static upper size limit for PA-TNC messages
This commit is contained in:
@@ -192,6 +192,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
{
|
{
|
||||||
bio_writer_t *writer;
|
bio_writer_t *writer;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
writer = bio_writer_create(PA_ERROR_HEADER_SIZE + PA_ERROR_MSG_INFO_SIZE);
|
writer = bio_writer_create(PA_ERROR_HEADER_SIZE + PA_ERROR_MSG_INFO_SIZE);
|
||||||
writer->write_uint8 (writer, PA_ERROR_RESERVED);
|
writer->write_uint8 (writer, PA_ERROR_RESERVED);
|
||||||
writer->write_uint24(writer, this->error_vendor_id);
|
writer->write_uint24(writer, this->error_vendor_id);
|
||||||
|
|||||||
@@ -125,6 +125,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
enumerator_t *enumerator;
|
enumerator_t *enumerator;
|
||||||
port_entry_t *entry;
|
port_entry_t *entry;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
writer = bio_writer_create(this->ports->get_count(this->ports) *
|
writer = bio_writer_create(this->ports->get_count(this->ports) *
|
||||||
PORT_FILTER_ENTRY_SIZE);
|
PORT_FILTER_ENTRY_SIZE);
|
||||||
|
|
||||||
|
|||||||
@@ -122,6 +122,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
bio_writer_t *writer;
|
bio_writer_t *writer;
|
||||||
chunk_t product_name;
|
chunk_t product_name;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
product_name = chunk_create(this->product_name, strlen(this->product_name));
|
product_name = chunk_create(this->product_name, strlen(this->product_name));
|
||||||
|
|
||||||
writer = bio_writer_create(PRODUCT_INFO_MIN_SIZE);
|
writer = bio_writer_create(PRODUCT_INFO_MIN_SIZE);
|
||||||
|
|||||||
+48
-25
@@ -47,6 +47,11 @@ struct private_imc_agent_t {
|
|||||||
*/
|
*/
|
||||||
TNC_MessageSubtype subtype;
|
TNC_MessageSubtype subtype;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Maximum PA-TNC Message size
|
||||||
|
*/
|
||||||
|
size_t max_msg_len;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* ID of IMC as assigned by TNCC
|
* ID of IMC as assigned by TNCC
|
||||||
*/
|
*/
|
||||||
@@ -461,6 +466,7 @@ METHOD(imc_agent_t, send_message, TNC_Result,
|
|||||||
pa_tnc_attr_t *attr;
|
pa_tnc_attr_t *attr;
|
||||||
pa_tnc_msg_t *pa_tnc_msg;
|
pa_tnc_msg_t *pa_tnc_msg;
|
||||||
chunk_t msg;
|
chunk_t msg;
|
||||||
|
enumerator_t *enumerator;
|
||||||
|
|
||||||
state = find_connection(this, connection_id);
|
state = find_connection(this, connection_id);
|
||||||
if (!state)
|
if (!state)
|
||||||
@@ -470,36 +476,52 @@ METHOD(imc_agent_t, send_message, TNC_Result,
|
|||||||
return TNC_RESULT_FATAL;
|
return TNC_RESULT_FATAL;
|
||||||
}
|
}
|
||||||
|
|
||||||
pa_tnc_msg = pa_tnc_msg_create();
|
while (attr_list->get_count(attr_list))
|
||||||
|
|
||||||
while (attr_list->remove_first(attr_list, (void**)&attr) == SUCCESS)
|
|
||||||
{
|
{
|
||||||
pa_tnc_msg->add_attribute(pa_tnc_msg, attr);
|
pa_tnc_msg = pa_tnc_msg_create(this->max_msg_len);
|
||||||
}
|
|
||||||
pa_tnc_msg->build(pa_tnc_msg);
|
|
||||||
msg = pa_tnc_msg->get_encoding(pa_tnc_msg);
|
|
||||||
|
|
||||||
if (state->has_long(state) && this->send_message_long)
|
enumerator = attr_list->create_enumerator(attr_list);
|
||||||
{
|
while (enumerator->enumerate(enumerator, &attr))
|
||||||
if (!src_imc_id)
|
|
||||||
{
|
{
|
||||||
src_imc_id = this->id;
|
if (!pa_tnc_msg->add_attribute(pa_tnc_msg, attr))
|
||||||
|
{
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
attr_list->remove_at(attr_list, enumerator);
|
||||||
}
|
}
|
||||||
msg_flags = excl ? TNC_MESSAGE_FLAGS_EXCLUSIVE : 0;
|
enumerator->destroy(enumerator);
|
||||||
|
|
||||||
result = this->send_message_long(src_imc_id, connection_id, msg_flags,
|
/* build and send the PA-TNC message via the IF-IMC interface */
|
||||||
msg.ptr, msg.len, this->vendor_id,
|
pa_tnc_msg->build(pa_tnc_msg);
|
||||||
this->subtype, dst_imv_id);
|
msg = pa_tnc_msg->get_encoding(pa_tnc_msg);
|
||||||
|
|
||||||
|
if (state->has_long(state) && this->send_message_long)
|
||||||
|
{
|
||||||
|
if (!src_imc_id)
|
||||||
|
{
|
||||||
|
src_imc_id = this->id;
|
||||||
|
}
|
||||||
|
msg_flags = excl ? TNC_MESSAGE_FLAGS_EXCLUSIVE : 0;
|
||||||
|
|
||||||
|
result = this->send_message_long(src_imc_id, connection_id,
|
||||||
|
msg_flags, msg.ptr, msg.len, this->vendor_id,
|
||||||
|
this->subtype, dst_imv_id);
|
||||||
|
}
|
||||||
|
else if (this->send_message)
|
||||||
|
{
|
||||||
|
type = (this->vendor_id << 8) | this->subtype;
|
||||||
|
|
||||||
|
result = this->send_message(this->id, connection_id, msg.ptr,
|
||||||
|
msg.len, type);
|
||||||
|
}
|
||||||
|
|
||||||
|
pa_tnc_msg->destroy(pa_tnc_msg);
|
||||||
|
|
||||||
|
if (result != TNC_RESULT_SUCCESS)
|
||||||
|
{
|
||||||
|
break;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
else if (this->send_message)
|
|
||||||
{
|
|
||||||
type = (this->vendor_id << 8) | this->subtype;
|
|
||||||
|
|
||||||
result = this->send_message(this->id, connection_id, msg.ptr, msg.len,
|
|
||||||
type);
|
|
||||||
}
|
|
||||||
pa_tnc_msg->destroy(pa_tnc_msg);
|
|
||||||
|
|
||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -549,7 +571,7 @@ METHOD(imc_agent_t, receive_message, TNC_Result,
|
|||||||
break;
|
break;
|
||||||
case VERIFY_ERROR:
|
case VERIFY_ERROR:
|
||||||
/* build error message */
|
/* build error message */
|
||||||
error_msg = pa_tnc_msg_create();
|
error_msg = pa_tnc_msg_create(this->max_msg_len);
|
||||||
enumerator = pa_msg->create_error_enumerator(pa_msg);
|
enumerator = pa_msg->create_error_enumerator(pa_msg);
|
||||||
while (enumerator->enumerate(enumerator, &error_attr))
|
while (enumerator->enumerate(enumerator, &error_attr))
|
||||||
{
|
{
|
||||||
@@ -693,6 +715,7 @@ imc_agent_t *imc_agent_create(const char *name,
|
|||||||
.name = name,
|
.name = name,
|
||||||
.vendor_id = vendor_id,
|
.vendor_id = vendor_id,
|
||||||
.subtype = subtype,
|
.subtype = subtype,
|
||||||
|
.max_msg_len = 65490,
|
||||||
.id = id,
|
.id = id,
|
||||||
.additional_ids = linked_list_create(),
|
.additional_ids = linked_list_create(),
|
||||||
.connections = linked_list_create(),
|
.connections = linked_list_create(),
|
||||||
|
|||||||
+50
-26
@@ -47,6 +47,11 @@ struct private_imv_agent_t {
|
|||||||
*/
|
*/
|
||||||
TNC_MessageSubtype subtype;
|
TNC_MessageSubtype subtype;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Maximum PA-TNC Message size
|
||||||
|
*/
|
||||||
|
size_t max_msg_len;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* ID of IMV as assigned by TNCS
|
* ID of IMV as assigned by TNCS
|
||||||
*/
|
*/
|
||||||
@@ -471,13 +476,14 @@ METHOD(imv_agent_t, send_message, TNC_Result,
|
|||||||
private_imv_agent_t *this, TNC_ConnectionID connection_id, bool excl,
|
private_imv_agent_t *this, TNC_ConnectionID connection_id, bool excl,
|
||||||
TNC_UInt32 src_imv_id, TNC_UInt32 dst_imc_id, linked_list_t *attr_list)
|
TNC_UInt32 src_imv_id, TNC_UInt32 dst_imc_id, linked_list_t *attr_list)
|
||||||
{
|
{
|
||||||
TNC_Result result = TNC_RESULT_FATAL;
|
|
||||||
TNC_MessageType type;
|
TNC_MessageType type;
|
||||||
TNC_UInt32 msg_flags;
|
TNC_UInt32 msg_flags;
|
||||||
|
TNC_Result result = TNC_RESULT_FATAL;
|
||||||
imv_state_t *state;
|
imv_state_t *state;
|
||||||
pa_tnc_attr_t *attr;
|
pa_tnc_attr_t *attr;
|
||||||
pa_tnc_msg_t *pa_tnc_msg;
|
pa_tnc_msg_t *pa_tnc_msg;
|
||||||
chunk_t msg;
|
chunk_t msg;
|
||||||
|
enumerator_t *enumerator;
|
||||||
|
|
||||||
state = find_connection(this, connection_id);
|
state = find_connection(this, connection_id);
|
||||||
if (!state)
|
if (!state)
|
||||||
@@ -487,36 +493,53 @@ METHOD(imv_agent_t, send_message, TNC_Result,
|
|||||||
return TNC_RESULT_FATAL;
|
return TNC_RESULT_FATAL;
|
||||||
}
|
}
|
||||||
|
|
||||||
pa_tnc_msg = pa_tnc_msg_create();
|
pa_tnc_msg = pa_tnc_msg_create(this->max_msg_len);
|
||||||
|
while (attr_list->get_count(attr_list))
|
||||||
while (attr_list->remove_first(attr_list, (void**)&attr) == SUCCESS)
|
|
||||||
{
|
{
|
||||||
pa_tnc_msg->add_attribute(pa_tnc_msg, attr);
|
pa_tnc_msg = pa_tnc_msg_create(this->max_msg_len);
|
||||||
}
|
|
||||||
pa_tnc_msg->build(pa_tnc_msg);
|
|
||||||
msg = pa_tnc_msg->get_encoding(pa_tnc_msg);
|
|
||||||
|
|
||||||
if (state->has_long(state) && this->send_message_long)
|
enumerator = attr_list->create_enumerator(attr_list);
|
||||||
{
|
while (enumerator->enumerate(enumerator, &attr))
|
||||||
if (!src_imv_id)
|
|
||||||
{
|
{
|
||||||
src_imv_id = this->id;
|
if (!pa_tnc_msg->add_attribute(pa_tnc_msg, attr))
|
||||||
|
{
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
attr_list->remove_at(attr_list, enumerator);
|
||||||
}
|
}
|
||||||
msg_flags = excl ? TNC_MESSAGE_FLAGS_EXCLUSIVE : 0;
|
enumerator->destroy(enumerator);
|
||||||
|
|
||||||
result = this->send_message_long(src_imv_id, connection_id, msg_flags,
|
/* build and send the PA-TNC message via the IF-IMV interface */
|
||||||
msg.ptr, msg.len, this->vendor_id,
|
pa_tnc_msg->build(pa_tnc_msg);
|
||||||
this->subtype, dst_imc_id);
|
msg = pa_tnc_msg->get_encoding(pa_tnc_msg);
|
||||||
|
|
||||||
|
if (state->has_long(state) && this->send_message_long)
|
||||||
|
{
|
||||||
|
if (!src_imv_id)
|
||||||
|
{
|
||||||
|
src_imv_id = this->id;
|
||||||
|
}
|
||||||
|
msg_flags = excl ? TNC_MESSAGE_FLAGS_EXCLUSIVE : 0;
|
||||||
|
|
||||||
|
result = this->send_message_long(src_imv_id, connection_id,
|
||||||
|
msg_flags, msg.ptr, msg.len, this->vendor_id,
|
||||||
|
this->subtype, dst_imc_id);
|
||||||
|
}
|
||||||
|
else if (this->send_message)
|
||||||
|
{
|
||||||
|
type = (this->vendor_id << 8) | this->subtype;
|
||||||
|
|
||||||
|
result = this->send_message(this->id, connection_id, msg.ptr,
|
||||||
|
msg.len, type);
|
||||||
|
}
|
||||||
|
|
||||||
|
pa_tnc_msg->destroy(pa_tnc_msg);
|
||||||
|
|
||||||
|
if (result != TNC_RESULT_SUCCESS)
|
||||||
|
{
|
||||||
|
break;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
else if (this->send_message)
|
|
||||||
{
|
|
||||||
type = (this->vendor_id << 8) | this->subtype;
|
|
||||||
|
|
||||||
result = this->send_message(this->id, connection_id, msg.ptr, msg.len,
|
|
||||||
type);
|
|
||||||
}
|
|
||||||
pa_tnc_msg->destroy(pa_tnc_msg);
|
|
||||||
|
|
||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -585,7 +608,7 @@ METHOD(imv_agent_t, receive_message, TNC_Result,
|
|||||||
break;
|
break;
|
||||||
case VERIFY_ERROR:
|
case VERIFY_ERROR:
|
||||||
/* build error message */
|
/* build error message */
|
||||||
error_msg = pa_tnc_msg_create();
|
error_msg = pa_tnc_msg_create(this->max_msg_len);
|
||||||
enumerator = pa_msg->create_error_enumerator(pa_msg);
|
enumerator = pa_msg->create_error_enumerator(pa_msg);
|
||||||
while (enumerator->enumerate(enumerator, &error_attr))
|
while (enumerator->enumerate(enumerator, &error_attr))
|
||||||
{
|
{
|
||||||
@@ -791,6 +814,7 @@ imv_agent_t *imv_agent_create(const char *name,
|
|||||||
.name = name,
|
.name = name,
|
||||||
.vendor_id = vendor_id,
|
.vendor_id = vendor_id,
|
||||||
.subtype = subtype,
|
.subtype = subtype,
|
||||||
|
.max_msg_len = 65490,
|
||||||
.id = id,
|
.id = id,
|
||||||
.additional_ids = linked_list_create(),
|
.additional_ids = linked_list_create(),
|
||||||
.connections = linked_list_create(),
|
.connections = linked_list_create(),
|
||||||
|
|||||||
@@ -95,6 +95,10 @@ METHOD(pa_tnc_attr_t, set_noskip_flag,void,
|
|||||||
METHOD(pa_tnc_attr_t, build, void,
|
METHOD(pa_tnc_attr_t, build, void,
|
||||||
private_ita_attr_command_t *this)
|
private_ita_attr_command_t *this)
|
||||||
{
|
{
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
this->value = chunk_create(this->command, strlen(this->command));
|
this->value = chunk_create(this->command, strlen(this->command));
|
||||||
this->value = chunk_clone(this->value);
|
this->value = chunk_clone(this->value);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -95,6 +95,10 @@ METHOD(pa_tnc_attr_t, set_noskip_flag,void,
|
|||||||
METHOD(pa_tnc_attr_t, build, void,
|
METHOD(pa_tnc_attr_t, build, void,
|
||||||
private_ita_attr_dummy_t *this)
|
private_ita_attr_dummy_t *this)
|
||||||
{
|
{
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
this->value = chunk_alloc(this->size);
|
this->value = chunk_alloc(this->size);
|
||||||
memset(this->value.ptr, 0xdd, this->value.len);
|
memset(this->value.ptr, 0xdd, this->value.len);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -89,6 +89,16 @@ struct private_pa_tnc_msg_t {
|
|||||||
*/
|
*/
|
||||||
u_int32_t identifier;
|
u_int32_t identifier;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Current PA-TNC Message size
|
||||||
|
*/
|
||||||
|
size_t msg_len;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Maximum PA-TNC Message size
|
||||||
|
*/
|
||||||
|
size_t max_msg_len;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Encoded message
|
* Encoded message
|
||||||
*/
|
*/
|
||||||
@@ -101,10 +111,25 @@ METHOD(pa_tnc_msg_t, get_encoding, chunk_t,
|
|||||||
return this->encoding;
|
return this->encoding;
|
||||||
}
|
}
|
||||||
|
|
||||||
METHOD(pa_tnc_msg_t, add_attribute, void,
|
METHOD(pa_tnc_msg_t, add_attribute, bool,
|
||||||
private_pa_tnc_msg_t *this, pa_tnc_attr_t *attr)
|
private_pa_tnc_msg_t *this, pa_tnc_attr_t *attr)
|
||||||
{
|
{
|
||||||
|
chunk_t attr_value;
|
||||||
|
size_t attr_len;
|
||||||
|
|
||||||
|
attr->build(attr);
|
||||||
|
attr_value = attr->get_value(attr);
|
||||||
|
attr_len = PA_TNC_ATTR_HEADER_SIZE + attr_value.len;
|
||||||
|
|
||||||
|
if (this->msg_len + attr_len > this->max_msg_len)
|
||||||
|
{
|
||||||
|
/* attribute just does not fit into this message */
|
||||||
|
return FALSE;
|
||||||
|
}
|
||||||
|
this->msg_len += attr_len;
|
||||||
|
|
||||||
this->attributes->insert_last(this->attributes, attr);
|
this->attributes->insert_last(this->attributes, attr);
|
||||||
|
return TRUE;
|
||||||
}
|
}
|
||||||
|
|
||||||
METHOD(pa_tnc_msg_t, build, void,
|
METHOD(pa_tnc_msg_t, build, void,
|
||||||
@@ -127,16 +152,15 @@ METHOD(pa_tnc_msg_t, build, void,
|
|||||||
DBG2(DBG_TNC, "creating PA-TNC message with ID 0x%08x", this->identifier);
|
DBG2(DBG_TNC, "creating PA-TNC message with ID 0x%08x", this->identifier);
|
||||||
|
|
||||||
/* build message header */
|
/* build message header */
|
||||||
writer = bio_writer_create(PA_TNC_HEADER_SIZE);
|
writer = bio_writer_create(this->msg_len);
|
||||||
writer->write_uint8 (writer, PA_TNC_VERSION);
|
writer->write_uint8 (writer, PA_TNC_VERSION);
|
||||||
writer->write_uint24(writer, PA_TNC_RESERVED);
|
writer->write_uint24(writer, PA_TNC_RESERVED);
|
||||||
writer->write_uint32(writer, this->identifier);
|
writer->write_uint32(writer, this->identifier);
|
||||||
|
|
||||||
/* build and append encoding of PA-TNC attributes */
|
/* append encoded value of PA-TNC attributes */
|
||||||
enumerator = this->attributes->create_enumerator(this->attributes);
|
enumerator = this->attributes->create_enumerator(this->attributes);
|
||||||
while (enumerator->enumerate(enumerator, &attr))
|
while (enumerator->enumerate(enumerator, &attr))
|
||||||
{
|
{
|
||||||
attr->build(attr);
|
|
||||||
vendor_id = attr->get_vendor_id(attr);
|
vendor_id = attr->get_vendor_id(attr);
|
||||||
type = attr->get_type(attr);
|
type = attr->get_type(attr);
|
||||||
value = attr->get_value(attr);
|
value = attr->get_value(attr);
|
||||||
@@ -292,7 +316,7 @@ METHOD(pa_tnc_msg_t, process, status_t,
|
|||||||
offset + PA_TNC_ATTR_HEADER_SIZE + attr_offset);
|
offset + PA_TNC_ATTR_HEADER_SIZE + attr_offset);
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
add_attribute(this, attr);
|
this->attributes->insert_last(this->attributes, attr);
|
||||||
offset += length;
|
offset += length;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -391,6 +415,33 @@ METHOD(pa_tnc_msg_t, destroy, void,
|
|||||||
free(this);
|
free(this);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* See header
|
||||||
|
*/
|
||||||
|
pa_tnc_msg_t *pa_tnc_msg_create(size_t max_msg_len)
|
||||||
|
{
|
||||||
|
private_pa_tnc_msg_t *this;
|
||||||
|
|
||||||
|
INIT(this,
|
||||||
|
.public = {
|
||||||
|
.get_encoding = _get_encoding,
|
||||||
|
.add_attribute = _add_attribute,
|
||||||
|
.build = _build,
|
||||||
|
.process = _process,
|
||||||
|
.process_ietf_std_errors = _process_ietf_std_errors,
|
||||||
|
.create_attribute_enumerator = _create_attribute_enumerator,
|
||||||
|
.create_error_enumerator = _create_error_enumerator,
|
||||||
|
.destroy = _destroy,
|
||||||
|
},
|
||||||
|
.attributes = linked_list_create(),
|
||||||
|
.errors = linked_list_create(),
|
||||||
|
.msg_len = PA_TNC_HEADER_SIZE,
|
||||||
|
.max_msg_len = max_msg_len,
|
||||||
|
);
|
||||||
|
|
||||||
|
return &this->public;
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* See header
|
* See header
|
||||||
*/
|
*/
|
||||||
@@ -417,11 +468,3 @@ pa_tnc_msg_t *pa_tnc_msg_create_from_data(chunk_t data)
|
|||||||
return &this->public;
|
return &this->public;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
|
||||||
* See header
|
|
||||||
*/
|
|
||||||
pa_tnc_msg_t *pa_tnc_msg_create(void)
|
|
||||||
{
|
|
||||||
return pa_tnc_msg_create_from_data(chunk_empty);
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|||||||
@@ -46,8 +46,9 @@ struct pa_tnc_msg_t {
|
|||||||
* Add a PA-TNC attribute
|
* Add a PA-TNC attribute
|
||||||
*
|
*
|
||||||
* @param attr PA-TNC attribute to be addedd
|
* @param attr PA-TNC attribute to be addedd
|
||||||
|
* @return TRUE if attribute fit into message and was added
|
||||||
*/
|
*/
|
||||||
void (*add_attribute)(pa_tnc_msg_t *this, pa_tnc_attr_t* attr);
|
bool (*add_attribute)(pa_tnc_msg_t *this, pa_tnc_attr_t* attr);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Build the PA-TNC message
|
* Build the PA-TNC message
|
||||||
@@ -91,7 +92,7 @@ struct pa_tnc_msg_t {
|
|||||||
/**
|
/**
|
||||||
* Create an empty PA-TNC message
|
* Create an empty PA-TNC message
|
||||||
*/
|
*/
|
||||||
pa_tnc_msg_t* pa_tnc_msg_create(void);
|
pa_tnc_msg_t* pa_tnc_msg_create(size_t max_msg_len);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Create an unprocessed PA-TNC message from received data
|
* Create an unprocessed PA-TNC message from received data
|
||||||
|
|||||||
@@ -108,7 +108,7 @@ static TNC_Result receive_message(TNC_IMVID imv_id,
|
|||||||
enumerator_t *enumerator;
|
enumerator_t *enumerator;
|
||||||
TNC_Result result;
|
TNC_Result result;
|
||||||
int rounds;
|
int rounds;
|
||||||
bool fatal_error, retry = FALSE;
|
bool fatal_error, received_command = FALSE, retry = FALSE;
|
||||||
|
|
||||||
if (!imv_test)
|
if (!imv_test)
|
||||||
{
|
{
|
||||||
@@ -154,6 +154,7 @@ static TNC_Result receive_message(TNC_IMVID imv_id,
|
|||||||
ita_attr_command_t *ita_attr;
|
ita_attr_command_t *ita_attr;
|
||||||
char *command;
|
char *command;
|
||||||
|
|
||||||
|
received_command = TRUE;
|
||||||
ita_attr = (ita_attr_command_t*)attr;
|
ita_attr = (ita_attr_command_t*)attr;
|
||||||
command = ita_attr->get_command(ita_attr);
|
command = ita_attr->get_command(ita_attr);
|
||||||
|
|
||||||
@@ -228,7 +229,9 @@ static TNC_Result receive_message(TNC_IMVID imv_id,
|
|||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
return imv_test->provide_recommendation(imv_test, connection_id);
|
return received_command ?
|
||||||
|
imv_test->provide_recommendation(imv_test, connection_id) :
|
||||||
|
TNC_RESULT_SUCCESS;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -117,6 +117,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
cred_encoding_type_t encoding_type = CERT_ASN1_DER;
|
cred_encoding_type_t encoding_type = CERT_ASN1_DER;
|
||||||
chunk_t aik_blob;
|
chunk_t aik_blob;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
if (this->aik->get_type(this->aik) == CERT_TRUSTED_PUBKEY)
|
if (this->aik->get_type(this->aik) == CERT_TRUSTED_PUBKEY)
|
||||||
{
|
{
|
||||||
flags |= PTS_AIK_FLAGS_NAKED_KEY;
|
flags |= PTS_AIK_FLAGS_NAKED_KEY;
|
||||||
|
|||||||
@@ -128,6 +128,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
{
|
{
|
||||||
bio_writer_t *writer;
|
bio_writer_t *writer;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
writer = bio_writer_create(PTS_DH_NONCE_FINISH_SIZE);
|
writer = bio_writer_create(PTS_DH_NONCE_FINISH_SIZE);
|
||||||
writer->write_uint8 (writer, PTS_DH_NONCE_FINISH_RESERVED);
|
writer->write_uint8 (writer, PTS_DH_NONCE_FINISH_RESERVED);
|
||||||
writer->write_uint8 (writer, this->initiator_nonce.len);
|
writer->write_uint8 (writer, this->initiator_nonce.len);
|
||||||
|
|||||||
@@ -119,6 +119,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
{
|
{
|
||||||
bio_writer_t *writer;
|
bio_writer_t *writer;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
writer = bio_writer_create(PTS_DH_NONCE_PARAMS_REQ_SIZE);
|
writer = bio_writer_create(PTS_DH_NONCE_PARAMS_REQ_SIZE);
|
||||||
writer->write_uint8 (writer, PTS_DH_NONCE_PARAMS_REQ_RESERVED);
|
writer->write_uint8 (writer, PTS_DH_NONCE_PARAMS_REQ_RESERVED);
|
||||||
writer->write_uint8 (writer, this->min_nonce_len);
|
writer->write_uint8 (writer, this->min_nonce_len);
|
||||||
|
|||||||
@@ -135,6 +135,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
{
|
{
|
||||||
bio_writer_t *writer;
|
bio_writer_t *writer;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
writer = bio_writer_create(PTS_DH_NONCE_PARAMS_RESP_SIZE);
|
writer = bio_writer_create(PTS_DH_NONCE_PARAMS_RESP_SIZE);
|
||||||
writer->write_uint24(writer, PTS_DH_NONCE_PARAMS_RESP_RESERVED);
|
writer->write_uint24(writer, PTS_DH_NONCE_PARAMS_RESP_RESERVED);
|
||||||
writer->write_uint8 (writer, this->responder_nonce.len);
|
writer->write_uint8 (writer, this->responder_nonce.len);
|
||||||
|
|||||||
@@ -135,6 +135,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
chunk_t measurement;
|
chunk_t measurement;
|
||||||
bool first = TRUE;
|
bool first = TRUE;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
number_of_files = this->measurements->get_file_count(this->measurements);
|
number_of_files = this->measurements->get_file_count(this->measurements);
|
||||||
request_id = this->measurements->get_request_id(this->measurements);
|
request_id = this->measurements->get_request_id(this->measurements);
|
||||||
|
|
||||||
|
|||||||
@@ -110,6 +110,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
{
|
{
|
||||||
bio_writer_t *writer;
|
bio_writer_t *writer;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
writer = bio_writer_create(PTS_GEN_ATTEST_EVID_SIZE);
|
writer = bio_writer_create(PTS_GEN_ATTEST_EVID_SIZE);
|
||||||
writer->write_uint32 (writer, PTS_GEN_ATTEST_EVID_RESERVED);
|
writer->write_uint32 (writer, PTS_GEN_ATTEST_EVID_RESERVED);
|
||||||
|
|
||||||
|
|||||||
@@ -107,6 +107,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
{
|
{
|
||||||
bio_writer_t *writer;
|
bio_writer_t *writer;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
writer = bio_writer_create(PTS_GET_AIK_SIZE);
|
writer = bio_writer_create(PTS_GET_AIK_SIZE);
|
||||||
writer->write_uint32 (writer, PTS_GET_AIK_RESERVED);
|
writer->write_uint32 (writer, PTS_GET_AIK_RESERVED);
|
||||||
|
|
||||||
|
|||||||
@@ -110,6 +110,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
{
|
{
|
||||||
bio_writer_t *writer;
|
bio_writer_t *writer;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
writer = bio_writer_create(PTS_GET_TPM_VER_INFO_SIZE);
|
writer = bio_writer_create(PTS_GET_TPM_VER_INFO_SIZE);
|
||||||
writer->write_uint32 (writer, PTS_GET_TPM_VER_INFO_RESERVED);
|
writer->write_uint32 (writer, PTS_GET_TPM_VER_INFO_RESERVED);
|
||||||
|
|
||||||
|
|||||||
@@ -113,6 +113,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
{
|
{
|
||||||
bio_writer_t *writer;
|
bio_writer_t *writer;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
writer = bio_writer_create(PTS_MEAS_ALGO_SIZE);
|
writer = bio_writer_create(PTS_MEAS_ALGO_SIZE);
|
||||||
writer->write_uint16(writer, PTS_MEAS_ALGO_RESERVED);
|
writer->write_uint16(writer, PTS_MEAS_ALGO_RESERVED);
|
||||||
writer->write_uint16(writer, this->algorithms);
|
writer->write_uint16(writer, this->algorithms);
|
||||||
|
|||||||
@@ -113,6 +113,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
{
|
{
|
||||||
bio_writer_t *writer;
|
bio_writer_t *writer;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
writer = bio_writer_create(PTS_PROTO_CAPS_SIZE);
|
writer = bio_writer_create(PTS_PROTO_CAPS_SIZE);
|
||||||
writer->write_uint16(writer, PTS_PROTO_CAPS_RESERVED);
|
writer->write_uint16(writer, PTS_PROTO_CAPS_RESERVED);
|
||||||
writer->write_uint16(writer, this->flags);
|
writer->write_uint16(writer, this->flags);
|
||||||
|
|||||||
@@ -136,6 +136,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
chunk_t pathname;
|
chunk_t pathname;
|
||||||
bio_writer_t *writer;
|
bio_writer_t *writer;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
if (this->directory_flag)
|
if (this->directory_flag)
|
||||||
{
|
{
|
||||||
flags |= DIRECTORY_CONTENTS_FLAG;
|
flags |= DIRECTORY_CONTENTS_FLAG;
|
||||||
|
|||||||
@@ -129,6 +129,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
chunk_t pathname;
|
chunk_t pathname;
|
||||||
bio_writer_t *writer;
|
bio_writer_t *writer;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
if (this->directory_flag)
|
if (this->directory_flag)
|
||||||
{
|
{
|
||||||
flags |= DIRECTORY_CONTENTS_FLAG;
|
flags |= DIRECTORY_CONTENTS_FLAG;
|
||||||
|
|||||||
@@ -177,6 +177,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
enumerator_t *enumerator;
|
enumerator_t *enumerator;
|
||||||
entry_t *entry;
|
entry_t *entry;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
writer = bio_writer_create(PTS_REQ_FUNC_COMP_EVID_SIZE);
|
writer = bio_writer_create(PTS_REQ_FUNC_COMP_EVID_SIZE);
|
||||||
|
|
||||||
enumerator = this->list->create_enumerator(this->list);
|
enumerator = this->list->create_enumerator(this->list);
|
||||||
|
|||||||
@@ -195,6 +195,11 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
time_t measurement_time;
|
time_t measurement_time;
|
||||||
chunk_t measurement, utc_time, pcr_before, pcr_after, policy_uri;
|
chunk_t measurement, utc_time, pcr_before, pcr_after, policy_uri;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
/* Extract parameters from comp_evidence_t object */
|
/* Extract parameters from comp_evidence_t object */
|
||||||
name = this->evidence->get_comp_func_name(this->evidence,
|
name = this->evidence->get_comp_func_name(this->evidence,
|
||||||
&depth);
|
&depth);
|
||||||
|
|||||||
@@ -169,6 +169,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
bio_writer_t *writer;
|
bio_writer_t *writer;
|
||||||
u_int8_t flags;
|
u_int8_t flags;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
flags = this->flags & PTS_SIMPLE_EVID_FINAL_FLAG_MASK;
|
flags = this->flags & PTS_SIMPLE_EVID_FINAL_FLAG_MASK;
|
||||||
|
|
||||||
if (this->has_evid_sig)
|
if (this->has_evid_sig)
|
||||||
|
|||||||
@@ -114,6 +114,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
{
|
{
|
||||||
bio_writer_t *writer;
|
bio_writer_t *writer;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
writer = bio_writer_create(PTS_TPM_VER_INFO_SIZE);
|
writer = bio_writer_create(PTS_TPM_VER_INFO_SIZE);
|
||||||
writer->write_data(writer, this->tpm_version_info);
|
writer->write_data(writer, this->tpm_version_info);
|
||||||
|
|
||||||
|
|||||||
@@ -148,6 +148,10 @@ METHOD(pa_tnc_attr_t, build, void,
|
|||||||
pts_file_metadata_t *entry;
|
pts_file_metadata_t *entry;
|
||||||
u_int64_t number_of_files;
|
u_int64_t number_of_files;
|
||||||
|
|
||||||
|
if (this->value.ptr)
|
||||||
|
{
|
||||||
|
return;
|
||||||
|
}
|
||||||
number_of_files = this->metadata->get_file_count(this->metadata);
|
number_of_files = this->metadata->get_file_count(this->metadata);
|
||||||
writer = bio_writer_create(PTS_FILE_META_SIZE);
|
writer = bio_writer_create(PTS_FILE_META_SIZE);
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user