Apply a mutual EAP auth_cfg not before the EAP method completes

This commit is contained in:
Martin Willi
2013-02-26 13:15:27 +01:00
parent cc787697b8
commit d8a94c18c6
2 changed files with 18 additions and 1 deletions
@@ -667,6 +667,16 @@ METHOD(authenticator_t, build_client, status_t,
METHOD(authenticator_t, is_mutual, bool,
private_eap_authenticator_t *this)
{
if (this->method)
{
u_int32_t vendor;
if (this->method->get_type(this->method, &vendor) != EAP_IDENTITY ||
vendor != 0)
{
return this->method->is_mutual(this->method);
}
}
/* we don't know yet, but insist on it after EAP is complete */
this->require_mutual = TRUE;
return TRUE;
+8 -1
View File
@@ -980,7 +980,10 @@ METHOD(task_t, process_i, status_t,
goto peer_auth_failed;
}
apply_auth_cfg(this, FALSE);
if (!mutual_eap)
{
apply_auth_cfg(this, FALSE);
}
}
if (this->my_auth)
@@ -989,6 +992,10 @@ METHOD(task_t, process_i, status_t,
{
case SUCCESS:
apply_auth_cfg(this, TRUE);
if (this->my_auth->is_mutual(this->my_auth))
{
apply_auth_cfg(this, FALSE);
}
this->my_auth->destroy(this->my_auth);
this->my_auth = NULL;
this->do_another_auth = do_another_auth(this);