charon-systemd: Add support to configure user and group via strongswan.conf
Fixes #887.
This commit is contained in:
@@ -39,6 +39,17 @@
|
|||||||
#include <threading/thread.h>
|
#include <threading/thread.h>
|
||||||
#include <threading/rwlock.h>
|
#include <threading/rwlock.h>
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Default user and group
|
||||||
|
*/
|
||||||
|
#ifndef IPSEC_USER
|
||||||
|
#define IPSEC_USER NULL
|
||||||
|
#endif
|
||||||
|
|
||||||
|
#ifndef IPSEC_GROUP
|
||||||
|
#define IPSEC_GROUP NULL
|
||||||
|
#endif
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* hook in library for debugging messages
|
* hook in library for debugging messages
|
||||||
*/
|
*/
|
||||||
@@ -268,18 +279,20 @@ static int run()
|
|||||||
*/
|
*/
|
||||||
static bool lookup_uid_gid()
|
static bool lookup_uid_gid()
|
||||||
{
|
{
|
||||||
#ifdef IPSEC_USER
|
char *name
|
||||||
if (!lib->caps->resolve_uid(lib->caps, IPSEC_USER))
|
|
||||||
|
name = lib->settings->get_str(lib->settings, "%s.user", IPSEC_USER,
|
||||||
|
lib->ns);
|
||||||
|
if (name && !lib->caps->resolve_uid(lib->caps, name))
|
||||||
{
|
{
|
||||||
return FALSE;
|
return FALSE;
|
||||||
}
|
}
|
||||||
#endif /* IPSEC_USER */
|
name = lib->settings->get_str(lib->settings, "%s.group", IPSEC_GROUP,
|
||||||
#ifdef IPSEC_GROUP
|
lib->ns);
|
||||||
if (!lib->caps->resolve_gid(lib->caps, IPSEC_GROUP))
|
if (name && !lib->caps->resolve_gid(lib->caps, name))
|
||||||
{
|
{
|
||||||
return FALSE;
|
return FALSE;
|
||||||
}
|
}
|
||||||
#endif /* IPSEC_GROUP */
|
|
||||||
return TRUE;
|
return TRUE;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user