Martin Willi
c64a4b4f8e
Implemented post-authentication certificate handling for IKEv1
2012-03-20 17:31:13 +01:00
Martin Willi
9ad5b8fa95
Cleanup CERT payload constructors
2012-03-20 17:31:13 +01:00
Martin Willi
0bcdb8e571
Implemented pre-authentication certificate handling for IKEv1
2012-03-20 17:31:13 +01:00
Martin Willi
8c33850615
Added task types for IKEv1 certificate handling
2012-03-20 17:31:13 +01:00
Martin Willi
6ccabe2561
Reverted ike_cert tasks to IKEv2 only, we use dedicated IKEv1 tasks
2012-03-20 17:31:13 +01:00
Tobias Brunner
9f80110bc6
Install SAs with UDP encapsulation during Quick Mode.
2012-03-20 17:31:13 +01:00
Martin Willi
aaa8f88906
Fix support for plain RSA authentication in IKEv1, both as initiator and responder
2012-03-20 17:31:13 +01:00
Martin Willi
a974700fc0
Fix referencing of multiple CERTREQ payload with IKEv1, other cleanups
2012-03-20 17:31:12 +01:00
Clavister OpenSource
d82a68642d
XAUTH additions for certificates.
2012-03-20 17:31:12 +01:00
Clavister OpenSource
a874a1f50b
signature payload handling.
2012-03-20 17:31:12 +01:00
Clavister OpenSource
8ad5cd1f6c
certificate tasks added to passive list for responder
2012-03-20 17:31:12 +01:00
Clavister OpenSource
7d9269bfce
certificate handling for XAuth responder.
2012-03-20 17:31:11 +01:00
Clavister OpenSource
a846be3116
keymat: derive_ike_keys updated with XAUTH RSA:s
2012-03-20 17:31:11 +01:00
Clavister OpenSource
07abb470c6
IKEv1: Added basic support for INFORMATIONAL exchange types, and for NOTIFY_V1 messages in the 3rd message in quick_mode.
2012-03-20 17:31:11 +01:00
Tobias Brunner
8cb6f4f979
Don't stop processing tasks if one returns SUCCESS.
...
Only send a response if at least one of the tasks requires it.
2012-03-20 17:31:11 +01:00
Clavister OpenSource
4394d96844
IKEv1 XAuth: Added a "NULL" XAuth plugin which sends a hardcoded user/pass, and blindly accepts whatever user/pass is sent it. Changed the xauth_request task to use this new plugin. Add --enable-xauth-null to your configure line to build with the new plugin.
2012-03-20 17:31:11 +01:00
Clavister OpenSource
9c5366446a
IKEv1 XAuth: Added plugin support for XAuth, which allows us to have plugins to talk to servers with different quirks for XAuth authentication.
2012-03-20 17:31:11 +01:00
Tobias Brunner
3bf0be6b08
Add NAT-OA payloads during Quick Mode if transport mode is used.
...
We don't parse them currently, as the Linux kernel does not need them to fix
the IP header checksum.
2012-03-20 17:31:11 +01:00
Tobias Brunner
29b0cb328a
Negotiate UDP encapsulation during Quick Mode if NAT is detected.
2012-03-20 17:31:10 +01:00
Tobias Brunner
1cc4ec46cf
Task added for IKEv1 NAT detection.
...
There is already support for both Main and Aggressive Mode.
2012-03-20 17:31:10 +01:00
Tobias Brunner
61e2a1ad8a
Create negotiated hasher earlier during Main Mode so it is available for building NAT-D payloads.
2012-03-20 17:31:10 +01:00
Tobias Brunner
4ace4daf0c
Added a function to keymat_v1 to create the hasher earlier than during key derivation.
...
The negotiated hasher is also used to generate NAT-D payloads.
2012-03-20 17:31:10 +01:00
Clavister OpenSource
c5dc9d3383
IKEv1 XAuth: Moving the state change to IKE_CONNECTED until after XAuth exchanges are complete.
2012-03-20 17:31:10 +01:00
Clavister OpenSource
02c36eeb86
IKEv1 XAuth: Adding "initiate" flag parameter to the initiate_xauth method, signalling whether or not to call the task_manager->initiate method after queueing the task.
2012-03-20 17:31:10 +01:00
Tobias Brunner
06d29be714
Handle IKEv1 NAT-T vendor ID payload (only RFC 3947 for now).
2012-03-20 17:31:10 +01:00
Tobias Brunner
1e97783c99
Added payloads for IKEv1 NAT-Traversal negotiation.
2012-03-20 17:31:09 +01:00
Clavister OpenSource
3fa8db8b59
IKEv1 XAuth: Clean up debug prints in xauth_request task.
2012-03-20 17:31:09 +01:00
Clavister OpenSource
735fa3e5b9
IKEv1 XAuth: Remove XAuth task from the passive task list for ID_PROT.
2012-03-20 17:31:09 +01:00
Clavister OpenSource
0ea77083bb
Revert "IKEv1 XAuth: Added new MIGRATE status type to status_t."
...
This reverts commit b57df8310a867a0a65abf17279bf1b6e6bb2f5d3.
Conflicts:
src/libcharon/sa/task_manager_v1.c
2012-03-20 17:31:09 +01:00
Clavister OpenSource
c961d110ab
IKEv1 XAuth + CfgMode: Added ability to process CfgMode messages in the xauth task. Migrated away from using the MIGRATE method to switch queues.
2012-03-20 17:31:09 +01:00
Clavister OpenSource
ef2eac7fb0
IKEv1 XAuth: Change the main_mode task to use the new initiate_xauth job instead of the old MIGRATE method.
2012-03-20 17:31:09 +01:00
Clavister OpenSource
56fb0f0b3a
IKEv1 XAuth: Added XAuthResp authentication modes.
2012-03-20 17:31:09 +01:00
Clavister OpenSource
65359ccbbc
IKEv1 XAuth: Add "initiate xauth" method, which adds the xauth task into the queue for initiation.
2012-03-20 17:31:09 +01:00
Tobias Brunner
9eefb5f9b4
Use quiet generator when creating IKEv1 message hashes.
...
This avoids cluttering the log with duplicate log messages when
generating and especially confusing log messages when parsing
authenticated messages.
2012-03-20 17:31:09 +01:00
Tobias Brunner
4cfd0db854
Respond with NO_PROPOSAL_CHOSEN, if we don't find an ike_cfg.
2012-03-20 17:31:09 +01:00
Tobias Brunner
6be8d33daa
Don't respond to malformed INFORMATIONAL_V1 messages with another INFORMATIONAL_V1 exchange.
2012-03-20 17:31:08 +01:00
Tobias Brunner
37639e94fb
Handle invalid IKEv1 hashes more specifically.
2012-03-20 17:31:08 +01:00
Tobias Brunner
29a5e0707e
Handle unsupported IKEv1 exchange types more specifically.
2012-03-20 17:31:08 +01:00
Tobias Brunner
b235e69cde
Send an INFORMATIONAL message on IKEv1 parse errors.
2012-03-20 17:31:08 +01:00
Tobias Brunner
983e852af8
Handle INFORMATIONAL_V1 messages when no keys have been derived yet.
...
This allows to gracefully process the INFORMATIONAL_V1 message rules which
require the payloads to be encrypted and thus the exchange to be
authenticated with a HASH payload. If such an exchange is now initiated
before the ISAKMP_SA is established, the message is simply sent unencrypted
and without HASH payload.
2012-03-20 17:31:08 +01:00
Tobias Brunner
e6732003f4
Error reporting for invalid IKEv2 responses fixed.
2012-03-20 17:31:08 +01:00
Tobias Brunner
7519106d07
Set request flag to proper value for IKEv1 messages before parsing them.
2012-03-20 17:31:08 +01:00
Tobias Brunner
1960312cfd
Avoid parsing retransmits we already responded to.
...
Decryption will fail as we already moved the IV when we sent the
response. Without this change, encrypted retransmits would have been
discarded during parsing already.
2012-03-20 17:31:08 +01:00
Tobias Brunner
68c6863bbb
Moved main part of message processing to task managers.
...
This will allow individual error handling for each IKE version and should
allow better handling of IKEv1 retransmits.
2012-03-20 17:31:08 +01:00
Tobias Brunner
44ff1153e8
Addded ike_sa_t.set_statistic to set timestamps from task manager.
2012-03-20 17:31:08 +01:00
Clavister OpenSource
52ac2cebe2
IKEv1 XAuth: Fix XAuth task so that it reinitiates.
2012-03-20 17:31:07 +01:00
Clavister OpenSource
e63cb7f816
Revert "IKEv1 XAuth: Temporarilty add an "initiate_later" flag to the task manager. When set to TRUE it will cause "initiate" to be called when the current process_response call is finished. This change should be reverted once we have a better method in place."
...
This reverts commit c6c28f4ac522dd8afb457847bca79eee77f78706.
Revert "IKEv1 XAuth: Added temporary "initiate_xauth" public method to ike_sa_t. This allows us to initiate an XAuth password authentication exchange after responding to the final message of Main Mode. This change should be reverted once we have a better method to initiate this exchange."
This reverts commit 5529dc50477e25df9dd5f3c442bb1521c0baf225.
2012-03-20 17:31:07 +01:00
Clavister OpenSource
2c49c53186
IKEv1 XAuth: Fix main mode to work with XAuth PSK.
2012-03-20 17:31:07 +01:00
Martin Willi
a2f8fc9711
Use a dedicated IKEv1 vendor ID task to fix using IKEv2 payloads in IKEv1
2012-03-20 17:31:07 +01:00
Martin Willi
abf9784786
Pass concrete auth_method to key derivation, as we have that as a responder
2012-03-20 17:30:53 +01:00