ike-auth: Handle REDIRECT notifies during IKE_AUTH

This commit is contained in:
Tobias Brunner
2016-03-04 16:02:59 +01:00
parent f20e00fe54
commit f5a9025ce9
+25 -3
View File
@@ -118,6 +118,11 @@ struct private_ike_auth_t {
* Is EAP acceptable, did we strictly authenticate peer? * Is EAP acceptable, did we strictly authenticate peer?
*/ */
bool eap_acceptable; bool eap_acceptable;
/**
* Gateway ID if redirected
*/
identification_t *redirect_to;
}; };
/** /**
@@ -988,6 +993,15 @@ METHOD(task_t, process_i, status_t,
case ME_ENDPOINT: case ME_ENDPOINT:
/* handled in ike_me task */ /* handled in ike_me task */
break; break;
case REDIRECT:
DESTROY_IF(this->redirect_to);
this->redirect_to = redirect_data_parse(
notify->get_notification_data(notify), NULL);
if (!this->redirect_to)
{
DBG1(DBG_IKE, "received invalid REDIRECT notify");
}
break;
default: default:
{ {
if (type <= 16383) if (type <= 16383)
@@ -1118,8 +1132,10 @@ METHOD(task_t, process_i, status_t,
{ {
this->expect_another_auth = FALSE; this->expect_another_auth = FALSE;
} }
if (!this->expect_another_auth && !this->do_another_auth && !this->my_auth) if (this->expect_another_auth || this->do_another_auth || this->my_auth)
{ {
return NEED_MORE;
}
if (!update_cfg_candidates(this, TRUE)) if (!update_cfg_candidates(this, TRUE))
{ {
goto peer_auth_failed; goto peer_auth_failed;
@@ -1139,9 +1155,12 @@ METHOD(task_t, process_i, status_t,
this->ike_sa->get_other_id(this->ike_sa)); this->ike_sa->get_other_id(this->ike_sa));
this->ike_sa->set_state(this->ike_sa, IKE_ESTABLISHED); this->ike_sa->set_state(this->ike_sa, IKE_ESTABLISHED);
charon->bus->ike_updown(charon->bus, this->ike_sa, TRUE); charon->bus->ike_updown(charon->bus, this->ike_sa, TRUE);
return SUCCESS;
if (this->redirect_to)
{
this->ike_sa->handle_redirect(this->ike_sa, this->redirect_to);
} }
return NEED_MORE; return SUCCESS;
peer_auth_failed: peer_auth_failed:
charon->bus->alert(charon->bus, ALERT_PEER_AUTH_FAILED); charon->bus->alert(charon->bus, ALERT_PEER_AUTH_FAILED);
@@ -1165,6 +1184,7 @@ METHOD(task_t, migrate, void,
DESTROY_IF(this->peer_cfg); DESTROY_IF(this->peer_cfg);
DESTROY_IF(this->my_auth); DESTROY_IF(this->my_auth);
DESTROY_IF(this->other_auth); DESTROY_IF(this->other_auth);
DESTROY_IF(this->redirect_to);
this->candidates->destroy_offset(this->candidates, offsetof(peer_cfg_t, destroy)); this->candidates->destroy_offset(this->candidates, offsetof(peer_cfg_t, destroy));
this->my_packet = NULL; this->my_packet = NULL;
@@ -1173,6 +1193,7 @@ METHOD(task_t, migrate, void,
this->peer_cfg = NULL; this->peer_cfg = NULL;
this->my_auth = NULL; this->my_auth = NULL;
this->other_auth = NULL; this->other_auth = NULL;
this->redirect_to = NULL;
this->do_another_auth = TRUE; this->do_another_auth = TRUE;
this->expect_another_auth = TRUE; this->expect_another_auth = TRUE;
this->authentication_failed = FALSE; this->authentication_failed = FALSE;
@@ -1189,6 +1210,7 @@ METHOD(task_t, destroy, void,
DESTROY_IF(this->my_auth); DESTROY_IF(this->my_auth);
DESTROY_IF(this->other_auth); DESTROY_IF(this->other_auth);
DESTROY_IF(this->peer_cfg); DESTROY_IF(this->peer_cfg);
DESTROY_IF(this->redirect_to);
this->candidates->destroy_offset(this->candidates, offsetof(peer_cfg_t, destroy)); this->candidates->destroy_offset(this->candidates, offsetof(peer_cfg_t, destroy));
free(this); free(this);
} }