Reto Buerki
6c237edb9a
Remove netlink proxy from TKM kernel interface
...
The TKM is now able to manage simple child SAs, so there is no need for
the netlink proxy anymore.
2013-03-19 15:23:47 +01:00
Reto Buerki
a642e3ba27
Avoid proxy for bypass_socket, enable_udp_decap
...
This is in preparation for the removal of the netlink kernel proxy. The
code is copied as-is from the kernel_netlink_ipsec plugin.
2013-03-19 15:23:47 +01:00
Reto Buerki
8f1dfb3d9e
chunk_map: Store key, value pair in entry_t struct
...
To make the chunk map more robust it now stores a clone of the data
chunk given on insertion. The entry struct is needed to properly free
the allocated chunk after use.
2013-03-19 15:23:47 +01:00
Reto Buerki
3972769690
Call ike_isa_auth_psk in listener authorize hook
...
This exchange initiates the AUTH verification in the TKM.
2013-03-19 15:23:47 +01:00
Reto Buerki
9df5645623
listener: Register message hook
...
Use the message hook to save the AUTHENTICATION payload of an incoming
IKE_AUTH message.
The AUTH payload will be passed on to the TKM ike_isa_auth operation in
the authorize hook.
2013-03-19 15:23:47 +01:00
Reto Buerki
071e792a85
keymat: Add AUTH payload setter/getter functions
...
These functions are used in the TKM specific bus listener to
store/retrieve the AUTH payload chunk in the message/authorize hooks.
2013-03-19 15:23:47 +01:00
Reto Buerki
d0ce4116b0
Register TKM bus listener in charon-tkm
2013-03-19 15:23:47 +01:00
Reto Buerki
c6c8d74026
Add TKM specific bus listener skeleton
...
This listener gets informed about IKE authorization rounds and will be
used to call ike_isa_auth on a given ISA.
2013-03-19 15:23:47 +01:00
Reto Buerki
d91acfdb5d
Add ISA context id getter to TKM keymat
2013-03-19 15:23:47 +01:00
Reto Buerki
cdd4d73ff5
keymat: Acquire AE context ID on initialization
2013-03-19 15:23:47 +01:00
Reto Buerki
c755645032
Add TKM_CTX_AE (Authenticated Endpoint context)
2013-03-19 15:23:47 +01:00
Reto Buerki
bf1034a776
keymat: Acquire ISA context ID on initialization
2013-03-19 15:23:47 +01:00
Reto Buerki
7fb3e5ed10
Add TKM_CTX_ISA (IKE SA context)
2013-03-19 15:23:46 +01:00
Reto Buerki
fa22fc2419
Use remote PSK signature computed by TKM
2013-03-19 15:23:46 +01:00
Reto Buerki
e7a497c307
keymat: Check for aes256-sha512 in derive_ike_keys
...
Return FALSE if peers try to use other algorithm combinations.
2013-03-19 15:23:46 +01:00
Reto Buerki
e285544be2
Factor out AEAD transform creation
...
Introduce static aead_create_from_keys function to initialize AEAD
transforms from key chunks.
2013-03-19 15:23:46 +01:00
Reto Buerki
4be8471fab
Add keymat IKE key derivation test case
2013-03-19 15:23:46 +01:00
Reto Buerki
3290b9995c
keymat: Create inbound and outbound AEAD transforms
...
Create and initialize AEAD transforms with keys derived by the TKM.
Return these transforms in the get_aead function.
IKE keys used by charon are derived by TKM now.
2013-03-19 15:23:46 +01:00
Reto Buerki
4c38878db5
keymat: Extract enc,inc algorithms from proposal
...
Extract encryption and integrity algorithms from proposal and check them
before deriving IKE keys.
2013-03-19 15:23:46 +01:00
Reto Buerki
fc828aaac6
keymat: Call TKM Isa_Create procedure
2013-03-19 15:23:46 +01:00
Reto Buerki
0327fac6b6
Implement chunk_to_sequence function
...
This function converts a given chunk to a variable-length byte sequence.
2013-03-19 15:23:46 +01:00
Reto Buerki
53232d5883
Implement sequence_to_chunk function
...
This function converts a given TKM variable-length byte sequence to
chunk.
2013-03-19 15:23:46 +01:00
Reto Buerki
ebe592a393
id_manager: Use calloc instead of malloc
...
This way we don't need to manually initialize the slot status; free
slots are now indicated by 0 though.
2013-03-19 15:23:46 +01:00
Reto Buerki
1ee792f9ea
Use ikev2 keymat proxy
...
Forward incoming calls to default ikev2 keymat instance. This is needed
to make a stepwise migration to TKM keymat possible. It will be removed
once the corresponding parts are implemented in the TKM.
2013-03-19 15:23:45 +01:00
Reto Buerki
5b3bcdfada
Add skeleton for TKM keymat variant
2013-03-19 15:23:45 +01:00
Reto Buerki
84967b4439
id_manager: Use limits given by TKM
2013-03-19 15:23:45 +01:00
Reto Buerki
50e35e66d2
Pass context limits on to id manager
2013-03-19 15:23:45 +01:00
Reto Buerki
ef5372395a
Request limits from TKM on init
2013-03-19 15:23:45 +01:00
Reto Buerki
7aa573a50e
id_manager: Use array of bool instead of list
...
Instead of storing the acquired context ids in a linked list, use an
array of booleans for the job. A boolean value of true in the array
designates an available context id.
2013-03-19 15:23:45 +01:00
Reto Buerki
49c513c1d9
Use id manager to acquire DH context id
2013-03-19 15:23:45 +01:00
Reto Buerki
65a777f7fb
Add TKM_CTX_DH (Diffie-Hellman context) to id manager
2013-03-19 15:23:45 +01:00
Reto Buerki
c38459d77d
Use id manager to acquire nonce context id
2013-03-19 15:23:45 +01:00
Reto Buerki
f3cd7f50de
Add initial TKM Diffie-Hellman implementation
...
The tkm_diffie_hellman_t plugin acquires a DH context from the Trusted
Key Manager and uses it to get a DH public value and the calculated
shared secret. Proper context handling is still missing though, the
plugin currently uses context ID 1.
The get_shared_secret function will be removed as soon as the TKM
specific keymat is ready.
2013-03-19 15:23:45 +01:00
Reto Buerki
d51305aa3f
charon-tkm: Register tkm nonce generator
2013-03-19 15:23:45 +01:00
Reto Buerki
8e95bf455d
tkm_nonceg: Return nonce generated by TKM
2013-03-19 15:23:45 +01:00
Reto Buerki
3d2746309e
Initialize TKM client library in tkm.c
2013-03-19 15:23:45 +01:00
Reto Buerki
559fe48c50
Introduce TKM specific charon daemon (charon-tkm)
...
Analogous to charon-nm the charon-tkm daemon is a specialized charon
instance used in combination with the trusted key manager (TKM) written
in Ada.
The charon-tkm is basically a copy of the charon-nm code which will
register it's own TKM specific plugins.
The daemon binary is built using the gprbuild utility. This is needed
because it uses the tkm-rpc Ada library and consequently the Ada
runtime. gprbuild takes care of the complete binding and linker steps
required to properly initialize the Ada runtime.
2013-03-19 15:23:45 +01:00
Reto Buerki
b32e732b2f
Check kvm command existence in start-testing
2013-02-22 19:22:08 +01:00
Reto Buerki
88bffacfdc
Drop vim swap file
2013-01-17 16:55:04 +01:00
Reto Buerki
f3db566983
Enforce reception of multicast traffic on virbr[1|2]
...
This is needed to let the ha/both-active test pass.
2013-01-17 16:55:04 +01:00
Reto Buerki
41943e9c1b
Make core dumps work
...
Core dumps are written to the /var/local/dumps directory.
2013-01-17 16:55:04 +01:00
Reto Buerki
e3a3013323
Append seconds to TESTDATE
...
This avoids 'file exists' warnings when running tests multiple times in
one minute.
2013-01-17 16:55:04 +01:00
Reto Buerki
2c4954ad24
Switch to 'mapped' access mode for hostfs
...
Passthrough mode only works as expected when running as root. On
Debian/Ubuntu systems qemu runs as user 'libvirt-qemu' and group 'kvm'
so all shared files must be chowned to grant access from guests.
Symlinks created on the host are still problematic because the Plan 9
filesystem has no direct notion of symbolic links, see [1].
[1] - http://ericvh.github.com/9p-rfc/rfc9p2000.u.html
2013-01-17 16:55:04 +01:00
Reto Buerki
677795c3e7
Make guest ACPI shutdown work
2013-01-17 16:55:03 +01:00
Reto Buerki
c25f850601
Drop obsolete Gentoo dhcpd init script
2013-01-17 16:55:03 +01:00
Reto Buerki
530f7b8421
No need to enable ip_forward in pretest files
...
It is enabled by default now.
2013-01-17 16:55:03 +01:00
Reto Buerki
49b1655ae1
Auto-create symlink to testing directory in workdir
2013-01-17 16:55:03 +01:00
Reto Buerki
aafc0a1799
Make test scripts callable from any path
2013-01-17 16:54:58 +01:00
Reto Buerki
0593b6c975
Export compile directory to guests
...
Use 9p over virtio to share files on the host with the guest domains.
The files are accessible in the guests /hostfs directory.
2013-01-17 16:54:58 +01:00
Reto Buerki
48ea1d8b0b
Create all images in $BUILDDIR/images
2013-01-17 16:54:58 +01:00
Reto Buerki
482d3ec9ff
Also restore 'default' host configuration
2013-01-17 16:54:58 +01:00
Reto Buerki
58e0b386ea
Add eth1 NIC to alice domain
2013-01-17 16:54:58 +01:00
Reto Buerki
602ba2f6d1
Adjust ikev2/farp test to qemu network interfaces
2013-01-17 16:54:58 +01:00
Reto Buerki
23382d2e00
Directly use STRONGSWANHOSTS in build-guestimages
...
Drop support for building guests specified on the command line; creating
all images unconditionally is very fast now thanks to qcow2.
2013-01-17 16:54:57 +01:00
Reto Buerki
12f1ff3a0e
Drop SELECTEDTESTSONLY support
2013-01-17 16:54:57 +01:00
Reto Buerki
50fb9b8457
Use exit trap to kill open ssh sessions
2013-01-17 16:54:57 +01:00
Reto Buerki
7fa92110e8
Adjust ikev2/dhcp tests to qemu network interfaces
2013-01-17 16:54:57 +01:00
Reto Buerki
b351656cc7
Disable checksum offloading on moon's eth1 interface
...
Disable checksum offloading on eth1 because it does not currently work
with virtio and the isc-dhcp-server running on venus, see [1].
[1] - https://bugs.mageia.org/show_bug.cgi?id=1243
2013-01-17 16:54:57 +01:00
Reto Buerki
63178a8830
Add ethtool to debootstrap package includes
2013-01-17 16:54:56 +01:00
Reto Buerki
82499010eb
stop-testing requires virsh
2013-01-17 16:54:56 +01:00
Reto Buerki
bd4c6122a4
Add ssh config to guest root account
2013-01-17 16:54:56 +01:00
Reto Buerki
cbe031d755
Make root image a clone of the base image
2013-01-17 16:54:56 +01:00
Reto Buerki
76ccd25a05
Add expect-connection guest image script
...
This script can be used in pretest.dat files to wait until an IPsec
connection becomes available. This avoids unconditional sleeps and
improves test performance.
The ipv6 tests have been updated to use the expect-connection script.
2013-01-17 16:54:55 +01:00
Reto Buerki
44e83859e0
Rename build-umlhostfs script to build-guestimages
2013-01-17 16:54:55 +01:00
Reto Buerki
90dd71e41c
Rename build-umlrootfs script to build-rootimg
2013-01-17 16:54:55 +01:00
Reto Buerki
258cbd40cf
Unify naming of base,root image settings
2013-01-17 16:54:55 +01:00
Reto Buerki
aba43136c2
Drop now obsolete UML helper functions
2013-01-17 16:54:55 +01:00
Reto Buerki
345dba0de4
Exclude iptables from debootstrap
2013-01-17 16:54:55 +01:00
Reto Buerki
74c0839ad6
Run on_exit commands in FILO order
2013-01-17 16:54:54 +01:00
Reto Buerki
97265abaf0
Inform kernel about /dev/nbd0 partition changes
2013-01-17 16:54:54 +01:00
Reto Buerki
b24d3ed5fc
Test availability of required commands
2013-01-17 16:54:54 +01:00
Reto Buerki
f241f46d88
Exit make-testing on script failure
2013-01-17 16:54:54 +01:00
Reto Buerki
8ed98c1373
Switch from raw images to qcow2 format
...
This allows to use minimal copy-on-write clones of the base image as
guest images, which in turn saves a lot of disk space.
2013-01-17 16:54:54 +01:00
Reto Buerki
7fa2719185
Set default TESTDIR to /srv/strongswan-testing
2013-01-17 16:54:54 +01:00
Reto Buerki
bc3cc45e8b
Drop unneeded TZUML variable
2013-01-17 16:54:53 +01:00
Reto Buerki
043caec129
Set BUILDDIR to $TESTDIR/build
2013-01-17 16:54:53 +01:00
Reto Buerki
619c5430b8
Drop unneeded UMLKERNEL variable
2013-01-17 16:54:53 +01:00
Reto Buerki
bf48ee33e5
Rename UMLTESTDIR variable to TESTDIR
2013-01-17 16:54:53 +01:00
Reto Buerki
36a3fe90d8
Drop cecho functions
2013-01-17 16:54:53 +01:00
Reto Buerki
8cb4628ff9
Use log_action function in do-tests script
2013-01-17 16:54:53 +01:00
Reto Buerki
1102a8c1cc
Remove executable bit from testing.conf
2013-01-17 16:54:52 +01:00
Reto Buerki
9b3316ed27
Use qemu/KVM virtualization instead of UML
...
Guest and network configuration is setup using the libvirt
virtualization API. The [start|stop]_testing scripts have been updated
accordingly.
qemu/KVM does not currently support a hostfs, so the shared build tree
mount has been dropped for now.
2013-01-17 16:54:52 +01:00
Reto Buerki
f9df3d06b5
Rename build-umlkernel script to build-guestkernel
2013-01-17 15:22:11 +01:00
Reto Buerki
62a277cfae
Move ROOTFSDIR declaration to testing.conf
2013-01-17 15:22:11 +01:00
Reto Buerki
ee1cd88c7a
Prefix all recipes with a number
2013-01-17 15:22:11 +01:00
Reto Buerki
0cc4063799
Use do_on_exit() in build scripts for cleanup
2013-01-17 15:22:11 +01:00
Reto Buerki
9a045eef8e
Provide do_on_exit() function
...
This function allows to register an exit action which executes when the
calling script terminates.
2013-01-17 15:22:11 +01:00
Reto Buerki
7c2ef58e86
Import testing.conf file in function.sh
...
This is needed to have access to $LOGFILE and possibly other config
settings.
2013-01-17 15:22:10 +01:00
Reto Buerki
261cf0e395
Drop build-hostconfig script
...
Use processed host configurations directly instead.
2013-01-17 15:22:10 +01:00
Reto Buerki
2d1577d661
Update build-umlhostfs script to new log format
2013-01-17 15:22:10 +01:00
Reto Buerki
bf3ff0e585
Update build-umlrootfs script to new log format
2013-01-17 15:22:10 +01:00
Reto Buerki
5828e434bd
Update build-umlkernel script to new log format
2013-01-17 15:22:10 +01:00
Reto Buerki
fb2aab414a
Use red color in die() function
...
This is the function where red color SHOULD be used.
2013-01-17 15:22:10 +01:00
Reto Buerki
b86866579a
Move execute wrappers to function.sh file
2013-01-17 15:22:09 +01:00
Reto Buerki
9574bf7a5e
Use log_action, log_status in build-baseimage script
2013-01-17 15:22:09 +01:00
Reto Buerki
c120f25e60
Provide log_action and log_status functions
...
These two functions are used to log action descriptions and the
corresponding command exit status in a consistent way.
2013-01-17 15:22:09 +01:00
Reto Buerki
3c9df38c5e
Add chroot() helper function
2013-01-17 15:22:09 +01:00
Reto Buerki
3b75c7ddc8
Use execute wrapper to disable root password
2013-01-17 15:22:09 +01:00
Reto Buerki
6022f37aec
Simplify test starting and stopping logic
...
Reduce the coupling of the different scripts.
make-testing : Build the testing environment
start-testing : Start switches and guests
do-tests : Run tests
stop-testing : Stop switches and guests
2013-01-17 15:22:09 +01:00
Reto Buerki
beff82dd98
Adjust strongSwan version handling in HTML output
2013-01-17 15:22:08 +01:00