Commit Graph
1215 Commits
Author SHA1 Message Date
Martin Willi 483a258ad8 stroke: support %dynamic in left/rightsubnet for dynamic selectors
This has the same meaning as omitting left/rightsubnet, i.e. replace it
by the IKE address. Supporting %dynamic allows configurations with multiple
dynamic selectors in a left/rightsubnet, each with potentially different
proto/port selectors.
2013-06-19 16:36:01 +02:00
Martin Willi 4a7c29bf02 stroke: support a specific proto/port for each net defined in left/rightsubnet 2013-06-19 16:36:01 +02:00
Martin Willi de2debf8e0 stroke: add exportconn{cert,chain} commands in addition to exportx509
The new commands either export a single end entity certificate or the
full trust chain for a specific connection name.
2013-06-19 16:27:19 +02:00
Martin Willi 24303f99f7 dhcp: search for transactions only for connections having a poolname "dhcp"
When a connection has a single pool that queries recursively the DHCP backend,
we shouldn't return any attributes directly from DHCP when queried for that
pool.
2013-06-18 09:50:29 +02:00
Tobias Brunner c6f1929a45 socket-default: Make sure sockets are open when checking with FD_ISSET 2013-06-14 17:25:16 +02:00
Tobias Brunner 1889837767 socket-default: Properly initialize NAT-T port if opening regular socket failed 2013-06-14 16:42:56 +02:00
Tobias Brunner 44fb978169 ha: Fix CHILD_SA installation in ha_dispatcher after adding initiator flag 2013-06-13 13:17:55 +02:00
Martin Willi a8c9454423 kernel-interface: add an exchange initiator parameter to add_sa()
This new flag gives the kernel-interface a hint how it should priorize the
use of newly installed SAs during rekeying.

Consider the following rekey procedure in IKEv2:

Initiator  ---    Responder

I1 -------CREATE-------> R1
I2 <------CREATE--------
   -------DELETE-------> R2
I3 <------DELETE--------

SAs are always handled as pairs, the following happens at the SA level:

  * Initiator starts the exchange at I1
  * Responder installs new SA pair at R1
  * Initiator installs new SA pair at I2
  * Responder removes old SA pair at R2
  * Initiator removes old SA pair at I3

This makes sure SAs get installed/removed overlapping during rekeying. However,
to avoid any packet loss, it is crucial that the new outbound SA gets
activated at the correct position:

  * as exchange initiator, in I2
  * as exchange responder, in R2

This should guarantee that we don't use the new outbound SA before the peer
could install its corresponding inbound SA.

The new parameter allows the kernel backend to install the new SA with
appropriate priorities, i.e. it should:

  * as exchange inititator, have the new outbound SA installed with higher
    priority than the old SA
  * as exchange responder, have the new outbound SA installed with lower
    priority than the old SA

While we could split up the SA installation at the responder, this approach
has another advantage: it allows the kernel backend to switch SAs based on
other criteria, for example when receiving traffic on the new inbound SA.
2013-06-11 15:58:48 +02:00
Tobias Brunner 31a416a5b2 Removed stray *_plugin_create() declarations from header files 2013-06-11 11:18:19 +02:00
Tobias Brunner 460488b180 eap-radius: Do initialization in a plugin feature callback 2013-06-11 11:18:19 +02:00
Tobias Brunner 49d7a98f47 Refactored plugin-loader with improved dependency resolution
With the new implementation the plugins don't have to be listed in any
special order, dependencies are properly resolved.  The order only
matters if two plugins provide the same feature.
2013-06-11 11:18:19 +02:00
Tobias Brunner facc781500 android-log: Use plugin features 2013-06-11 11:18:19 +02:00
Tobias Brunner df60999b5f android-dns: Use plugin features to register attribute handler 2013-06-11 11:18:19 +02:00
Tobias Brunner e183a6c36d maemo: Use plugin features 2013-06-11 11:18:19 +02:00
Tobias Brunner 6d766925b2 medsrv: Use plugin features with dependency on database implementation 2013-06-11 11:18:19 +02:00
Tobias Brunner da7c3f8900 medcli: Use plugin features with dependency on database implementation 2013-06-11 11:18:19 +02:00
Tobias Brunner d0ccae4dd2 whitelist: Use plugin features to register listener 2013-06-11 11:18:19 +02:00
Tobias Brunner 49d333ac67 updown: Use plugin features to register listener and attribute handler 2013-06-11 11:18:19 +02:00
Tobias Brunner 819cb66298 unity: Use plugin features to register listener and attribute handler/provider 2013-06-11 11:18:19 +02:00
Tobias Brunner b033d59d1e unit-tester: Use plugin features 2013-06-11 11:18:19 +02:00
Tobias Brunner e1360331e9 uci: Use plugin features to register backend and credential set 2013-06-11 11:18:19 +02:00
Tobias Brunner 36f27c1506 systime-fix: Use plugin features to register validator 2013-06-11 11:18:19 +02:00
Tobias Brunner c1f5841bb2 smp: Use plugin features 2013-06-11 11:18:19 +02:00
Tobias Brunner 64b0c2575f radattr: Use plugin features to register listener 2013-06-11 11:18:18 +02:00
Tobias Brunner d94c0913b1 lookip: Use plugin features to register listener 2013-06-11 11:18:18 +02:00
Tobias Brunner dfe97d63d8 led: Use plugin features to register listener 2013-06-11 11:18:18 +02:00
Tobias Brunner 21d094f402 ipseckey: Allow en-/disabling at runtime using plugin reload feature 2013-06-11 11:18:18 +02:00
Tobias Brunner 82d3f5122b ipseckey: Use plugin features and depend on RESOLVER
Also fixed a double-free of the resolver instance.
2013-06-11 11:18:18 +02:00
Tobias Brunner 924196d6d4 ha: Use plugin features to register listeners and attribute provider 2013-06-11 11:18:18 +02:00
Tobias Brunner e5f4b3ca5b farp: Use plugin features to register listener 2013-06-11 11:18:17 +02:00
Tobias Brunner aa71f5f515 error-notify: Use plugin features to register listener 2013-06-11 11:18:17 +02:00
Tobias Brunner 57c29f6895 duplicheck: Use plugin features to register listener 2013-06-11 11:18:17 +02:00
Tobias Brunner 6c51ff745c coupling: Use plugin features and soft depend on SHA1 2013-06-11 11:18:17 +02:00
Tobias Brunner 0c52198bc1 certexpire: Use plugin features to register listener 2013-06-11 11:18:17 +02:00
Tobias Brunner 94ca7252c1 addrblock: Use plugin features with soft dependency on X.509 decoding 2013-06-11 11:18:17 +02:00
Tobias Brunner 12459a4dc8 dhcp: Use plugin features with dependency to RNG implementation 2013-06-11 11:18:17 +02:00
Tobias Brunner 11a27ea28f sql: Use plugin features with dependency to database backend 2013-06-11 11:18:17 +02:00
Tobias Brunner 270e425b24 Socket plugins soft depend on the kernel-ipsec plugin feature
On most platforms calls to methods to bypass the IKE sockets and enabling
UDP decapsulation are required.
2013-06-11 11:18:17 +02:00
Tobias Brunner de42bf35f9 Converted test for recursive mutex_t 2013-06-11 11:03:11 +02:00
Tobias Brunner 4e67f19528 Converted tests for chunk_t 2013-06-11 11:03:11 +02:00
Tobias Brunner e09461bf77 Converted and added tests for hashtable_t 2013-06-11 11:03:10 +02:00
Tobias Brunner 0298be5705 Converted tests for identification_t 2013-06-11 11:03:10 +02:00
Tobias Brunner 3cbacad40b Remove obsolete enumerator/linked_list tests in unit_tester plugin 2013-06-11 11:03:10 +02:00
Emanuil Hristov 2ce403438f updown: pass IKE_SA unique ID in PLUTO_UNIQUEID 2013-05-16 10:13:22 +02:00
Tobias Brunner 6040eff900 stroke: Add second password if provided 2013-05-08 15:02:41 +02:00
Tobias Brunner 1c080407b2 stroke: Fail silently if another builder calls PW callback after giving up
Also reduced the number of tries to 3.
2013-05-08 15:02:41 +02:00
Tobias Brunner 4a64c3e9a0 stroke: Cache passwords so the user is not prompted multiple times for the same password
To verify/decrypt a PKCS#12 container a password might be needed
multiple times.  If it was entered correctly we don't want to bother the
user again with another password prompt.
The passwords for MAC creation and encryption could be different so the
user might be prompted multiple times after all.
2013-05-08 15:02:41 +02:00
Tobias Brunner e240b03e68 stroke: Fix prompt and error messages in passphrase callback 2013-05-08 15:02:41 +02:00
Tobias Brunner 7971278c92 stroke: Load credentials from PKCS#12 files (P12 token) 2013-05-08 15:02:41 +02:00
Tobias Brunner 87692be215 Load any type (RSA/ECDSA) of public key via left|rightsigkey 2013-05-07 17:08:31 +02:00