ikev2: Don't destroy the SA if an IKE_SA_INIT with unexpected MID is received

This reverts 8f727d8007 ("Clean up IKE_SA state if IKE_SA_INIT request
does not have message ID 0") because it allowed to close any IKE_SA by
sending an IKE_SA_INIT with an unexpected MID and both SPIs set to those
of that SA.

The next commit will prevent SAs from getting created for IKE_SA_INIT messages
with invalid MID.

Fixes #816.
This commit is contained in:
Tobias Brunner
2015-03-04 13:47:53 +01:00
parent 1a31fe5580
commit eb25190629
-4
View File
@@ -1355,10 +1355,6 @@ METHOD(task_manager_t, process_message, status_t,
{
DBG1(DBG_IKE, "received message ID %d, expected %d. Ignored",
mid, this->responding.mid);
if (msg->get_exchange_type(msg) == IKE_SA_INIT)
{ /* clean up IKE_SA state if IKE_SA_INIT has invalid msg ID */
return DESTROY_ME;
}
}
}
else