Reto Buerki
3972769690
Call ike_isa_auth_psk in listener authorize hook
...
This exchange initiates the AUTH verification in the TKM.
2013-03-19 15:23:47 +01:00
Reto Buerki
9df5645623
listener: Register message hook
...
Use the message hook to save the AUTHENTICATION payload of an incoming
IKE_AUTH message.
The AUTH payload will be passed on to the TKM ike_isa_auth operation in
the authorize hook.
2013-03-19 15:23:47 +01:00
Reto Buerki
071e792a85
keymat: Add AUTH payload setter/getter functions
...
These functions are used in the TKM specific bus listener to
store/retrieve the AUTH payload chunk in the message/authorize hooks.
2013-03-19 15:23:47 +01:00
Reto Buerki
d0ce4116b0
Register TKM bus listener in charon-tkm
2013-03-19 15:23:47 +01:00
Reto Buerki
c6c8d74026
Add TKM specific bus listener skeleton
...
This listener gets informed about IKE authorization rounds and will be
used to call ike_isa_auth on a given ISA.
2013-03-19 15:23:47 +01:00
Reto Buerki
d91acfdb5d
Add ISA context id getter to TKM keymat
2013-03-19 15:23:47 +01:00
Reto Buerki
cdd4d73ff5
keymat: Acquire AE context ID on initialization
2013-03-19 15:23:47 +01:00
Reto Buerki
c755645032
Add TKM_CTX_AE (Authenticated Endpoint context)
2013-03-19 15:23:47 +01:00
Reto Buerki
bf1034a776
keymat: Acquire ISA context ID on initialization
2013-03-19 15:23:47 +01:00
Reto Buerki
7fb3e5ed10
Add TKM_CTX_ISA (IKE SA context)
2013-03-19 15:23:46 +01:00
Reto Buerki
fa22fc2419
Use remote PSK signature computed by TKM
2013-03-19 15:23:46 +01:00
Reto Buerki
e7a497c307
keymat: Check for aes256-sha512 in derive_ike_keys
...
Return FALSE if peers try to use other algorithm combinations.
2013-03-19 15:23:46 +01:00
Adrian-Ken Rueegsegger
51fdbd0429
keymat: Call ike_isa_sign_psk in get_psk_sig
...
Get PSK signed AUTH octets from TKM in initiator case.
2013-03-19 15:23:46 +01:00
Reto Buerki
e285544be2
Factor out AEAD transform creation
...
Introduce static aead_create_from_keys function to initialize AEAD
transforms from key chunks.
2013-03-19 15:23:46 +01:00
Reto Buerki
4be8471fab
Add keymat IKE key derivation test case
2013-03-19 15:23:46 +01:00
Reto Buerki
3290b9995c
keymat: Create inbound and outbound AEAD transforms
...
Create and initialize AEAD transforms with keys derived by the TKM.
Return these transforms in the get_aead function.
IKE keys used by charon are derived by TKM now.
2013-03-19 15:23:46 +01:00
Reto Buerki
4c38878db5
keymat: Extract enc,inc algorithms from proposal
...
Extract encryption and integrity algorithms from proposal and check them
before deriving IKE keys.
2013-03-19 15:23:46 +01:00
Reto Buerki
fc828aaac6
keymat: Call TKM Isa_Create procedure
2013-03-19 15:23:46 +01:00
Reto Buerki
0327fac6b6
Implement chunk_to_sequence function
...
This function converts a given chunk to a variable-length byte sequence.
2013-03-19 15:23:46 +01:00
Reto Buerki
53232d5883
Implement sequence_to_chunk function
...
This function converts a given TKM variable-length byte sequence to
chunk.
2013-03-19 15:23:46 +01:00
Adrian-Ken Rueegsegger
d61cea7524
keymat: Log nonce and DH context ids
2013-03-19 15:23:46 +01:00
Adrian-Ken Rueegsegger
528fc21ffe
Add context id getter to TKM DH implementation
2013-03-19 15:23:46 +01:00
Adrian-Ken Rueegsegger
ba0d7d9a76
keymat: Get context id of local nonce
...
To derive IKE keys using TKM the nonce context id of the local nonce is needed.
Get the id for a given chunk using the chunk map.
2013-03-19 15:23:46 +01:00
Adrian-Ken Rueegsegger
624178fece
nonceg: Insert id mapping when allocating nonce
2013-03-19 15:23:46 +01:00
Adrian-Ken Rueegsegger
3242a178b3
Add chunk map
...
This data structure allows to store mappings of chunks to ids. This will
be used to map nonces to their corresponding nonce context ids.
2013-03-19 15:23:46 +01:00
Adrian-Ken Rueegsegger
601de9f36f
Add context id getter to TKM nonce generator
2013-03-19 15:23:46 +01:00
Reto Buerki
ebe592a393
id_manager: Use calloc instead of malloc
...
This way we don't need to manually initialize the slot status; free
slots are now indicated by 0 though.
2013-03-19 15:23:46 +01:00
Reto Buerki
1ee792f9ea
Use ikev2 keymat proxy
...
Forward incoming calls to default ikev2 keymat instance. This is needed
to make a stepwise migration to TKM keymat possible. It will be removed
once the corresponding parts are implemented in the TKM.
2013-03-19 15:23:45 +01:00
Reto Buerki
5b3bcdfada
Add skeleton for TKM keymat variant
2013-03-19 15:23:45 +01:00
Reto Buerki
84967b4439
id_manager: Use limits given by TKM
2013-03-19 15:23:45 +01:00
Reto Buerki
50e35e66d2
Pass context limits on to id manager
2013-03-19 15:23:45 +01:00
Reto Buerki
ef5372395a
Request limits from TKM on init
2013-03-19 15:23:45 +01:00
Reto Buerki
7aa573a50e
id_manager: Use array of bool instead of list
...
Instead of storing the acquired context ids in a linked list, use an
array of booleans for the job. A boolean value of true in the array
designates an available context id.
2013-03-19 15:23:45 +01:00
Reto Buerki
49c513c1d9
Use id manager to acquire DH context id
2013-03-19 15:23:45 +01:00
Reto Buerki
65a777f7fb
Add TKM_CTX_DH (Diffie-Hellman context) to id manager
2013-03-19 15:23:45 +01:00
Reto Buerki
c38459d77d
Use id manager to acquire nonce context id
2013-03-19 15:23:45 +01:00
Reto Buerki
f3cd7f50de
Add initial TKM Diffie-Hellman implementation
...
The tkm_diffie_hellman_t plugin acquires a DH context from the Trusted
Key Manager and uses it to get a DH public value and the calculated
shared secret. Proper context handling is still missing though, the
plugin currently uses context ID 1.
The get_shared_secret function will be removed as soon as the TKM
specific keymat is ready.
2013-03-19 15:23:45 +01:00
Reto Buerki
d51305aa3f
charon-tkm: Register tkm nonce generator
2013-03-19 15:23:45 +01:00
Reto Buerki
8e95bf455d
tkm_nonceg: Return nonce generated by TKM
2013-03-19 15:23:45 +01:00
Reto Buerki
3d2746309e
Initialize TKM client library in tkm.c
2013-03-19 15:23:45 +01:00
Reto Buerki
559fe48c50
Introduce TKM specific charon daemon (charon-tkm)
...
Analogous to charon-nm the charon-tkm daemon is a specialized charon
instance used in combination with the trusted key manager (TKM) written
in Ada.
The charon-tkm is basically a copy of the charon-nm code which will
register it's own TKM specific plugins.
The daemon binary is built using the gprbuild utility. This is needed
because it uses the tkm-rpc Ada library and consequently the Ada
runtime. gprbuild takes care of the complete binding and linker steps
required to properly initialize the Ada runtime.
2013-03-19 15:23:45 +01:00