medsrv/medcli: Remove prototypical medsrv web application and plugins
This was from a student project that has never been developed further. And similar to the manager web application it lacks all sorts of modern standards. So just remove it and the two plugins it relied on. The test scenario is renamed to avoid confusion (neither of the two p2pnat scenarios uses medsrv/medcli).
This commit is contained in:
@@ -20,7 +20,6 @@ options = \
|
||||
options/imcv.opt \
|
||||
options/imv_policy_manager.opt \
|
||||
options/iptfs.opt \
|
||||
options/medsrv.opt \
|
||||
options/pki.opt \
|
||||
options/pool.opt \
|
||||
options/starter.opt \
|
||||
|
||||
@@ -1,27 +0,0 @@
|
||||
medsrv.database =
|
||||
Mediation server database URI. If it contains a password, make
|
||||
sure to adjust the permissions of the config file accordingly.
|
||||
|
||||
medsrv.debug = no
|
||||
Debugging in mediation server web application.
|
||||
|
||||
medsrv.dpd = 5m
|
||||
DPD timeout to use in mediation server plugin.
|
||||
|
||||
medsrv.load =
|
||||
Plugins to load in mediation server plugin.
|
||||
|
||||
medsrv.password_length = 6
|
||||
Minimum password length required for mediation server user accounts.
|
||||
|
||||
medsrv.rekey = 20m
|
||||
Rekeying time on mediation connections in mediation server plugin.
|
||||
|
||||
medsrv.socket =
|
||||
Run Mediation server web application statically on socket.
|
||||
|
||||
medsrv.threads = 5
|
||||
Number of thread for mediation service web application.
|
||||
|
||||
medsrv.timeout = 15m
|
||||
Session timeout for mediation service.
|
||||
+18
-39
@@ -290,8 +290,6 @@ ARG_ENABL_SET([conftest], [enforce Suite B conformance test framework.])
|
||||
ARG_ENABL_SET([fast], [enable libfast (FastCGI Application Server w/ templates.])
|
||||
ARG_ENABL_SET([fuzzing], [enable fuzzing scripts (found in directory fuzz).])
|
||||
ARG_ENABL_SET([libipsec], [enable user space IPsec implementation.])
|
||||
ARG_ENABL_SET([medcli], [enable mediation client configuration database plugin.])
|
||||
ARG_ENABL_SET([medsrv], [enable mediation server web frontend and daemon plugin.])
|
||||
ARG_ENABL_SET([nm], [enable NetworkManager backend.])
|
||||
ARG_DISBL_SET([pki], [disable pki certificate utility.])
|
||||
ARG_DISBL_SET([scripts], [disable additional utilities (found in directory scripts).])
|
||||
@@ -473,15 +471,6 @@ if test x$tnccs_11 = xtrue -o x$tnc_ifmap = xtrue; then
|
||||
xml=true
|
||||
fi
|
||||
|
||||
if test x$medsrv = xtrue; then
|
||||
mediation=true
|
||||
fast=true
|
||||
fi
|
||||
|
||||
if test x$medcli = xtrue; then
|
||||
mediation=true
|
||||
fi
|
||||
|
||||
if test x$ruby_gems_install = xtrue; then
|
||||
ruby_gems=true
|
||||
fi
|
||||
@@ -1528,7 +1517,6 @@ pool_plugins=
|
||||
attest_plugins=
|
||||
pki_plugins=
|
||||
scripts_plugins=
|
||||
medsrv_plugins=
|
||||
nm_plugins=
|
||||
cmd_plugins=
|
||||
aikgen_plugins=
|
||||
@@ -1548,26 +1536,26 @@ ADD_PLUGIN([unbound], [s charon scripts])
|
||||
ADD_PLUGIN([ldap], [s charon pki scripts nm cmd])
|
||||
ADD_PLUGIN([pkcs11], [s charon pki nm cmd])
|
||||
ADD_PLUGIN([tpm], [p charon pki nm cmd])
|
||||
ADD_PLUGIN([aesni], [s charon swanctl pki scripts medsrv attest nm cmd aikgen])
|
||||
ADD_PLUGIN([aesni], [s charon swanctl pki scripts attest nm cmd aikgen])
|
||||
ADD_PLUGIN([aes], [s charon swanctl pki scripts nm cmd])
|
||||
ADD_PLUGIN([des], [s charon swanctl pki scripts nm cmd])
|
||||
ADD_PLUGIN([blowfish], [s charon swanctl pki scripts nm cmd])
|
||||
ADD_PLUGIN([rc2], [s charon swanctl pki scripts nm cmd])
|
||||
ADD_PLUGIN([sha2], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fc])
|
||||
ADD_PLUGIN([sha3], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fc])
|
||||
ADD_PLUGIN([sha1], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fc])
|
||||
ADD_PLUGIN([sha2], [s charon swanctl pki scripts attest nm cmd aikgen fc])
|
||||
ADD_PLUGIN([sha3], [s charon swanctl pki scripts attest nm cmd aikgen fc])
|
||||
ADD_PLUGIN([sha1], [s charon swanctl pki scripts attest nm cmd aikgen fc])
|
||||
ADD_PLUGIN([md4], [s charon swanctl pki nm cmd])
|
||||
ADD_PLUGIN([md5], [s charon swanctl pki scripts attest nm cmd aikgen])
|
||||
ADD_PLUGIN([mgf1], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fc])
|
||||
ADD_PLUGIN([rdrand], [s charon swanctl pki scripts medsrv attest nm cmd aikgen])
|
||||
ADD_PLUGIN([random], [s charon swanctl pki scripts medsrv attest nm cmd aikgen])
|
||||
ADD_PLUGIN([mgf1], [s charon swanctl pki scripts attest nm cmd aikgen fc])
|
||||
ADD_PLUGIN([rdrand], [s charon swanctl pki scripts attest nm cmd aikgen])
|
||||
ADD_PLUGIN([random], [s charon swanctl pki scripts attest nm cmd aikgen])
|
||||
ADD_PLUGIN([nonce], [s charon nm cmd aikgen])
|
||||
ADD_PLUGIN([x509], [s charon swanctl pki scripts attest nm cmd aikgen fd fc])
|
||||
ADD_PLUGIN([revocation], [s charon pki nm cmd])
|
||||
ADD_PLUGIN([constraints], [s charon pki nm cmd])
|
||||
ADD_PLUGIN([acert], [s charon])
|
||||
ADD_PLUGIN([pubkey], [s charon swanctl pki cmd aikgen])
|
||||
ADD_PLUGIN([pkcs1], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fd fc])
|
||||
ADD_PLUGIN([pkcs1], [s charon swanctl pki scripts attest nm cmd aikgen fd fc])
|
||||
ADD_PLUGIN([pkcs7], [s charon swanctl pki scripts nm cmd])
|
||||
ADD_PLUGIN([pkcs12], [s charon swanctl pki scripts cmd])
|
||||
ADD_PLUGIN([pgp], [s charon])
|
||||
@@ -1575,16 +1563,16 @@ ADD_PLUGIN([dnskey], [s charon swanctl pki])
|
||||
ADD_PLUGIN([sshkey], [s charon swanctl pki nm cmd])
|
||||
ADD_PLUGIN([dnscert], [c charon])
|
||||
ADD_PLUGIN([ipseckey], [c charon])
|
||||
ADD_PLUGIN([pem], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fd fc])
|
||||
ADD_PLUGIN([pem], [s charon swanctl pki scripts attest nm cmd aikgen fd fc])
|
||||
ADD_PLUGIN([padlock], [s charon])
|
||||
ADD_PLUGIN([openssl], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fd])
|
||||
ADD_PLUGIN([wolfssl], [s charon swanctl pki scripts medsrv attest nm cmd aikgen])
|
||||
ADD_PLUGIN([gcrypt], [s charon swanctl pki scripts medsrv attest nm cmd aikgen])
|
||||
ADD_PLUGIN([botan], [s charon swanctl pki scripts medsrv attest nm cmd aikgen])
|
||||
ADD_PLUGIN([pkcs8], [s charon swanctl pki scripts medsrv attest nm cmd])
|
||||
ADD_PLUGIN([af-alg], [s charon swanctl pki scripts medsrv attest nm cmd aikgen])
|
||||
ADD_PLUGIN([openssl], [s charon swanctl pki scripts attest nm cmd aikgen fd])
|
||||
ADD_PLUGIN([wolfssl], [s charon swanctl pki scripts attest nm cmd aikgen])
|
||||
ADD_PLUGIN([gcrypt], [s charon swanctl pki scripts attest nm cmd aikgen])
|
||||
ADD_PLUGIN([botan], [s charon swanctl pki scripts attest nm cmd aikgen])
|
||||
ADD_PLUGIN([pkcs8], [s charon swanctl pki scripts attest nm cmd])
|
||||
ADD_PLUGIN([af-alg], [s charon swanctl pki scripts attest nm cmd aikgen])
|
||||
ADD_PLUGIN([fips-prf], [s charon nm cmd])
|
||||
ADD_PLUGIN([gmp], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fc])
|
||||
ADD_PLUGIN([gmp], [s charon swanctl pki scripts attest nm cmd aikgen fc])
|
||||
ADD_PLUGIN([curve25519], [s charon swanctl pki scripts nm cmd])
|
||||
ADD_PLUGIN([agent], [s charon nm cmd])
|
||||
ADD_PLUGIN([keychain], [s charon cmd])
|
||||
@@ -1602,8 +1590,8 @@ ADD_PLUGIN([curl], [s charon pki scripts nm cmd])
|
||||
ADD_PLUGIN([files], [s charon pki scripts nm cmd])
|
||||
ADD_PLUGIN([winhttp], [s charon pki scripts])
|
||||
ADD_PLUGIN([soup], [s charon pki scripts nm cmd])
|
||||
ADD_PLUGIN([mysql], [s charon pki pool medsrv attest])
|
||||
ADD_PLUGIN([sqlite], [s charon pki pool medsrv attest])
|
||||
ADD_PLUGIN([mysql], [s charon pki pool attest])
|
||||
ADD_PLUGIN([sqlite], [s charon pki pool attest])
|
||||
ADD_PLUGIN([openxpki], [s pki])
|
||||
ADD_PLUGIN([attr], [c charon])
|
||||
ADD_PLUGIN([attr-sql], [c charon])
|
||||
@@ -1659,8 +1647,6 @@ ADD_PLUGIN([tnc-tnccs], [t charon])
|
||||
ADD_PLUGIN([tnccs-20], [t charon])
|
||||
ADD_PLUGIN([tnccs-11], [t charon])
|
||||
ADD_PLUGIN([tnccs-dynamic], [t charon])
|
||||
ADD_PLUGIN([medsrv], [c charon])
|
||||
ADD_PLUGIN([medcli], [c charon])
|
||||
ADD_PLUGIN([dhcp], [c charon])
|
||||
ADD_PLUGIN([osx-attr], [c charon cmd])
|
||||
ADD_PLUGIN([p-cscf], [c charon cmd])
|
||||
@@ -1687,7 +1673,6 @@ AC_SUBST(pool_plugins)
|
||||
AC_SUBST(attest_plugins)
|
||||
AC_SUBST(pki_plugins)
|
||||
AC_SUBST(scripts_plugins)
|
||||
AC_SUBST(medsrv_plugins)
|
||||
AC_SUBST(nm_plugins)
|
||||
AC_SUBST(cmd_plugins)
|
||||
AC_SUBST(aikgen_plugins)
|
||||
@@ -1770,8 +1755,6 @@ AM_CONDITIONAL(USE_ML, test x$ml = xtrue)
|
||||
# ----------------
|
||||
AM_CONDITIONAL(USE_STROKE, test x$stroke = xtrue)
|
||||
AM_CONDITIONAL(USE_VICI, test x$vici = xtrue)
|
||||
AM_CONDITIONAL(USE_MEDSRV, test x$medsrv = xtrue)
|
||||
AM_CONDITIONAL(USE_MEDCLI, test x$medcli = xtrue)
|
||||
AM_CONDITIONAL(USE_OSX_ATTR, test x$osx_attr = xtrue)
|
||||
AM_CONDITIONAL(USE_P_CSCF, test x$p_cscf = xtrue)
|
||||
AM_CONDITIONAL(USE_ANDROID_DNS, test x$android_dns = xtrue)
|
||||
@@ -1975,7 +1958,6 @@ AM_COND_IF([USE_IMCV], [strongswan_options=${strongswan_options}" imcv imv_polic
|
||||
AM_COND_IF([USE_IMC_SWIMA], [strongswan_options=${strongswan_options}" sw-collector"])
|
||||
AM_COND_IF([USE_IMV_SWIMA], [strongswan_options=${strongswan_options}" sec-updater"])
|
||||
AM_COND_IF([USE_LIBTNCCS], [strongswan_options=${strongswan_options}" tnc"])
|
||||
AM_COND_IF([USE_MEDSRV], [strongswan_options=${strongswan_options}" medsrv"])
|
||||
AM_COND_IF([USE_CMD], [strongswan_options=${strongswan_options}" charon-cmd"])
|
||||
AM_COND_IF([USE_NM], [strongswan_options=${strongswan_options}" charon-nm"])
|
||||
AM_COND_IF([USE_PKI], [strongswan_options=${strongswan_options}" pki"])
|
||||
@@ -2132,8 +2114,6 @@ AC_CONFIG_FILES([
|
||||
src/libcharon/plugins/sql/Makefile
|
||||
src/libcharon/plugins/dnscert/Makefile
|
||||
src/libcharon/plugins/ipseckey/Makefile
|
||||
src/libcharon/plugins/medsrv/Makefile
|
||||
src/libcharon/plugins/medcli/Makefile
|
||||
src/libcharon/plugins/addrblock/Makefile
|
||||
src/libcharon/plugins/unity/Makefile
|
||||
src/libcharon/plugins/ha/Makefile
|
||||
@@ -2183,7 +2163,6 @@ AC_CONFIG_FILES([
|
||||
src/pki/man/Makefile
|
||||
src/pool/Makefile
|
||||
src/libfast/Makefile
|
||||
src/medsrv/Makefile
|
||||
src/checksum/Makefile
|
||||
src/conftest/Makefile
|
||||
src/pt-tls-client/Makefile
|
||||
|
||||
+1
-1
@@ -304,7 +304,7 @@ all|alpine|codeql|coverage|sonarcloud|no-dbg|no-testable-ke)
|
||||
# no TrouSerS either
|
||||
CONFIG="$CONFIG --disable-tss-trousers --disable-aikgen"
|
||||
# and no Clearsilver
|
||||
CONFIG="$CONFIG --disable-fast --disable-medsrv"
|
||||
CONFIG="$CONFIG --disable-fast"
|
||||
fi
|
||||
if test "$1" = "build-deps"; then
|
||||
build_botan
|
||||
|
||||
@@ -91,10 +91,6 @@ if USE_FAST
|
||||
SUBDIRS += libfast
|
||||
endif
|
||||
|
||||
if USE_MEDSRV
|
||||
SUBDIRS += medsrv
|
||||
endif
|
||||
|
||||
if USE_ATTR_SQL
|
||||
SUBDIRS += pool
|
||||
else
|
||||
|
||||
@@ -502,20 +502,6 @@ if MONOLITHIC
|
||||
endif
|
||||
endif
|
||||
|
||||
if USE_MEDSRV
|
||||
SUBDIRS += plugins/medsrv
|
||||
if MONOLITHIC
|
||||
libcharon_la_LIBADD += plugins/medsrv/libstrongswan-medsrv.la
|
||||
endif
|
||||
endif
|
||||
|
||||
if USE_MEDCLI
|
||||
SUBDIRS += plugins/medcli
|
||||
if MONOLITHIC
|
||||
libcharon_la_LIBADD += plugins/medcli/libstrongswan-medcli.la
|
||||
endif
|
||||
endif
|
||||
|
||||
if USE_DHCP
|
||||
SUBDIRS += plugins/dhcp
|
||||
if MONOLITHIC
|
||||
|
||||
@@ -1,20 +0,0 @@
|
||||
AM_CPPFLAGS = \
|
||||
-I$(top_srcdir)/src/libstrongswan \
|
||||
-I$(top_srcdir)/src/libcharon
|
||||
|
||||
AM_CFLAGS = \
|
||||
$(PLUGIN_CFLAGS)
|
||||
|
||||
if MONOLITHIC
|
||||
noinst_LTLIBRARIES = libstrongswan-medcli.la
|
||||
else
|
||||
plugin_LTLIBRARIES = libstrongswan-medcli.la
|
||||
endif
|
||||
|
||||
libstrongswan_medcli_la_SOURCES = \
|
||||
medcli_plugin.h medcli_plugin.c \
|
||||
medcli_creds.h medcli_creds.c \
|
||||
medcli_config.h medcli_config.c \
|
||||
medcli_listener.h medcli_listener.c
|
||||
|
||||
libstrongswan_medcli_la_LDFLAGS = -module -avoid-version
|
||||
@@ -1,434 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#define _GNU_SOURCE
|
||||
#include <string.h>
|
||||
|
||||
#include "medcli_config.h"
|
||||
|
||||
#include <daemon.h>
|
||||
#include <processing/jobs/callback_job.h>
|
||||
|
||||
typedef struct private_medcli_config_t private_medcli_config_t;
|
||||
|
||||
/**
|
||||
* Name of the mediation connection
|
||||
*/
|
||||
#define MEDIATION_CONN_NAME "medcli-mediation"
|
||||
|
||||
/**
|
||||
* Private data of an medcli_config_t object
|
||||
*/
|
||||
struct private_medcli_config_t {
|
||||
|
||||
/**
|
||||
* Public part
|
||||
*/
|
||||
medcli_config_t public;
|
||||
|
||||
/**
|
||||
* database connection
|
||||
*/
|
||||
database_t *db;
|
||||
|
||||
/**
|
||||
* rekey time
|
||||
*/
|
||||
int rekey;
|
||||
|
||||
/**
|
||||
* dpd delay
|
||||
*/
|
||||
int dpd;
|
||||
|
||||
/**
|
||||
* default ike config
|
||||
*/
|
||||
ike_cfg_t *ike;
|
||||
};
|
||||
|
||||
/**
|
||||
* create a traffic selector from a CIDR notation string
|
||||
*/
|
||||
static traffic_selector_t *ts_from_string(char *str)
|
||||
{
|
||||
if (str)
|
||||
{
|
||||
traffic_selector_t *ts;
|
||||
|
||||
ts = traffic_selector_create_from_cidr(str, 0, 0, 65535);
|
||||
if (ts)
|
||||
{
|
||||
return ts;
|
||||
}
|
||||
}
|
||||
return traffic_selector_create_dynamic(0, 0, 65535);
|
||||
}
|
||||
|
||||
/**
|
||||
* Build a mediation config
|
||||
*/
|
||||
static peer_cfg_t *build_mediation_config(private_medcli_config_t *this,
|
||||
peer_cfg_create_t *defaults)
|
||||
{
|
||||
enumerator_t *e;
|
||||
auth_cfg_t *auth;
|
||||
ike_cfg_t *ike_cfg;
|
||||
peer_cfg_t *med_cfg;
|
||||
ike_cfg_create_t ike = {
|
||||
.version = IKEV2,
|
||||
.local = "0.0.0.0",
|
||||
.local_port = charon->socket->get_port(charon->socket, FALSE),
|
||||
.remote_port = IKEV2_UDP_PORT,
|
||||
.no_certreq = TRUE,
|
||||
};
|
||||
peer_cfg_create_t peer = *defaults;
|
||||
chunk_t me, other;
|
||||
|
||||
/* query mediation server config:
|
||||
* - build ike_cfg/peer_cfg for mediation connection on-the-fly
|
||||
*/
|
||||
e = this->db->query(this->db,
|
||||
"SELECT Address, ClientConfig.KeyId, MediationServerConfig.KeyId "
|
||||
"FROM MediationServerConfig JOIN ClientConfig",
|
||||
DB_TEXT, DB_BLOB, DB_BLOB);
|
||||
if (!e || !e->enumerate(e, &ike.remote, &me, &other))
|
||||
{
|
||||
DESTROY_IF(e);
|
||||
return NULL;
|
||||
}
|
||||
ike_cfg = ike_cfg_create(&ike);
|
||||
ike_cfg->add_proposal(ike_cfg, proposal_create_default(PROTO_IKE));
|
||||
ike_cfg->add_proposal(ike_cfg, proposal_create_default_aead(PROTO_IKE));
|
||||
|
||||
peer.mediation = TRUE;
|
||||
med_cfg = peer_cfg_create(MEDIATION_CONN_NAME, ike_cfg, &peer);
|
||||
e->destroy(e);
|
||||
|
||||
auth = auth_cfg_create();
|
||||
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY);
|
||||
auth->add(auth, AUTH_RULE_IDENTITY,
|
||||
identification_create_from_encoding(ID_KEY_ID, me));
|
||||
med_cfg->add_auth_cfg(med_cfg, auth, TRUE);
|
||||
auth = auth_cfg_create();
|
||||
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY);
|
||||
auth->add(auth, AUTH_RULE_IDENTITY,
|
||||
identification_create_from_encoding(ID_KEY_ID, other));
|
||||
med_cfg->add_auth_cfg(med_cfg, auth, FALSE);
|
||||
return med_cfg;
|
||||
}
|
||||
|
||||
METHOD(backend_t, get_peer_cfg_by_name, peer_cfg_t*,
|
||||
private_medcli_config_t *this, char *name)
|
||||
{
|
||||
enumerator_t *e;
|
||||
auth_cfg_t *auth;
|
||||
peer_cfg_t *peer_cfg;
|
||||
child_cfg_t *child_cfg;
|
||||
chunk_t me, other;
|
||||
char *local_net, *remote_net;
|
||||
peer_cfg_create_t peer = {
|
||||
.cert_policy = CERT_NEVER_SEND,
|
||||
.unique = UNIQUE_REPLACE,
|
||||
.keyingtries = 1,
|
||||
.rekey_time = this->rekey * 60,
|
||||
.jitter_time = this->rekey * 5,
|
||||
.over_time = this->rekey * 3,
|
||||
.dpd = this->dpd,
|
||||
};
|
||||
child_cfg_create_t child = {
|
||||
.lifetime = {
|
||||
.time = {
|
||||
.life = this->rekey * 60 + this->rekey,
|
||||
.rekey = this->rekey,
|
||||
.jitter = this->rekey
|
||||
},
|
||||
},
|
||||
.mode = MODE_TUNNEL,
|
||||
};
|
||||
|
||||
if (streq(name, "medcli-mediation"))
|
||||
{
|
||||
return build_mediation_config(this, &peer);
|
||||
}
|
||||
|
||||
/* query mediated config:
|
||||
* - use any-any ike_cfg
|
||||
* - build peer_cfg on-the-fly using med_cfg
|
||||
* - add a child_cfg
|
||||
*/
|
||||
e = this->db->query(this->db,
|
||||
"SELECT ClientConfig.KeyId, Connection.KeyId, "
|
||||
"Connection.LocalSubnet, Connection.RemoteSubnet "
|
||||
"FROM ClientConfig JOIN Connection "
|
||||
"WHERE Active AND Alias = ?", DB_TEXT, name,
|
||||
DB_BLOB, DB_BLOB, DB_TEXT, DB_TEXT);
|
||||
if (!e || !e->enumerate(e, &me, &other, &local_net, &remote_net))
|
||||
{
|
||||
DESTROY_IF(e);
|
||||
return NULL;
|
||||
}
|
||||
peer.mediated_by = MEDIATION_CONN_NAME;
|
||||
peer.peer_id = identification_create_from_encoding(ID_KEY_ID, other);
|
||||
peer_cfg = peer_cfg_create(name, this->ike->get_ref(this->ike), &peer);
|
||||
|
||||
auth = auth_cfg_create();
|
||||
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY);
|
||||
auth->add(auth, AUTH_RULE_IDENTITY,
|
||||
identification_create_from_encoding(ID_KEY_ID, me));
|
||||
peer_cfg->add_auth_cfg(peer_cfg, auth, TRUE);
|
||||
auth = auth_cfg_create();
|
||||
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY);
|
||||
auth->add(auth, AUTH_RULE_IDENTITY,
|
||||
identification_create_from_encoding(ID_KEY_ID, other));
|
||||
peer_cfg->add_auth_cfg(peer_cfg, auth, FALSE);
|
||||
|
||||
child_cfg = child_cfg_create(name, &child);
|
||||
child_cfg->add_proposal(child_cfg, proposal_create_default_aead(PROTO_ESP));
|
||||
child_cfg->add_proposal(child_cfg, proposal_create_default(PROTO_ESP));
|
||||
child_cfg->add_traffic_selector(child_cfg, TRUE, ts_from_string(local_net));
|
||||
child_cfg->add_traffic_selector(child_cfg, FALSE, ts_from_string(remote_net));
|
||||
peer_cfg->add_child_cfg(peer_cfg, child_cfg);
|
||||
e->destroy(e);
|
||||
return peer_cfg;
|
||||
}
|
||||
|
||||
METHOD(backend_t, create_ike_cfg_enumerator, enumerator_t*,
|
||||
private_medcli_config_t *this, host_t *me, host_t *other)
|
||||
{
|
||||
return enumerator_create_single(this->ike, NULL);
|
||||
}
|
||||
|
||||
typedef struct {
|
||||
/** implements enumerator */
|
||||
enumerator_t public;
|
||||
/** inner SQL enumerator */
|
||||
enumerator_t *inner;
|
||||
/** currently enumerated peer config */
|
||||
peer_cfg_t *current;
|
||||
/** ike cfg to use in peer cfg */
|
||||
ike_cfg_t *ike;
|
||||
/** rekey time */
|
||||
int rekey;
|
||||
/** dpd time */
|
||||
int dpd;
|
||||
} peer_enumerator_t;
|
||||
|
||||
METHOD(enumerator_t, peer_enumerator_enumerate, bool,
|
||||
peer_enumerator_t *this, va_list args)
|
||||
{
|
||||
char *name, *local_net, *remote_net;
|
||||
chunk_t me, other;
|
||||
peer_cfg_t **cfg;
|
||||
child_cfg_t *child_cfg;
|
||||
auth_cfg_t *auth;
|
||||
peer_cfg_create_t peer = {
|
||||
.cert_policy = CERT_NEVER_SEND,
|
||||
.unique = UNIQUE_REPLACE,
|
||||
.keyingtries = 1,
|
||||
.rekey_time = this->rekey * 60,
|
||||
.jitter_time = this->rekey * 5,
|
||||
.over_time = this->rekey * 3,
|
||||
.dpd = this->dpd,
|
||||
};
|
||||
child_cfg_create_t child = {
|
||||
.lifetime = {
|
||||
.time = {
|
||||
.life = this->rekey * 60 + this->rekey,
|
||||
.rekey = this->rekey,
|
||||
.jitter = this->rekey
|
||||
},
|
||||
},
|
||||
.mode = MODE_TUNNEL,
|
||||
};
|
||||
|
||||
VA_ARGS_VGET(args, cfg);
|
||||
|
||||
DESTROY_IF(this->current);
|
||||
if (!this->inner->enumerate(this->inner, &name, &me, &other,
|
||||
&local_net, &remote_net))
|
||||
{
|
||||
this->current = NULL;
|
||||
return FALSE;
|
||||
}
|
||||
this->current = peer_cfg_create(name, this->ike->get_ref(this->ike), &peer);
|
||||
|
||||
auth = auth_cfg_create();
|
||||
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY);
|
||||
auth->add(auth, AUTH_RULE_IDENTITY,
|
||||
identification_create_from_encoding(ID_KEY_ID, me));
|
||||
this->current->add_auth_cfg(this->current, auth, TRUE);
|
||||
auth = auth_cfg_create();
|
||||
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY);
|
||||
auth->add(auth, AUTH_RULE_IDENTITY,
|
||||
identification_create_from_encoding(ID_KEY_ID, other));
|
||||
this->current->add_auth_cfg(this->current, auth, FALSE);
|
||||
|
||||
child_cfg = child_cfg_create(name, &child);
|
||||
child_cfg->add_proposal(child_cfg, proposal_create_default_aead(PROTO_ESP));
|
||||
child_cfg->add_proposal(child_cfg, proposal_create_default(PROTO_ESP));
|
||||
child_cfg->add_traffic_selector(child_cfg, TRUE, ts_from_string(local_net));
|
||||
child_cfg->add_traffic_selector(child_cfg, FALSE, ts_from_string(remote_net));
|
||||
this->current->add_child_cfg(this->current, child_cfg);
|
||||
*cfg = this->current;
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(enumerator_t, peer_enumerator_destroy, void,
|
||||
peer_enumerator_t *this)
|
||||
{
|
||||
DESTROY_IF(this->current);
|
||||
this->inner->destroy(this->inner);
|
||||
free(this);
|
||||
}
|
||||
|
||||
METHOD(backend_t, create_peer_cfg_enumerator, enumerator_t*,
|
||||
private_medcli_config_t *this, identification_t *me,
|
||||
identification_t *other)
|
||||
{
|
||||
peer_enumerator_t *e;
|
||||
|
||||
INIT(e,
|
||||
.public = {
|
||||
.enumerate = enumerator_enumerate_default,
|
||||
.venumerate = _peer_enumerator_enumerate,
|
||||
.destroy = _peer_enumerator_destroy,
|
||||
},
|
||||
.ike = this->ike,
|
||||
.rekey = this->rekey,
|
||||
.dpd = this->dpd,
|
||||
);
|
||||
|
||||
/* filter on IDs: NULL or ANY or matching KEY_ID */
|
||||
e->inner = this->db->query(this->db,
|
||||
"SELECT Alias, ClientConfig.KeyId, Connection.KeyId, "
|
||||
"Connection.LocalSubnet, Connection.RemoteSubnet "
|
||||
"FROM ClientConfig JOIN Connection "
|
||||
"WHERE Active AND "
|
||||
"(? OR ClientConfig.KeyId = ?) AND (? OR Connection.KeyId = ?)",
|
||||
DB_INT, me == NULL || me->get_type(me) == ID_ANY,
|
||||
DB_BLOB, me && me->get_type(me) == ID_KEY_ID ?
|
||||
me->get_encoding(me) : chunk_empty,
|
||||
DB_INT, other == NULL || other->get_type(other) == ID_ANY,
|
||||
DB_BLOB, other && other->get_type(other) == ID_KEY_ID ?
|
||||
other->get_encoding(other) : chunk_empty,
|
||||
DB_TEXT, DB_BLOB, DB_BLOB, DB_TEXT, DB_TEXT);
|
||||
if (!e->inner)
|
||||
{
|
||||
free(e);
|
||||
return NULL;
|
||||
}
|
||||
return &e->public;
|
||||
}
|
||||
|
||||
/**
|
||||
* initiate a peer config
|
||||
*/
|
||||
static job_requeue_t initiate_config(peer_cfg_t *peer_cfg)
|
||||
{
|
||||
enumerator_t *enumerator;
|
||||
child_cfg_t *child_cfg = NULL;
|
||||
|
||||
enumerator = peer_cfg->create_child_cfg_enumerator(peer_cfg);
|
||||
enumerator->enumerate(enumerator, &child_cfg);
|
||||
if (child_cfg)
|
||||
{
|
||||
child_cfg->get_ref(child_cfg);
|
||||
peer_cfg->get_ref(peer_cfg);
|
||||
enumerator->destroy(enumerator);
|
||||
charon->controller->initiate(charon->controller, peer_cfg, child_cfg,
|
||||
NULL, NULL, 0, 0, FALSE);
|
||||
}
|
||||
else
|
||||
{
|
||||
enumerator->destroy(enumerator);
|
||||
}
|
||||
return JOB_REQUEUE_NONE;
|
||||
}
|
||||
|
||||
/**
|
||||
* schedule initiation of all "active" connections
|
||||
*/
|
||||
static void schedule_autoinit(private_medcli_config_t *this)
|
||||
{
|
||||
enumerator_t *e;
|
||||
char *name;
|
||||
|
||||
e = this->db->query(this->db, "SELECT Alias FROM Connection WHERE Active",
|
||||
DB_TEXT);
|
||||
if (e)
|
||||
{
|
||||
while (e->enumerate(e, &name))
|
||||
{
|
||||
peer_cfg_t *peer_cfg;
|
||||
|
||||
peer_cfg = get_peer_cfg_by_name(this, name);
|
||||
if (peer_cfg)
|
||||
{
|
||||
/* schedule asynchronous initiation job */
|
||||
lib->processor->queue_job(lib->processor,
|
||||
(job_t*)callback_job_create(
|
||||
(callback_job_cb_t)initiate_config,
|
||||
peer_cfg, (void*)peer_cfg->destroy, NULL));
|
||||
}
|
||||
}
|
||||
e->destroy(e);
|
||||
}
|
||||
}
|
||||
|
||||
METHOD(medcli_config_t, destroy, void,
|
||||
private_medcli_config_t *this)
|
||||
{
|
||||
this->ike->destroy(this->ike);
|
||||
free(this);
|
||||
}
|
||||
|
||||
/**
|
||||
* Described in header.
|
||||
*/
|
||||
medcli_config_t *medcli_config_create(database_t *db)
|
||||
{
|
||||
private_medcli_config_t *this;
|
||||
ike_cfg_create_t ike = {
|
||||
.version = IKEV2,
|
||||
.local = "0.0.0.0",
|
||||
.local_port = charon->socket->get_port(charon->socket, FALSE),
|
||||
.remote = "0.0.0.0",
|
||||
.remote_port = IKEV2_UDP_PORT,
|
||||
.no_certreq = TRUE,
|
||||
};
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.backend = {
|
||||
.create_peer_cfg_enumerator = _create_peer_cfg_enumerator,
|
||||
.create_ike_cfg_enumerator = _create_ike_cfg_enumerator,
|
||||
.get_peer_cfg_by_name = _get_peer_cfg_by_name,
|
||||
},
|
||||
.destroy = _destroy,
|
||||
},
|
||||
.db = db,
|
||||
.rekey = lib->settings->get_time(lib->settings, "medcli.rekey", 1200),
|
||||
.dpd = lib->settings->get_time(lib->settings, "medcli.dpd", 300),
|
||||
.ike = ike_cfg_create(&ike),
|
||||
);
|
||||
this->ike->add_proposal(this->ike, proposal_create_default(PROTO_IKE));
|
||||
this->ike->add_proposal(this->ike, proposal_create_default_aead(PROTO_IKE));
|
||||
|
||||
schedule_autoinit(this);
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
@@ -1,54 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup medcli_config_i medcli_config
|
||||
* @{ @ingroup medcli
|
||||
*/
|
||||
|
||||
#ifndef MEDCLI_CONFIG_H_
|
||||
#define MEDCLI_CONFIG_H_
|
||||
|
||||
#include <config/backend.h>
|
||||
#include <database/database.h>
|
||||
|
||||
typedef struct medcli_config_t medcli_config_t;
|
||||
|
||||
/**
|
||||
* Mediation client configuration backend.
|
||||
*/
|
||||
struct medcli_config_t {
|
||||
|
||||
/**
|
||||
* Implements backend_t interface
|
||||
*/
|
||||
backend_t backend;
|
||||
|
||||
/**
|
||||
* Destroy the backend.
|
||||
*/
|
||||
void (*destroy)(medcli_config_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Create a medcli_config backend instance.
|
||||
*
|
||||
* @param db underlying database
|
||||
* @return backend instance
|
||||
*/
|
||||
medcli_config_t *medcli_config_create(database_t *db);
|
||||
|
||||
#endif /** MEDCLI_CONFIG_H_ @}*/
|
||||
@@ -1,242 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "medcli_creds.h"
|
||||
|
||||
#include <daemon.h>
|
||||
#include <library.h>
|
||||
#include <collections/enumerator.h>
|
||||
|
||||
typedef struct private_medcli_creds_t private_medcli_creds_t;
|
||||
|
||||
/**
|
||||
* Private data of an medcli_creds_t object
|
||||
*/
|
||||
struct private_medcli_creds_t {
|
||||
|
||||
/**
|
||||
* Public part
|
||||
*/
|
||||
medcli_creds_t public;
|
||||
|
||||
/**
|
||||
* underlying database handle
|
||||
*/
|
||||
database_t *db;
|
||||
};
|
||||
|
||||
/**
|
||||
* enumerator over private keys
|
||||
*/
|
||||
typedef struct {
|
||||
/** implements enumerator */
|
||||
enumerator_t public;
|
||||
/** inner SQL enumerator */
|
||||
enumerator_t *inner;
|
||||
/** currently enumerated private key */
|
||||
private_key_t *current;
|
||||
} private_enumerator_t;
|
||||
|
||||
METHOD(enumerator_t, private_enumerator_enumerate, bool,
|
||||
private_enumerator_t *this, va_list args)
|
||||
{
|
||||
private_key_t **key;
|
||||
chunk_t chunk;
|
||||
|
||||
VA_ARGS_VGET(args, key);
|
||||
|
||||
DESTROY_IF(this->current);
|
||||
while (this->inner->enumerate(this->inner, &chunk))
|
||||
{
|
||||
this->current = lib->creds->create(lib->creds, CRED_PRIVATE_KEY, KEY_RSA,
|
||||
BUILD_BLOB_ASN1_DER, chunk,
|
||||
BUILD_END);
|
||||
if (this->current)
|
||||
{
|
||||
*key = this->current;
|
||||
return TRUE;
|
||||
}
|
||||
}
|
||||
this->current = NULL;
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
METHOD(enumerator_t, private_enumerator_destroy, void,
|
||||
private_enumerator_t *this)
|
||||
{
|
||||
DESTROY_IF(this->current);
|
||||
this->inner->destroy(this->inner);
|
||||
free(this);
|
||||
}
|
||||
|
||||
METHOD(credential_set_t, create_private_enumerator, enumerator_t*,
|
||||
private_medcli_creds_t *this, key_type_t type, identification_t *id)
|
||||
{
|
||||
private_enumerator_t *e;
|
||||
|
||||
if ((type != KEY_RSA && type != KEY_ANY) ||
|
||||
id == NULL || id->get_type(id) != ID_KEY_ID)
|
||||
{
|
||||
DBG1(DBG_CFG, "%N - %Y", key_type_names, type, id);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
INIT(e,
|
||||
.public = {
|
||||
.enumerate = enumerator_enumerate_default,
|
||||
.venumerate = _private_enumerator_enumerate,
|
||||
.destroy = _private_enumerator_destroy,
|
||||
},
|
||||
);
|
||||
e->inner = this->db->query(this->db,
|
||||
"SELECT PrivateKey FROM ClientConfig WHERE KeyId = ?",
|
||||
DB_BLOB, id->get_encoding(id),
|
||||
DB_BLOB);
|
||||
if (!e->inner)
|
||||
{
|
||||
free(e);
|
||||
return NULL;
|
||||
}
|
||||
return &e->public;
|
||||
}
|
||||
|
||||
/**
|
||||
* enumerator over certificates
|
||||
*/
|
||||
typedef struct {
|
||||
/** implements enumerator */
|
||||
enumerator_t public;
|
||||
/** inner SQL enumerator */
|
||||
enumerator_t *inner;
|
||||
/** currently enumerated cert */
|
||||
certificate_t *current;
|
||||
/** type of requested key */
|
||||
key_type_t type;
|
||||
} cert_enumerator_t;
|
||||
|
||||
METHOD(enumerator_t, cert_enumerator_enumerate, bool,
|
||||
cert_enumerator_t *this, va_list args)
|
||||
{
|
||||
certificate_t **cert;
|
||||
public_key_t *public;
|
||||
chunk_t chunk;
|
||||
|
||||
VA_ARGS_VGET(args, cert);
|
||||
|
||||
DESTROY_IF(this->current);
|
||||
while (this->inner->enumerate(this->inner, &chunk))
|
||||
{
|
||||
public = lib->creds->create(lib->creds, CRED_PUBLIC_KEY, KEY_ANY,
|
||||
BUILD_BLOB_ASN1_DER, chunk,
|
||||
BUILD_END);
|
||||
if (public)
|
||||
{
|
||||
if (this->type == KEY_ANY || this->type == public->get_type(public))
|
||||
{
|
||||
this->current = lib->creds->create(lib->creds,
|
||||
CRED_CERTIFICATE, CERT_TRUSTED_PUBKEY,
|
||||
BUILD_PUBLIC_KEY, public, BUILD_END);
|
||||
public->destroy(public);
|
||||
if (this->current)
|
||||
{
|
||||
*cert = this->current;
|
||||
return TRUE;
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
public->destroy(public);
|
||||
}
|
||||
}
|
||||
}
|
||||
this->current = NULL;
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
METHOD(enumerator_t, cert_enumerator_destroy, void,
|
||||
cert_enumerator_t *this)
|
||||
{
|
||||
DESTROY_IF(this->current);
|
||||
this->inner->destroy(this->inner);
|
||||
free(this);
|
||||
}
|
||||
|
||||
METHOD(credential_set_t, create_cert_enumerator, enumerator_t*,
|
||||
private_medcli_creds_t *this, certificate_type_t cert, key_type_t key,
|
||||
identification_t *id, bool trusted)
|
||||
{
|
||||
cert_enumerator_t *e;
|
||||
|
||||
if ((cert != CERT_TRUSTED_PUBKEY && cert != CERT_ANY) ||
|
||||
id == NULL || id->get_type(id) != ID_KEY_ID)
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
|
||||
INIT(e,
|
||||
.public = {
|
||||
.enumerate = enumerator_enumerate_default,
|
||||
.venumerate = _cert_enumerator_enumerate,
|
||||
.destroy = _cert_enumerator_destroy,
|
||||
},
|
||||
.type = key,
|
||||
);
|
||||
e->inner = this->db->query(this->db,
|
||||
"SELECT PublicKey FROM ClientConfig WHERE KeyId = ? UNION "
|
||||
"SELECT PublicKey FROM MediationServerConfig WHERE KeyId = ? UNION "
|
||||
"SELECT PublicKey FROM Connection WHERE KeyId = ?",
|
||||
DB_BLOB, id->get_encoding(id),
|
||||
DB_BLOB, id->get_encoding(id),
|
||||
DB_BLOB, id->get_encoding(id),
|
||||
DB_BLOB);
|
||||
if (!e->inner)
|
||||
{
|
||||
free(e);
|
||||
return NULL;
|
||||
}
|
||||
return &e->public;
|
||||
}
|
||||
|
||||
METHOD(medcli_creds_t, destroy, void,
|
||||
private_medcli_creds_t *this)
|
||||
{
|
||||
free(this);
|
||||
}
|
||||
|
||||
/**
|
||||
* Described in header.
|
||||
*/
|
||||
medcli_creds_t *medcli_creds_create(database_t *db)
|
||||
{
|
||||
private_medcli_creds_t *this;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.set = {
|
||||
.create_private_enumerator = _create_private_enumerator,
|
||||
.create_cert_enumerator = _create_cert_enumerator,
|
||||
.create_shared_enumerator = (void*)return_null,
|
||||
.create_cdp_enumerator = (void*)return_null,
|
||||
.cache_cert = (void*)nop,
|
||||
},
|
||||
.destroy = _destroy,
|
||||
},
|
||||
.db = db,
|
||||
);
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
|
||||
@@ -1,54 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup medcli_creds_i medcli_creds
|
||||
* @{ @ingroup medcli
|
||||
*/
|
||||
|
||||
#ifndef MEDCLI_CREDS_H_
|
||||
#define MEDCLI_CREDS_H_
|
||||
|
||||
#include <credentials/credential_set.h>
|
||||
#include <database/database.h>
|
||||
|
||||
typedef struct medcli_creds_t medcli_creds_t;
|
||||
|
||||
/**
|
||||
* Mediation client credentials database.
|
||||
*/
|
||||
struct medcli_creds_t {
|
||||
|
||||
/**
|
||||
* Implements credential_set_t interface
|
||||
*/
|
||||
credential_set_t set;
|
||||
|
||||
/**
|
||||
* Destroy the credentials database.
|
||||
*/
|
||||
void (*destroy)(medcli_creds_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Create the medcli credential set.
|
||||
*
|
||||
* @param database underlying database
|
||||
* @return credential set implementation on that database
|
||||
*/
|
||||
medcli_creds_t *medcli_creds_create(database_t *database);
|
||||
|
||||
#endif /** MEDCLI_CREDS_H_ @}*/
|
||||
@@ -1,132 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "medcli_listener.h"
|
||||
|
||||
#include <daemon.h>
|
||||
#include <library.h>
|
||||
|
||||
typedef struct private_medcli_listener_t private_medcli_listener_t;
|
||||
typedef enum mediated_state_t mediated_state_t;
|
||||
|
||||
/**
|
||||
* state of a mediated connection
|
||||
*/
|
||||
enum mediated_state_t {
|
||||
STATE_DOWN = 1,
|
||||
STATE_CONNECTING = 2,
|
||||
STATE_UP = 3,
|
||||
};
|
||||
|
||||
/**
|
||||
* Private data of an medcli_listener_t object
|
||||
*/
|
||||
struct private_medcli_listener_t {
|
||||
|
||||
/**
|
||||
* Public part
|
||||
*/
|
||||
medcli_listener_t public;
|
||||
|
||||
/**
|
||||
* underlying database handle
|
||||
*/
|
||||
database_t *db;
|
||||
};
|
||||
|
||||
/**
|
||||
* Update connection status in the database
|
||||
*/
|
||||
static void set_state(private_medcli_listener_t *this, char *alias,
|
||||
mediated_state_t state)
|
||||
{
|
||||
this->db->execute(this->db, NULL,
|
||||
"UPDATE Connection SET Status = ? WHERE Alias = ?",
|
||||
DB_UINT, state, DB_TEXT, alias);
|
||||
}
|
||||
|
||||
METHOD(listener_t, ike_state_change, bool,
|
||||
private_medcli_listener_t *this, ike_sa_t *ike_sa, ike_sa_state_t state)
|
||||
{
|
||||
if (ike_sa)
|
||||
{
|
||||
switch (state)
|
||||
{
|
||||
case IKE_CONNECTING:
|
||||
set_state(this, ike_sa->get_name(ike_sa), STATE_CONNECTING);
|
||||
break;
|
||||
case IKE_DESTROYING:
|
||||
set_state(this, ike_sa->get_name(ike_sa), STATE_DOWN);
|
||||
default:
|
||||
break;
|
||||
}
|
||||
}
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(listener_t, child_state_change, bool,
|
||||
private_medcli_listener_t *this, ike_sa_t *ike_sa, child_sa_t *child_sa,
|
||||
child_sa_state_t state)
|
||||
{
|
||||
if (ike_sa && child_sa)
|
||||
{
|
||||
switch (state)
|
||||
{
|
||||
case CHILD_INSTALLED:
|
||||
set_state(this, child_sa->get_name(child_sa), STATE_UP);
|
||||
break;
|
||||
case CHILD_DESTROYING:
|
||||
set_state(this, child_sa->get_name(child_sa), STATE_DOWN);
|
||||
break;
|
||||
default:
|
||||
break;
|
||||
}
|
||||
}
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(medcli_listener_t, destroy, void,
|
||||
private_medcli_listener_t *this)
|
||||
{
|
||||
this->db->execute(this->db, NULL, "UPDATE Connection SET Status = ?",
|
||||
DB_UINT, STATE_DOWN);
|
||||
free(this);
|
||||
}
|
||||
|
||||
/**
|
||||
* Described in header.
|
||||
*/
|
||||
medcli_listener_t *medcli_listener_create(database_t *db)
|
||||
{
|
||||
private_medcli_listener_t *this;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.listener = {
|
||||
.ike_state_change = _ike_state_change,
|
||||
.child_state_change = _child_state_change,
|
||||
},
|
||||
.destroy = _destroy,
|
||||
},
|
||||
.db = db,
|
||||
);
|
||||
|
||||
db->execute(db, NULL, "UPDATE Connection SET Status = ?",
|
||||
DB_UINT, STATE_DOWN);
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
|
||||
@@ -1,54 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup medcli_listener_i medcli_listener
|
||||
* @{ @ingroup medcli
|
||||
*/
|
||||
|
||||
#ifndef MEDCLI_LISTENER_H_
|
||||
#define MEDCLI_LISTENER_H_
|
||||
|
||||
#include <bus/bus.h>
|
||||
#include <database/database.h>
|
||||
|
||||
typedef struct medcli_listener_t medcli_listener_t;
|
||||
|
||||
/**
|
||||
* Mediation client listener, writes connection status to database
|
||||
*/
|
||||
struct medcli_listener_t {
|
||||
|
||||
/**
|
||||
* Implements bus_listener_t interface
|
||||
*/
|
||||
listener_t listener;
|
||||
|
||||
/**
|
||||
* Destroy the credentials database.
|
||||
*/
|
||||
void (*destroy)(medcli_listener_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Create the medcli credential set.
|
||||
*
|
||||
* @param database underlying database
|
||||
* @return listener
|
||||
*/
|
||||
medcli_listener_t *medcli_listener_create(database_t *database);
|
||||
|
||||
#endif /** MEDCLI_LISTENER_H_ @}*/
|
||||
@@ -1,147 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2013 Tobias Brunner
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "medcli_plugin.h"
|
||||
|
||||
#include "medcli_creds.h"
|
||||
#include "medcli_config.h"
|
||||
#include "medcli_listener.h"
|
||||
|
||||
#include <daemon.h>
|
||||
|
||||
typedef struct private_medcli_plugin_t private_medcli_plugin_t;
|
||||
|
||||
/**
|
||||
* private data of medcli plugin
|
||||
*/
|
||||
struct private_medcli_plugin_t {
|
||||
|
||||
/**
|
||||
* implements plugin interface
|
||||
*/
|
||||
medcli_plugin_t public;
|
||||
|
||||
/**
|
||||
* database connection instance
|
||||
*/
|
||||
database_t *db;
|
||||
|
||||
/**
|
||||
* medcli credential set instance
|
||||
*/
|
||||
medcli_creds_t *creds;
|
||||
|
||||
/**
|
||||
* medcli config database
|
||||
*/
|
||||
medcli_config_t *config;
|
||||
|
||||
/**
|
||||
* Listener to update database connection state
|
||||
*/
|
||||
medcli_listener_t *listener;
|
||||
};
|
||||
|
||||
METHOD(plugin_t, get_name, char*,
|
||||
private_medcli_plugin_t *this)
|
||||
{
|
||||
return "medcli";
|
||||
}
|
||||
|
||||
/**
|
||||
* Connect to database
|
||||
*/
|
||||
static bool open_database(private_medcli_plugin_t *this,
|
||||
plugin_feature_t *feature, bool reg, void *cb_data)
|
||||
{
|
||||
if (reg)
|
||||
{
|
||||
char *uri;
|
||||
|
||||
uri = lib->settings->get_str(lib->settings,
|
||||
"medcli.database", NULL);
|
||||
if (!uri)
|
||||
{
|
||||
DBG1(DBG_CFG, "mediation client database URI not defined, skipped");
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
this->db = lib->db->create(lib->db, uri);
|
||||
if (this->db == NULL)
|
||||
{
|
||||
DBG1(DBG_CFG, "opening mediation client database failed");
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
this->creds = medcli_creds_create(this->db);
|
||||
this->config = medcli_config_create(this->db);
|
||||
this->listener = medcli_listener_create(this->db);
|
||||
|
||||
lib->credmgr->add_set(lib->credmgr, &this->creds->set);
|
||||
charon->backends->add_backend(charon->backends, &this->config->backend);
|
||||
charon->bus->add_listener(charon->bus, &this->listener->listener);
|
||||
}
|
||||
else
|
||||
{
|
||||
charon->bus->remove_listener(charon->bus, &this->listener->listener);
|
||||
charon->backends->remove_backend(charon->backends, &this->config->backend);
|
||||
lib->credmgr->remove_set(lib->credmgr, &this->creds->set);
|
||||
this->listener->destroy(this->listener);
|
||||
this->config->destroy(this->config);
|
||||
this->creds->destroy(this->creds);
|
||||
this->db->destroy(this->db);
|
||||
}
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(plugin_t, get_features, int,
|
||||
private_medcli_plugin_t *this, plugin_feature_t *features[])
|
||||
{
|
||||
static plugin_feature_t f[] = {
|
||||
PLUGIN_CALLBACK((plugin_feature_callback_t)open_database, NULL),
|
||||
PLUGIN_PROVIDE(CUSTOM, "medcli"),
|
||||
PLUGIN_DEPENDS(DATABASE, DB_ANY),
|
||||
};
|
||||
*features = f;
|
||||
return countof(f);
|
||||
}
|
||||
|
||||
METHOD(plugin_t, destroy, void,
|
||||
private_medcli_plugin_t *this)
|
||||
{
|
||||
free(this);
|
||||
}
|
||||
|
||||
/*
|
||||
* see header file
|
||||
*/
|
||||
PLUGIN_DEFINE(medcli)
|
||||
{
|
||||
private_medcli_plugin_t *this;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.plugin = {
|
||||
.get_name = _get_name,
|
||||
.get_features = _get_features,
|
||||
.destroy = _destroy,
|
||||
},
|
||||
},
|
||||
);
|
||||
|
||||
return &this->public.plugin;
|
||||
}
|
||||
@@ -1,43 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup medcli medcli
|
||||
* @ingroup cplugins
|
||||
*
|
||||
* @defgroup medcli_plugin medcli_plugin
|
||||
* @{ @ingroup medcli
|
||||
*/
|
||||
|
||||
#ifndef MEDCLI_PLUGIN_H_
|
||||
#define MEDCLI_PLUGIN_H_
|
||||
|
||||
#include <plugins/plugin.h>
|
||||
|
||||
typedef struct medcli_plugin_t medcli_plugin_t;
|
||||
|
||||
/**
|
||||
* Mediation client database plugin.
|
||||
*/
|
||||
struct medcli_plugin_t {
|
||||
|
||||
/**
|
||||
* implements plugin interface
|
||||
*/
|
||||
plugin_t plugin;
|
||||
};
|
||||
|
||||
#endif /** MEDCLI_PLUGIN_H_ @}*/
|
||||
@@ -1,32 +0,0 @@
|
||||
|
||||
CREATE TABLE `ClientConfig` (
|
||||
`IdClientConfig` int(11) NOT NULL,
|
||||
`KeyId` varbinary(20) NOT NULL,
|
||||
`PublicKey` blob NOT NULL,
|
||||
`PrivateKey` blob NOT NULL,
|
||||
PRIMARY KEY (`IdClientConfig`)
|
||||
);
|
||||
|
||||
|
||||
CREATE TABLE `MediationServerConfig` (
|
||||
`IdMediationServerConfig` int(11) NOT NULL,
|
||||
`Address` varchar(200) NOT NULL,
|
||||
`KeyId` varbinary(20) NOT NULL,
|
||||
`PublicKey` blob NOT NULL,
|
||||
PRIMARY KEY (`IdMediationServerConfig`)
|
||||
);
|
||||
|
||||
|
||||
CREATE TABLE `Connection` (
|
||||
`IdConnection` int(11) NOT NULL auto_increment,
|
||||
`Active` tinyint(1) NOT NULL,
|
||||
`Alias` varchar(50) NOT NULL,
|
||||
`KeyId` varbinary(20) NOT NULL,
|
||||
`PublicKey` blob NOT NULL,
|
||||
`LocalSubnet` varchar(20),
|
||||
`RemoteSubnet` varchar(20),
|
||||
`Status` int(11) NOT NULL,
|
||||
PRIMARY KEY (`IdConnection`),
|
||||
UNIQUE (`Alias`),
|
||||
UNIQUE (`KeyId`)
|
||||
);
|
||||
@@ -1,19 +0,0 @@
|
||||
AM_CPPFLAGS = \
|
||||
-I$(top_srcdir)/src/libstrongswan \
|
||||
-I$(top_srcdir)/src/libcharon
|
||||
|
||||
AM_CFLAGS = \
|
||||
$(PLUGIN_CFLAGS)
|
||||
|
||||
if MONOLITHIC
|
||||
noinst_LTLIBRARIES = libstrongswan-medsrv.la
|
||||
else
|
||||
plugin_LTLIBRARIES = libstrongswan-medsrv.la
|
||||
endif
|
||||
|
||||
libstrongswan_medsrv_la_SOURCES = \
|
||||
medsrv_plugin.h medsrv_plugin.c \
|
||||
medsrv_creds.h medsrv_creds.c \
|
||||
medsrv_config.h medsrv_config.c
|
||||
|
||||
libstrongswan_medsrv_la_LDFLAGS = -module -avoid-version
|
||||
@@ -1,161 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include <string.h>
|
||||
|
||||
#include "medsrv_config.h"
|
||||
|
||||
#include <daemon.h>
|
||||
|
||||
typedef struct private_medsrv_config_t private_medsrv_config_t;
|
||||
|
||||
/**
|
||||
* Private data of an medsrv_config_t object
|
||||
*/
|
||||
struct private_medsrv_config_t {
|
||||
|
||||
/**
|
||||
* Public part
|
||||
*/
|
||||
medsrv_config_t public;
|
||||
|
||||
/**
|
||||
* database connection
|
||||
*/
|
||||
database_t *db;
|
||||
|
||||
/**
|
||||
* rekey time
|
||||
*/
|
||||
int rekey;
|
||||
|
||||
/**
|
||||
* dpd delay
|
||||
*/
|
||||
int dpd;
|
||||
|
||||
/**
|
||||
* default ike config
|
||||
*/
|
||||
ike_cfg_t *ike;
|
||||
};
|
||||
|
||||
METHOD(backend_t, get_peer_cfg_by_name, peer_cfg_t*,
|
||||
private_medsrv_config_t *this, char *name)
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
|
||||
METHOD(backend_t, create_ike_cfg_enumerator, enumerator_t*,
|
||||
private_medsrv_config_t *this, host_t *me, host_t *other)
|
||||
{
|
||||
return enumerator_create_single(this->ike, NULL);
|
||||
}
|
||||
|
||||
METHOD(backend_t, create_peer_cfg_enumerator, enumerator_t*,
|
||||
private_medsrv_config_t *this, identification_t *me,
|
||||
identification_t *other)
|
||||
{
|
||||
enumerator_t *e;
|
||||
|
||||
if (!me || !other || other->get_type(other) != ID_KEY_ID)
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
e = this->db->query(this->db,
|
||||
"SELECT CONCAT(peer.alias, CONCAT('@', user.login)) FROM "
|
||||
"peer JOIN user ON peer.user = user.id "
|
||||
"WHERE peer.keyid = ?", DB_BLOB, other->get_encoding(other),
|
||||
DB_TEXT);
|
||||
if (e)
|
||||
{
|
||||
peer_cfg_t *peer_cfg;
|
||||
auth_cfg_t *auth;
|
||||
char *name;
|
||||
|
||||
if (e->enumerate(e, &name))
|
||||
{
|
||||
peer_cfg_create_t peer = {
|
||||
.cert_policy = CERT_NEVER_SEND,
|
||||
.unique = UNIQUE_REPLACE,
|
||||
.keyingtries = 1,
|
||||
.rekey_time = this->rekey * 60,
|
||||
.jitter_time = this->rekey * 5,
|
||||
.over_time = this->rekey * 3,
|
||||
.dpd = this->dpd,
|
||||
.mediation = TRUE,
|
||||
};
|
||||
peer_cfg = peer_cfg_create(name, this->ike->get_ref(this->ike),
|
||||
&peer);
|
||||
e->destroy(e);
|
||||
|
||||
auth = auth_cfg_create();
|
||||
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY);
|
||||
auth->add(auth, AUTH_RULE_IDENTITY, me->clone(me));
|
||||
peer_cfg->add_auth_cfg(peer_cfg, auth, TRUE);
|
||||
auth = auth_cfg_create();
|
||||
auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY);
|
||||
auth->add(auth, AUTH_RULE_IDENTITY, other->clone(other));
|
||||
peer_cfg->add_auth_cfg(peer_cfg, auth, FALSE);
|
||||
|
||||
return enumerator_create_single(peer_cfg, (void*)peer_cfg->destroy);
|
||||
}
|
||||
e->destroy(e);
|
||||
}
|
||||
return NULL;
|
||||
}
|
||||
|
||||
METHOD(medsrv_config_t, destroy, void,
|
||||
private_medsrv_config_t *this)
|
||||
{
|
||||
this->ike->destroy(this->ike);
|
||||
free(this);
|
||||
}
|
||||
|
||||
/**
|
||||
* Described in header.
|
||||
*/
|
||||
medsrv_config_t *medsrv_config_create(database_t *db)
|
||||
{
|
||||
private_medsrv_config_t *this;
|
||||
ike_cfg_create_t ike = {
|
||||
.version = IKEV2,
|
||||
.local = "0.0.0.0",
|
||||
.local_port = charon->socket->get_port(charon->socket, FALSE),
|
||||
.remote = "0.0.0.0",
|
||||
.remote_port = IKEV2_UDP_PORT,
|
||||
.no_certreq = TRUE,
|
||||
};
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.backend = {
|
||||
.create_peer_cfg_enumerator = _create_peer_cfg_enumerator,
|
||||
.create_ike_cfg_enumerator = _create_ike_cfg_enumerator,
|
||||
.get_peer_cfg_by_name = _get_peer_cfg_by_name,
|
||||
},
|
||||
.destroy = _destroy,
|
||||
},
|
||||
.db = db,
|
||||
.rekey = lib->settings->get_time(lib->settings, "medsrv.rekey", 1200),
|
||||
.dpd = lib->settings->get_time(lib->settings, "medsrv.dpd", 300),
|
||||
.ike = ike_cfg_create(&ike),
|
||||
);
|
||||
this->ike->add_proposal(this->ike, proposal_create_default(PROTO_IKE));
|
||||
this->ike->add_proposal(this->ike, proposal_create_default_aead(PROTO_IKE));
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
@@ -1,54 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup medsrv_config_i medsrv_config
|
||||
* @{ @ingroup medsrv_p
|
||||
*/
|
||||
|
||||
#ifndef MEDSRV_CONFIG_H_
|
||||
#define MEDSRV_CONFIG_H_
|
||||
|
||||
#include <config/backend.h>
|
||||
#include <database/database.h>
|
||||
|
||||
typedef struct medsrv_config_t medsrv_config_t;
|
||||
|
||||
/**
|
||||
* Mediation server configuration backend.
|
||||
*/
|
||||
struct medsrv_config_t {
|
||||
|
||||
/**
|
||||
* Implements backend_t interface
|
||||
*/
|
||||
backend_t backend;
|
||||
|
||||
/**
|
||||
* Destroy the backend.
|
||||
*/
|
||||
void (*destroy)(medsrv_config_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Create a medsrv_config backend instance.
|
||||
*
|
||||
* @param db underlying database
|
||||
* @return backend instance
|
||||
*/
|
||||
medsrv_config_t *medsrv_config_create(database_t *db);
|
||||
|
||||
#endif /** MEDSRV_CONFIG_H_ @}*/
|
||||
@@ -1,163 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "medsrv_creds.h"
|
||||
|
||||
#include <daemon.h>
|
||||
#include <library.h>
|
||||
#include <collections/enumerator.h>
|
||||
|
||||
typedef struct private_medsrv_creds_t private_medsrv_creds_t;
|
||||
|
||||
/**
|
||||
* Private data of an medsrv_creds_t object
|
||||
*/
|
||||
struct private_medsrv_creds_t {
|
||||
|
||||
/**
|
||||
* Public part
|
||||
*/
|
||||
medsrv_creds_t public;
|
||||
|
||||
/**
|
||||
* underlying database handle
|
||||
*/
|
||||
database_t *db;
|
||||
};
|
||||
|
||||
/**
|
||||
* enumerator over certificates
|
||||
*/
|
||||
typedef struct {
|
||||
/** implements enumerator */
|
||||
enumerator_t public;
|
||||
/** inner SQL enumerator */
|
||||
enumerator_t *inner;
|
||||
/** currently enumerated cert */
|
||||
certificate_t *current;
|
||||
/** type of requested key */
|
||||
key_type_t type;
|
||||
} cert_enumerator_t;
|
||||
|
||||
METHOD(enumerator_t, cert_enumerator_enumerate, bool,
|
||||
cert_enumerator_t *this, va_list args)
|
||||
{
|
||||
certificate_t *trusted, **cert;
|
||||
public_key_t *public;
|
||||
chunk_t chunk;
|
||||
|
||||
VA_ARGS_VGET(args, cert);
|
||||
|
||||
DESTROY_IF(this->current);
|
||||
while (this->inner->enumerate(this->inner, &chunk))
|
||||
{
|
||||
public = lib->creds->create(lib->creds, CRED_PUBLIC_KEY, KEY_ANY,
|
||||
BUILD_BLOB_ASN1_DER, chunk,
|
||||
BUILD_END);
|
||||
if (public)
|
||||
{
|
||||
if (this->type == KEY_ANY || this->type == public->get_type(public))
|
||||
{
|
||||
trusted = lib->creds->create(lib->creds,
|
||||
CRED_CERTIFICATE, CERT_TRUSTED_PUBKEY,
|
||||
BUILD_PUBLIC_KEY, public, BUILD_END);
|
||||
public->destroy(public);
|
||||
if (trusted)
|
||||
{
|
||||
*cert = this->current = trusted;
|
||||
return TRUE;
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
public->destroy(public);
|
||||
}
|
||||
}
|
||||
}
|
||||
this->current = NULL;
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
METHOD(enumerator_t, cert_enumerator_destroy, void,
|
||||
cert_enumerator_t *this)
|
||||
{
|
||||
DESTROY_IF(this->current);
|
||||
this->inner->destroy(this->inner);
|
||||
free(this);
|
||||
}
|
||||
|
||||
METHOD(credential_set_t, create_cert_enumerator, enumerator_t*,
|
||||
private_medsrv_creds_t *this, certificate_type_t cert, key_type_t key,
|
||||
identification_t *id, bool trusted)
|
||||
{
|
||||
cert_enumerator_t *e;
|
||||
|
||||
if ((cert != CERT_TRUSTED_PUBKEY && cert != CERT_ANY) ||
|
||||
id == NULL || id->get_type(id) != ID_KEY_ID)
|
||||
{
|
||||
return NULL;
|
||||
}
|
||||
|
||||
INIT(e,
|
||||
.public = {
|
||||
.enumerate = enumerator_enumerate_default,
|
||||
.venumerate = _cert_enumerator_enumerate,
|
||||
.destroy = _cert_enumerator_destroy,
|
||||
},
|
||||
.type = key,
|
||||
.inner = this->db->query(this->db,
|
||||
"SELECT public_key FROM peer WHERE keyid = ?",
|
||||
DB_BLOB, id->get_encoding(id),
|
||||
DB_BLOB),
|
||||
);
|
||||
if (!e->inner)
|
||||
{
|
||||
free(e);
|
||||
return NULL;
|
||||
}
|
||||
return &e->public;
|
||||
}
|
||||
|
||||
METHOD(medsrv_creds_t, destroy, void,
|
||||
private_medsrv_creds_t *this)
|
||||
{
|
||||
free(this);
|
||||
}
|
||||
|
||||
/**
|
||||
* Described in header.
|
||||
*/
|
||||
medsrv_creds_t *medsrv_creds_create(database_t *db)
|
||||
{
|
||||
private_medsrv_creds_t *this;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.set = {
|
||||
.create_private_enumerator = (void*)return_null,
|
||||
.create_cert_enumerator = _create_cert_enumerator,
|
||||
.create_shared_enumerator = (void*)return_null,
|
||||
.create_cdp_enumerator = (void*)return_null,
|
||||
.cache_cert = (void*)nop,
|
||||
},
|
||||
.destroy = _destroy,
|
||||
},
|
||||
.db = db,
|
||||
);
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
|
||||
@@ -1,54 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2007-2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup medsrv_creds_i medsrv_creds
|
||||
* @{ @ingroup medsrv_p
|
||||
*/
|
||||
|
||||
#ifndef MEDSRV_CREDS_H_
|
||||
#define MEDSRV_CREDS_H_
|
||||
|
||||
#include <credentials/credential_set.h>
|
||||
#include <database/database.h>
|
||||
|
||||
typedef struct medsrv_creds_t medsrv_creds_t;
|
||||
|
||||
/**
|
||||
* Mediation credentials database.
|
||||
*/
|
||||
struct medsrv_creds_t {
|
||||
|
||||
/**
|
||||
* Implements credential_set_t interface
|
||||
*/
|
||||
credential_set_t set;
|
||||
|
||||
/**
|
||||
* Destroy the credentials database.
|
||||
*/
|
||||
void (*destroy)(medsrv_creds_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Create the medsrv credentials db.
|
||||
*
|
||||
* @param database underlying database
|
||||
* @return credential set implementation on that database
|
||||
*/
|
||||
medsrv_creds_t *medsrv_creds_create(database_t *database);
|
||||
|
||||
#endif /** MEDSRV_CREDS_H_ @}*/
|
||||
@@ -1,137 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2013 Tobias Brunner
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "medsrv_plugin.h"
|
||||
|
||||
#include "medsrv_creds.h"
|
||||
#include "medsrv_config.h"
|
||||
|
||||
#include <daemon.h>
|
||||
|
||||
typedef struct private_medsrv_plugin_t private_medsrv_plugin_t;
|
||||
|
||||
/**
|
||||
* private data of medsrv plugin
|
||||
*/
|
||||
struct private_medsrv_plugin_t {
|
||||
|
||||
/**
|
||||
* implements plugin interface
|
||||
*/
|
||||
medsrv_plugin_t public;
|
||||
|
||||
/**
|
||||
* database connection instance
|
||||
*/
|
||||
database_t *db;
|
||||
|
||||
/**
|
||||
* medsrv credential set instance
|
||||
*/
|
||||
medsrv_creds_t *creds;
|
||||
|
||||
/**
|
||||
* medsrv config database
|
||||
*/
|
||||
medsrv_config_t *config;
|
||||
};
|
||||
|
||||
METHOD(plugin_t, get_name, char*,
|
||||
private_medsrv_plugin_t *this)
|
||||
{
|
||||
return "medsrv";
|
||||
}
|
||||
|
||||
/**
|
||||
* Connect to database
|
||||
*/
|
||||
static bool open_database(private_medsrv_plugin_t *this,
|
||||
plugin_feature_t *feature, bool reg, void *cb_data)
|
||||
{
|
||||
if (reg)
|
||||
{
|
||||
char *uri;
|
||||
|
||||
uri = lib->settings->get_str(lib->settings,
|
||||
"medsrv.database", NULL);
|
||||
if (!uri)
|
||||
{
|
||||
DBG1(DBG_CFG, "mediation database URI not defined, skipped");
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
this->db = lib->db->create(lib->db, uri);
|
||||
if (this->db == NULL)
|
||||
{
|
||||
DBG1(DBG_CFG, "opening mediation server database failed");
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
this->creds = medsrv_creds_create(this->db);
|
||||
this->config = medsrv_config_create(this->db);
|
||||
|
||||
lib->credmgr->add_set(lib->credmgr, &this->creds->set);
|
||||
charon->backends->add_backend(charon->backends, &this->config->backend);
|
||||
}
|
||||
else
|
||||
{
|
||||
charon->backends->remove_backend(charon->backends, &this->config->backend);
|
||||
lib->credmgr->remove_set(lib->credmgr, &this->creds->set);
|
||||
this->config->destroy(this->config);
|
||||
this->creds->destroy(this->creds);
|
||||
this->db->destroy(this->db);
|
||||
}
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
METHOD(plugin_t, get_features, int,
|
||||
private_medsrv_plugin_t *this, plugin_feature_t *features[])
|
||||
{
|
||||
static plugin_feature_t f[] = {
|
||||
PLUGIN_CALLBACK((plugin_feature_callback_t)open_database, NULL),
|
||||
PLUGIN_PROVIDE(CUSTOM, "medsrv"),
|
||||
PLUGIN_DEPENDS(DATABASE, DB_ANY),
|
||||
};
|
||||
*features = f;
|
||||
return countof(f);
|
||||
}
|
||||
|
||||
METHOD(plugin_t, destroy, void,
|
||||
private_medsrv_plugin_t *this)
|
||||
{
|
||||
free(this);
|
||||
}
|
||||
|
||||
/*
|
||||
* see header file
|
||||
*/
|
||||
PLUGIN_DEFINE(medsrv)
|
||||
{
|
||||
private_medsrv_plugin_t *this;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.plugin = {
|
||||
.get_name = _get_name,
|
||||
.get_features = _get_features,
|
||||
.destroy = _destroy,
|
||||
},
|
||||
},
|
||||
);
|
||||
|
||||
return &this->public.plugin;
|
||||
}
|
||||
@@ -1,43 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup medsrv_p medsrv
|
||||
* @ingroup cplugins
|
||||
*
|
||||
* @defgroup medsrv_plugin medsrv_plugin
|
||||
* @{ @ingroup medsrv_p
|
||||
*/
|
||||
|
||||
#ifndef MEDSRV_PLUGIN_H_
|
||||
#define MEDSRV_PLUGIN_H_
|
||||
|
||||
#include <plugins/plugin.h>
|
||||
|
||||
typedef struct medsrv_plugin_t medsrv_plugin_t;
|
||||
|
||||
/**
|
||||
* Mediation server database plugin.
|
||||
*/
|
||||
struct medsrv_plugin_t {
|
||||
|
||||
/**
|
||||
* implements plugin interface
|
||||
*/
|
||||
plugin_t plugin;
|
||||
};
|
||||
|
||||
#endif /** MEDSRV_PLUGIN_H_ @}*/
|
||||
@@ -1,21 +0,0 @@
|
||||
|
||||
CREATE TABLE IF NOT EXISTS `peer` (
|
||||
`id` int(10) unsigned NOT NULL auto_increment,
|
||||
`user` int(10) unsigned NOT NULL,
|
||||
`alias` varchar(30) NOT NULL,
|
||||
`keyid` varbinary(20) NOT NULL,
|
||||
`public_key` blob,
|
||||
PRIMARY KEY (`id`),
|
||||
UNIQUE KEY (`user`,`alias`),
|
||||
UNIQUE KEY (`keyid`),
|
||||
KEY (`user`)
|
||||
) ENGINE=MyISAM DEFAULT CHARSET=utf8 COLLATE=utf8_unicode_ci;
|
||||
|
||||
CREATE TABLE IF NOT EXISTS `user` (
|
||||
`id` int(10) unsigned NOT NULL auto_increment,
|
||||
`login` varchar(30) NOT NULL,
|
||||
`password` varbinary(20) NOT NULL,
|
||||
PRIMARY KEY (`id`),
|
||||
UNIQUE KEY (`login`)
|
||||
) ENGINE=MyISAM DEFAULT CHARSET=utf8 COLLATE=utf8_unicode_ci;
|
||||
|
||||
@@ -1,9 +0,0 @@
|
||||
|
||||
INSERT INTO `Peer` (
|
||||
`IdPeer`, `IdUser`, `Alias`, `KeyId`, `PublicKey`
|
||||
) VALUES (
|
||||
1, 0, 'sidv150',
|
||||
X'ed90e64feca21f4b6897992422e0de21b9d62629',
|
||||
X'30820122300d06092a864886f70d01010105000382010f003082010a0282010100cd946c229f7d52b21da1cb5384e7dcaf6529f760534a56355efd49e87a9c6f1ddd5ff303bd7eb49c23de03adc487456f41eb5f92947bdc8ff8dbe443f8d112e0da2c98145e7c4d1cd15cddd08577f4d4f3d0a2e1da3c08c94cd819758751931e7a9724cc43d73a11b8e176a268b4cdbbf3995cb09723abc9bfc477c25e714a4661a84c078be7404d8986be55f20437e3a6b278a3cc89aec085941f1a1aafaf4b22ae146fe4684d5567dc30658a32087d01b98515070cb1653311cb6102f82a83c638c2a79985dbb9600752e9cbc272014a5c547b4ab59130c3a948658bff794b6f202cf95939ffa73b10521f05c060cecb15f8597ed95d72b9e405ee31f1b5d90203010001'
|
||||
);
|
||||
|
||||
@@ -1 +0,0 @@
|
||||
medsrv.fcgi
|
||||
@@ -1,45 +0,0 @@
|
||||
medsrvdir = ${ipsecdir}/medsrv
|
||||
|
||||
medsrv_PROGRAMS = medsrv.fcgi
|
||||
|
||||
medsrv_fcgi_SOURCES = user.h user.c \
|
||||
main.c filter/auth_filter.c filter/auth_filter.h \
|
||||
controller/user_controller.c controller/user_controller.h \
|
||||
controller/peer_controller.c controller/peer_controller.h
|
||||
|
||||
medsrv_fcgi_LDADD = $(top_builddir)/src/libstrongswan/libstrongswan.la $(top_builddir)/src/libfast/libfast.la
|
||||
main.o : $(top_builddir)/config.status
|
||||
|
||||
AM_CPPFLAGS = \
|
||||
-I$(top_srcdir)/src/libstrongswan \
|
||||
-I$(top_srcdir)/src/libfast \
|
||||
-DIPSECDIR=\"${ipsecdir}\" \
|
||||
-DIPSEC_PIDDIR=\"${piddir}\" \
|
||||
-DPLUGINS=\""${medsrv_plugins}\""
|
||||
|
||||
AM_CFLAGS = \
|
||||
$(PLUGIN_CFLAGS)
|
||||
|
||||
# Don't forget to add templates to EXTRA_DIST !!! How to automate?
|
||||
medsrv_templatesdir = ${medsrvdir}/templates
|
||||
medsrv_templates_DATA = templates/header.cs templates/footer.cs
|
||||
|
||||
medsrv_templates_userdir = ${medsrv_templatesdir}/user
|
||||
medsrv_templates_user_DATA = templates/user/add.cs templates/user/edit.cs \
|
||||
templates/user/login.cs templates/user/help.cs
|
||||
|
||||
medsrv_templates_peerdir = ${medsrv_templatesdir}/peer
|
||||
medsrv_templates_peer_DATA = templates/peer/add.cs templates/peer/edit.cs \
|
||||
templates/peer/list.cs
|
||||
|
||||
medsrv_templates_staticdir = ${medsrv_templatesdir}/static
|
||||
medsrv_templates_static_DATA = templates/header.cs templates/footer.cs \
|
||||
templates/static/style.css templates/static/strongswan.png \
|
||||
templates/static/favicon.ico
|
||||
|
||||
EXTRA_DIST = templates/header.cs templates/footer.cs \
|
||||
templates/static/style.css templates/static/strongswan.png \
|
||||
templates/static/favicon.ico \
|
||||
templates/peer/add.cs templates/peer/edit.cs templates/peer/list.cs \
|
||||
templates/user/login.cs templates/user/add.cs templates/user/edit.cs \
|
||||
templates/user/help.cs
|
||||
@@ -1,380 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
* Copyright (C) 2008 Philip Boetschi, Adrian Doerig
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#define _GNU_SOURCE
|
||||
#include <string.h>
|
||||
|
||||
#include "peer_controller.h"
|
||||
|
||||
#include <library.h>
|
||||
#include <utils/debug.h>
|
||||
#include <asn1/asn1.h>
|
||||
#include <asn1/oid.h>
|
||||
#include <utils/identification.h>
|
||||
#include <credentials/keys/public_key.h>
|
||||
|
||||
typedef struct private_peer_controller_t private_peer_controller_t;
|
||||
|
||||
/**
|
||||
* private data of the peer_controller
|
||||
*/
|
||||
struct private_peer_controller_t {
|
||||
|
||||
/**
|
||||
* public functions
|
||||
*/
|
||||
peer_controller_t public;
|
||||
|
||||
/**
|
||||
* active user session
|
||||
*/
|
||||
user_t *user;
|
||||
|
||||
/**
|
||||
* underlying database
|
||||
*/
|
||||
database_t *db;
|
||||
};
|
||||
|
||||
/**
|
||||
* list the configured peer configs
|
||||
*/
|
||||
static void list(private_peer_controller_t *this, fast_request_t *request)
|
||||
{
|
||||
enumerator_t *query;
|
||||
|
||||
query = this->db->query(this->db,
|
||||
"SELECT id, alias, keyid FROM peer WHERE user = ? ORDER BY alias",
|
||||
DB_UINT, this->user->get_user(this->user),
|
||||
DB_UINT, DB_TEXT, DB_BLOB);
|
||||
|
||||
if (query)
|
||||
{
|
||||
u_int id;
|
||||
char *alias;
|
||||
chunk_t keyid;
|
||||
identification_t *identifier;
|
||||
|
||||
while (query->enumerate(query, &id, &alias, &keyid))
|
||||
{
|
||||
request->setf(request, "peers.%d.alias=%s", id, alias);
|
||||
identifier = identification_create_from_encoding(ID_KEY_ID, keyid);
|
||||
request->setf(request, "peers.%d.identifier=%Y", id, identifier);
|
||||
identifier->destroy(identifier);
|
||||
}
|
||||
query->destroy(query);
|
||||
}
|
||||
request->render(request, "templates/peer/list.cs");
|
||||
}
|
||||
|
||||
/**
|
||||
* verify a peer alias
|
||||
*/
|
||||
static bool verify_alias(private_peer_controller_t *this, fast_request_t *request,
|
||||
char *alias)
|
||||
{
|
||||
if (!alias || *alias == '\0')
|
||||
{
|
||||
request->setf(request, "error=Alias is missing.");
|
||||
return FALSE;
|
||||
}
|
||||
while (*alias != '\0')
|
||||
{
|
||||
switch (*alias)
|
||||
{
|
||||
case 'a' ... 'z':
|
||||
case 'A' ... 'Z':
|
||||
case '0' ... '9':
|
||||
case '-':
|
||||
case '_':
|
||||
case '@':
|
||||
case '.':
|
||||
alias++;
|
||||
continue;
|
||||
default:
|
||||
request->setf(request, "error=Alias invalid, "
|
||||
"valid characters: A-Z a-z 0-9 - _ @ .");
|
||||
return FALSE;
|
||||
}
|
||||
}
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
/**
|
||||
* parse and verify a public key
|
||||
*/
|
||||
static bool parse_public_key(private_peer_controller_t *this,
|
||||
fast_request_t *request, char *public_key,
|
||||
chunk_t *encoding, chunk_t *keyid)
|
||||
{
|
||||
public_key_t *public;
|
||||
chunk_t blob, id;
|
||||
|
||||
if (!public_key || *public_key == '\0')
|
||||
{
|
||||
request->setf(request, "error=Public key is missing.");
|
||||
return FALSE;
|
||||
}
|
||||
blob = chunk_clone(chunk_create(public_key, strlen(public_key)));
|
||||
public = lib->creds->create(lib->creds, CRED_PUBLIC_KEY, KEY_ANY,
|
||||
BUILD_BLOB_PEM, blob,
|
||||
BUILD_END);
|
||||
chunk_free(&blob);
|
||||
if (!public)
|
||||
{
|
||||
request->setf(request, "error=Parsing public key failed.");
|
||||
return FALSE;
|
||||
}
|
||||
/* TODO: use get_encoding() with an encoding type */
|
||||
if (!public->get_fingerprint(public, KEYID_PUBKEY_SHA1, &id) ||
|
||||
!public->get_encoding(public, PUBKEY_SPKI_ASN1_DER, encoding))
|
||||
{
|
||||
request->setf(request, "error=Encoding public key failed.");
|
||||
return FALSE;
|
||||
}
|
||||
*keyid = chunk_clone(id);
|
||||
public->destroy(public);
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
/**
|
||||
* register a new peer
|
||||
*/
|
||||
static void add(private_peer_controller_t *this, fast_request_t *request)
|
||||
{
|
||||
char *alias = "", *public_key = "";
|
||||
|
||||
if (request->get_query_data(request, "back"))
|
||||
{
|
||||
return request->redirect(request, "peer/list");
|
||||
}
|
||||
while (request->get_query_data(request, "add"))
|
||||
{
|
||||
chunk_t encoding, keyid;
|
||||
|
||||
alias = request->get_query_data(request, "alias");
|
||||
public_key = request->get_query_data(request, "public_key");
|
||||
|
||||
if (!verify_alias(this, request, alias))
|
||||
{
|
||||
break;
|
||||
}
|
||||
if (!parse_public_key(this, request, public_key, &encoding, &keyid))
|
||||
{
|
||||
break;
|
||||
}
|
||||
if (this->db->execute(this->db, NULL,
|
||||
"INSERT INTO peer (user, alias, public_key, keyid) "
|
||||
"VALUES (?, ?, ?, ?)",
|
||||
DB_UINT, this->user->get_user(this->user),
|
||||
DB_TEXT, alias, DB_BLOB, encoding,
|
||||
DB_BLOB, keyid) <= 0)
|
||||
{
|
||||
request->setf(request, "error=Peer already exists.");
|
||||
free(keyid.ptr);
|
||||
free(encoding.ptr);
|
||||
break;
|
||||
}
|
||||
free(keyid.ptr);
|
||||
free(encoding.ptr);
|
||||
return request->redirect(request, "peer/list");
|
||||
}
|
||||
request->set(request, "alias", alias);
|
||||
request->set(request, "public_key", public_key);
|
||||
|
||||
return request->render(request, "templates/peer/add.cs");
|
||||
}
|
||||
|
||||
/**
|
||||
* pem encode a public key into an allocated string
|
||||
*/
|
||||
static char* pem_encode(chunk_t der)
|
||||
{
|
||||
static const char *begin = "-----BEGIN PUBLIC KEY-----\n";
|
||||
static const char *end = "-----END PUBLIC KEY-----";
|
||||
size_t len;
|
||||
char *pem;
|
||||
chunk_t base64;
|
||||
int i = 0;
|
||||
|
||||
base64 = chunk_to_base64(der, NULL);
|
||||
len = strlen(begin) + base64.len + base64.len/64 + strlen(end) + 2;
|
||||
pem = malloc(len + 1);
|
||||
|
||||
strcpy(pem, begin);
|
||||
do
|
||||
{
|
||||
strncat(pem, base64.ptr + i, 64);
|
||||
strcat(pem, "\n");
|
||||
i += 64;
|
||||
}
|
||||
while (i < base64.len - 2);
|
||||
strcat(pem, end);
|
||||
|
||||
free(base64.ptr);
|
||||
return pem;
|
||||
}
|
||||
|
||||
/**
|
||||
* edit a peer
|
||||
*/
|
||||
static void edit(private_peer_controller_t *this, fast_request_t *request, int id)
|
||||
{
|
||||
char *alias = "", *public_key = "", *pem;
|
||||
chunk_t encoding, keyid;
|
||||
|
||||
if (request->get_query_data(request, "back"))
|
||||
{
|
||||
return request->redirect(request, "peer/list");
|
||||
}
|
||||
if (request->get_query_data(request, "delete"))
|
||||
{
|
||||
this->db->execute(this->db, NULL,
|
||||
"DELETE FROM peer WHERE id = ? AND user = ?",
|
||||
DB_INT, id, DB_UINT, this->user->get_user(this->user));
|
||||
return request->redirect(request, "peer/list");
|
||||
}
|
||||
if (request->get_query_data(request, "save"))
|
||||
{
|
||||
while (TRUE)
|
||||
{
|
||||
alias = request->get_query_data(request, "alias");
|
||||
public_key = request->get_query_data(request, "public_key");
|
||||
|
||||
if (!verify_alias(this, request, alias))
|
||||
{
|
||||
break;
|
||||
}
|
||||
if (!parse_public_key(this, request, public_key, &encoding, &keyid))
|
||||
{
|
||||
break;
|
||||
}
|
||||
if (this->db->execute(this->db, NULL,
|
||||
"UPDATE peer SET alias = ?, public_key = ?, keyid = ? "
|
||||
"WHERE id = ? AND user = ?",
|
||||
DB_TEXT, alias, DB_BLOB, encoding, DB_BLOB, keyid,
|
||||
DB_INT, id, DB_UINT, this->user->get_user(this->user)) < 0)
|
||||
{
|
||||
request->setf(request, "error=Peer already exists.");
|
||||
free(keyid.ptr);
|
||||
free(encoding.ptr);
|
||||
break;
|
||||
}
|
||||
free(keyid.ptr);
|
||||
free(encoding.ptr);
|
||||
return request->redirect(request, "peer/list");
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
enumerator_t *query = this->db->query(this->db,
|
||||
"SELECT alias, public_key FROM peer WHERE id = ? AND user = ?",
|
||||
DB_INT, id, DB_UINT, this->user->get_user(this->user),
|
||||
DB_TEXT, DB_BLOB);
|
||||
if (query && query->enumerate(query, &alias, &encoding))
|
||||
{
|
||||
alias = strdupa(alias);
|
||||
pem = pem_encode(encoding);
|
||||
public_key = strdupa(pem);
|
||||
free(pem);
|
||||
}
|
||||
else
|
||||
{
|
||||
return request->redirect(request, "peer/list");
|
||||
}
|
||||
DESTROY_IF(query);
|
||||
}
|
||||
request->set(request, "alias", alias);
|
||||
request->set(request, "public_key", public_key);
|
||||
return request->render(request, "templates/peer/edit.cs");
|
||||
}
|
||||
|
||||
/**
|
||||
* delete a peer from the database
|
||||
*/
|
||||
static void delete(private_peer_controller_t *this, fast_request_t *request, int id)
|
||||
{
|
||||
this->db->execute(this->db, NULL,
|
||||
"DELETE FROM peer WHERE id = ? AND user = ?",
|
||||
DB_INT, id, DB_UINT, this->user->get_user(this->user));
|
||||
}
|
||||
|
||||
METHOD(fast_controller_t, get_name, char*,
|
||||
private_peer_controller_t *this)
|
||||
{
|
||||
return "peer";
|
||||
}
|
||||
|
||||
METHOD(fast_controller_t, handle, void,
|
||||
private_peer_controller_t *this, fast_request_t *request, char *action,
|
||||
char *idstr, char *p3, char *p4, char *p5)
|
||||
{
|
||||
if (action)
|
||||
{
|
||||
int id = 0;
|
||||
if (idstr)
|
||||
{
|
||||
id = atoi(idstr);
|
||||
}
|
||||
|
||||
if (streq(action, "list"))
|
||||
{
|
||||
return list(this, request);
|
||||
}
|
||||
else if (streq(action, "add"))
|
||||
{
|
||||
return add(this, request);
|
||||
}
|
||||
else if (streq(action, "edit") && id)
|
||||
{
|
||||
return edit(this, request, id);
|
||||
}
|
||||
else if (streq(action, "delete") && id)
|
||||
{
|
||||
delete(this, request, id);
|
||||
}
|
||||
}
|
||||
request->redirect(request, "peer/list");
|
||||
}
|
||||
|
||||
METHOD(fast_controller_t, destroy, void,
|
||||
private_peer_controller_t *this)
|
||||
{
|
||||
free(this);
|
||||
}
|
||||
|
||||
/*
|
||||
* see header file
|
||||
*/
|
||||
fast_controller_t *peer_controller_create(user_t *user, database_t *db)
|
||||
{
|
||||
private_peer_controller_t *this;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.controller = {
|
||||
.get_name = _get_name,
|
||||
.handle = _handle,
|
||||
.destroy = _destroy,
|
||||
},
|
||||
},
|
||||
.user = user,
|
||||
.db = db,
|
||||
);
|
||||
|
||||
return &this->public.controller;
|
||||
}
|
||||
@@ -1,49 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
* Copyright (C) 2008 Philip Boetschi, Adrian Doerig
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup peer_controller_server peer_controller
|
||||
* @{ @ingroup medsrv
|
||||
*/
|
||||
|
||||
#ifndef PEER_CONTROLLER_H_
|
||||
#define PEER_CONTROLLER_H_
|
||||
|
||||
#include <user.h>
|
||||
|
||||
#include <fast_controller.h>
|
||||
#include <database/database.h>
|
||||
|
||||
typedef struct peer_controller_t peer_controller_t;
|
||||
|
||||
/**
|
||||
* Peer controller. Manages peers associated to a user.
|
||||
*/
|
||||
struct peer_controller_t {
|
||||
|
||||
/**
|
||||
* Implements controller_t interface.
|
||||
*/
|
||||
fast_controller_t controller;
|
||||
};
|
||||
|
||||
/**
|
||||
* Create a peer_controller controller instance.
|
||||
*/
|
||||
fast_controller_t *peer_controller_create(user_t *user, database_t *db);
|
||||
|
||||
#endif /** PEER_CONTROLLER_H_ @}*/
|
||||
@@ -1,367 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
* Copyright (C) 2008 Philip Boetschi, Adrian Doerig
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#define _GNU_SOURCE
|
||||
#include <string.h>
|
||||
|
||||
#include "user_controller.h"
|
||||
|
||||
#include <library.h>
|
||||
|
||||
typedef struct private_user_controller_t private_user_controller_t;
|
||||
|
||||
/**
|
||||
* private data of the user_controller
|
||||
*/
|
||||
struct private_user_controller_t {
|
||||
|
||||
/**
|
||||
* public functions
|
||||
*/
|
||||
user_controller_t public;
|
||||
|
||||
/**
|
||||
* database connection
|
||||
*/
|
||||
database_t *db;
|
||||
|
||||
/**
|
||||
* user session
|
||||
*/
|
||||
user_t *user;
|
||||
|
||||
/**
|
||||
* minimum required password length
|
||||
*/
|
||||
u_int password_length;
|
||||
};
|
||||
|
||||
/**
|
||||
* hash the password for database storage
|
||||
*/
|
||||
static chunk_t hash_password(char *login, char *password)
|
||||
{
|
||||
hasher_t *hasher;
|
||||
chunk_t hash, data;
|
||||
|
||||
hasher = lib->crypto->create_hasher(lib->crypto, HASH_SHA1);
|
||||
if (!hasher)
|
||||
{
|
||||
return chunk_empty;
|
||||
}
|
||||
data = chunk_cata("cc", chunk_create(login, strlen(login)),
|
||||
chunk_create(password, strlen(password)));
|
||||
if (!hasher->allocate_hash(hasher, data, &hash))
|
||||
{
|
||||
hasher->destroy(hasher);
|
||||
return chunk_empty;
|
||||
}
|
||||
hasher->destroy(hasher);
|
||||
return hash;
|
||||
}
|
||||
|
||||
/**
|
||||
* Login a user.
|
||||
*/
|
||||
static void login(private_user_controller_t *this, fast_request_t *request)
|
||||
{
|
||||
if (request->get_query_data(request, "submit"))
|
||||
{
|
||||
char *login, *password;
|
||||
|
||||
login = request->get_query_data(request, "login");
|
||||
password = request->get_query_data(request, "password");
|
||||
|
||||
if (login && password)
|
||||
{
|
||||
enumerator_t *query;
|
||||
u_int id = 0;
|
||||
chunk_t hash;
|
||||
|
||||
hash = hash_password(login, password);
|
||||
query = this->db->query(this->db,
|
||||
"SELECT id FROM user WHERE login = ? AND password = ?",
|
||||
DB_TEXT, login, DB_BLOB, hash, DB_UINT);
|
||||
if (query)
|
||||
{
|
||||
query->enumerate(query, &id);
|
||||
query->destroy(query);
|
||||
}
|
||||
free(hash.ptr);
|
||||
if (id)
|
||||
{
|
||||
this->user->set_user(this->user, id);
|
||||
return request->redirect(request, "peer/list");
|
||||
}
|
||||
}
|
||||
request->setf(request, "error=Invalid username or password.");
|
||||
}
|
||||
request->render(request, "templates/user/login.cs");
|
||||
}
|
||||
|
||||
/**
|
||||
* Logout a user.
|
||||
*/
|
||||
static void logout(private_user_controller_t *this, fast_request_t *request)
|
||||
{
|
||||
request->redirect(request, "user/login");
|
||||
request->close_session(request);
|
||||
}
|
||||
|
||||
/**
|
||||
* verify a user entered username for validity
|
||||
*/
|
||||
static bool verify_login(private_user_controller_t *this,
|
||||
fast_request_t *request, char *login)
|
||||
{
|
||||
if (!login || *login == '\0')
|
||||
{
|
||||
request->setf(request, "error=Username is missing.");
|
||||
return FALSE;
|
||||
}
|
||||
while (*login != '\0')
|
||||
{
|
||||
switch (*login)
|
||||
{
|
||||
case 'a' ... 'z':
|
||||
case 'A' ... 'Z':
|
||||
case '0' ... '9':
|
||||
case '-':
|
||||
case '_':
|
||||
case '@':
|
||||
case '.':
|
||||
login++;
|
||||
continue;
|
||||
default:
|
||||
request->setf(request, "error=Username invalid, "
|
||||
"valid characters: A-Z a-z 0-9 - _ @ .");
|
||||
return FALSE;
|
||||
}
|
||||
}
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
/**
|
||||
* verify a user entered password for validity
|
||||
*/
|
||||
static bool verify_password(private_user_controller_t *this,
|
||||
fast_request_t *request,
|
||||
char *password, char *confirm)
|
||||
{
|
||||
if (!password || *password == '\0')
|
||||
{
|
||||
request->setf(request, "error=Password is missing.");
|
||||
return FALSE;
|
||||
}
|
||||
if (strlen(password) < this->password_length)
|
||||
{
|
||||
request->setf(request, "error=Password requires at least %d characters.",
|
||||
this->password_length);
|
||||
return FALSE;
|
||||
}
|
||||
if (!confirm || !streq(password, confirm))
|
||||
{
|
||||
request->setf(request, "error=Password not confirmed.");
|
||||
return FALSE;
|
||||
}
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
/**
|
||||
* Register a user.
|
||||
*/
|
||||
static void add(private_user_controller_t *this, fast_request_t *request)
|
||||
{
|
||||
char *login = "";
|
||||
|
||||
while (request->get_query_data(request, "register"))
|
||||
{
|
||||
char *password, *confirm;
|
||||
chunk_t hash;
|
||||
u_int id;
|
||||
|
||||
login = request->get_query_data(request, "new_login");
|
||||
password = request->get_query_data(request, "new_password");
|
||||
confirm = request->get_query_data(request, "confirm_password");
|
||||
|
||||
if (!verify_login(this, request, login) ||
|
||||
!verify_password(this, request, password, confirm))
|
||||
{
|
||||
break;
|
||||
}
|
||||
|
||||
hash = hash_password(login, password);
|
||||
if (!hash.ptr || this->db->execute(this->db, &id,
|
||||
"INSERT INTO user (login, password) VALUES (?, ?)",
|
||||
DB_TEXT, login, DB_BLOB, hash) < 0)
|
||||
{
|
||||
request->setf(request, "error=Username already exists.");
|
||||
free(hash.ptr);
|
||||
break;
|
||||
}
|
||||
free(hash.ptr);
|
||||
this->user->set_user(this->user, id);
|
||||
return request->redirect(request, "peer/list");
|
||||
}
|
||||
request->set(request, "new_login", login);
|
||||
request->setf(request, "password_length=%d", this->password_length);
|
||||
request->render(request, "templates/user/add.cs");
|
||||
}
|
||||
|
||||
/**
|
||||
* Edit the logged in user
|
||||
*/
|
||||
static void edit(private_user_controller_t *this, fast_request_t *request)
|
||||
{
|
||||
enumerator_t *query;
|
||||
char *old_login;
|
||||
|
||||
/* lookup old login */
|
||||
query = this->db->query(this->db, "SELECT login FROM user WHERE id = ?",
|
||||
DB_INT, this->user->get_user(this->user),
|
||||
DB_TEXT);
|
||||
if (!query || !query->enumerate(query, &old_login))
|
||||
{
|
||||
DESTROY_IF(query);
|
||||
request->close_session(request);
|
||||
return request->redirect(request, "user/login");
|
||||
}
|
||||
old_login = strdupa(old_login);
|
||||
query->destroy(query);
|
||||
|
||||
/* back pressed */
|
||||
if (request->get_query_data(request, "back"))
|
||||
{
|
||||
return request->redirect(request, "peer/list");
|
||||
}
|
||||
/* delete pressed */
|
||||
if (request->get_query_data(request, "delete"))
|
||||
{
|
||||
this->db->execute(this->db, NULL, "DELETE FROM user WHERE id = ?",
|
||||
DB_UINT, this->user->get_user(this->user));
|
||||
this->db->execute(this->db, NULL,
|
||||
"DELETE FROM peer WHERE user = ?",
|
||||
DB_UINT, this->user->get_user(this->user));
|
||||
return logout(this, request);
|
||||
}
|
||||
/* save pressed */
|
||||
while (request->get_query_data(request, "save"))
|
||||
{
|
||||
char *new_login, *old_pass, *new_pass, *confirm;
|
||||
chunk_t old_hash, new_hash;
|
||||
|
||||
new_login = request->get_query_data(request, "old_login");
|
||||
old_pass = request->get_query_data(request, "old_password");
|
||||
new_pass = request->get_query_data(request, "new_password");
|
||||
confirm = request->get_query_data(request, "confirm_password");
|
||||
|
||||
if (!verify_login(this, request, new_login) ||
|
||||
!verify_password(this, request, new_pass, confirm))
|
||||
{
|
||||
old_login = new_login;
|
||||
break;
|
||||
}
|
||||
old_hash = hash_password(old_login, old_pass);
|
||||
new_hash = hash_password(new_login, new_pass);
|
||||
|
||||
if (this->db->execute(this->db, NULL,
|
||||
"UPDATE user SET login = ?, password = ? "
|
||||
"WHERE id = ? AND password = ?",
|
||||
DB_TEXT, new_login, DB_BLOB, new_hash,
|
||||
DB_UINT, this->user->get_user(this->user), DB_BLOB, old_hash) <= 0)
|
||||
{
|
||||
free(new_hash.ptr);
|
||||
free(old_hash.ptr);
|
||||
old_login = new_login;
|
||||
request->setf(request, "error=Password verification failed.");
|
||||
break;
|
||||
}
|
||||
free(new_hash.ptr);
|
||||
free(old_hash.ptr);
|
||||
return request->redirect(request, "peer/list");
|
||||
}
|
||||
/* on error/template rendering */
|
||||
request->set(request, "old_login", old_login);
|
||||
request->setf(request, "password_length=%d", this->password_length);
|
||||
request->render(request, "templates/user/edit.cs");
|
||||
}
|
||||
|
||||
METHOD(fast_controller_t, get_name, char*,
|
||||
private_user_controller_t *this)
|
||||
{
|
||||
return "user";
|
||||
}
|
||||
|
||||
METHOD(fast_controller_t, handle, void,
|
||||
private_user_controller_t *this, fast_request_t *request, char *action,
|
||||
char *p2, char *p3, char *p4, char *p5)
|
||||
{
|
||||
if (action)
|
||||
{
|
||||
if (streq(action, "add"))
|
||||
{
|
||||
return add(this, request);
|
||||
}
|
||||
if (streq(action, "login"))
|
||||
{
|
||||
return login(this, request);
|
||||
}
|
||||
else if (streq(action, "logout"))
|
||||
{
|
||||
return logout(this, request);
|
||||
}
|
||||
else if (streq(action, "edit"))
|
||||
{
|
||||
return edit(this, request);
|
||||
}
|
||||
else if (streq(action, "help"))
|
||||
{
|
||||
return request->render(request, "templates/user/help.cs");
|
||||
}
|
||||
}
|
||||
request->redirect(request, "user/login");
|
||||
}
|
||||
|
||||
METHOD(fast_controller_t, destroy, void,
|
||||
private_user_controller_t *this)
|
||||
{
|
||||
free(this);
|
||||
}
|
||||
|
||||
/*
|
||||
* see header file
|
||||
*/
|
||||
fast_controller_t *user_controller_create(user_t *user, database_t *db)
|
||||
{
|
||||
private_user_controller_t *this;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.controller = {
|
||||
.get_name = _get_name,
|
||||
.handle = _handle,
|
||||
.destroy = _destroy,
|
||||
},
|
||||
},
|
||||
.user = user,
|
||||
.db = db,
|
||||
.password_length = lib->settings->get_int(lib->settings,
|
||||
"medsrv.password_length", 6),
|
||||
);
|
||||
|
||||
return &this->public.controller;
|
||||
}
|
||||
@@ -1,49 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
* Copyright (C) 2008 Philip Boetschi, Adrian Doerig
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup user_controller_server user_controller
|
||||
* @{ @ingroup medsrv
|
||||
*/
|
||||
|
||||
#ifndef USER_CONTROLLER_H_
|
||||
#define USER_CONTROLLER_H_
|
||||
|
||||
#include <user.h>
|
||||
|
||||
#include <fast_controller.h>
|
||||
#include <database/database.h>
|
||||
|
||||
typedef struct user_controller_t user_controller_t;
|
||||
|
||||
/**
|
||||
* User controller. Register, Login and user management.
|
||||
*/
|
||||
struct user_controller_t {
|
||||
|
||||
/**
|
||||
* Implements controller_t interface.
|
||||
*/
|
||||
fast_controller_t controller;
|
||||
};
|
||||
|
||||
/**
|
||||
* Create a user_controller controller instance.
|
||||
*/
|
||||
fast_controller_t *user_controller_create(user_t *user, database_t *db);
|
||||
|
||||
#endif /** USER_CONTROLLER_H_ @}*/
|
||||
@@ -1,99 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
* Copyright (C) 2008 Philip Boetschi, Adrian Doerig
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "auth_filter.h"
|
||||
|
||||
#include <utils/debug.h>
|
||||
|
||||
typedef struct private_auth_filter_t private_auth_filter_t;
|
||||
|
||||
/**
|
||||
* private data of auth_filter
|
||||
*/
|
||||
struct private_auth_filter_t {
|
||||
/**
|
||||
* public functions
|
||||
*/
|
||||
auth_filter_t public;
|
||||
|
||||
/**
|
||||
* user session
|
||||
*/
|
||||
user_t *user;
|
||||
|
||||
/**
|
||||
* database connection
|
||||
*/
|
||||
database_t *db;
|
||||
};
|
||||
|
||||
METHOD(fast_filter_t, run, bool,
|
||||
private_auth_filter_t *this, fast_request_t *request, char *controller,
|
||||
char *action, char *p2, char *p3, char *p4, char *p5)
|
||||
{
|
||||
if (this->user->get_user(this->user))
|
||||
{
|
||||
enumerator_t *query;
|
||||
char *login;
|
||||
|
||||
query = this->db->query(this->db, "SELECT login FROM user WHERE id = ?",
|
||||
DB_INT, this->user->get_user(this->user),
|
||||
DB_TEXT);
|
||||
if (query && query->enumerate(query, &login))
|
||||
{
|
||||
request->set(request, "login", login);
|
||||
query->destroy(query);
|
||||
return TRUE;
|
||||
}
|
||||
DESTROY_IF(query);
|
||||
this->user->set_user(this->user, 0);
|
||||
}
|
||||
if (controller && streq(controller, "user") && action &&
|
||||
(streq(action, "add") || streq(action, "login") || streq(action, "help")))
|
||||
{ /* add/login allowed */
|
||||
return TRUE;
|
||||
}
|
||||
request->redirect(request, "user/login");
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
METHOD(fast_filter_t, destroy, void,
|
||||
private_auth_filter_t *this)
|
||||
{
|
||||
free(this);
|
||||
}
|
||||
|
||||
/*
|
||||
* see header file
|
||||
*/
|
||||
fast_filter_t *auth_filter_create(user_t *user, database_t *db)
|
||||
{
|
||||
private_auth_filter_t *this;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.filter = {
|
||||
.destroy = _destroy,
|
||||
.run = _run,
|
||||
},
|
||||
},
|
||||
.user = user,
|
||||
.db = db,
|
||||
);
|
||||
|
||||
return &this->public.filter;
|
||||
}
|
||||
@@ -1,49 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
* Copyright (C) 2008 Philip Boetschi, Adrian Doerig
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup auth_filter_server auth_filter
|
||||
* @{ @ingroup medsrv
|
||||
*/
|
||||
|
||||
#ifndef AUTH_FILTER_H_
|
||||
#define AUTH_FILTER_H_
|
||||
|
||||
#include <library.h>
|
||||
#include <fast_filter.h>
|
||||
|
||||
#include "user.h"
|
||||
|
||||
typedef struct auth_filter_t auth_filter_t;
|
||||
|
||||
/**
|
||||
* Authentication/Authorization filter.
|
||||
*/
|
||||
struct auth_filter_t {
|
||||
|
||||
/**
|
||||
* Implements filter_t interface.
|
||||
*/
|
||||
fast_filter_t filter;
|
||||
};
|
||||
|
||||
/**
|
||||
* Create a auth_filter instance.
|
||||
*/
|
||||
fast_filter_t *auth_filter_create(user_t *user, database_t *db);
|
||||
|
||||
#endif /** AUTH_FILTER_H_ @}*/
|
||||
@@ -1,79 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
* Copyright (C) 2008 Philip Boetschi, Adrian Doerig
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include <stdio.h>
|
||||
|
||||
#include <fast_dispatcher.h>
|
||||
#include <utils/debug.h>
|
||||
#include <database/database.h>
|
||||
|
||||
#include "filter/auth_filter.h"
|
||||
#include "controller/user_controller.h"
|
||||
#include "controller/peer_controller.h"
|
||||
|
||||
int main(int arc, char *argv[])
|
||||
{
|
||||
fast_dispatcher_t *dispatcher;
|
||||
database_t *db;
|
||||
char *socket;
|
||||
bool debug;
|
||||
char *uri;
|
||||
int timeout, threads;
|
||||
|
||||
library_init(NULL, "medsrv");
|
||||
if (!lib->plugins->load(lib->plugins,
|
||||
lib->settings->get_str(lib->settings, "medsrv.load", PLUGINS)))
|
||||
{
|
||||
return 1;
|
||||
}
|
||||
|
||||
socket = lib->settings->get_str(lib->settings, "medsrv.socket", NULL);
|
||||
debug = lib->settings->get_bool(lib->settings, "medsrv.debug", FALSE);
|
||||
timeout = lib->settings->get_time(lib->settings, "medsrv.timeout", 900);
|
||||
threads = lib->settings->get_int(lib->settings, "medsrv.threads", 5);
|
||||
uri = lib->settings->get_str(lib->settings, "medsrv.database", NULL);
|
||||
if (uri == NULL)
|
||||
{
|
||||
fprintf(stderr, "database URI medsrv.database not defined.\n");
|
||||
return 1;
|
||||
}
|
||||
|
||||
db = lib->db->create(lib->db, uri);
|
||||
if (db == NULL)
|
||||
{
|
||||
fprintf(stderr, "opening database failed.\n");
|
||||
return 1;
|
||||
}
|
||||
|
||||
dispatcher = fast_dispatcher_create(socket, debug, timeout,
|
||||
(fast_context_constructor_t)user_create, db);
|
||||
dispatcher->add_filter(dispatcher,
|
||||
(fast_filter_constructor_t)auth_filter_create, db);
|
||||
dispatcher->add_controller(dispatcher,
|
||||
(fast_controller_constructor_t)user_controller_create, db);
|
||||
dispatcher->add_controller(dispatcher,
|
||||
(fast_controller_constructor_t)peer_controller_create, db);
|
||||
|
||||
dispatcher->run(dispatcher, threads);
|
||||
|
||||
dispatcher->waitsignal(dispatcher);
|
||||
dispatcher->destroy(dispatcher);
|
||||
db->destroy(db);
|
||||
|
||||
library_deinit();
|
||||
return 0;
|
||||
}
|
||||
@@ -1,4 +0,0 @@
|
||||
</div>
|
||||
</div>
|
||||
</body>
|
||||
</html>
|
||||
@@ -1,31 +0,0 @@
|
||||
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/2002/REC-xhtml1-20020801/DTD/xhtml1-transitional.dtd">
|
||||
<html xmlns="http://www.w3.org/1999/xhtml">
|
||||
<head>
|
||||
<title>strongSwan Mediation Service</title>
|
||||
<link rel="stylesheet" type="text/css" href="<?cs var:base ?>/static/style.css"/>
|
||||
<link rel="icon" href="<?cs var:base ?>/static/favicon.ico" type="image/x-icon" />
|
||||
<script type="text/javascript" src="<?cs var:base ?>/static/mootools.js"></script>
|
||||
<script type="text/javascript" src="<?cs var:base ?>/static/script.js"></script>
|
||||
</head>
|
||||
<body>
|
||||
<div class="fleft">
|
||||
<a href="<?cs var:base ?>/peer/list">
|
||||
<img class="fleft" src="<?cs var:base ?>/static/strongswan.png"/>
|
||||
</a>
|
||||
<h1>Mediation Service</h1>
|
||||
</div>
|
||||
<div class="menu">
|
||||
<?cs if:?login ?>
|
||||
Logged in as <i><?cs var:login ?></i>
|
||||
| <a href="<?cs var:base ?>/user/edit">Edit</a>
|
||||
| <a href="<?cs var:base ?>/user/logout">Logout</a>
|
||||
| <a href="<?cs var:base ?>/user/help">Help</a>
|
||||
<?cs else ?>
|
||||
| <a href="<?cs var:base ?>/user/help">Help</a>
|
||||
| <a href="<?cs var:base ?>/user/login">Login</a>
|
||||
| <a href="<?cs var:base ?>/user/add">Register</a>
|
||||
<?cs /if ?>
|
||||
</div>
|
||||
<hr class="cleft"/>
|
||||
<div class="center">
|
||||
<div class="content">
|
||||
@@ -1,24 +0,0 @@
|
||||
<?cs include:"templates/header.cs" ?>
|
||||
<form method="post">
|
||||
<?cs if:?error ?>
|
||||
<div class="error"><?cs var:error ?></div>
|
||||
<?cs /if ?>
|
||||
<table class="peer">
|
||||
<tr>
|
||||
<td><label for="alias">Alias</label></td>
|
||||
<td><input type="text" id="alias" name="alias" autofocus maxlength="30" value="<?cs var:alias ?>";"/></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td valign="top"><label for="public_key">Public Key</label></td>
|
||||
<td><textarea id="public_key" name="public_key"><?cs var:public_key ?></textarea></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td></td>
|
||||
<td class="right">
|
||||
<input type="submit" value="Back" name="back"/>
|
||||
<input type="submit" value="Add" name="add"/>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
</form>
|
||||
<?cs include:"templates/footer.cs" ?>
|
||||
@@ -1,25 +0,0 @@
|
||||
<?cs include:"templates/header.cs" ?>
|
||||
<form method="post" name="form">
|
||||
<?cs if:?error ?>
|
||||
<div class="error"><?cs var:error ?></div>
|
||||
<?cs /if ?>
|
||||
<table class="peer">
|
||||
<tr>
|
||||
<td><label for="alias">Alias</label></td>
|
||||
<td><input type="text" id="alias" name="alias" maxlength="30" autofocus value="<?cs var:alias ?>"/></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td valign="top"><label for="public_key">Public Key</label></td>
|
||||
<td><textarea id="public_key" name="public_key"><?cs var:public_key ?></textarea></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td></td>
|
||||
<td align="right">
|
||||
<input type="submit" value="Back" name="back"/>
|
||||
<input type="submit" value="Delete" name="delete" onclick="return confirm('Permanently delete this peer?')"/>
|
||||
<input type="submit" value="Save" name="save"/>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
</form>
|
||||
<?cs include:"templates/footer.cs" ?>
|
||||
@@ -1,28 +0,0 @@
|
||||
<?cs include:"templates/header.cs" ?>
|
||||
<div>
|
||||
<?cs if subcount(peers) > 0 ?>
|
||||
<table class="list">
|
||||
<tr>
|
||||
<th>Alias</th>
|
||||
<th>Key Identifier</th>
|
||||
</tr>
|
||||
<?cs each:peer = peers ?>
|
||||
<tr>
|
||||
<td>
|
||||
<a href="<?cs var:base ?>/peer/edit/<?cs name:peer?>"><?cs var:peer.alias ?></a>
|
||||
</td>
|
||||
<td>
|
||||
<a href="<?cs var:base ?>/peer/edit/<?cs name:peer?>"><?cs var:peer.identifier ?></a>
|
||||
</td>
|
||||
</tr>
|
||||
<?cs /each ?>
|
||||
</table>
|
||||
<?cs else ?>
|
||||
No peers defined.
|
||||
<?cs /if ?>
|
||||
<div class="right">
|
||||
<form action="<?cs var:base ?>/peer/add" method="get">
|
||||
<input type="submit" value="Add Peer"/></td>
|
||||
</form>
|
||||
</div>
|
||||
<?cs include:"templates/footer.cs" ?>
|
||||
Binary file not shown.
|
Before Width: | Height: | Size: 894 B |
Binary file not shown.
|
Before Width: | Height: | Size: 19 KiB |
@@ -1,128 +0,0 @@
|
||||
|
||||
body {
|
||||
font-family: Verdana, Arial, Helvetica, sans-serif;
|
||||
color: #230100;
|
||||
background-color: #f7f4d3;
|
||||
margin: 0;
|
||||
}
|
||||
|
||||
.content {
|
||||
}
|
||||
|
||||
.content > * {
|
||||
background-color: #e5bf5e;
|
||||
border: solid 2px;
|
||||
padding: 1em 1em 1em 1em;
|
||||
margin: 1em;
|
||||
text-align: left;
|
||||
}
|
||||
|
||||
textarea, select, input {
|
||||
background-color: #ffec9e;
|
||||
border: 1px solid;
|
||||
padding: 1px 3px 1px 3px;
|
||||
}
|
||||
|
||||
table.user input[type="text"], table.user input[type="password"] {
|
||||
width: 15em;
|
||||
}
|
||||
|
||||
table.peer textarea {
|
||||
height: 20em;
|
||||
width: 42.3em;
|
||||
|
||||
}
|
||||
|
||||
table.peer input[type="text"] {
|
||||
width: 38em;
|
||||
}
|
||||
|
||||
.menu {
|
||||
text-align: right;
|
||||
background-color: #e5bf5e;
|
||||
padding: 3px;
|
||||
border-bottom: solid 2px;
|
||||
}
|
||||
|
||||
a {
|
||||
color: black;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
a:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
h1 {
|
||||
margin-top: 1.5em;
|
||||
font-size: 2.1em;
|
||||
white-space: nowrap;
|
||||
}
|
||||
|
||||
hr {
|
||||
border: solid 1px;
|
||||
}
|
||||
|
||||
a img {
|
||||
border: none;
|
||||
}
|
||||
|
||||
.center {
|
||||
text-align: center;
|
||||
}
|
||||
|
||||
.left {
|
||||
text-align: left;
|
||||
}
|
||||
|
||||
.right {
|
||||
text-align: right;
|
||||
}
|
||||
|
||||
.fleft {
|
||||
margin-right: 2em;
|
||||
float: left;
|
||||
}
|
||||
|
||||
.fright {
|
||||
float: left;
|
||||
}
|
||||
|
||||
.cleft {
|
||||
clear:left;
|
||||
}
|
||||
|
||||
.cright {
|
||||
clear:right;
|
||||
}
|
||||
|
||||
.both {
|
||||
clear:both;
|
||||
}
|
||||
|
||||
.error {
|
||||
color: #dd0000;
|
||||
}
|
||||
|
||||
table.list * {
|
||||
padding: 0px 1em 0px 0.2em;
|
||||
}
|
||||
|
||||
table.list tr td, table.list tr th {
|
||||
border: solid 1px;
|
||||
border-color: black;
|
||||
}
|
||||
|
||||
table.list tr th {
|
||||
background-color: #ffec9e;
|
||||
}
|
||||
|
||||
table.list tr:nth-child(odd) td {
|
||||
background-color: #f2cd6f;
|
||||
}
|
||||
|
||||
table.list tr td a {
|
||||
text-decoration: none;
|
||||
display: inline-block;
|
||||
width: 100%;
|
||||
}
|
||||
@@ -1,28 +0,0 @@
|
||||
<?cs include:"templates/header.cs" ?>
|
||||
<form method="post">
|
||||
<?cs if:?error ?>
|
||||
<div class="error"><?cs var:error ?></div>
|
||||
<?cs /if ?>
|
||||
<table class="user">
|
||||
<tr>
|
||||
<td><label for="new_login">Username</label></td>
|
||||
<td><input type="text" id="new_login" name="new_login" autofocus maxlength="30" value="<?cs var:new_login ?>"/></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><label for="new_password">Password</label></td>
|
||||
<td><input type="password" id="new_password" name="new_password"/></td>
|
||||
<td><small>min. <?cs var:password_length ?> characters</small></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><label for="confirm_password">Confirm password</label></td>
|
||||
<td><input type="password" id="confirm_password" name="confirm_password"/></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td/>
|
||||
<td class="right">
|
||||
<input type="submit" value="Register" name="register"/>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
</form>
|
||||
<?cs include:"templates/footer.cs" ?>
|
||||
@@ -1,35 +0,0 @@
|
||||
<?cs include:"templates/header.cs" ?>
|
||||
<form method="post">
|
||||
<?cs if:?error ?>
|
||||
<div class="error"><?cs var:error ?></div>
|
||||
<?cs /if ?>
|
||||
<table class="user">
|
||||
<tr>
|
||||
<td><label for="old_login">Username</label></td>
|
||||
<td><input type="text" id="old_login" name="old_login" maxlength="30" value="<?cs var:old_login ?>" /></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><label for="old_password">Old password</label></td>
|
||||
<td><input type="password" id="old_password" name="old_password"/></td>
|
||||
<td></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><label for="new_password">New password</label></td>
|
||||
<td><input type="password" id="new_password" name="new_password"/></td>
|
||||
<td><small>min. <?cs var:password_length ?> characters</small></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><label for="confirm_password">Confirm new password</label></td>
|
||||
<td><input type="password" id="confirm_password" name="confirm_password"/></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td></td>
|
||||
<td class="right">
|
||||
<input type="submit" value="Back" name="back"/>
|
||||
<input type="submit" value="Delete" name="delete" onclick="return confirm('Permanently delete your account?')"/>
|
||||
<input type="submit" value="Save" name="save"/>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
</form>
|
||||
<?cs include:"templates/footer.cs" ?>
|
||||
@@ -1,34 +0,0 @@
|
||||
<?cs include:"templates/header.cs" ?>
|
||||
<div>
|
||||
<h3>strongSwan Mediation Service web frontend</h3>
|
||||
<p>This web application builds the end user front end for a Mediation Service
|
||||
as defined in the <i>
|
||||
<a href="http://www.ietf.org/internet-drafts/draft-brunner-ikev2-mediation-00.txt">
|
||||
IKEv2 Mediation Extension draft</a></i>.</p>
|
||||
<h4>Mediation connection</h4>
|
||||
<p>The authentication between Mediation Server and connecting clients is based
|
||||
on RSA public keys. The identities used for IKEv2 are the public key identifier
|
||||
of each clients key, encapsulated in a ID_KEY_ID identity.</p>
|
||||
<p>The public key of this Mediation Server is:</p>
|
||||
<pre>-----BEGIN PUBLIC KEY-----
|
||||
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzZRsIp99UrIdoctThOfc
|
||||
r2Up92BTSlY1Xv1J6Hqcbx3dX/MDvX60nCPeA63Eh0VvQetfkpR73I/42+RD+NES
|
||||
4NosmBRefE0c0Vzd0IV39NTz0KLh2jwIyUzYGXWHUZMeepckzEPXOhG44XaiaLTN
|
||||
u/OZXLCXI6vJv8R3wl5xSkZhqEwHi+dATYmGvlXyBDfjprJ4o8yJrsCFlB8aGq+v
|
||||
SyKuFG/kaE1VZ9wwZYoyCH0BuYUVBwyxZTMRy2EC+CqDxjjCp5mF27lgB1Lpy8Jy
|
||||
AUpcVHtKtZEww6lIZYv/eUtvICz5WTn/pzsQUh8FwGDOyxX4WX7ZXXK55AXuMfG1
|
||||
2QIDAQAB
|
||||
-----END PUBLIC KEY-----</pre>
|
||||
<p>The Mediation Server is reachable at <i>mediation.strongswan.org</i>.</p>
|
||||
The mediation server allows connections from all registered peers.</p>
|
||||
<h4>Mediated connections</h4>
|
||||
<p>The authentication between mediated clients is done between clients, they
|
||||
can use own keys or the same keys as defined for authentication of the
|
||||
mediation connection.
|
||||
<form action="<?cs var:base ?>/peer/list" method="get">
|
||||
<div class="right">
|
||||
<input type="submit" value="Back"/></td>
|
||||
</div>
|
||||
</form>
|
||||
</div>
|
||||
<?cs include:"templates/footer.cs" ?>
|
||||
@@ -1,23 +0,0 @@
|
||||
<?cs include:"templates/header.cs" ?>
|
||||
<form method="post">
|
||||
<?cs if:?error ?>
|
||||
<div class="error"><?cs var:error ?></div>
|
||||
<?cs /if ?>
|
||||
<table class="user">
|
||||
<tr>
|
||||
<td><label for="login">Username</label></td>
|
||||
<td><input type="text" id="login" name="login" size="30" maxlength="30" autofocus /></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td><label for="password">Password</label></td>
|
||||
<td><input type="password" id="password" name="password" size="30"/></td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td/>
|
||||
<td class="right">
|
||||
<input type="submit" value="Login" name="submit"/>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
</form>
|
||||
<?cs include:"templates/footer.cs" ?>
|
||||
@@ -1,73 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
#include "user.h"
|
||||
|
||||
typedef struct private_user_t private_user_t;
|
||||
|
||||
/**
|
||||
* private data of user
|
||||
*/
|
||||
struct private_user_t {
|
||||
|
||||
/**
|
||||
* public functions
|
||||
*/
|
||||
user_t public;
|
||||
|
||||
/**
|
||||
* user id, if we are logged in; otherwise 0
|
||||
*/
|
||||
u_int user;
|
||||
};
|
||||
|
||||
METHOD(user_t, set_user, void,
|
||||
private_user_t *this, u_int id)
|
||||
{
|
||||
this->user = id;
|
||||
}
|
||||
|
||||
METHOD(user_t, get_user, u_int,
|
||||
private_user_t *this)
|
||||
{
|
||||
return this->user;
|
||||
}
|
||||
|
||||
METHOD(fast_context_t, destroy, void,
|
||||
private_user_t *this)
|
||||
{
|
||||
free(this);
|
||||
}
|
||||
|
||||
/*
|
||||
* see header file
|
||||
*/
|
||||
user_t *user_create(void *param)
|
||||
{
|
||||
private_user_t *this;
|
||||
|
||||
INIT(this,
|
||||
.public = {
|
||||
.set_user = _set_user,
|
||||
.get_user = _get_user,
|
||||
.context = {
|
||||
.destroy = _destroy,
|
||||
},
|
||||
},
|
||||
);
|
||||
|
||||
return &this->public;
|
||||
}
|
||||
@@ -1,58 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2008 Martin Willi
|
||||
*
|
||||
* Copyright (C) secunet Security Networks AG
|
||||
*
|
||||
* This program is free software; you can redistribute it and/or modify it
|
||||
* under the terms of the GNU General Public License as published by the
|
||||
* Free Software Foundation; either version 2 of the License, or (at your
|
||||
* option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
|
||||
*
|
||||
* This program is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
|
||||
* or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
|
||||
* for more details.
|
||||
*/
|
||||
|
||||
/**
|
||||
* @defgroup medsrv medsrv
|
||||
*
|
||||
* @defgroup user user
|
||||
* @{ @ingroup medsrv
|
||||
*/
|
||||
|
||||
#ifndef USER_H_
|
||||
#define USER_H_
|
||||
|
||||
#include <fast_context.h>
|
||||
#include <library.h>
|
||||
|
||||
typedef struct user_t user_t;
|
||||
|
||||
/**
|
||||
* Per session context. Contains user user state and data.
|
||||
*/
|
||||
struct user_t {
|
||||
|
||||
/**
|
||||
* implements context_t interface
|
||||
*/
|
||||
fast_context_t context;
|
||||
|
||||
/**
|
||||
* Set the user ID of the logged in user.
|
||||
*/
|
||||
void (*set_user)(user_t *this, u_int id);
|
||||
|
||||
/**
|
||||
* Get the user ID of the logged in user.
|
||||
*/
|
||||
u_int (*get_user)(user_t *this);
|
||||
};
|
||||
|
||||
/**
|
||||
* Create a user instance.
|
||||
*/
|
||||
user_t *user_create(void *param);
|
||||
|
||||
#endif /** USER_H_ @} */
|
||||
Reference in New Issue
Block a user