Apply a mutual EAP auth_cfg not before the EAP method completes
This commit is contained in:
@@ -667,6 +667,16 @@ METHOD(authenticator_t, build_client, status_t,
|
|||||||
METHOD(authenticator_t, is_mutual, bool,
|
METHOD(authenticator_t, is_mutual, bool,
|
||||||
private_eap_authenticator_t *this)
|
private_eap_authenticator_t *this)
|
||||||
{
|
{
|
||||||
|
if (this->method)
|
||||||
|
{
|
||||||
|
u_int32_t vendor;
|
||||||
|
|
||||||
|
if (this->method->get_type(this->method, &vendor) != EAP_IDENTITY ||
|
||||||
|
vendor != 0)
|
||||||
|
{
|
||||||
|
return this->method->is_mutual(this->method);
|
||||||
|
}
|
||||||
|
}
|
||||||
/* we don't know yet, but insist on it after EAP is complete */
|
/* we don't know yet, but insist on it after EAP is complete */
|
||||||
this->require_mutual = TRUE;
|
this->require_mutual = TRUE;
|
||||||
return TRUE;
|
return TRUE;
|
||||||
|
|||||||
@@ -980,7 +980,10 @@ METHOD(task_t, process_i, status_t,
|
|||||||
goto peer_auth_failed;
|
goto peer_auth_failed;
|
||||||
}
|
}
|
||||||
|
|
||||||
apply_auth_cfg(this, FALSE);
|
if (!mutual_eap)
|
||||||
|
{
|
||||||
|
apply_auth_cfg(this, FALSE);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (this->my_auth)
|
if (this->my_auth)
|
||||||
@@ -989,6 +992,10 @@ METHOD(task_t, process_i, status_t,
|
|||||||
{
|
{
|
||||||
case SUCCESS:
|
case SUCCESS:
|
||||||
apply_auth_cfg(this, TRUE);
|
apply_auth_cfg(this, TRUE);
|
||||||
|
if (this->my_auth->is_mutual(this->my_auth))
|
||||||
|
{
|
||||||
|
apply_auth_cfg(this, FALSE);
|
||||||
|
}
|
||||||
this->my_auth->destroy(this->my_auth);
|
this->my_auth->destroy(this->my_auth);
|
||||||
this->my_auth = NULL;
|
this->my_auth = NULL;
|
||||||
this->do_another_auth = do_another_auth(this);
|
this->do_another_auth = do_another_auth(this);
|
||||||
|
|||||||
Reference in New Issue
Block a user