Install fallback drop policies to avoid transmitting unencrypted packets.
During the update of a CHILD_SA (e.g. caused by MOBIKE) the old policy is first uninstalled and then the new one is installed. In the short time in between, where no policy is available in the kernel, unencrypted packets could have been transmitted.
This commit is contained in:
@@ -715,6 +715,17 @@ METHOD(child_sa_t, add_policies, status_t,
|
||||
enumerator = create_policy_enumerator(this);
|
||||
while (enumerator->enumerate(enumerator, &my_ts, &other_ts))
|
||||
{
|
||||
/* install outbound drop policy to avoid packets leaving unencrypted
|
||||
* when updating policies */
|
||||
if (priority == POLICY_PRIORITY_DEFAULT)
|
||||
{
|
||||
status |= hydra->kernel_interface->add_policy(
|
||||
hydra->kernel_interface,
|
||||
this->my_addr, this->other_addr, my_ts, other_ts,
|
||||
POLICY_OUT, POLICY_DROP, &other_sa,
|
||||
this->mark_out, POLICY_PRIORITY_FALLBACK);
|
||||
}
|
||||
|
||||
/* install 3 policies: out, in and forward */
|
||||
status |= hydra->kernel_interface->add_policy(
|
||||
hydra->kernel_interface,
|
||||
@@ -963,6 +974,12 @@ METHOD(child_sa_t, destroy, void,
|
||||
other_ts, my_ts, POLICY_FWD, this->reqid,
|
||||
this->mark_in, priority);
|
||||
}
|
||||
if (priority == POLICY_PRIORITY_DEFAULT)
|
||||
{
|
||||
hydra->kernel_interface->del_policy(hydra->kernel_interface,
|
||||
my_ts, other_ts, POLICY_OUT, this->reqid,
|
||||
this->mark_out, POLICY_PRIORITY_FALLBACK);
|
||||
}
|
||||
}
|
||||
enumerator->destroy(enumerator);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user