pubkey-authenticator: Avoid conflict with config switch based on EAP-Identity

The referenced commit ignored that INVALID_ARG was returned by this
authenticator if an unsupported signature scheme is encountered.  This
caused a crash in find_alternative_eap_cfg() as no EAP identity is
stored in the current auth config.

Since we don't distinguish the situation outside of the authenticator,
we can just return FAILED.

Closes strongswan/strongswan#2979

Fixes: 2f2e4abe3c ("ikev2: Add support to switch peer configs based on EAP-Identities")
This commit is contained in:
Tobias Brunner
2026-01-28 14:16:23 +01:00
parent 353bb42937
commit e73af66f4a
@@ -631,7 +631,7 @@ METHOD(authenticator_t, process, status_t,
DBG1(DBG_IKE, "%N authentication %s", auth_method_names,
auth_method, reason);
signature_params_destroy(params);
return INVALID_ARG;
return FAILED;
}
id = this->ike_sa->get_other_id(this->ike_sa);
if (!get_auth_octets_scheme(this, TRUE, id, this->ppk, &octets, &params))