This was primarily used in our labs to visualize some TNC aspects but
the third-party daemon and frontend we used have not seen any development
in a decade. There never was any industry interest in this protocol
anyway, so just remove it.
This plugin was developed for a customer who had very specific
requirements. It never did anything useful for regular users and
usually caused confusing errors if they enabled it by mistake. So
just remove it.
This was from a student project that has never been developed further.
And similar to the manager web application it lacks all sorts of modern
standards. So just remove it and the two plugins it relied on.
The test scenario is renamed to avoid confusion (neither of the two
p2pnat scenarios uses medsrv/medcli).
While for most uses the length is fixed and public (e.g. PRF/MAC outputs),
there are a few (e.g. in xauth-generic) that compare variable length
data.
The previous code directly leaked a differing length by short-circuiting
before comparing anything. While we could limit the comparison by the
minimum length (and call `memeq_const()`), that could still leak the
length because the time will plateau once the secret's length is reached.
Similarly, if the comparison was bound by the longer chunk (would prevent
the use of `memeq_const()`), the length could also be revealed once the
input gets longer than the secret and the time increases.
This changes the semantics of the function by declaring the first
argument the expected/reference secret and the second the variable input.
This strictly makes the function constant-time, bound by the secret's
length. So the length can't be guessed by providing different input (but
if an attacker can trigger the comparison against different secrets, of
potentially known lengths, it might still be possible). If the chunks
are known to have the same length, the order doesn't matter.
Callers of this function have been updated accordingly.
Should be rare that the eap-identity plugin is not loaded when
authenticating clients with EAP. And the second error path will
currently never get used as `process()` always succeeds.
Fixes: 79f2102cb4 ("implemented server side support for EAP-TTLS")
If multiple clients call list commands concurrently, each would replace
the global certificate printer instance the previous client created
and then operate on shared state. The destruction then causes a
double-free or NULL-pointer dereference.
Fixes: 02d431022c ("Refactored certificate management for the vici and stroke interfaces")
This could prevent the VIP from getting installed later and actually
causes those threads to block indefinitely as they wait for the entry to
either get removed or the VIP marked as installed, which will never
happen.
Fixes: c6b401581a ("Changed how kernel-netlink handles virtual IP addresses")
This applies some of the same fixes found in the previous commit but also
ensures that the offsets are valid before accessing the bitmask. Because
of an off-by-one error in the latter, the last address could get released
incorrectly (the pool constructor explicitly excludes it).
Fixes: 98d0343870 ("Implemented a HA enabled in-memory address pool")
The return value is now also fixed. The reply allocation previously
prevented that sections with failed CA certs were rejected.
Also fixes two potential leaks if duplicate settings are sent by a VICI
client.
Fixes: 63d370387d ("vici: Certification Authority support added.")
These rules don't depend on traffic selectors, so for SAs with multiple
traffic selectors we'd install several duplicate rules. Since this
plugin is used for transport mode SAs, it probably never was an issue
in practice.
Fixes: b8973b2661 ("connmark: Add CONNMARK rules to select correct output SA based on conntrack")
This ensures that secrets that are associated with the server identity,
usually they are assigned to the username exclusively, will only be tried
if the username also matched. Otherwise, it could be possible for users
who know at least one password to impersonate another user.
Fixes: 462c9a4f72 ("Try all matching XAuth secrets we find, not only the first one")
The code was written with `child_sa_t::destroy` in mind, which deletes
the inbound SA before the outbound SA. The problem is that the rekeying
code was changed meanwhile so the outbound SA is removed before the
inbound SA in order to avoid traffic loss. That could cause a
use-after-free as the already destroyed item remained in the `isas` list.
This change fixes this so the SAs can be removed in any order. The SPIs
are used as marker for whether a specific direction is installed. It
also fixes an issue in `expire_job()`, which removed the entry from
`osas` without holding the lock.
Fixes: f351d9ef7d ("kernel-wfp: Reference SA/SP sets by SPI and destination, not reqid")
Fixes: 44107cb7b7 ("child-delete: Delay the removal of the inbound SA of rekeyed CHILD_SAs")
This prevents other processes from binding the same ports and
misusing the protocol/port-specific bypass rules installed in WFP to
bypass the VPN.
Fixes: 11e7d0677c ("socket-win: Install IKE bypass policies using bypass_socket()")
The previous code checked in the IKE_SA before using it again to
add attributes based on it to the interim update message. This
change ensures the IKE_SA is only accessed while it is checked out.
The Acct-Status-Type attribute is still sent first, but the
Acct-Session-Id and Class attributes are now sent after the IKE
parameters, which shouldn't really matter, though.
Fixes: d019764ab6 ("Add support for RADIUS Interim accounting updates")
On typical systems that have overcommitting enabled, the 16 MiB maximum
that's allocated via the 24-bit length field in the AVP header shouldn't
be an issue as there are various limits that affect how much data can
actually be written to the allocated buffer (e.g. the maximum IKE message
size, the maximum TLS record size, or the maximum number of accepted
EAP-TTLS payloads), so this is primarily a defense-in-depth measure.
The length field of an EAP payload, which is the only type of AVP we
accept, is 16 bits, so that's what we now enforce as maximum.
Same as the previous commit for consistency, but not an issue here as
only transport mode SAs are handled.
Fixes: b8973b2661 ("connmark: Add CONNMARK rules to select correct output SA based on conntrack")
Not an issue in typical scenarios where the plugin is used on a gateway
with roadwarriors that use /32 addresses. But could be an issue if used
on a client that tunnels everything to the gateway.
Fixes: e5ad2e6614 ("forecast: Add the broadcast/multicast forwarding plugin called forecast")
The policies reference the provider, so it might not actually get removed
and be left dangling in the WFP system (maybe Windows refcounts it and
still removes it).
This avoids accepting expired certificates again should the time get
rolled back for some reason.
Fixes: c81b87ac26 ("systime-fix: Add timeout option to stop waiting for valid system time")
Fixes: 295e42a47f ("systime-fix disables certificate lifetime validation if system time not synced")
This is documented as a requirement in the man page, so the caller of the
conversation function might expect such an array. Although, since we
only accept non-interactive requests, for which no response is expected,
it's doubtful whether it will actually try to access elements in the
array. And if the passed pointer was initialized to NULL, passing it to
free() is probably also fine.
Fixes: 2312504d1e ("xauth-pam: Open/close a PAM session for each connected client")
These were never correct. And the first referenced commit, unfortunately,
just simplified the incorrect code.
Fixes: 08a3ee0cce ("bus: Change ike_update() signature and only call it once")
Fixes: b8973b2661 ("connmark: Add CONNMARK rules to select correct output SA based on conntrack")
The `transaction` variable was previously still set to the one that
was enumerated last even if the received DHCP OFFER did not match
it. So the transaction was incorrectly modified. Once the real
DHCP OFFER would arrive, it would get modified again, but it could
allow adding unintended DNS servers.
EAP-PEAP transports results as separate AVPs, we expect one after the
first phase 2 authentication (if not using certificates). However, with
the previous caching of the result of that, the client could then send
another confirmation as response to the EAP-TNC request to skip it.
Since no group membership is set if EAP-TNC is not complete, it shouldn't
really affect its outcome, though.
Fixes: 1be296dfb2 ("implemented the PEAP tunneling protocol as an EAP plugin")
The entry was updated and the previous EAP method and IKE SA destroyed
under a read lock, which is not safe (there could be threads in
get_state(), or even some that called it before and now still hold
that read lock while interacting with the EAP method).
Fixes: 37884ab10f ("Add locking to TNC-PDP connections")
As `tv_sec` is a `time_t`, i.e. typically 64 bits, assigning the result
of `htonl()` leaves the upper 32 bits zero. Copying from the
`sizeof(time_t) - 4` offset then copies those zeroes on little-endian
systems, which is not what was intended according to the comments.
Another issue was that the type of `tv_usec`, `suseconds_t`, is typically
a `long`, i.e. signed, so shifting the maximum value 0x000f423f (999'999)
by 12 bits technically overflows this. The cast fixes that.
Fixes: 1aba82bfd7 ("eap-aka-3gpp: Add plugin that implements 3GPP MILENAGE algorithm in software")
Basically the same as the previous commit.
Fixes: edcb2dd35b ("Moved reauth/pseudonym functionality from eap-sim-file to separate plugins, usable by any SIM/AKA backend")
This also protects access to the RNG, which is not always thread-safe.
Fixes: edcb2dd35b ("Moved reauth/pseudonym functionality from eap-sim-file to separate plugins, usable by any SIM/AKA backend")