make peer IP address and peer IP available to the xauth_module.verify_secret() method
This commit is contained in:
+1
-1
@@ -647,7 +647,7 @@ xauth_get_secret(xauth_t *xauth_secret)
|
|||||||
* find a matching secret
|
* find a matching secret
|
||||||
*/
|
*/
|
||||||
static bool
|
static bool
|
||||||
xauth_verify_secret(const char *conn_name, const xauth_t *xauth_secret)
|
xauth_verify_secret(const xauth_peer_t *peer, const xauth_t *xauth_secret)
|
||||||
{
|
{
|
||||||
bool found = FALSE;
|
bool found = FALSE;
|
||||||
secret_t *s;
|
secret_t *s;
|
||||||
|
|||||||
+8
-3
@@ -967,6 +967,12 @@ xauth_inR1(struct msg_digest *md)
|
|||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
|
xauth_peer_t peer;
|
||||||
|
|
||||||
|
peer.conn_name = st->st_connection->name;
|
||||||
|
addrtot(&md->sender, 0, peer.ip_address, sizeof(peer.ip_address));
|
||||||
|
idtoa(&md->st->st_connection->spd.that.id, peer.id, sizeof(peer.id));
|
||||||
|
|
||||||
DBG(DBG_CONTROL,
|
DBG(DBG_CONTROL,
|
||||||
DBG_log("peer xauth user name is '%.*s'"
|
DBG_log("peer xauth user name is '%.*s'"
|
||||||
, ia.xauth_secret.user_name.len
|
, ia.xauth_secret.user_name.len
|
||||||
@@ -977,9 +983,8 @@ xauth_inR1(struct msg_digest *md)
|
|||||||
, ia.xauth_secret.user_password.len
|
, ia.xauth_secret.user_password.len
|
||||||
, ia.xauth_secret.user_password.ptr)
|
, ia.xauth_secret.user_password.ptr)
|
||||||
)
|
)
|
||||||
/* verify the user credentials using a plugn function */
|
/* verify the user credentials using a plugin function */
|
||||||
st->st_xauth.status = xauth_module.verify_secret(st->st_connection->name
|
st->st_xauth.status = xauth_module.verify_secret(&peer, &ia.xauth_secret);
|
||||||
, &ia.xauth_secret);
|
|
||||||
plog("extended authentication %s", st->st_xauth.status? "was successful":"failed");
|
plog("extended authentication %s", st->st_xauth.status? "was successful":"failed");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -44,7 +44,7 @@ xauth_init(void)
|
|||||||
DBG_log("xauth module: found get_secret() function");
|
DBG_log("xauth module: found get_secret() function");
|
||||||
}
|
}
|
||||||
)
|
)
|
||||||
xauth_module.verify_secret = (bool (*) (const char*, const xauth_t*))
|
xauth_module.verify_secret = (bool (*) (const xauth_peer_t*, const xauth_t*))
|
||||||
dlsym(xauth_module.handle, "verify_secret");
|
dlsym(xauth_module.handle, "verify_secret");
|
||||||
DBG(DBG_CONTROL,
|
DBG(DBG_CONTROL,
|
||||||
if (xauth_module.verify_secret != NULL)
|
if (xauth_module.verify_secret != NULL)
|
||||||
|
|||||||
+10
-1
@@ -18,10 +18,19 @@
|
|||||||
#ifndef _XAUTH_H
|
#ifndef _XAUTH_H
|
||||||
#define _XAUTH_H
|
#define _XAUTH_H
|
||||||
|
|
||||||
|
#include <freeswan.h>
|
||||||
|
#include "defs.h"
|
||||||
|
|
||||||
/* XAUTH credentials */
|
/* XAUTH credentials */
|
||||||
|
|
||||||
struct chunk_t;
|
struct chunk_t;
|
||||||
|
|
||||||
|
typedef struct {
|
||||||
|
char *conn_name;
|
||||||
|
char id[BUF_LEN];
|
||||||
|
char ip_address[ADDRTOT_BUF];
|
||||||
|
} xauth_peer_t;
|
||||||
|
|
||||||
typedef struct {
|
typedef struct {
|
||||||
chunk_t user_name;
|
chunk_t user_name;
|
||||||
chunk_t user_password;
|
chunk_t user_password;
|
||||||
@@ -30,7 +39,7 @@ typedef struct {
|
|||||||
typedef struct {
|
typedef struct {
|
||||||
void *handle;
|
void *handle;
|
||||||
bool (*get_secret) (xauth_t *xauth_secret);
|
bool (*get_secret) (xauth_t *xauth_secret);
|
||||||
bool (*verify_secret) (const char *conn_name, const xauth_t *xauth_secret);
|
bool (*verify_secret) (const xauth_peer_t *peer, const xauth_t *xauth_secret);
|
||||||
} xauth_module_t;
|
} xauth_module_t;
|
||||||
|
|
||||||
extern xauth_module_t xauth_module;
|
extern xauth_module_t xauth_module;
|
||||||
|
|||||||
Reference in New Issue
Block a user