refactored TNC framework

This commit is contained in:
Andreas Steffen
2011-10-25 01:10:16 +02:00
parent c008d2cc46
commit f0a8bf47f7
52 changed files with 971 additions and 605 deletions
+7 -3
View File
@@ -6,7 +6,11 @@ ipseclib_LTLIBRARIES = libtnccs.la
libtnccs_la_LIBADD = $(top_builddir)/src/libtncif/libtncif.la
libtnccs_la_SOURCES = \
imc/imc.h imc/imc_manager.h \
imv/imv.h imv/imv_manager.h \
imv/imv_recommendations.h imv/imv_recommendations.c
tnc/tnc.h tnc/tnc.c \
tnc/imc/imc.h tnc/imc/imc_manager.h \
tnc/imv/imv.h tnc/imv/imv_manager.h \
tnc/imv/imv_recommendations.h tnc/imv/imv_recommendations.c \
tnc/tnccs/tnccs.h tnc/tnccs/tnccs.c \
tnc/tnccs/tnccs_manager.h tnc/tnccs/tnccs_manager.c
@@ -48,6 +48,14 @@ struct imc_manager_t {
*/
imc_t* (*remove)(imc_manager_t *this, TNC_IMCID id);
/**
* Load all IMC instances
*
* @param filename configuration file containt IMC paths
* @return TRUE if initialization of all IMCs succeeded
*/
bool (*load_all)(imc_manager_t *this, char *filename);
/**
* Check if an IMC with a given ID is registered with the IMC manager
*
@@ -49,6 +49,14 @@ struct imv_manager_t {
*/
imv_t* (*remove)(imv_manager_t *this, TNC_IMVID id);
/**
* Load all IMV instances
*
* @param filename configuration file containing IMV paths
* @return TRUE if initialization of all IMVs succeeded
*/
bool (*load_all)(imv_manager_t *this, char *filename);
/**
* Check if an IMV with a given ID is registered with the IMV manager
*
+137
View File
@@ -0,0 +1,137 @@
/*
* Copyright (C) 2011 Andreas Steffen
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#include "tnc.h"
typedef struct private_tnc_t private_tnc_t;
typedef tnccs_manager_t *(*tnc_create_tnccs_manager_t)(void);
typedef imc_manager_t *(*tnc_create_imc_manager_t)(void);
typedef imv_manager_t *(*tnc_create_imv_manager_t)(void);
/**
* Private additions to tnc_t.
*/
struct private_tnc_t {
/**
* Public members of tnc_t.
*/
tnc_t public;
};
/**
* Single instance of tnc_t.
*/
tnc_t *tnc;
/**
* Described in header.
*/
void libtnccs_init(void)
{
private_tnc_t *this;
INIT(this,
.public = {
},
);
tnc = &this->public;
}
/**
* Described in header.
*/
void libtnccs_deinit(void)
{
private_tnc_t *this = (private_tnc_t*)tnc;
free(this);
tnc = NULL;
}
/**
* Described in header.
*/
bool tnc_manager_register(plugin_t *plugin, plugin_feature_t *feature,
bool reg, void *data)
{
char *tnc_config;
tnc_config = lib->settings->get_str(lib->settings,
"libtnccs.tnc_config", "/etc/tnc_config");
if (feature->type == FEATURE_CUSTOM)
{
if (streq(feature->arg.custom, "tnccs-manager"))
{
if (reg)
{
tnc->tnccs = ((tnc_create_tnccs_manager_t)data)();
}
else
{
tnc->tnccs->destroy(tnc->tnccs);
tnc->tnccs = NULL;
}
}
else if (streq(feature->arg.custom, "imc-manager"))
{
if (reg)
{
tnc->imcs = ((tnc_create_imc_manager_t)data)();
if (!tnc->imcs->load_all(tnc->imcs, tnc_config))
{
tnc->imcs->destroy(tnc->imcs);
tnc->imcs = NULL;
return FALSE;
}
}
else
{
tnc->imcs->destroy(tnc->imcs);
tnc->imcs = NULL;
}
}
else if (streq(feature->arg.custom, "imv-manager"))
{
if (reg)
{
tnc->imvs = ((tnc_create_imv_manager_t)data)();
if (!tnc->imvs->load_all(tnc->imvs, tnc_config))
{
tnc->imvs->destroy(tnc->imvs);
tnc->imvs = NULL;
return FALSE;
}
}
else
{
tnc->imvs->destroy(tnc->imvs);
tnc->imvs = NULL;
}
}
else
{
return FALSE;
}
}
return TRUE;
}
+88
View File
@@ -0,0 +1,88 @@
/*
* Copyright (C) 2011 Andreas Steffen
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup tnc tnc
* @ingroup tnc
*
* @defgroup tnc tnc
* @{ @ingroup tnc
*/
#ifndef TNC_H_
#define TNC_H_
typedef struct tnc_t tnc_t;
#include "tnc/imc/imc_manager.h"
#include "tnc/imv/imv_manager.h"
#include "tnc/tnccs/tnccs_manager.h"
#include <library.h>
/**
* TNC management support object.
*/
struct tnc_t {
/**
* TNC-IMC manager controlling Integrity Measurement Collectors
*/
imc_manager_t *imcs;
/**
* TNC-IMV manager controlling Integrity Measurement Verifiers
*/
imv_manager_t *imvs;
/**
* TNC-TNCCS manager controlling the TNC Server and Client protocols
*/
tnccs_manager_t *tnccs;
};
/**
* The single instance of tnc_t.
*
* Exists between calls to libtnccs_init() and libtnccs_deinit().
*/
extern tnc_t *tnc;
/**
* Initialize libtnccs.
*/
void libtnccs_init(void);
/**
* Deinitialize libtnccs
*/
void libtnccs_deinit(void);
/**
* Helper function to (un-)register TNC managers from plugin features.
*
* This function is a plugin_feature_callback_t and can be used with the
* PLUGIN_CALLBACK macro to register a TNC manager constructor.
*
* @param plugin plugin registering the TNC manager
* @param feature associated plugin feature
* @param reg TRUE to register, FALSE to unregister.
* @param data data passed to callback, a TNC manager constructor
*/
bool tnc_manager_register(plugin_t *plugin, plugin_feature_t *feature,
bool reg, void *data);
#endif /** TNC_H_ @}*/
+24
View File
@@ -0,0 +1,24 @@
/*
* Copyright (C) 2010 Andreas Steffen
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#include "tnccs.h"
ENUM(tnccs_type_names, TNCCS_UNKNOWN, TNCCS_2_0,
"unknown TNCCS",
"TNCCS 1.1",
"TNCCS SOH",
"TNCCS 2.0",
);
+77
View File
@@ -0,0 +1,77 @@
/*
* Copyright (C) 2010-1011 Andreas Steffen
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup tnccs tnccs
* @ingroup tnc
*
* @defgroup tnccst tnccs
* @{ @ingroup tnccs
*/
#ifndef TNCCS_H_
#define TNCCS_H_
typedef struct tnccs_t tnccs_t;
typedef enum tnccs_type_t tnccs_type_t;
#include <tncif.h>
#include <tncifimc.h>
#include <tncifimv.h>
#include <library.h>
#include <plugins/plugin.h>
/**
* Type of TNC Client/Server protocol
*/
enum tnccs_type_t {
TNCCS_UNKNOWN,
TNCCS_1_1,
TNCCS_SOH,
TNCCS_2_0,
TNCCS_DYNAMIC
};
/**
* enum names for tnccs_type_t.
*/
extern enum_name_t *tnccs_type_names;
/**
* Constructor definition for a pluggable TNCCS protocol implementation.
*
* @param is_server TRUE if TNC Server, FALSE if TNC Client
* @return implementation of the tnccs_t interface
*/
typedef tnccs_t *(*tnccs_constructor_t)(bool is_server);
/**
* Callback function adding a message to a TNCCS batch
*
* @param imc_id ID of IMC or TNC_IMCID_ANY
* @param imc_id ID of IMV or TNC_IMVID_ANY
* @param msg message to be added
* @param msg_len message length
* @param msg_type message type
* @return result code
*/
typedef TNC_Result (*tnccs_send_message_t)(tnccs_t* tncss, TNC_IMCID imc_id,
TNC_IMVID imv_id,
TNC_BufferReference msg,
TNC_UInt32 msg_len,
TNC_MessageType msg_type);
#endif /** TNCCS_H_ @}*/
+63
View File
@@ -0,0 +1,63 @@
/*
* Copyright (C) 2011 Andreas Steffen
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
#include "tnccs_manager.h"
#include "tnc/tnc.h"
#include <debug.h>
/**
* See header
*/
bool tnccs_method_register(plugin_t *plugin, plugin_feature_t *feature,
bool reg, void *data)
{
if (!tnc || !tnc->tnccs)
{
DBG1(DBG_TNC, "TNC TNCCS manager does not exist");
return FALSE;
}
if (reg)
{
if (feature->type == FEATURE_CUSTOM)
{
tnccs_type_t type = TNCCS_UNKNOWN;
if (streq(feature->arg.custom, "tnccs-2.0"))
{
type = TNCCS_2_0;
}
else if (streq(feature->arg.custom, "tnccs-1.1"))
{
type = TNCCS_1_1;
}
else if (streq(feature->arg.custom, "tnccs-dynamic"))
{
type = TNCCS_DYNAMIC;
}
else
{
return FALSE;
}
tnc->tnccs->add_method(tnc->tnccs, type, (tnccs_constructor_t)data);
}
}
else
{
tnc->tnccs->remove_method(tnc->tnccs, (tnccs_constructor_t)data);
}
return TRUE;
}
+194
View File
@@ -0,0 +1,194 @@
/*
* Copyright (C) 2010 Andreas Steffen
* HSR Hochschule fuer Technik Rapperswil
*
* This program is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License as published by the
* Free Software Foundation; either version 2 of the License, or (at your
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
*
* This program is distributed in the hope that it will be useful, but
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* for more details.
*/
/**
* @defgroup tnccs_manager tnccs_manager
* @{ @ingroup tnccs
*/
#ifndef TNCCS_MANAGER_H_
#define TNCCS_MANAGER_H_
typedef struct tnccs_manager_t tnccs_manager_t;
#include "tnccs.h"
#include "tnc/imv/imv_recommendations.h"
/**
* The TNCCS manager manages all TNCCS implementations and creates instances.
*
* A plugin registers its implemented TNCCS protocol with the manager by
* providing type and a constructor function. The manager then creates
* TNCCS protocol instances via the provided constructor.
*/
struct tnccs_manager_t {
/**
* Register a TNCCS protocol implementation.
*
* @param type TNCCS protocol type
* @param constructor constructor, returns a TNCCS protocol implementation
*/
void (*add_method)(tnccs_manager_t *this, tnccs_type_t type,
tnccs_constructor_t constructor);
/**
* Unregister a TNCCS protocol implementation using it's constructor.
*
* @param constructor constructor function to remove, as added in add_method
*/
void (*remove_method)(tnccs_manager_t *this, tnccs_constructor_t constructor);
/**
* Create a new TNCCS protocol instance.
*
* @param type type of the TNCCS protocol
* @param is_server TRUE if TNC Server, FALSE if TNC Client
* @return TNCCS protocol instance, NULL if no constructor found
*/
tnccs_t* (*create_instance)(tnccs_manager_t *this, tnccs_type_t type,
bool is_server);
/**
* Create a TNCCS connection and assign a unique connection ID as well a
* callback function for adding a message to a TNCCS batch and create
* an empty set for collecting IMV recommendations
*
* @param tnccs TNCCS connection instance
* @param send_message TNCCS callback function
* @param request_handshake_retry pointer to boolean variable
* @param recs pointer to IMV recommendation set
* @return assigned connection ID
*/
TNC_ConnectionID (*create_connection)(tnccs_manager_t *this, tnccs_t *tnccs,
tnccs_send_message_t send_message,
bool *request_handshake_retry,
recommendations_t **recs);
/**
* Remove a TNCCS connection using its connection ID.
*
* @param id ID of the connection to be removed
* @param is_server TNC Server if TRUE, TNC Client if FALSE
*/
void (*remove_connection)(tnccs_manager_t *this, TNC_ConnectionID id,
bool is_server);
/**
* Request a handshake retry
*
* @param is_imc TRUE if IMC, FALSE if IMV
* @param imcv_id ID of IMC or IMV requesting the retry
* @param id ID of a specific connection or any connection
* @param reason reason for the handshake retry
* @return return code
*/
TNC_Result (*request_handshake_retry)(tnccs_manager_t *this, bool is_imc,
TNC_UInt32 imcv_id,
TNC_ConnectionID id,
TNC_RetryReason reason);
/**
* Add an IMC/IMV message to the batch of a given connection ID.
*
* @param imc_id ID of IMC or TNC_IMCID_ANY
* @param imv_id ID of IMV or TNC_IMVID_ANY
* @param id ID of target connection
* @param msg message to be added
* @param msg_len message length
* @param msg_type message type
* @return return code
*/
TNC_Result (*send_message)(tnccs_manager_t *this, TNC_IMCID imc_id,
TNC_IMVID imv_id,
TNC_ConnectionID id,
TNC_BufferReference msg,
TNC_UInt32 msg_len,
TNC_MessageType msg_type);
/**
* Deliver an IMV Action Recommendation and IMV Evaluation Result to the TNCS
*
* @param imv_id ID of the IMV providing the recommendation
* @param id ID of target connection
* @param rec action recommendation
* @param eval evaluation result
* @return return code
*/
TNC_Result (*provide_recommendation)(tnccs_manager_t *this,
TNC_IMVID imv_id,
TNC_ConnectionID id,
TNC_IMV_Action_Recommendation rec,
TNC_IMV_Evaluation_Result eval);
/**
* Get the value of an attribute associated with a connection or with the
* TNCS as a whole.
*
* @param imv_id ID of the IMV requesting the attribute
* @param id ID of target connection
* @param attribute_id ID of the requested attribute
* @param buffer_len length of the buffer in bytes
* @param buffer pointer to the buffer
* @param out_value_len actual length of the returned attribute
* @return return code
*/
TNC_Result (*get_attribute)(tnccs_manager_t *this,
TNC_IMVID imv_id,
TNC_ConnectionID id,
TNC_AttributeID attribute_id,
TNC_UInt32 buffer_len,
TNC_BufferReference buffer,
TNC_UInt32 *out_value_len);
/**
* Set the value of an attribute associated with a connection or with the
* TNCS as a whole.
*
* @param imv_id ID of the IMV setting the attribute
* @param id ID of target connection
* @param attribute_id ID of the attribute to be set
* @param buffer_len length of the buffer in bytes
* @param buffer pointer to the buffer
* @return return code
*/
TNC_Result (*set_attribute)(tnccs_manager_t *this,
TNC_IMVID imv_id,
TNC_ConnectionID id,
TNC_AttributeID attribute_id,
TNC_UInt32 buffer_len,
TNC_BufferReference buffer);
/**
* Destroy a tnccs_manager instance.
*/
void (*destroy)(tnccs_manager_t *this);
};
/**
* Helper function to (un-)register TNCCS methods from plugin features.
*
* This function is a plugin_feature_callback_t and can be used with the
* PLUGIN_CALLBACK macro to register a TNCCS method constructor.
*
* @param plugin plugin registering the TNCCS method constructor
* @param feature associated plugin feature
* @param reg TRUE to register, FALSE to unregister.
* @param data data passed to callback, a tnccs_constructor_t
*/
bool tnccs_method_register(plugin_t *plugin, plugin_feature_t *feature,
bool reg, void *data);
#endif /** TNCCS_MANAGER_H_ @}*/