SUCCESS)
{
DBG1(DBG_IKE, "unable to generate session ID for P2P_CONNECT");
rand->destroy(rand);
return FAILED;
}
}
if (rand->allocate_pseudo_random_bytes(rand,
P2P_SESSIONKEY_LEN, &this->session_key) != SUCCESS)
{
DBG1(DBG_IKE, "unable to generate session key for P2P_CONNECT");
rand->destroy(rand);
return FAILED;
}
rand->destroy(rand);
message->add_notify(message, FALSE, P2P_SESSIONID, this->session_id);
message->add_notify(message, FALSE, P2P_SESSIONKEY, this->session_key);
if (this->response)
{
message->add_notify(message, FALSE, P2P_RESPONSE, chunk_empty);
}
else
{
// FIXME: should we make that configurable
message->add_notify(message, FALSE, P2P_CALLBACK, chunk_empty);
}
gather_and_add_endpoints(this, message);
break;
}
}
return NEED_MORE;
}
/**
* Implementation of task_t.process for responder
*/
static status_t process_r(private_ike_p2p_t *this, message_t *message)
{
switch(message->get_exchange_type(message))
{
case P2P_CONNECT:
{
id_payload_t *id_payload;
id_payload = (id_payload_t*)message->get_payload(message, ID_PEER);
if (!id_payload)
{
DBG1(DBG_IKE, "received P2P_CONNECT without ID_PEER payload, aborting");
break;
}
this->peer_id = id_payload->get_identification(id_payload);
process_payloads(this, message);
if (this->callback)
{
DBG1(DBG_IKE, "received P2P_CALLBACK for '%D'", this->peer_id);
break;
}
if (!this->session_id.ptr)
{
DBG1(DBG_IKE, "received P2P_CONNECT without P2P_SESSIONID notify, aborting");
this->invalid_syntax = TRUE;
break;
}
if (!this->session_key.ptr)
{
DBG1(DBG_IKE, "received P2P_CONNECT without P2P_SESSIONKEY notify, aborting");
this->invalid_syntax = TRUE;
break;
}
if (!this->remote_endpoints->get_count(this->remote_endpoints))
{
DBG1(DBG_IKE, "received P2P_CONNECT without any P2P_ENDPOINT payloads, aborting");
this->invalid_syntax = TRUE;
break;
}
DBG1(DBG_IKE, "received P2P_CONNECT");
break;
}
}
return NEED_MORE;
}
/**
* Implementation of task_t.build for responder
*/
static status_t build_r(private_ike_p2p_t *this, message_t *message)
{
switch(message->get_exchange_type(message))
{
case P2P_CONNECT:
{
if (this->invalid_syntax)
{
message->add_notify(message, TRUE, INVALID_SYNTAX, chunk_empty);
break;
}
if (this->callback)
{
charon->connect_manager->check_and_initiate(charon->connect_manager,
this->ike_sa->get_id(this->ike_sa),
this->ike_sa->get_my_id(this->ike_sa), this->peer_id);
return SUCCESS;
}
if (this->response)
{
// FIXME: handle result of set_responder_data
// as initiator, upon receiving a response from another peer,
// update the checklist and start sending checks
charon->connect_manager->set_responder_data(charon->connect_manager,
this->session_id, this->session_key, this->remote_endpoints);
}
else
{
// FIXME: handle result of set_initiator_data
// as responder, create a checklist with the initiator's data
charon->connect_manager->set_initiator_data(charon->connect_manager,
this->peer_id, this->ike_sa->get_my_id(this->ike_sa),
this->session_id, this->session_key, this->remote_endpoints,
FALSE);
if (this->ike_sa->respond(this->ike_sa, this->peer_id,
this->session_id) != SUCCESS)
{
return FAILED;
}
}
break;
}
}
return SUCCESS;
}
/**
* Implementation of task_t.process for initiator
*/
static status_t process_i(private_ike_p2p_t *this, message_t *message)
{
switch(message->get_exchange_type(message))
{
case IKE_SA_INIT:
{
process_payloads(this, message);
if (!this->mediation)
{
DBG1(DBG_IKE, "server did not return a P2P_MEDIATION, aborting");
return FAILED;
}
return NEED_MORE;
}
case IKE_AUTH:
{
process_payloads(this, message);
//FIXME: we should update the server reflexive endpoint somehow, if mobike notices a change
endpoint_notify_t *reflexive;
if (this->remote_endpoints->get_first(this->remote_endpoints, (void**)&reflexive) == SUCCESS &&
reflexive->get_type(reflexive) == SERVER_REFLEXIVE)
{//FIXME: should we accept this endpoint even if we did not send a request?
host_t *endpoint = reflexive->get_host(reflexive);
DBG2(DBG_IKE, "received server reflexive endpoint %#H", endpoint);
this->ike_sa->set_server_reflexive_host(this->ike_sa, endpoint->clone(endpoint));
}
// FIXME: what if it failed? e.g. AUTH failure
SIG(CHILD_UP_SUCCESS, "established mediation connection without CHILD_SA successfully");
break;
}
case P2P_CONNECT:
{
process_payloads(this, message);
if (this->failed)
{
DBG1(DBG_IKE, "peer '%D' is not online", this->peer_id);
// FIXME: notify the mediated connection (job?)
// FIXME: probably delete the created checklist, at least as responder
}
else
{
if (this->response)
{
// FIXME: handle result of set_responder_data
// as responder, we update the checklist and start sending checks
charon->connect_manager->set_responder_data(charon->connect_manager,
this->session_id, this->session_key, this->local_endpoints);
}
else
{
// FIXME: handle result of set_initiator_data
// as initiator, we create a checklist and set the initiator's data
charon->connect_manager->set_initiator_data(charon->connect_manager,
this->ike_sa->get_my_id(this->ike_sa), this->peer_id,
this->session_id, this->session_key, this->local_endpoints,
TRUE);
}
}
break;
}
}
return SUCCESS;
}
// -----------------------------------------------------------------------------
/**
* Implementation of task_t.process for initiator (mediation server)
*/
static status_t build_i_ms(private_ike_p2p_t *this, message_t *message)
{
switch(message->get_exchange_type(message))
{
case P2P_CONNECT:
{
id_payload_t *id_payload = id_payload_create_from_identification(ID_PEER, this->peer_id);
message->add_payload(message, (payload_t*)id_payload);
if (this->callback)
{
message->add_notify(message, FALSE, P2P_CALLBACK, chunk_empty);
}
else
{
notify_payload_t *notify;
if (this->response)
{
message->add_notify(message, FALSE, P2P_RESPONSE, chunk_empty);
}
message->add_notify(message, FALSE, P2P_SESSIONID, this->session_id);
message->add_notify(message, FALSE, P2P_SESSIONKEY, this->session_key);
add_endpoints_to_message(message, this->remote_endpoints);
}
break;
}
}
return NEED_MORE;
}
/**
* Implementation of task_t.process for responder (mediation server)
*/
static status_t process_r_ms(private_ike_p2p_t *this, message_t *message)
{
switch(message->get_exchange_type(message))
{
case IKE_SA_INIT:
{
process_payloads(this, message);
return this->mediation ? NEED_MORE : SUCCESS;
}
case IKE_AUTH:
{
process_payloads(this, message);
break;
}
case P2P_CONNECT:
{
id_payload_t *id_payload;
id_payload = (id_payload_t*)message->get_payload(message, ID_PEER);
if (!id_payload)
{
DBG1(DBG_IKE, "received P2P_CONNECT without ID_PEER payload, aborting");
this->invalid_syntax = TRUE;
break;
}
this->peer_id = id_payload->get_identification(id_payload);
process_payloads(this, message);
if (!this->session_id.ptr)
{
DBG1(DBG_IKE, "received P2P_CONNECT without P2P_SESSIONID notify, aborting");
this->invalid_syntax = TRUE;
break;
}
if (!this->session_key.ptr)
{
DBG1(DBG_IKE, "received P2P_CONNECT without P2P_SESSIONKEY notify, aborting");
this->invalid_syntax = TRUE;
break;
}
if (!this->remote_endpoints->get_count(this->remote_endpoints))
{
DBG1(DBG_IKE, "received P2P_CONNECT without any P2P_ENDPOINT payloads, aborting");
this->invalid_syntax = TRUE;
break;
}
break;
}
}
return NEED_MORE;
}
/**
* Implementation of task_t.build for responder (mediation server)
*/
static status_t build_r_ms(private_ike_p2p_t *this, message_t *message)
{
switch(message->get_exchange_type(message))
{
case IKE_SA_INIT:
{
message->add_notify(message, FALSE, P2P_MEDIATION, chunk_empty);
return NEED_MORE;
}
case IKE_AUTH:
{
endpoint_notify_t *endpoint;
if (this->remote_endpoints->get_first(this->remote_endpoints, (void**)&endpoint) == SUCCESS &&
endpoint->get_type(endpoint) == SERVER_REFLEXIVE)
{
host_t *host = this->ike_sa->get_other_host(this->ike_sa);
DBG2(DBG_IKE, "received request for a server reflexive endpoint "
"sending: %#H", host);
endpoint = endpoint_notify_create_from_host(SERVER_REFLEXIVE, host, NULL);
message->add_payload(message, (payload_t*)endpoint->build_notify(endpoint));
}
charon->mediation_manager->update_sa_id(charon->mediation_manager,
this->ike_sa->get_other_id(this->ike_sa),
this->ike_sa->get_id(this->ike_sa));
SIG(CHILD_UP_SUCCESS, "established mediation connection without CHILD_SA successfully");
break;
}
case P2P_CONNECT:
{
if (this->invalid_syntax)
{
message->add_notify(message, TRUE, INVALID_SYNTAX, chunk_empty);
break;
}
ike_sa_id_t *peer_sa;
if (this->callback)
{
peer_sa = charon->mediation_manager->check_and_register(charon->mediation_manager,
this->peer_id, this->ike_sa->get_other_id(this->ike_sa));
}
else
{
peer_sa = charon->mediation_manager->check(charon->mediation_manager,
this->peer_id);
}
if (!peer_sa)
{
// the peer is not online
message->add_notify(message, TRUE, P2P_CONNECT_FAILED, chunk_empty);
break;
}
job_t *job = (job_t*)mediation_job_create(this->peer_id,
this->ike_sa->get_other_id(this->ike_sa), this->session_id,
this->session_key, this->remote_endpoints, this->response);
charon->processor->queue_job(charon->processor, job);
break;
}
}
return SUCCESS;
}
/**
* Implementation of task_t.process for initiator (mediation server)
*/
static status_t process_i_ms(private_ike_p2p_t *this, message_t *message)
{
switch(message->get_exchange_type(message))
{
case P2P_CONNECT:
{
break;
}
}
return SUCCESS;
}
// -----------------------------------------------------------------------------
/**
* Implementation of ike_p2p.connect
*/
static void p2p_connect(private_ike_p2p_t *this, identification_t *peer_id)
{
this->peer_id = peer_id->clone(peer_id);
}
/**
* Implementation of ike_p2p.respond
*/
static void p2p_respond(private_ike_p2p_t *this, identification_t *peer_id,
chunk_t session_id)
{
this->peer_id = peer_id->clone(peer_id);
this->session_id = chunk_clone(session_id);
this->response = TRUE;
}
/**
* Implementation of ike_p2p.callback
*/
static void p2p_callback(private_ike_p2p_t *this, identification_t *peer_id)
{
this->peer_id = peer_id->clone(peer_id);
this->callback = TRUE;
}
/**
* Implementation of ike_p2p.relay
*/
static void relay(private_ike_p2p_t *this, identification_t *requester, chunk_t session_id,
chunk_t session_key, linked_list_t *endpoints, bool response)
{
this->peer_id = requester->clone(requester);
this->session_id = chunk_clone(session_id);
this->session_key = chunk_clone(session_key);
this->remote_endpoints = endpoints->clone_offset(endpoints, offsetof(endpoint_notify_t, clone));
this->response = response;
}
/**
* Implementation of task_t.get_type
*/
static task_type_t get_type(private_ike_p2p_t *this)
{
return IKE_P2P;
}
/**
* Implementation of task_t.migrate
*/
static void migrate(private_ike_p2p_t *this, ike_sa_t *ike_sa)
{
this->ike_sa = ike_sa;
}
/**
* Implementation of task_t.destroy
*/
static void destroy(private_ike_p2p_t *this)
{
DESTROY_IF(this->peer_id);
chunk_free(&this->session_id);
chunk_free(&this->session_key);
this->local_endpoints->destroy_offset(this->local_endpoints, offsetof(endpoint_notify_t, destroy));
this->remote_endpoints->destroy_offset(this->remote_endpoints, offsetof(endpoint_notify_t, destroy));
DESTROY_IF(this->mediated_cfg);
free(this);
}
/*
* Described in header.
*/
ike_p2p_t *ike_p2p_create(ike_sa_t *ike_sa, bool initiator)
{
private_ike_p2p_t *this = malloc_thing(private_ike_p2p_t);
this->public.task.get_type = (task_type_t(*)(task_t*))get_type;
this->public.task.migrate = (void(*)(task_t*,ike_sa_t*))migrate;
this->public.task.destroy = (void(*)(task_t*))destroy;
ike_sa_id_t *id = ike_sa->get_id(ike_sa);
if (id->is_initiator(id))
{
if (initiator)
{
this->public.task.build = (status_t(*)(task_t*,message_t*))build_i;
this->public.task.process = (status_t(*)(task_t*,message_t*))process_i;
}
else
{
this->public.task.build = (status_t(*)(task_t*,message_t*))build_r;
this->public.task.process = (status_t(*)(task_t*,message_t*))process_r;
}
}
else
{
// mediation server
if (initiator)
{
this->public.task.build = (status_t(*)(task_t*,message_t*))build_i_ms;
this->public.task.process = (status_t(*)(task_t*,message_t*))process_i_ms;
}
else
{
this->public.task.build = (status_t(*)(task_t*,message_t*))build_r_ms;
this->public.task.process = (status_t(*)(task_t*,message_t*))process_r_ms;
}
}
this->public.connect = (void(*)(ike_p2p_t*,identification_t*))p2p_connect;
this->public.respond = (void(*)(ike_p2p_t*,identification_t*,chunk_t))p2p_respond;
this->public.callback = (void(*)(ike_p2p_t*,identification_t*))p2p_callback;
this->public.relay = (void(*)(ike_p2p_t*,identification_t*,chunk_t,chunk_t,linked_list_t*,bool))relay;
this->ike_sa = ike_sa;
this->initiator = initiator;
this->peer_id = NULL;
this->session_id = chunk_empty;
this->session_key = chunk_empty;
this->local_endpoints = linked_list_create();
this->remote_endpoints = linked_list_create();
this->mediation = FALSE;
this->response = FALSE;
this->callback = FALSE;
this->failed = FALSE;
this->invalid_syntax = FALSE;
this->mediated_cfg = NULL;
return &this->public;
}
+110
View File
@@ -0,0 +1,110 @@
/**
* @file ike_p2p.h
*
* @brief Interface ike_p2p_t.
*
*/
/*
* Copyright (C) 2007 Tobias Brunner
* Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#ifndef IKE_P2P_H_
#define IKE_P2P_H_
typedef struct ike_p2p_t ike_p2p_t;
#include <library.h>
#include <sa/ike_sa.h>
#include <sa/tasks/task.h>
/**
* @brief Task of type IKE_P2P, detects and handles P2P-NAT-T extensions.
*
* This tasks handles the P2P_MEDIATION notify exchange to setup a mediation
* connection, allows to initiate mediated connections using P2P_CONNECT
* exchanges and to request reflexive addresses from the mediation server using
* P2P_ENDPOINT notifies.
*
* @note This task has to be activated before the IKE_AUTH task, because that
* task generates the IKE_SA_INIT message so that no more payloads can be added
* to it afterwards.
*
* @b Constructors:
* - ike_p2p_create()
*
* @ingroup tasks
*/
struct ike_p2p_t {
/**
* Implements the task_t interface
*/
task_t task;
/**
* @brief Initiates a connection with another peer (i.e. sends a P2P_CONNECT
* to the mediation server)
*
* @param this object
* @param peer_id ID of the other peer (gets cloned)
*/
void (*connect)(ike_p2p_t *this, identification_t *peer_id);
/**
* @brief Responds to a P2P_CONNECT from another peer (i.e. sends a P2P_CONNECT
* to the mediation server)
*
* @param this object
* @param peer_id ID of the other peer (gets cloned)
* @param session_id the session ID as provided by the initiator (gets cloned)
*/
void (*respond)(ike_p2p_t *this, identification_t *peer_id, chunk_t session_id);
/**
* @brief Sends a P2P_CALLBACK to a peer that previously requested another peer.
*
* @param this object
* @param peer_id ID of the other peer (gets cloned)
*/
void (*callback)(ike_p2p_t *this, identification_t *peer_id);
/**
* @brief Relays data to another peer (i.e. sends a P2P_CONNECT to the peer)
*
* Data gets cloned.
*
* @param this object
* @param requester ID of the requesting peer
* @param session_id content of the P2P_SESSIONID notify
* @param session_key content of the P2P_SESSIONKEY notify
* @param endpoints endpoints
* @param response TRUE if this is a response
*/
void (*relay)(ike_p2p_t *this, identification_t *requester, chunk_t session_id,
chunk_t session_key, linked_list_t *endpoints, bool response);
};
/**
* @brief Create a new ike_p2p task.
*
* @param ike_sa IKE_SA this task works for
* @param initiator TRUE if taks is initiated by us
* @return ike_p2p task to handle by the task_manager
*/
ike_p2p_t *ike_p2p_create(ike_sa_t *ike_sa, bool initiator);
#endif /*IKE_P2P_H_*/
+4
View File
@@ -6,6 +6,7 @@
*/
/*
* Copyright (C) 2007 Tobias Brunner
* Copyright (C) 2007 Martin Willi
* Hochschule fuer Technik Rapperswil
*
@@ -33,6 +34,9 @@ ENUM(task_type_names, IKE_INIT, CHILD_REKEY,
"IKE_REAUTH",
"IKE_DELETE",
"IKE_DPD",
#ifdef P2P
"IKE_P2P",
#endif /* P2P */
"CHILD_CREATE",
"CHILD_DELETE",
"CHILD_REKEY",
+5
View File
@@ -6,6 +6,7 @@
*/
/*
* Copyright (C) 2007 Tobias Brunner
* Copyright (C) 2006 Martin Willi
* Hochschule fuer Technik Rapperswil
*
@@ -56,6 +57,10 @@ enum task_type_t {
IKE_DELETE,
/** liveness check */
IKE_DPD,
#ifdef P2P
/** handle P2P-NAT-T stuff */
IKE_P2P,
#endif /* P2P */
/** establish a CHILD_SA within an IKE_SA */
CHILD_CREATE,
/** delete an established CHILD_SA */