make peer IP address and peer IP available to the xauth_module.verify_secret() method

This commit is contained in:
Andreas Steffen
2008-04-02 19:04:45 +00:00
parent 97da3d2de0
commit f342cc08c0
4 changed files with 20 additions and 6 deletions
+1 -1
View File
@@ -647,7 +647,7 @@ xauth_get_secret(xauth_t *xauth_secret)
* find a matching secret
*/
static bool
xauth_verify_secret(const char *conn_name, const xauth_t *xauth_secret)
xauth_verify_secret(const xauth_peer_t *peer, const xauth_t *xauth_secret)
{
bool found = FALSE;
secret_t *s;
+8 -3
View File
@@ -967,6 +967,12 @@ xauth_inR1(struct msg_digest *md)
}
else
{
xauth_peer_t peer;
peer.conn_name = st->st_connection->name;
addrtot(&md->sender, 0, peer.ip_address, sizeof(peer.ip_address));
idtoa(&md->st->st_connection->spd.that.id, peer.id, sizeof(peer.id));
DBG(DBG_CONTROL,
DBG_log("peer xauth user name is '%.*s'"
, ia.xauth_secret.user_name.len
@@ -977,9 +983,8 @@ xauth_inR1(struct msg_digest *md)
, ia.xauth_secret.user_password.len
, ia.xauth_secret.user_password.ptr)
)
/* verify the user credentials using a plugn function */
st->st_xauth.status = xauth_module.verify_secret(st->st_connection->name
, &ia.xauth_secret);
/* verify the user credentials using a plugin function */
st->st_xauth.status = xauth_module.verify_secret(&peer, &ia.xauth_secret);
plog("extended authentication %s", st->st_xauth.status? "was successful":"failed");
}
+1 -1
View File
@@ -44,7 +44,7 @@ xauth_init(void)
DBG_log("xauth module: found get_secret() function");
}
)
xauth_module.verify_secret = (bool (*) (const char*, const xauth_t*))
xauth_module.verify_secret = (bool (*) (const xauth_peer_t*, const xauth_t*))
dlsym(xauth_module.handle, "verify_secret");
DBG(DBG_CONTROL,
if (xauth_module.verify_secret != NULL)
+10 -1
View File
@@ -18,10 +18,19 @@
#ifndef _XAUTH_H
#define _XAUTH_H
#include <freeswan.h>
#include "defs.h"
/* XAUTH credentials */
struct chunk_t;
typedef struct {
char *conn_name;
char id[BUF_LEN];
char ip_address[ADDRTOT_BUF];
} xauth_peer_t;
typedef struct {
chunk_t user_name;
chunk_t user_password;
@@ -30,7 +39,7 @@ typedef struct {
typedef struct {
void *handle;
bool (*get_secret) (xauth_t *xauth_secret);
bool (*verify_secret) (const char *conn_name, const xauth_t *xauth_secret);
bool (*verify_secret) (const xauth_peer_t *peer, const xauth_t *xauth_secret);
} xauth_module_t;
extern xauth_module_t xauth_module;