diff --git a/conf/Makefile.am b/conf/Makefile.am index 6fefbf630..d2601b677 100644 --- a/conf/Makefile.am +++ b/conf/Makefile.am @@ -20,7 +20,6 @@ options = \ options/imcv.opt \ options/imv_policy_manager.opt \ options/iptfs.opt \ - options/medsrv.opt \ options/pki.opt \ options/pool.opt \ options/starter.opt \ diff --git a/conf/options/medsrv.opt b/conf/options/medsrv.opt deleted file mode 100644 index f673b7e03..000000000 --- a/conf/options/medsrv.opt +++ /dev/null @@ -1,27 +0,0 @@ -medsrv.database = - Mediation server database URI. If it contains a password, make - sure to adjust the permissions of the config file accordingly. - -medsrv.debug = no - Debugging in mediation server web application. - -medsrv.dpd = 5m - DPD timeout to use in mediation server plugin. - -medsrv.load = - Plugins to load in mediation server plugin. - -medsrv.password_length = 6 - Minimum password length required for mediation server user accounts. - -medsrv.rekey = 20m - Rekeying time on mediation connections in mediation server plugin. - -medsrv.socket = - Run Mediation server web application statically on socket. - -medsrv.threads = 5 - Number of thread for mediation service web application. - -medsrv.timeout = 15m - Session timeout for mediation service. diff --git a/configure.ac b/configure.ac index 2c7dc637a..66be9fab7 100644 --- a/configure.ac +++ b/configure.ac @@ -290,8 +290,6 @@ ARG_ENABL_SET([conftest], [enforce Suite B conformance test framework.]) ARG_ENABL_SET([fast], [enable libfast (FastCGI Application Server w/ templates.]) ARG_ENABL_SET([fuzzing], [enable fuzzing scripts (found in directory fuzz).]) ARG_ENABL_SET([libipsec], [enable user space IPsec implementation.]) -ARG_ENABL_SET([medcli], [enable mediation client configuration database plugin.]) -ARG_ENABL_SET([medsrv], [enable mediation server web frontend and daemon plugin.]) ARG_ENABL_SET([nm], [enable NetworkManager backend.]) ARG_DISBL_SET([pki], [disable pki certificate utility.]) ARG_DISBL_SET([scripts], [disable additional utilities (found in directory scripts).]) @@ -473,15 +471,6 @@ if test x$tnccs_11 = xtrue -o x$tnc_ifmap = xtrue; then xml=true fi -if test x$medsrv = xtrue; then - mediation=true - fast=true -fi - -if test x$medcli = xtrue; then - mediation=true -fi - if test x$ruby_gems_install = xtrue; then ruby_gems=true fi @@ -1528,7 +1517,6 @@ pool_plugins= attest_plugins= pki_plugins= scripts_plugins= -medsrv_plugins= nm_plugins= cmd_plugins= aikgen_plugins= @@ -1548,26 +1536,26 @@ ADD_PLUGIN([unbound], [s charon scripts]) ADD_PLUGIN([ldap], [s charon pki scripts nm cmd]) ADD_PLUGIN([pkcs11], [s charon pki nm cmd]) ADD_PLUGIN([tpm], [p charon pki nm cmd]) -ADD_PLUGIN([aesni], [s charon swanctl pki scripts medsrv attest nm cmd aikgen]) +ADD_PLUGIN([aesni], [s charon swanctl pki scripts attest nm cmd aikgen]) ADD_PLUGIN([aes], [s charon swanctl pki scripts nm cmd]) ADD_PLUGIN([des], [s charon swanctl pki scripts nm cmd]) ADD_PLUGIN([blowfish], [s charon swanctl pki scripts nm cmd]) ADD_PLUGIN([rc2], [s charon swanctl pki scripts nm cmd]) -ADD_PLUGIN([sha2], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fc]) -ADD_PLUGIN([sha3], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fc]) -ADD_PLUGIN([sha1], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fc]) +ADD_PLUGIN([sha2], [s charon swanctl pki scripts attest nm cmd aikgen fc]) +ADD_PLUGIN([sha3], [s charon swanctl pki scripts attest nm cmd aikgen fc]) +ADD_PLUGIN([sha1], [s charon swanctl pki scripts attest nm cmd aikgen fc]) ADD_PLUGIN([md4], [s charon swanctl pki nm cmd]) ADD_PLUGIN([md5], [s charon swanctl pki scripts attest nm cmd aikgen]) -ADD_PLUGIN([mgf1], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fc]) -ADD_PLUGIN([rdrand], [s charon swanctl pki scripts medsrv attest nm cmd aikgen]) -ADD_PLUGIN([random], [s charon swanctl pki scripts medsrv attest nm cmd aikgen]) +ADD_PLUGIN([mgf1], [s charon swanctl pki scripts attest nm cmd aikgen fc]) +ADD_PLUGIN([rdrand], [s charon swanctl pki scripts attest nm cmd aikgen]) +ADD_PLUGIN([random], [s charon swanctl pki scripts attest nm cmd aikgen]) ADD_PLUGIN([nonce], [s charon nm cmd aikgen]) ADD_PLUGIN([x509], [s charon swanctl pki scripts attest nm cmd aikgen fd fc]) ADD_PLUGIN([revocation], [s charon pki nm cmd]) ADD_PLUGIN([constraints], [s charon pki nm cmd]) ADD_PLUGIN([acert], [s charon]) ADD_PLUGIN([pubkey], [s charon swanctl pki cmd aikgen]) -ADD_PLUGIN([pkcs1], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fd fc]) +ADD_PLUGIN([pkcs1], [s charon swanctl pki scripts attest nm cmd aikgen fd fc]) ADD_PLUGIN([pkcs7], [s charon swanctl pki scripts nm cmd]) ADD_PLUGIN([pkcs12], [s charon swanctl pki scripts cmd]) ADD_PLUGIN([pgp], [s charon]) @@ -1575,16 +1563,16 @@ ADD_PLUGIN([dnskey], [s charon swanctl pki]) ADD_PLUGIN([sshkey], [s charon swanctl pki nm cmd]) ADD_PLUGIN([dnscert], [c charon]) ADD_PLUGIN([ipseckey], [c charon]) -ADD_PLUGIN([pem], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fd fc]) +ADD_PLUGIN([pem], [s charon swanctl pki scripts attest nm cmd aikgen fd fc]) ADD_PLUGIN([padlock], [s charon]) -ADD_PLUGIN([openssl], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fd]) -ADD_PLUGIN([wolfssl], [s charon swanctl pki scripts medsrv attest nm cmd aikgen]) -ADD_PLUGIN([gcrypt], [s charon swanctl pki scripts medsrv attest nm cmd aikgen]) -ADD_PLUGIN([botan], [s charon swanctl pki scripts medsrv attest nm cmd aikgen]) -ADD_PLUGIN([pkcs8], [s charon swanctl pki scripts medsrv attest nm cmd]) -ADD_PLUGIN([af-alg], [s charon swanctl pki scripts medsrv attest nm cmd aikgen]) +ADD_PLUGIN([openssl], [s charon swanctl pki scripts attest nm cmd aikgen fd]) +ADD_PLUGIN([wolfssl], [s charon swanctl pki scripts attest nm cmd aikgen]) +ADD_PLUGIN([gcrypt], [s charon swanctl pki scripts attest nm cmd aikgen]) +ADD_PLUGIN([botan], [s charon swanctl pki scripts attest nm cmd aikgen]) +ADD_PLUGIN([pkcs8], [s charon swanctl pki scripts attest nm cmd]) +ADD_PLUGIN([af-alg], [s charon swanctl pki scripts attest nm cmd aikgen]) ADD_PLUGIN([fips-prf], [s charon nm cmd]) -ADD_PLUGIN([gmp], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fc]) +ADD_PLUGIN([gmp], [s charon swanctl pki scripts attest nm cmd aikgen fc]) ADD_PLUGIN([curve25519], [s charon swanctl pki scripts nm cmd]) ADD_PLUGIN([agent], [s charon nm cmd]) ADD_PLUGIN([keychain], [s charon cmd]) @@ -1602,8 +1590,8 @@ ADD_PLUGIN([curl], [s charon pki scripts nm cmd]) ADD_PLUGIN([files], [s charon pki scripts nm cmd]) ADD_PLUGIN([winhttp], [s charon pki scripts]) ADD_PLUGIN([soup], [s charon pki scripts nm cmd]) -ADD_PLUGIN([mysql], [s charon pki pool medsrv attest]) -ADD_PLUGIN([sqlite], [s charon pki pool medsrv attest]) +ADD_PLUGIN([mysql], [s charon pki pool attest]) +ADD_PLUGIN([sqlite], [s charon pki pool attest]) ADD_PLUGIN([openxpki], [s pki]) ADD_PLUGIN([attr], [c charon]) ADD_PLUGIN([attr-sql], [c charon]) @@ -1659,8 +1647,6 @@ ADD_PLUGIN([tnc-tnccs], [t charon]) ADD_PLUGIN([tnccs-20], [t charon]) ADD_PLUGIN([tnccs-11], [t charon]) ADD_PLUGIN([tnccs-dynamic], [t charon]) -ADD_PLUGIN([medsrv], [c charon]) -ADD_PLUGIN([medcli], [c charon]) ADD_PLUGIN([dhcp], [c charon]) ADD_PLUGIN([osx-attr], [c charon cmd]) ADD_PLUGIN([p-cscf], [c charon cmd]) @@ -1687,7 +1673,6 @@ AC_SUBST(pool_plugins) AC_SUBST(attest_plugins) AC_SUBST(pki_plugins) AC_SUBST(scripts_plugins) -AC_SUBST(medsrv_plugins) AC_SUBST(nm_plugins) AC_SUBST(cmd_plugins) AC_SUBST(aikgen_plugins) @@ -1770,8 +1755,6 @@ AM_CONDITIONAL(USE_ML, test x$ml = xtrue) # ---------------- AM_CONDITIONAL(USE_STROKE, test x$stroke = xtrue) AM_CONDITIONAL(USE_VICI, test x$vici = xtrue) -AM_CONDITIONAL(USE_MEDSRV, test x$medsrv = xtrue) -AM_CONDITIONAL(USE_MEDCLI, test x$medcli = xtrue) AM_CONDITIONAL(USE_OSX_ATTR, test x$osx_attr = xtrue) AM_CONDITIONAL(USE_P_CSCF, test x$p_cscf = xtrue) AM_CONDITIONAL(USE_ANDROID_DNS, test x$android_dns = xtrue) @@ -1975,7 +1958,6 @@ AM_COND_IF([USE_IMCV], [strongswan_options=${strongswan_options}" imcv imv_polic AM_COND_IF([USE_IMC_SWIMA], [strongswan_options=${strongswan_options}" sw-collector"]) AM_COND_IF([USE_IMV_SWIMA], [strongswan_options=${strongswan_options}" sec-updater"]) AM_COND_IF([USE_LIBTNCCS], [strongswan_options=${strongswan_options}" tnc"]) -AM_COND_IF([USE_MEDSRV], [strongswan_options=${strongswan_options}" medsrv"]) AM_COND_IF([USE_CMD], [strongswan_options=${strongswan_options}" charon-cmd"]) AM_COND_IF([USE_NM], [strongswan_options=${strongswan_options}" charon-nm"]) AM_COND_IF([USE_PKI], [strongswan_options=${strongswan_options}" pki"]) @@ -2132,8 +2114,6 @@ AC_CONFIG_FILES([ src/libcharon/plugins/sql/Makefile src/libcharon/plugins/dnscert/Makefile src/libcharon/plugins/ipseckey/Makefile - src/libcharon/plugins/medsrv/Makefile - src/libcharon/plugins/medcli/Makefile src/libcharon/plugins/addrblock/Makefile src/libcharon/plugins/unity/Makefile src/libcharon/plugins/ha/Makefile @@ -2183,7 +2163,6 @@ AC_CONFIG_FILES([ src/pki/man/Makefile src/pool/Makefile src/libfast/Makefile - src/medsrv/Makefile src/checksum/Makefile src/conftest/Makefile src/pt-tls-client/Makefile diff --git a/scripts/test.sh b/scripts/test.sh index 74c540e92..d3489d43b 100755 --- a/scripts/test.sh +++ b/scripts/test.sh @@ -304,7 +304,7 @@ all|alpine|codeql|coverage|sonarcloud|no-dbg|no-testable-ke) # no TrouSerS either CONFIG="$CONFIG --disable-tss-trousers --disable-aikgen" # and no Clearsilver - CONFIG="$CONFIG --disable-fast --disable-medsrv" + CONFIG="$CONFIG --disable-fast" fi if test "$1" = "build-deps"; then build_botan diff --git a/src/Makefile.am b/src/Makefile.am index f74c9010d..3a94b37a7 100644 --- a/src/Makefile.am +++ b/src/Makefile.am @@ -91,10 +91,6 @@ if USE_FAST SUBDIRS += libfast endif -if USE_MEDSRV - SUBDIRS += medsrv -endif - if USE_ATTR_SQL SUBDIRS += pool else diff --git a/src/libcharon/Makefile.am b/src/libcharon/Makefile.am index 38364595a..c6707ae3f 100644 --- a/src/libcharon/Makefile.am +++ b/src/libcharon/Makefile.am @@ -502,20 +502,6 @@ if MONOLITHIC endif endif -if USE_MEDSRV - SUBDIRS += plugins/medsrv -if MONOLITHIC - libcharon_la_LIBADD += plugins/medsrv/libstrongswan-medsrv.la -endif -endif - -if USE_MEDCLI - SUBDIRS += plugins/medcli -if MONOLITHIC - libcharon_la_LIBADD += plugins/medcli/libstrongswan-medcli.la -endif -endif - if USE_DHCP SUBDIRS += plugins/dhcp if MONOLITHIC diff --git a/src/libcharon/plugins/medcli/Makefile.am b/src/libcharon/plugins/medcli/Makefile.am deleted file mode 100644 index 0408c8963..000000000 --- a/src/libcharon/plugins/medcli/Makefile.am +++ /dev/null @@ -1,20 +0,0 @@ -AM_CPPFLAGS = \ - -I$(top_srcdir)/src/libstrongswan \ - -I$(top_srcdir)/src/libcharon - -AM_CFLAGS = \ - $(PLUGIN_CFLAGS) - -if MONOLITHIC -noinst_LTLIBRARIES = libstrongswan-medcli.la -else -plugin_LTLIBRARIES = libstrongswan-medcli.la -endif - -libstrongswan_medcli_la_SOURCES = \ - medcli_plugin.h medcli_plugin.c \ - medcli_creds.h medcli_creds.c \ - medcli_config.h medcli_config.c \ - medcli_listener.h medcli_listener.c - -libstrongswan_medcli_la_LDFLAGS = -module -avoid-version diff --git a/src/libcharon/plugins/medcli/medcli_config.c b/src/libcharon/plugins/medcli/medcli_config.c deleted file mode 100644 index 59a9358a1..000000000 --- a/src/libcharon/plugins/medcli/medcli_config.c +++ /dev/null @@ -1,434 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#define _GNU_SOURCE -#include - -#include "medcli_config.h" - -#include -#include - -typedef struct private_medcli_config_t private_medcli_config_t; - -/** - * Name of the mediation connection - */ -#define MEDIATION_CONN_NAME "medcli-mediation" - -/** - * Private data of an medcli_config_t object - */ -struct private_medcli_config_t { - - /** - * Public part - */ - medcli_config_t public; - - /** - * database connection - */ - database_t *db; - - /** - * rekey time - */ - int rekey; - - /** - * dpd delay - */ - int dpd; - - /** - * default ike config - */ - ike_cfg_t *ike; -}; - -/** - * create a traffic selector from a CIDR notation string - */ -static traffic_selector_t *ts_from_string(char *str) -{ - if (str) - { - traffic_selector_t *ts; - - ts = traffic_selector_create_from_cidr(str, 0, 0, 65535); - if (ts) - { - return ts; - } - } - return traffic_selector_create_dynamic(0, 0, 65535); -} - -/** - * Build a mediation config - */ -static peer_cfg_t *build_mediation_config(private_medcli_config_t *this, - peer_cfg_create_t *defaults) -{ - enumerator_t *e; - auth_cfg_t *auth; - ike_cfg_t *ike_cfg; - peer_cfg_t *med_cfg; - ike_cfg_create_t ike = { - .version = IKEV2, - .local = "0.0.0.0", - .local_port = charon->socket->get_port(charon->socket, FALSE), - .remote_port = IKEV2_UDP_PORT, - .no_certreq = TRUE, - }; - peer_cfg_create_t peer = *defaults; - chunk_t me, other; - - /* query mediation server config: - * - build ike_cfg/peer_cfg for mediation connection on-the-fly - */ - e = this->db->query(this->db, - "SELECT Address, ClientConfig.KeyId, MediationServerConfig.KeyId " - "FROM MediationServerConfig JOIN ClientConfig", - DB_TEXT, DB_BLOB, DB_BLOB); - if (!e || !e->enumerate(e, &ike.remote, &me, &other)) - { - DESTROY_IF(e); - return NULL; - } - ike_cfg = ike_cfg_create(&ike); - ike_cfg->add_proposal(ike_cfg, proposal_create_default(PROTO_IKE)); - ike_cfg->add_proposal(ike_cfg, proposal_create_default_aead(PROTO_IKE)); - - peer.mediation = TRUE; - med_cfg = peer_cfg_create(MEDIATION_CONN_NAME, ike_cfg, &peer); - e->destroy(e); - - auth = auth_cfg_create(); - auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY); - auth->add(auth, AUTH_RULE_IDENTITY, - identification_create_from_encoding(ID_KEY_ID, me)); - med_cfg->add_auth_cfg(med_cfg, auth, TRUE); - auth = auth_cfg_create(); - auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY); - auth->add(auth, AUTH_RULE_IDENTITY, - identification_create_from_encoding(ID_KEY_ID, other)); - med_cfg->add_auth_cfg(med_cfg, auth, FALSE); - return med_cfg; -} - -METHOD(backend_t, get_peer_cfg_by_name, peer_cfg_t*, - private_medcli_config_t *this, char *name) -{ - enumerator_t *e; - auth_cfg_t *auth; - peer_cfg_t *peer_cfg; - child_cfg_t *child_cfg; - chunk_t me, other; - char *local_net, *remote_net; - peer_cfg_create_t peer = { - .cert_policy = CERT_NEVER_SEND, - .unique = UNIQUE_REPLACE, - .keyingtries = 1, - .rekey_time = this->rekey * 60, - .jitter_time = this->rekey * 5, - .over_time = this->rekey * 3, - .dpd = this->dpd, - }; - child_cfg_create_t child = { - .lifetime = { - .time = { - .life = this->rekey * 60 + this->rekey, - .rekey = this->rekey, - .jitter = this->rekey - }, - }, - .mode = MODE_TUNNEL, - }; - - if (streq(name, "medcli-mediation")) - { - return build_mediation_config(this, &peer); - } - - /* query mediated config: - * - use any-any ike_cfg - * - build peer_cfg on-the-fly using med_cfg - * - add a child_cfg - */ - e = this->db->query(this->db, - "SELECT ClientConfig.KeyId, Connection.KeyId, " - "Connection.LocalSubnet, Connection.RemoteSubnet " - "FROM ClientConfig JOIN Connection " - "WHERE Active AND Alias = ?", DB_TEXT, name, - DB_BLOB, DB_BLOB, DB_TEXT, DB_TEXT); - if (!e || !e->enumerate(e, &me, &other, &local_net, &remote_net)) - { - DESTROY_IF(e); - return NULL; - } - peer.mediated_by = MEDIATION_CONN_NAME; - peer.peer_id = identification_create_from_encoding(ID_KEY_ID, other); - peer_cfg = peer_cfg_create(name, this->ike->get_ref(this->ike), &peer); - - auth = auth_cfg_create(); - auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY); - auth->add(auth, AUTH_RULE_IDENTITY, - identification_create_from_encoding(ID_KEY_ID, me)); - peer_cfg->add_auth_cfg(peer_cfg, auth, TRUE); - auth = auth_cfg_create(); - auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY); - auth->add(auth, AUTH_RULE_IDENTITY, - identification_create_from_encoding(ID_KEY_ID, other)); - peer_cfg->add_auth_cfg(peer_cfg, auth, FALSE); - - child_cfg = child_cfg_create(name, &child); - child_cfg->add_proposal(child_cfg, proposal_create_default_aead(PROTO_ESP)); - child_cfg->add_proposal(child_cfg, proposal_create_default(PROTO_ESP)); - child_cfg->add_traffic_selector(child_cfg, TRUE, ts_from_string(local_net)); - child_cfg->add_traffic_selector(child_cfg, FALSE, ts_from_string(remote_net)); - peer_cfg->add_child_cfg(peer_cfg, child_cfg); - e->destroy(e); - return peer_cfg; -} - -METHOD(backend_t, create_ike_cfg_enumerator, enumerator_t*, - private_medcli_config_t *this, host_t *me, host_t *other) -{ - return enumerator_create_single(this->ike, NULL); -} - -typedef struct { - /** implements enumerator */ - enumerator_t public; - /** inner SQL enumerator */ - enumerator_t *inner; - /** currently enumerated peer config */ - peer_cfg_t *current; - /** ike cfg to use in peer cfg */ - ike_cfg_t *ike; - /** rekey time */ - int rekey; - /** dpd time */ - int dpd; -} peer_enumerator_t; - -METHOD(enumerator_t, peer_enumerator_enumerate, bool, - peer_enumerator_t *this, va_list args) -{ - char *name, *local_net, *remote_net; - chunk_t me, other; - peer_cfg_t **cfg; - child_cfg_t *child_cfg; - auth_cfg_t *auth; - peer_cfg_create_t peer = { - .cert_policy = CERT_NEVER_SEND, - .unique = UNIQUE_REPLACE, - .keyingtries = 1, - .rekey_time = this->rekey * 60, - .jitter_time = this->rekey * 5, - .over_time = this->rekey * 3, - .dpd = this->dpd, - }; - child_cfg_create_t child = { - .lifetime = { - .time = { - .life = this->rekey * 60 + this->rekey, - .rekey = this->rekey, - .jitter = this->rekey - }, - }, - .mode = MODE_TUNNEL, - }; - - VA_ARGS_VGET(args, cfg); - - DESTROY_IF(this->current); - if (!this->inner->enumerate(this->inner, &name, &me, &other, - &local_net, &remote_net)) - { - this->current = NULL; - return FALSE; - } - this->current = peer_cfg_create(name, this->ike->get_ref(this->ike), &peer); - - auth = auth_cfg_create(); - auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY); - auth->add(auth, AUTH_RULE_IDENTITY, - identification_create_from_encoding(ID_KEY_ID, me)); - this->current->add_auth_cfg(this->current, auth, TRUE); - auth = auth_cfg_create(); - auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY); - auth->add(auth, AUTH_RULE_IDENTITY, - identification_create_from_encoding(ID_KEY_ID, other)); - this->current->add_auth_cfg(this->current, auth, FALSE); - - child_cfg = child_cfg_create(name, &child); - child_cfg->add_proposal(child_cfg, proposal_create_default_aead(PROTO_ESP)); - child_cfg->add_proposal(child_cfg, proposal_create_default(PROTO_ESP)); - child_cfg->add_traffic_selector(child_cfg, TRUE, ts_from_string(local_net)); - child_cfg->add_traffic_selector(child_cfg, FALSE, ts_from_string(remote_net)); - this->current->add_child_cfg(this->current, child_cfg); - *cfg = this->current; - return TRUE; -} - -METHOD(enumerator_t, peer_enumerator_destroy, void, - peer_enumerator_t *this) -{ - DESTROY_IF(this->current); - this->inner->destroy(this->inner); - free(this); -} - -METHOD(backend_t, create_peer_cfg_enumerator, enumerator_t*, - private_medcli_config_t *this, identification_t *me, - identification_t *other) -{ - peer_enumerator_t *e; - - INIT(e, - .public = { - .enumerate = enumerator_enumerate_default, - .venumerate = _peer_enumerator_enumerate, - .destroy = _peer_enumerator_destroy, - }, - .ike = this->ike, - .rekey = this->rekey, - .dpd = this->dpd, - ); - - /* filter on IDs: NULL or ANY or matching KEY_ID */ - e->inner = this->db->query(this->db, - "SELECT Alias, ClientConfig.KeyId, Connection.KeyId, " - "Connection.LocalSubnet, Connection.RemoteSubnet " - "FROM ClientConfig JOIN Connection " - "WHERE Active AND " - "(? OR ClientConfig.KeyId = ?) AND (? OR Connection.KeyId = ?)", - DB_INT, me == NULL || me->get_type(me) == ID_ANY, - DB_BLOB, me && me->get_type(me) == ID_KEY_ID ? - me->get_encoding(me) : chunk_empty, - DB_INT, other == NULL || other->get_type(other) == ID_ANY, - DB_BLOB, other && other->get_type(other) == ID_KEY_ID ? - other->get_encoding(other) : chunk_empty, - DB_TEXT, DB_BLOB, DB_BLOB, DB_TEXT, DB_TEXT); - if (!e->inner) - { - free(e); - return NULL; - } - return &e->public; -} - -/** - * initiate a peer config - */ -static job_requeue_t initiate_config(peer_cfg_t *peer_cfg) -{ - enumerator_t *enumerator; - child_cfg_t *child_cfg = NULL; - - enumerator = peer_cfg->create_child_cfg_enumerator(peer_cfg); - enumerator->enumerate(enumerator, &child_cfg); - if (child_cfg) - { - child_cfg->get_ref(child_cfg); - peer_cfg->get_ref(peer_cfg); - enumerator->destroy(enumerator); - charon->controller->initiate(charon->controller, peer_cfg, child_cfg, - NULL, NULL, 0, 0, FALSE); - } - else - { - enumerator->destroy(enumerator); - } - return JOB_REQUEUE_NONE; -} - -/** - * schedule initiation of all "active" connections - */ -static void schedule_autoinit(private_medcli_config_t *this) -{ - enumerator_t *e; - char *name; - - e = this->db->query(this->db, "SELECT Alias FROM Connection WHERE Active", - DB_TEXT); - if (e) - { - while (e->enumerate(e, &name)) - { - peer_cfg_t *peer_cfg; - - peer_cfg = get_peer_cfg_by_name(this, name); - if (peer_cfg) - { - /* schedule asynchronous initiation job */ - lib->processor->queue_job(lib->processor, - (job_t*)callback_job_create( - (callback_job_cb_t)initiate_config, - peer_cfg, (void*)peer_cfg->destroy, NULL)); - } - } - e->destroy(e); - } -} - -METHOD(medcli_config_t, destroy, void, - private_medcli_config_t *this) -{ - this->ike->destroy(this->ike); - free(this); -} - -/** - * Described in header. - */ -medcli_config_t *medcli_config_create(database_t *db) -{ - private_medcli_config_t *this; - ike_cfg_create_t ike = { - .version = IKEV2, - .local = "0.0.0.0", - .local_port = charon->socket->get_port(charon->socket, FALSE), - .remote = "0.0.0.0", - .remote_port = IKEV2_UDP_PORT, - .no_certreq = TRUE, - }; - - INIT(this, - .public = { - .backend = { - .create_peer_cfg_enumerator = _create_peer_cfg_enumerator, - .create_ike_cfg_enumerator = _create_ike_cfg_enumerator, - .get_peer_cfg_by_name = _get_peer_cfg_by_name, - }, - .destroy = _destroy, - }, - .db = db, - .rekey = lib->settings->get_time(lib->settings, "medcli.rekey", 1200), - .dpd = lib->settings->get_time(lib->settings, "medcli.dpd", 300), - .ike = ike_cfg_create(&ike), - ); - this->ike->add_proposal(this->ike, proposal_create_default(PROTO_IKE)); - this->ike->add_proposal(this->ike, proposal_create_default_aead(PROTO_IKE)); - - schedule_autoinit(this); - - return &this->public; -} diff --git a/src/libcharon/plugins/medcli/medcli_config.h b/src/libcharon/plugins/medcli/medcli_config.h deleted file mode 100644 index a22b2cf92..000000000 --- a/src/libcharon/plugins/medcli/medcli_config.h +++ /dev/null @@ -1,54 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup medcli_config_i medcli_config - * @{ @ingroup medcli - */ - -#ifndef MEDCLI_CONFIG_H_ -#define MEDCLI_CONFIG_H_ - -#include -#include - -typedef struct medcli_config_t medcli_config_t; - -/** - * Mediation client configuration backend. - */ -struct medcli_config_t { - - /** - * Implements backend_t interface - */ - backend_t backend; - - /** - * Destroy the backend. - */ - void (*destroy)(medcli_config_t *this); -}; - -/** - * Create a medcli_config backend instance. - * - * @param db underlying database - * @return backend instance - */ -medcli_config_t *medcli_config_create(database_t *db); - -#endif /** MEDCLI_CONFIG_H_ @}*/ diff --git a/src/libcharon/plugins/medcli/medcli_creds.c b/src/libcharon/plugins/medcli/medcli_creds.c deleted file mode 100644 index dc61cc5a7..000000000 --- a/src/libcharon/plugins/medcli/medcli_creds.c +++ /dev/null @@ -1,242 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "medcli_creds.h" - -#include -#include -#include - -typedef struct private_medcli_creds_t private_medcli_creds_t; - -/** - * Private data of an medcli_creds_t object - */ -struct private_medcli_creds_t { - - /** - * Public part - */ - medcli_creds_t public; - - /** - * underlying database handle - */ - database_t *db; -}; - -/** - * enumerator over private keys - */ -typedef struct { - /** implements enumerator */ - enumerator_t public; - /** inner SQL enumerator */ - enumerator_t *inner; - /** currently enumerated private key */ - private_key_t *current; -} private_enumerator_t; - -METHOD(enumerator_t, private_enumerator_enumerate, bool, - private_enumerator_t *this, va_list args) -{ - private_key_t **key; - chunk_t chunk; - - VA_ARGS_VGET(args, key); - - DESTROY_IF(this->current); - while (this->inner->enumerate(this->inner, &chunk)) - { - this->current = lib->creds->create(lib->creds, CRED_PRIVATE_KEY, KEY_RSA, - BUILD_BLOB_ASN1_DER, chunk, - BUILD_END); - if (this->current) - { - *key = this->current; - return TRUE; - } - } - this->current = NULL; - return FALSE; -} - -METHOD(enumerator_t, private_enumerator_destroy, void, - private_enumerator_t *this) -{ - DESTROY_IF(this->current); - this->inner->destroy(this->inner); - free(this); -} - -METHOD(credential_set_t, create_private_enumerator, enumerator_t*, - private_medcli_creds_t *this, key_type_t type, identification_t *id) -{ - private_enumerator_t *e; - - if ((type != KEY_RSA && type != KEY_ANY) || - id == NULL || id->get_type(id) != ID_KEY_ID) - { - DBG1(DBG_CFG, "%N - %Y", key_type_names, type, id); - return NULL; - } - - INIT(e, - .public = { - .enumerate = enumerator_enumerate_default, - .venumerate = _private_enumerator_enumerate, - .destroy = _private_enumerator_destroy, - }, - ); - e->inner = this->db->query(this->db, - "SELECT PrivateKey FROM ClientConfig WHERE KeyId = ?", - DB_BLOB, id->get_encoding(id), - DB_BLOB); - if (!e->inner) - { - free(e); - return NULL; - } - return &e->public; -} - -/** - * enumerator over certificates - */ -typedef struct { - /** implements enumerator */ - enumerator_t public; - /** inner SQL enumerator */ - enumerator_t *inner; - /** currently enumerated cert */ - certificate_t *current; - /** type of requested key */ - key_type_t type; -} cert_enumerator_t; - -METHOD(enumerator_t, cert_enumerator_enumerate, bool, - cert_enumerator_t *this, va_list args) -{ - certificate_t **cert; - public_key_t *public; - chunk_t chunk; - - VA_ARGS_VGET(args, cert); - - DESTROY_IF(this->current); - while (this->inner->enumerate(this->inner, &chunk)) - { - public = lib->creds->create(lib->creds, CRED_PUBLIC_KEY, KEY_ANY, - BUILD_BLOB_ASN1_DER, chunk, - BUILD_END); - if (public) - { - if (this->type == KEY_ANY || this->type == public->get_type(public)) - { - this->current = lib->creds->create(lib->creds, - CRED_CERTIFICATE, CERT_TRUSTED_PUBKEY, - BUILD_PUBLIC_KEY, public, BUILD_END); - public->destroy(public); - if (this->current) - { - *cert = this->current; - return TRUE; - } - } - else - { - public->destroy(public); - } - } - } - this->current = NULL; - return FALSE; -} - -METHOD(enumerator_t, cert_enumerator_destroy, void, - cert_enumerator_t *this) -{ - DESTROY_IF(this->current); - this->inner->destroy(this->inner); - free(this); -} - -METHOD(credential_set_t, create_cert_enumerator, enumerator_t*, - private_medcli_creds_t *this, certificate_type_t cert, key_type_t key, - identification_t *id, bool trusted) -{ - cert_enumerator_t *e; - - if ((cert != CERT_TRUSTED_PUBKEY && cert != CERT_ANY) || - id == NULL || id->get_type(id) != ID_KEY_ID) - { - return NULL; - } - - INIT(e, - .public = { - .enumerate = enumerator_enumerate_default, - .venumerate = _cert_enumerator_enumerate, - .destroy = _cert_enumerator_destroy, - }, - .type = key, - ); - e->inner = this->db->query(this->db, - "SELECT PublicKey FROM ClientConfig WHERE KeyId = ? UNION " - "SELECT PublicKey FROM MediationServerConfig WHERE KeyId = ? UNION " - "SELECT PublicKey FROM Connection WHERE KeyId = ?", - DB_BLOB, id->get_encoding(id), - DB_BLOB, id->get_encoding(id), - DB_BLOB, id->get_encoding(id), - DB_BLOB); - if (!e->inner) - { - free(e); - return NULL; - } - return &e->public; -} - -METHOD(medcli_creds_t, destroy, void, - private_medcli_creds_t *this) -{ - free(this); -} - -/** - * Described in header. - */ -medcli_creds_t *medcli_creds_create(database_t *db) -{ - private_medcli_creds_t *this; - - INIT(this, - .public = { - .set = { - .create_private_enumerator = _create_private_enumerator, - .create_cert_enumerator = _create_cert_enumerator, - .create_shared_enumerator = (void*)return_null, - .create_cdp_enumerator = (void*)return_null, - .cache_cert = (void*)nop, - }, - .destroy = _destroy, - }, - .db = db, - ); - - return &this->public; -} - diff --git a/src/libcharon/plugins/medcli/medcli_creds.h b/src/libcharon/plugins/medcli/medcli_creds.h deleted file mode 100644 index dc39a9e13..000000000 --- a/src/libcharon/plugins/medcli/medcli_creds.h +++ /dev/null @@ -1,54 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup medcli_creds_i medcli_creds - * @{ @ingroup medcli - */ - -#ifndef MEDCLI_CREDS_H_ -#define MEDCLI_CREDS_H_ - -#include -#include - -typedef struct medcli_creds_t medcli_creds_t; - -/** - * Mediation client credentials database. - */ -struct medcli_creds_t { - - /** - * Implements credential_set_t interface - */ - credential_set_t set; - - /** - * Destroy the credentials database. - */ - void (*destroy)(medcli_creds_t *this); -}; - -/** - * Create the medcli credential set. - * - * @param database underlying database - * @return credential set implementation on that database - */ -medcli_creds_t *medcli_creds_create(database_t *database); - -#endif /** MEDCLI_CREDS_H_ @}*/ diff --git a/src/libcharon/plugins/medcli/medcli_listener.c b/src/libcharon/plugins/medcli/medcli_listener.c deleted file mode 100644 index 27debb096..000000000 --- a/src/libcharon/plugins/medcli/medcli_listener.c +++ /dev/null @@ -1,132 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "medcli_listener.h" - -#include -#include - -typedef struct private_medcli_listener_t private_medcli_listener_t; -typedef enum mediated_state_t mediated_state_t; - -/** - * state of a mediated connection - */ -enum mediated_state_t { - STATE_DOWN = 1, - STATE_CONNECTING = 2, - STATE_UP = 3, -}; - -/** - * Private data of an medcli_listener_t object - */ -struct private_medcli_listener_t { - - /** - * Public part - */ - medcli_listener_t public; - - /** - * underlying database handle - */ - database_t *db; -}; - -/** - * Update connection status in the database - */ -static void set_state(private_medcli_listener_t *this, char *alias, - mediated_state_t state) -{ - this->db->execute(this->db, NULL, - "UPDATE Connection SET Status = ? WHERE Alias = ?", - DB_UINT, state, DB_TEXT, alias); -} - -METHOD(listener_t, ike_state_change, bool, - private_medcli_listener_t *this, ike_sa_t *ike_sa, ike_sa_state_t state) -{ - if (ike_sa) - { - switch (state) - { - case IKE_CONNECTING: - set_state(this, ike_sa->get_name(ike_sa), STATE_CONNECTING); - break; - case IKE_DESTROYING: - set_state(this, ike_sa->get_name(ike_sa), STATE_DOWN); - default: - break; - } - } - return TRUE; -} - -METHOD(listener_t, child_state_change, bool, - private_medcli_listener_t *this, ike_sa_t *ike_sa, child_sa_t *child_sa, - child_sa_state_t state) -{ - if (ike_sa && child_sa) - { - switch (state) - { - case CHILD_INSTALLED: - set_state(this, child_sa->get_name(child_sa), STATE_UP); - break; - case CHILD_DESTROYING: - set_state(this, child_sa->get_name(child_sa), STATE_DOWN); - break; - default: - break; - } - } - return TRUE; -} - -METHOD(medcli_listener_t, destroy, void, - private_medcli_listener_t *this) -{ - this->db->execute(this->db, NULL, "UPDATE Connection SET Status = ?", - DB_UINT, STATE_DOWN); - free(this); -} - -/** - * Described in header. - */ -medcli_listener_t *medcli_listener_create(database_t *db) -{ - private_medcli_listener_t *this; - - INIT(this, - .public = { - .listener = { - .ike_state_change = _ike_state_change, - .child_state_change = _child_state_change, - }, - .destroy = _destroy, - }, - .db = db, - ); - - db->execute(db, NULL, "UPDATE Connection SET Status = ?", - DB_UINT, STATE_DOWN); - - return &this->public; -} - diff --git a/src/libcharon/plugins/medcli/medcli_listener.h b/src/libcharon/plugins/medcli/medcli_listener.h deleted file mode 100644 index 8fb611266..000000000 --- a/src/libcharon/plugins/medcli/medcli_listener.h +++ /dev/null @@ -1,54 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup medcli_listener_i medcli_listener - * @{ @ingroup medcli - */ - -#ifndef MEDCLI_LISTENER_H_ -#define MEDCLI_LISTENER_H_ - -#include -#include - -typedef struct medcli_listener_t medcli_listener_t; - -/** - * Mediation client listener, writes connection status to database - */ -struct medcli_listener_t { - - /** - * Implements bus_listener_t interface - */ - listener_t listener; - - /** - * Destroy the credentials database. - */ - void (*destroy)(medcli_listener_t *this); -}; - -/** - * Create the medcli credential set. - * - * @param database underlying database - * @return listener - */ -medcli_listener_t *medcli_listener_create(database_t *database); - -#endif /** MEDCLI_LISTENER_H_ @}*/ diff --git a/src/libcharon/plugins/medcli/medcli_plugin.c b/src/libcharon/plugins/medcli/medcli_plugin.c deleted file mode 100644 index b5cbe7da3..000000000 --- a/src/libcharon/plugins/medcli/medcli_plugin.c +++ /dev/null @@ -1,147 +0,0 @@ -/* - * Copyright (C) 2013 Tobias Brunner - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "medcli_plugin.h" - -#include "medcli_creds.h" -#include "medcli_config.h" -#include "medcli_listener.h" - -#include - -typedef struct private_medcli_plugin_t private_medcli_plugin_t; - -/** - * private data of medcli plugin - */ -struct private_medcli_plugin_t { - - /** - * implements plugin interface - */ - medcli_plugin_t public; - - /** - * database connection instance - */ - database_t *db; - - /** - * medcli credential set instance - */ - medcli_creds_t *creds; - - /** - * medcli config database - */ - medcli_config_t *config; - - /** - * Listener to update database connection state - */ - medcli_listener_t *listener; -}; - -METHOD(plugin_t, get_name, char*, - private_medcli_plugin_t *this) -{ - return "medcli"; -} - -/** - * Connect to database - */ -static bool open_database(private_medcli_plugin_t *this, - plugin_feature_t *feature, bool reg, void *cb_data) -{ - if (reg) - { - char *uri; - - uri = lib->settings->get_str(lib->settings, - "medcli.database", NULL); - if (!uri) - { - DBG1(DBG_CFG, "mediation client database URI not defined, skipped"); - return FALSE; - } - - this->db = lib->db->create(lib->db, uri); - if (this->db == NULL) - { - DBG1(DBG_CFG, "opening mediation client database failed"); - return FALSE; - } - - this->creds = medcli_creds_create(this->db); - this->config = medcli_config_create(this->db); - this->listener = medcli_listener_create(this->db); - - lib->credmgr->add_set(lib->credmgr, &this->creds->set); - charon->backends->add_backend(charon->backends, &this->config->backend); - charon->bus->add_listener(charon->bus, &this->listener->listener); - } - else - { - charon->bus->remove_listener(charon->bus, &this->listener->listener); - charon->backends->remove_backend(charon->backends, &this->config->backend); - lib->credmgr->remove_set(lib->credmgr, &this->creds->set); - this->listener->destroy(this->listener); - this->config->destroy(this->config); - this->creds->destroy(this->creds); - this->db->destroy(this->db); - } - return TRUE; -} - -METHOD(plugin_t, get_features, int, - private_medcli_plugin_t *this, plugin_feature_t *features[]) -{ - static plugin_feature_t f[] = { - PLUGIN_CALLBACK((plugin_feature_callback_t)open_database, NULL), - PLUGIN_PROVIDE(CUSTOM, "medcli"), - PLUGIN_DEPENDS(DATABASE, DB_ANY), - }; - *features = f; - return countof(f); -} - -METHOD(plugin_t, destroy, void, - private_medcli_plugin_t *this) -{ - free(this); -} - -/* - * see header file - */ -PLUGIN_DEFINE(medcli) -{ - private_medcli_plugin_t *this; - - INIT(this, - .public = { - .plugin = { - .get_name = _get_name, - .get_features = _get_features, - .destroy = _destroy, - }, - }, - ); - - return &this->public.plugin; -} diff --git a/src/libcharon/plugins/medcli/medcli_plugin.h b/src/libcharon/plugins/medcli/medcli_plugin.h deleted file mode 100644 index a3dabc503..000000000 --- a/src/libcharon/plugins/medcli/medcli_plugin.h +++ /dev/null @@ -1,43 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup medcli medcli - * @ingroup cplugins - * - * @defgroup medcli_plugin medcli_plugin - * @{ @ingroup medcli - */ - -#ifndef MEDCLI_PLUGIN_H_ -#define MEDCLI_PLUGIN_H_ - -#include - -typedef struct medcli_plugin_t medcli_plugin_t; - -/** - * Mediation client database plugin. - */ -struct medcli_plugin_t { - - /** - * implements plugin interface - */ - plugin_t plugin; -}; - -#endif /** MEDCLI_PLUGIN_H_ @}*/ diff --git a/src/libcharon/plugins/medcli/mysql.sql b/src/libcharon/plugins/medcli/mysql.sql deleted file mode 100644 index 0107ad35a..000000000 --- a/src/libcharon/plugins/medcli/mysql.sql +++ /dev/null @@ -1,32 +0,0 @@ - -CREATE TABLE `ClientConfig` ( - `IdClientConfig` int(11) NOT NULL, - `KeyId` varbinary(20) NOT NULL, - `PublicKey` blob NOT NULL, - `PrivateKey` blob NOT NULL, - PRIMARY KEY (`IdClientConfig`) -); - - -CREATE TABLE `MediationServerConfig` ( - `IdMediationServerConfig` int(11) NOT NULL, - `Address` varchar(200) NOT NULL, - `KeyId` varbinary(20) NOT NULL, - `PublicKey` blob NOT NULL, - PRIMARY KEY (`IdMediationServerConfig`) -); - - -CREATE TABLE `Connection` ( - `IdConnection` int(11) NOT NULL auto_increment, - `Active` tinyint(1) NOT NULL, - `Alias` varchar(50) NOT NULL, - `KeyId` varbinary(20) NOT NULL, - `PublicKey` blob NOT NULL, - `LocalSubnet` varchar(20), - `RemoteSubnet` varchar(20), - `Status` int(11) NOT NULL, - PRIMARY KEY (`IdConnection`), - UNIQUE (`Alias`), - UNIQUE (`KeyId`) -); diff --git a/src/libcharon/plugins/medsrv/Makefile.am b/src/libcharon/plugins/medsrv/Makefile.am deleted file mode 100644 index 1d1cb4465..000000000 --- a/src/libcharon/plugins/medsrv/Makefile.am +++ /dev/null @@ -1,19 +0,0 @@ -AM_CPPFLAGS = \ - -I$(top_srcdir)/src/libstrongswan \ - -I$(top_srcdir)/src/libcharon - -AM_CFLAGS = \ - $(PLUGIN_CFLAGS) - -if MONOLITHIC -noinst_LTLIBRARIES = libstrongswan-medsrv.la -else -plugin_LTLIBRARIES = libstrongswan-medsrv.la -endif - -libstrongswan_medsrv_la_SOURCES = \ - medsrv_plugin.h medsrv_plugin.c \ - medsrv_creds.h medsrv_creds.c \ - medsrv_config.h medsrv_config.c - -libstrongswan_medsrv_la_LDFLAGS = -module -avoid-version diff --git a/src/libcharon/plugins/medsrv/medsrv_config.c b/src/libcharon/plugins/medsrv/medsrv_config.c deleted file mode 100644 index 4dd69f2d4..000000000 --- a/src/libcharon/plugins/medsrv/medsrv_config.c +++ /dev/null @@ -1,161 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include - -#include "medsrv_config.h" - -#include - -typedef struct private_medsrv_config_t private_medsrv_config_t; - -/** - * Private data of an medsrv_config_t object - */ -struct private_medsrv_config_t { - - /** - * Public part - */ - medsrv_config_t public; - - /** - * database connection - */ - database_t *db; - - /** - * rekey time - */ - int rekey; - - /** - * dpd delay - */ - int dpd; - - /** - * default ike config - */ - ike_cfg_t *ike; -}; - -METHOD(backend_t, get_peer_cfg_by_name, peer_cfg_t*, - private_medsrv_config_t *this, char *name) -{ - return NULL; -} - -METHOD(backend_t, create_ike_cfg_enumerator, enumerator_t*, - private_medsrv_config_t *this, host_t *me, host_t *other) -{ - return enumerator_create_single(this->ike, NULL); -} - -METHOD(backend_t, create_peer_cfg_enumerator, enumerator_t*, - private_medsrv_config_t *this, identification_t *me, - identification_t *other) -{ - enumerator_t *e; - - if (!me || !other || other->get_type(other) != ID_KEY_ID) - { - return NULL; - } - e = this->db->query(this->db, - "SELECT CONCAT(peer.alias, CONCAT('@', user.login)) FROM " - "peer JOIN user ON peer.user = user.id " - "WHERE peer.keyid = ?", DB_BLOB, other->get_encoding(other), - DB_TEXT); - if (e) - { - peer_cfg_t *peer_cfg; - auth_cfg_t *auth; - char *name; - - if (e->enumerate(e, &name)) - { - peer_cfg_create_t peer = { - .cert_policy = CERT_NEVER_SEND, - .unique = UNIQUE_REPLACE, - .keyingtries = 1, - .rekey_time = this->rekey * 60, - .jitter_time = this->rekey * 5, - .over_time = this->rekey * 3, - .dpd = this->dpd, - .mediation = TRUE, - }; - peer_cfg = peer_cfg_create(name, this->ike->get_ref(this->ike), - &peer); - e->destroy(e); - - auth = auth_cfg_create(); - auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY); - auth->add(auth, AUTH_RULE_IDENTITY, me->clone(me)); - peer_cfg->add_auth_cfg(peer_cfg, auth, TRUE); - auth = auth_cfg_create(); - auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY); - auth->add(auth, AUTH_RULE_IDENTITY, other->clone(other)); - peer_cfg->add_auth_cfg(peer_cfg, auth, FALSE); - - return enumerator_create_single(peer_cfg, (void*)peer_cfg->destroy); - } - e->destroy(e); - } - return NULL; -} - -METHOD(medsrv_config_t, destroy, void, - private_medsrv_config_t *this) -{ - this->ike->destroy(this->ike); - free(this); -} - -/** - * Described in header. - */ -medsrv_config_t *medsrv_config_create(database_t *db) -{ - private_medsrv_config_t *this; - ike_cfg_create_t ike = { - .version = IKEV2, - .local = "0.0.0.0", - .local_port = charon->socket->get_port(charon->socket, FALSE), - .remote = "0.0.0.0", - .remote_port = IKEV2_UDP_PORT, - .no_certreq = TRUE, - }; - - INIT(this, - .public = { - .backend = { - .create_peer_cfg_enumerator = _create_peer_cfg_enumerator, - .create_ike_cfg_enumerator = _create_ike_cfg_enumerator, - .get_peer_cfg_by_name = _get_peer_cfg_by_name, - }, - .destroy = _destroy, - }, - .db = db, - .rekey = lib->settings->get_time(lib->settings, "medsrv.rekey", 1200), - .dpd = lib->settings->get_time(lib->settings, "medsrv.dpd", 300), - .ike = ike_cfg_create(&ike), - ); - this->ike->add_proposal(this->ike, proposal_create_default(PROTO_IKE)); - this->ike->add_proposal(this->ike, proposal_create_default_aead(PROTO_IKE)); - - return &this->public; -} diff --git a/src/libcharon/plugins/medsrv/medsrv_config.h b/src/libcharon/plugins/medsrv/medsrv_config.h deleted file mode 100644 index 37545e65f..000000000 --- a/src/libcharon/plugins/medsrv/medsrv_config.h +++ /dev/null @@ -1,54 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup medsrv_config_i medsrv_config - * @{ @ingroup medsrv_p - */ - -#ifndef MEDSRV_CONFIG_H_ -#define MEDSRV_CONFIG_H_ - -#include -#include - -typedef struct medsrv_config_t medsrv_config_t; - -/** - * Mediation server configuration backend. - */ -struct medsrv_config_t { - - /** - * Implements backend_t interface - */ - backend_t backend; - - /** - * Destroy the backend. - */ - void (*destroy)(medsrv_config_t *this); -}; - -/** - * Create a medsrv_config backend instance. - * - * @param db underlying database - * @return backend instance - */ -medsrv_config_t *medsrv_config_create(database_t *db); - -#endif /** MEDSRV_CONFIG_H_ @}*/ diff --git a/src/libcharon/plugins/medsrv/medsrv_creds.c b/src/libcharon/plugins/medsrv/medsrv_creds.c deleted file mode 100644 index c415aaedf..000000000 --- a/src/libcharon/plugins/medsrv/medsrv_creds.c +++ /dev/null @@ -1,163 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "medsrv_creds.h" - -#include -#include -#include - -typedef struct private_medsrv_creds_t private_medsrv_creds_t; - -/** - * Private data of an medsrv_creds_t object - */ -struct private_medsrv_creds_t { - - /** - * Public part - */ - medsrv_creds_t public; - - /** - * underlying database handle - */ - database_t *db; -}; - -/** - * enumerator over certificates - */ -typedef struct { - /** implements enumerator */ - enumerator_t public; - /** inner SQL enumerator */ - enumerator_t *inner; - /** currently enumerated cert */ - certificate_t *current; - /** type of requested key */ - key_type_t type; -} cert_enumerator_t; - -METHOD(enumerator_t, cert_enumerator_enumerate, bool, - cert_enumerator_t *this, va_list args) -{ - certificate_t *trusted, **cert; - public_key_t *public; - chunk_t chunk; - - VA_ARGS_VGET(args, cert); - - DESTROY_IF(this->current); - while (this->inner->enumerate(this->inner, &chunk)) - { - public = lib->creds->create(lib->creds, CRED_PUBLIC_KEY, KEY_ANY, - BUILD_BLOB_ASN1_DER, chunk, - BUILD_END); - if (public) - { - if (this->type == KEY_ANY || this->type == public->get_type(public)) - { - trusted = lib->creds->create(lib->creds, - CRED_CERTIFICATE, CERT_TRUSTED_PUBKEY, - BUILD_PUBLIC_KEY, public, BUILD_END); - public->destroy(public); - if (trusted) - { - *cert = this->current = trusted; - return TRUE; - } - } - else - { - public->destroy(public); - } - } - } - this->current = NULL; - return FALSE; -} - -METHOD(enumerator_t, cert_enumerator_destroy, void, - cert_enumerator_t *this) -{ - DESTROY_IF(this->current); - this->inner->destroy(this->inner); - free(this); -} - -METHOD(credential_set_t, create_cert_enumerator, enumerator_t*, - private_medsrv_creds_t *this, certificate_type_t cert, key_type_t key, - identification_t *id, bool trusted) -{ - cert_enumerator_t *e; - - if ((cert != CERT_TRUSTED_PUBKEY && cert != CERT_ANY) || - id == NULL || id->get_type(id) != ID_KEY_ID) - { - return NULL; - } - - INIT(e, - .public = { - .enumerate = enumerator_enumerate_default, - .venumerate = _cert_enumerator_enumerate, - .destroy = _cert_enumerator_destroy, - }, - .type = key, - .inner = this->db->query(this->db, - "SELECT public_key FROM peer WHERE keyid = ?", - DB_BLOB, id->get_encoding(id), - DB_BLOB), - ); - if (!e->inner) - { - free(e); - return NULL; - } - return &e->public; -} - -METHOD(medsrv_creds_t, destroy, void, - private_medsrv_creds_t *this) -{ - free(this); -} - -/** - * Described in header. - */ -medsrv_creds_t *medsrv_creds_create(database_t *db) -{ - private_medsrv_creds_t *this; - - INIT(this, - .public = { - .set = { - .create_private_enumerator = (void*)return_null, - .create_cert_enumerator = _create_cert_enumerator, - .create_shared_enumerator = (void*)return_null, - .create_cdp_enumerator = (void*)return_null, - .cache_cert = (void*)nop, - }, - .destroy = _destroy, - }, - .db = db, - ); - - return &this->public; -} - diff --git a/src/libcharon/plugins/medsrv/medsrv_creds.h b/src/libcharon/plugins/medsrv/medsrv_creds.h deleted file mode 100644 index 21c7ac111..000000000 --- a/src/libcharon/plugins/medsrv/medsrv_creds.h +++ /dev/null @@ -1,54 +0,0 @@ -/* - * Copyright (C) 2007-2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup medsrv_creds_i medsrv_creds - * @{ @ingroup medsrv_p - */ - -#ifndef MEDSRV_CREDS_H_ -#define MEDSRV_CREDS_H_ - -#include -#include - -typedef struct medsrv_creds_t medsrv_creds_t; - -/** - * Mediation credentials database. - */ -struct medsrv_creds_t { - - /** - * Implements credential_set_t interface - */ - credential_set_t set; - - /** - * Destroy the credentials database. - */ - void (*destroy)(medsrv_creds_t *this); -}; - -/** - * Create the medsrv credentials db. - * - * @param database underlying database - * @return credential set implementation on that database - */ -medsrv_creds_t *medsrv_creds_create(database_t *database); - -#endif /** MEDSRV_CREDS_H_ @}*/ diff --git a/src/libcharon/plugins/medsrv/medsrv_plugin.c b/src/libcharon/plugins/medsrv/medsrv_plugin.c deleted file mode 100644 index 2ffd5e5f1..000000000 --- a/src/libcharon/plugins/medsrv/medsrv_plugin.c +++ /dev/null @@ -1,137 +0,0 @@ -/* - * Copyright (C) 2013 Tobias Brunner - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "medsrv_plugin.h" - -#include "medsrv_creds.h" -#include "medsrv_config.h" - -#include - -typedef struct private_medsrv_plugin_t private_medsrv_plugin_t; - -/** - * private data of medsrv plugin - */ -struct private_medsrv_plugin_t { - - /** - * implements plugin interface - */ - medsrv_plugin_t public; - - /** - * database connection instance - */ - database_t *db; - - /** - * medsrv credential set instance - */ - medsrv_creds_t *creds; - - /** - * medsrv config database - */ - medsrv_config_t *config; -}; - -METHOD(plugin_t, get_name, char*, - private_medsrv_plugin_t *this) -{ - return "medsrv"; -} - -/** - * Connect to database - */ -static bool open_database(private_medsrv_plugin_t *this, - plugin_feature_t *feature, bool reg, void *cb_data) -{ - if (reg) - { - char *uri; - - uri = lib->settings->get_str(lib->settings, - "medsrv.database", NULL); - if (!uri) - { - DBG1(DBG_CFG, "mediation database URI not defined, skipped"); - return FALSE; - } - - this->db = lib->db->create(lib->db, uri); - if (this->db == NULL) - { - DBG1(DBG_CFG, "opening mediation server database failed"); - return FALSE; - } - - this->creds = medsrv_creds_create(this->db); - this->config = medsrv_config_create(this->db); - - lib->credmgr->add_set(lib->credmgr, &this->creds->set); - charon->backends->add_backend(charon->backends, &this->config->backend); - } - else - { - charon->backends->remove_backend(charon->backends, &this->config->backend); - lib->credmgr->remove_set(lib->credmgr, &this->creds->set); - this->config->destroy(this->config); - this->creds->destroy(this->creds); - this->db->destroy(this->db); - } - return TRUE; -} - -METHOD(plugin_t, get_features, int, - private_medsrv_plugin_t *this, plugin_feature_t *features[]) -{ - static plugin_feature_t f[] = { - PLUGIN_CALLBACK((plugin_feature_callback_t)open_database, NULL), - PLUGIN_PROVIDE(CUSTOM, "medsrv"), - PLUGIN_DEPENDS(DATABASE, DB_ANY), - }; - *features = f; - return countof(f); -} - -METHOD(plugin_t, destroy, void, - private_medsrv_plugin_t *this) -{ - free(this); -} - -/* - * see header file - */ -PLUGIN_DEFINE(medsrv) -{ - private_medsrv_plugin_t *this; - - INIT(this, - .public = { - .plugin = { - .get_name = _get_name, - .get_features = _get_features, - .destroy = _destroy, - }, - }, - ); - - return &this->public.plugin; -} diff --git a/src/libcharon/plugins/medsrv/medsrv_plugin.h b/src/libcharon/plugins/medsrv/medsrv_plugin.h deleted file mode 100644 index e2c63bbe4..000000000 --- a/src/libcharon/plugins/medsrv/medsrv_plugin.h +++ /dev/null @@ -1,43 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup medsrv_p medsrv - * @ingroup cplugins - * - * @defgroup medsrv_plugin medsrv_plugin - * @{ @ingroup medsrv_p - */ - -#ifndef MEDSRV_PLUGIN_H_ -#define MEDSRV_PLUGIN_H_ - -#include - -typedef struct medsrv_plugin_t medsrv_plugin_t; - -/** - * Mediation server database plugin. - */ -struct medsrv_plugin_t { - - /** - * implements plugin interface - */ - plugin_t plugin; -}; - -#endif /** MEDSRV_PLUGIN_H_ @}*/ diff --git a/src/libcharon/plugins/medsrv/mysql.sql b/src/libcharon/plugins/medsrv/mysql.sql deleted file mode 100644 index eb9f57772..000000000 --- a/src/libcharon/plugins/medsrv/mysql.sql +++ /dev/null @@ -1,21 +0,0 @@ - -CREATE TABLE IF NOT EXISTS `peer` ( - `id` int(10) unsigned NOT NULL auto_increment, - `user` int(10) unsigned NOT NULL, - `alias` varchar(30) NOT NULL, - `keyid` varbinary(20) NOT NULL, - `public_key` blob, - PRIMARY KEY (`id`), - UNIQUE KEY (`user`,`alias`), - UNIQUE KEY (`keyid`), - KEY (`user`) -) ENGINE=MyISAM DEFAULT CHARSET=utf8 COLLATE=utf8_unicode_ci; - -CREATE TABLE IF NOT EXISTS `user` ( - `id` int(10) unsigned NOT NULL auto_increment, - `login` varchar(30) NOT NULL, - `password` varbinary(20) NOT NULL, - PRIMARY KEY (`id`), - UNIQUE KEY (`login`) -) ENGINE=MyISAM DEFAULT CHARSET=utf8 COLLATE=utf8_unicode_ci; - diff --git a/src/libcharon/plugins/medsrv/test.sql b/src/libcharon/plugins/medsrv/test.sql deleted file mode 100644 index cd964300d..000000000 --- a/src/libcharon/plugins/medsrv/test.sql +++ /dev/null @@ -1,9 +0,0 @@ - -INSERT INTO `Peer` ( - `IdPeer`, `IdUser`, `Alias`, `KeyId`, `PublicKey` -) VALUES ( - 1, 0, 'sidv150', - X'ed90e64feca21f4b6897992422e0de21b9d62629', - X'30820122300d06092a864886f70d01010105000382010f003082010a0282010100cd946c229f7d52b21da1cb5384e7dcaf6529f760534a56355efd49e87a9c6f1ddd5ff303bd7eb49c23de03adc487456f41eb5f92947bdc8ff8dbe443f8d112e0da2c98145e7c4d1cd15cddd08577f4d4f3d0a2e1da3c08c94cd819758751931e7a9724cc43d73a11b8e176a268b4cdbbf3995cb09723abc9bfc477c25e714a4661a84c078be7404d8986be55f20437e3a6b278a3cc89aec085941f1a1aafaf4b22ae146fe4684d5567dc30658a32087d01b98515070cb1653311cb6102f82a83c638c2a79985dbb9600752e9cbc272014a5c547b4ab59130c3a948658bff794b6f202cf95939ffa73b10521f05c060cecb15f8597ed95d72b9e405ee31f1b5d90203010001' -); - diff --git a/src/medsrv/.gitignore b/src/medsrv/.gitignore deleted file mode 100644 index ab09bc87f..000000000 --- a/src/medsrv/.gitignore +++ /dev/null @@ -1 +0,0 @@ -medsrv.fcgi diff --git a/src/medsrv/Makefile.am b/src/medsrv/Makefile.am deleted file mode 100644 index bee7ae1f0..000000000 --- a/src/medsrv/Makefile.am +++ /dev/null @@ -1,45 +0,0 @@ -medsrvdir = ${ipsecdir}/medsrv - -medsrv_PROGRAMS = medsrv.fcgi - -medsrv_fcgi_SOURCES = user.h user.c \ -main.c filter/auth_filter.c filter/auth_filter.h \ -controller/user_controller.c controller/user_controller.h \ -controller/peer_controller.c controller/peer_controller.h - -medsrv_fcgi_LDADD = $(top_builddir)/src/libstrongswan/libstrongswan.la $(top_builddir)/src/libfast/libfast.la -main.o : $(top_builddir)/config.status - -AM_CPPFLAGS = \ - -I$(top_srcdir)/src/libstrongswan \ - -I$(top_srcdir)/src/libfast \ - -DIPSECDIR=\"${ipsecdir}\" \ - -DIPSEC_PIDDIR=\"${piddir}\" \ - -DPLUGINS=\""${medsrv_plugins}\"" - -AM_CFLAGS = \ - $(PLUGIN_CFLAGS) - -# Don't forget to add templates to EXTRA_DIST !!! How to automate? -medsrv_templatesdir = ${medsrvdir}/templates -medsrv_templates_DATA = templates/header.cs templates/footer.cs - -medsrv_templates_userdir = ${medsrv_templatesdir}/user -medsrv_templates_user_DATA = templates/user/add.cs templates/user/edit.cs \ -templates/user/login.cs templates/user/help.cs - -medsrv_templates_peerdir = ${medsrv_templatesdir}/peer -medsrv_templates_peer_DATA = templates/peer/add.cs templates/peer/edit.cs \ -templates/peer/list.cs - -medsrv_templates_staticdir = ${medsrv_templatesdir}/static -medsrv_templates_static_DATA = templates/header.cs templates/footer.cs \ -templates/static/style.css templates/static/strongswan.png \ -templates/static/favicon.ico - -EXTRA_DIST = templates/header.cs templates/footer.cs \ -templates/static/style.css templates/static/strongswan.png \ -templates/static/favicon.ico \ -templates/peer/add.cs templates/peer/edit.cs templates/peer/list.cs \ -templates/user/login.cs templates/user/add.cs templates/user/edit.cs \ -templates/user/help.cs diff --git a/src/medsrv/controller/peer_controller.c b/src/medsrv/controller/peer_controller.c deleted file mode 100644 index 9fa02a207..000000000 --- a/src/medsrv/controller/peer_controller.c +++ /dev/null @@ -1,380 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * Copyright (C) 2008 Philip Boetschi, Adrian Doerig - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#define _GNU_SOURCE -#include - -#include "peer_controller.h" - -#include -#include -#include -#include -#include -#include - -typedef struct private_peer_controller_t private_peer_controller_t; - -/** - * private data of the peer_controller - */ -struct private_peer_controller_t { - - /** - * public functions - */ - peer_controller_t public; - - /** - * active user session - */ - user_t *user; - - /** - * underlying database - */ - database_t *db; -}; - -/** - * list the configured peer configs - */ -static void list(private_peer_controller_t *this, fast_request_t *request) -{ - enumerator_t *query; - - query = this->db->query(this->db, - "SELECT id, alias, keyid FROM peer WHERE user = ? ORDER BY alias", - DB_UINT, this->user->get_user(this->user), - DB_UINT, DB_TEXT, DB_BLOB); - - if (query) - { - u_int id; - char *alias; - chunk_t keyid; - identification_t *identifier; - - while (query->enumerate(query, &id, &alias, &keyid)) - { - request->setf(request, "peers.%d.alias=%s", id, alias); - identifier = identification_create_from_encoding(ID_KEY_ID, keyid); - request->setf(request, "peers.%d.identifier=%Y", id, identifier); - identifier->destroy(identifier); - } - query->destroy(query); - } - request->render(request, "templates/peer/list.cs"); -} - -/** - * verify a peer alias - */ -static bool verify_alias(private_peer_controller_t *this, fast_request_t *request, - char *alias) -{ - if (!alias || *alias == '\0') - { - request->setf(request, "error=Alias is missing."); - return FALSE; - } - while (*alias != '\0') - { - switch (*alias) - { - case 'a' ... 'z': - case 'A' ... 'Z': - case '0' ... '9': - case '-': - case '_': - case '@': - case '.': - alias++; - continue; - default: - request->setf(request, "error=Alias invalid, " - "valid characters: A-Z a-z 0-9 - _ @ ."); - return FALSE; - } - } - return TRUE; -} - -/** - * parse and verify a public key - */ -static bool parse_public_key(private_peer_controller_t *this, - fast_request_t *request, char *public_key, - chunk_t *encoding, chunk_t *keyid) -{ - public_key_t *public; - chunk_t blob, id; - - if (!public_key || *public_key == '\0') - { - request->setf(request, "error=Public key is missing."); - return FALSE; - } - blob = chunk_clone(chunk_create(public_key, strlen(public_key))); - public = lib->creds->create(lib->creds, CRED_PUBLIC_KEY, KEY_ANY, - BUILD_BLOB_PEM, blob, - BUILD_END); - chunk_free(&blob); - if (!public) - { - request->setf(request, "error=Parsing public key failed."); - return FALSE; - } - /* TODO: use get_encoding() with an encoding type */ - if (!public->get_fingerprint(public, KEYID_PUBKEY_SHA1, &id) || - !public->get_encoding(public, PUBKEY_SPKI_ASN1_DER, encoding)) - { - request->setf(request, "error=Encoding public key failed."); - return FALSE; - } - *keyid = chunk_clone(id); - public->destroy(public); - return TRUE; -} - -/** - * register a new peer - */ -static void add(private_peer_controller_t *this, fast_request_t *request) -{ - char *alias = "", *public_key = ""; - - if (request->get_query_data(request, "back")) - { - return request->redirect(request, "peer/list"); - } - while (request->get_query_data(request, "add")) - { - chunk_t encoding, keyid; - - alias = request->get_query_data(request, "alias"); - public_key = request->get_query_data(request, "public_key"); - - if (!verify_alias(this, request, alias)) - { - break; - } - if (!parse_public_key(this, request, public_key, &encoding, &keyid)) - { - break; - } - if (this->db->execute(this->db, NULL, - "INSERT INTO peer (user, alias, public_key, keyid) " - "VALUES (?, ?, ?, ?)", - DB_UINT, this->user->get_user(this->user), - DB_TEXT, alias, DB_BLOB, encoding, - DB_BLOB, keyid) <= 0) - { - request->setf(request, "error=Peer already exists."); - free(keyid.ptr); - free(encoding.ptr); - break; - } - free(keyid.ptr); - free(encoding.ptr); - return request->redirect(request, "peer/list"); - } - request->set(request, "alias", alias); - request->set(request, "public_key", public_key); - - return request->render(request, "templates/peer/add.cs"); -} - -/** - * pem encode a public key into an allocated string - */ -static char* pem_encode(chunk_t der) -{ - static const char *begin = "-----BEGIN PUBLIC KEY-----\n"; - static const char *end = "-----END PUBLIC KEY-----"; - size_t len; - char *pem; - chunk_t base64; - int i = 0; - - base64 = chunk_to_base64(der, NULL); - len = strlen(begin) + base64.len + base64.len/64 + strlen(end) + 2; - pem = malloc(len + 1); - - strcpy(pem, begin); - do - { - strncat(pem, base64.ptr + i, 64); - strcat(pem, "\n"); - i += 64; - } - while (i < base64.len - 2); - strcat(pem, end); - - free(base64.ptr); - return pem; -} - -/** - * edit a peer - */ -static void edit(private_peer_controller_t *this, fast_request_t *request, int id) -{ - char *alias = "", *public_key = "", *pem; - chunk_t encoding, keyid; - - if (request->get_query_data(request, "back")) - { - return request->redirect(request, "peer/list"); - } - if (request->get_query_data(request, "delete")) - { - this->db->execute(this->db, NULL, - "DELETE FROM peer WHERE id = ? AND user = ?", - DB_INT, id, DB_UINT, this->user->get_user(this->user)); - return request->redirect(request, "peer/list"); - } - if (request->get_query_data(request, "save")) - { - while (TRUE) - { - alias = request->get_query_data(request, "alias"); - public_key = request->get_query_data(request, "public_key"); - - if (!verify_alias(this, request, alias)) - { - break; - } - if (!parse_public_key(this, request, public_key, &encoding, &keyid)) - { - break; - } - if (this->db->execute(this->db, NULL, - "UPDATE peer SET alias = ?, public_key = ?, keyid = ? " - "WHERE id = ? AND user = ?", - DB_TEXT, alias, DB_BLOB, encoding, DB_BLOB, keyid, - DB_INT, id, DB_UINT, this->user->get_user(this->user)) < 0) - { - request->setf(request, "error=Peer already exists."); - free(keyid.ptr); - free(encoding.ptr); - break; - } - free(keyid.ptr); - free(encoding.ptr); - return request->redirect(request, "peer/list"); - } - } - else - { - enumerator_t *query = this->db->query(this->db, - "SELECT alias, public_key FROM peer WHERE id = ? AND user = ?", - DB_INT, id, DB_UINT, this->user->get_user(this->user), - DB_TEXT, DB_BLOB); - if (query && query->enumerate(query, &alias, &encoding)) - { - alias = strdupa(alias); - pem = pem_encode(encoding); - public_key = strdupa(pem); - free(pem); - } - else - { - return request->redirect(request, "peer/list"); - } - DESTROY_IF(query); - } - request->set(request, "alias", alias); - request->set(request, "public_key", public_key); - return request->render(request, "templates/peer/edit.cs"); -} - -/** - * delete a peer from the database - */ -static void delete(private_peer_controller_t *this, fast_request_t *request, int id) -{ - this->db->execute(this->db, NULL, - "DELETE FROM peer WHERE id = ? AND user = ?", - DB_INT, id, DB_UINT, this->user->get_user(this->user)); -} - -METHOD(fast_controller_t, get_name, char*, - private_peer_controller_t *this) -{ - return "peer"; -} - -METHOD(fast_controller_t, handle, void, - private_peer_controller_t *this, fast_request_t *request, char *action, - char *idstr, char *p3, char *p4, char *p5) -{ - if (action) - { - int id = 0; - if (idstr) - { - id = atoi(idstr); - } - - if (streq(action, "list")) - { - return list(this, request); - } - else if (streq(action, "add")) - { - return add(this, request); - } - else if (streq(action, "edit") && id) - { - return edit(this, request, id); - } - else if (streq(action, "delete") && id) - { - delete(this, request, id); - } - } - request->redirect(request, "peer/list"); -} - -METHOD(fast_controller_t, destroy, void, - private_peer_controller_t *this) -{ - free(this); -} - -/* - * see header file - */ -fast_controller_t *peer_controller_create(user_t *user, database_t *db) -{ - private_peer_controller_t *this; - - INIT(this, - .public = { - .controller = { - .get_name = _get_name, - .handle = _handle, - .destroy = _destroy, - }, - }, - .user = user, - .db = db, - ); - - return &this->public.controller; -} diff --git a/src/medsrv/controller/peer_controller.h b/src/medsrv/controller/peer_controller.h deleted file mode 100644 index fc817d456..000000000 --- a/src/medsrv/controller/peer_controller.h +++ /dev/null @@ -1,49 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * Copyright (C) 2008 Philip Boetschi, Adrian Doerig - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup peer_controller_server peer_controller - * @{ @ingroup medsrv - */ - -#ifndef PEER_CONTROLLER_H_ -#define PEER_CONTROLLER_H_ - -#include - -#include -#include - -typedef struct peer_controller_t peer_controller_t; - -/** - * Peer controller. Manages peers associated to a user. - */ -struct peer_controller_t { - - /** - * Implements controller_t interface. - */ - fast_controller_t controller; -}; - -/** - * Create a peer_controller controller instance. - */ -fast_controller_t *peer_controller_create(user_t *user, database_t *db); - -#endif /** PEER_CONTROLLER_H_ @}*/ diff --git a/src/medsrv/controller/user_controller.c b/src/medsrv/controller/user_controller.c deleted file mode 100644 index d4c20e287..000000000 --- a/src/medsrv/controller/user_controller.c +++ /dev/null @@ -1,367 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * Copyright (C) 2008 Philip Boetschi, Adrian Doerig - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#define _GNU_SOURCE -#include - -#include "user_controller.h" - -#include - -typedef struct private_user_controller_t private_user_controller_t; - -/** - * private data of the user_controller - */ -struct private_user_controller_t { - - /** - * public functions - */ - user_controller_t public; - - /** - * database connection - */ - database_t *db; - - /** - * user session - */ - user_t *user; - - /** - * minimum required password length - */ - u_int password_length; -}; - -/** - * hash the password for database storage - */ -static chunk_t hash_password(char *login, char *password) -{ - hasher_t *hasher; - chunk_t hash, data; - - hasher = lib->crypto->create_hasher(lib->crypto, HASH_SHA1); - if (!hasher) - { - return chunk_empty; - } - data = chunk_cata("cc", chunk_create(login, strlen(login)), - chunk_create(password, strlen(password))); - if (!hasher->allocate_hash(hasher, data, &hash)) - { - hasher->destroy(hasher); - return chunk_empty; - } - hasher->destroy(hasher); - return hash; -} - -/** - * Login a user. - */ -static void login(private_user_controller_t *this, fast_request_t *request) -{ - if (request->get_query_data(request, "submit")) - { - char *login, *password; - - login = request->get_query_data(request, "login"); - password = request->get_query_data(request, "password"); - - if (login && password) - { - enumerator_t *query; - u_int id = 0; - chunk_t hash; - - hash = hash_password(login, password); - query = this->db->query(this->db, - "SELECT id FROM user WHERE login = ? AND password = ?", - DB_TEXT, login, DB_BLOB, hash, DB_UINT); - if (query) - { - query->enumerate(query, &id); - query->destroy(query); - } - free(hash.ptr); - if (id) - { - this->user->set_user(this->user, id); - return request->redirect(request, "peer/list"); - } - } - request->setf(request, "error=Invalid username or password."); - } - request->render(request, "templates/user/login.cs"); -} - -/** - * Logout a user. - */ -static void logout(private_user_controller_t *this, fast_request_t *request) -{ - request->redirect(request, "user/login"); - request->close_session(request); -} - -/** - * verify a user entered username for validity - */ -static bool verify_login(private_user_controller_t *this, - fast_request_t *request, char *login) -{ - if (!login || *login == '\0') - { - request->setf(request, "error=Username is missing."); - return FALSE; - } - while (*login != '\0') - { - switch (*login) - { - case 'a' ... 'z': - case 'A' ... 'Z': - case '0' ... '9': - case '-': - case '_': - case '@': - case '.': - login++; - continue; - default: - request->setf(request, "error=Username invalid, " - "valid characters: A-Z a-z 0-9 - _ @ ."); - return FALSE; - } - } - return TRUE; -} - -/** - * verify a user entered password for validity - */ -static bool verify_password(private_user_controller_t *this, - fast_request_t *request, - char *password, char *confirm) -{ - if (!password || *password == '\0') - { - request->setf(request, "error=Password is missing."); - return FALSE; - } - if (strlen(password) < this->password_length) - { - request->setf(request, "error=Password requires at least %d characters.", - this->password_length); - return FALSE; - } - if (!confirm || !streq(password, confirm)) - { - request->setf(request, "error=Password not confirmed."); - return FALSE; - } - return TRUE; -} - -/** - * Register a user. - */ -static void add(private_user_controller_t *this, fast_request_t *request) -{ - char *login = ""; - - while (request->get_query_data(request, "register")) - { - char *password, *confirm; - chunk_t hash; - u_int id; - - login = request->get_query_data(request, "new_login"); - password = request->get_query_data(request, "new_password"); - confirm = request->get_query_data(request, "confirm_password"); - - if (!verify_login(this, request, login) || - !verify_password(this, request, password, confirm)) - { - break; - } - - hash = hash_password(login, password); - if (!hash.ptr || this->db->execute(this->db, &id, - "INSERT INTO user (login, password) VALUES (?, ?)", - DB_TEXT, login, DB_BLOB, hash) < 0) - { - request->setf(request, "error=Username already exists."); - free(hash.ptr); - break; - } - free(hash.ptr); - this->user->set_user(this->user, id); - return request->redirect(request, "peer/list"); - } - request->set(request, "new_login", login); - request->setf(request, "password_length=%d", this->password_length); - request->render(request, "templates/user/add.cs"); -} - -/** - * Edit the logged in user - */ -static void edit(private_user_controller_t *this, fast_request_t *request) -{ - enumerator_t *query; - char *old_login; - - /* lookup old login */ - query = this->db->query(this->db, "SELECT login FROM user WHERE id = ?", - DB_INT, this->user->get_user(this->user), - DB_TEXT); - if (!query || !query->enumerate(query, &old_login)) - { - DESTROY_IF(query); - request->close_session(request); - return request->redirect(request, "user/login"); - } - old_login = strdupa(old_login); - query->destroy(query); - - /* back pressed */ - if (request->get_query_data(request, "back")) - { - return request->redirect(request, "peer/list"); - } - /* delete pressed */ - if (request->get_query_data(request, "delete")) - { - this->db->execute(this->db, NULL, "DELETE FROM user WHERE id = ?", - DB_UINT, this->user->get_user(this->user)); - this->db->execute(this->db, NULL, - "DELETE FROM peer WHERE user = ?", - DB_UINT, this->user->get_user(this->user)); - return logout(this, request); - } - /* save pressed */ - while (request->get_query_data(request, "save")) - { - char *new_login, *old_pass, *new_pass, *confirm; - chunk_t old_hash, new_hash; - - new_login = request->get_query_data(request, "old_login"); - old_pass = request->get_query_data(request, "old_password"); - new_pass = request->get_query_data(request, "new_password"); - confirm = request->get_query_data(request, "confirm_password"); - - if (!verify_login(this, request, new_login) || - !verify_password(this, request, new_pass, confirm)) - { - old_login = new_login; - break; - } - old_hash = hash_password(old_login, old_pass); - new_hash = hash_password(new_login, new_pass); - - if (this->db->execute(this->db, NULL, - "UPDATE user SET login = ?, password = ? " - "WHERE id = ? AND password = ?", - DB_TEXT, new_login, DB_BLOB, new_hash, - DB_UINT, this->user->get_user(this->user), DB_BLOB, old_hash) <= 0) - { - free(new_hash.ptr); - free(old_hash.ptr); - old_login = new_login; - request->setf(request, "error=Password verification failed."); - break; - } - free(new_hash.ptr); - free(old_hash.ptr); - return request->redirect(request, "peer/list"); - } - /* on error/template rendering */ - request->set(request, "old_login", old_login); - request->setf(request, "password_length=%d", this->password_length); - request->render(request, "templates/user/edit.cs"); -} - -METHOD(fast_controller_t, get_name, char*, - private_user_controller_t *this) -{ - return "user"; -} - -METHOD(fast_controller_t, handle, void, - private_user_controller_t *this, fast_request_t *request, char *action, - char *p2, char *p3, char *p4, char *p5) -{ - if (action) - { - if (streq(action, "add")) - { - return add(this, request); - } - if (streq(action, "login")) - { - return login(this, request); - } - else if (streq(action, "logout")) - { - return logout(this, request); - } - else if (streq(action, "edit")) - { - return edit(this, request); - } - else if (streq(action, "help")) - { - return request->render(request, "templates/user/help.cs"); - } - } - request->redirect(request, "user/login"); -} - -METHOD(fast_controller_t, destroy, void, - private_user_controller_t *this) -{ - free(this); -} - -/* - * see header file - */ -fast_controller_t *user_controller_create(user_t *user, database_t *db) -{ - private_user_controller_t *this; - - INIT(this, - .public = { - .controller = { - .get_name = _get_name, - .handle = _handle, - .destroy = _destroy, - }, - }, - .user = user, - .db = db, - .password_length = lib->settings->get_int(lib->settings, - "medsrv.password_length", 6), - ); - - return &this->public.controller; -} diff --git a/src/medsrv/controller/user_controller.h b/src/medsrv/controller/user_controller.h deleted file mode 100644 index 33e0ec289..000000000 --- a/src/medsrv/controller/user_controller.h +++ /dev/null @@ -1,49 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * Copyright (C) 2008 Philip Boetschi, Adrian Doerig - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup user_controller_server user_controller - * @{ @ingroup medsrv - */ - -#ifndef USER_CONTROLLER_H_ -#define USER_CONTROLLER_H_ - -#include - -#include -#include - -typedef struct user_controller_t user_controller_t; - -/** - * User controller. Register, Login and user management. - */ -struct user_controller_t { - - /** - * Implements controller_t interface. - */ - fast_controller_t controller; -}; - -/** - * Create a user_controller controller instance. - */ -fast_controller_t *user_controller_create(user_t *user, database_t *db); - -#endif /** USER_CONTROLLER_H_ @}*/ diff --git a/src/medsrv/filter/auth_filter.c b/src/medsrv/filter/auth_filter.c deleted file mode 100644 index 20f3ceee4..000000000 --- a/src/medsrv/filter/auth_filter.c +++ /dev/null @@ -1,99 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * Copyright (C) 2008 Philip Boetschi, Adrian Doerig - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "auth_filter.h" - -#include - -typedef struct private_auth_filter_t private_auth_filter_t; - -/** - * private data of auth_filter - */ -struct private_auth_filter_t { - /** - * public functions - */ - auth_filter_t public; - - /** - * user session - */ - user_t *user; - - /** - * database connection - */ - database_t *db; -}; - -METHOD(fast_filter_t, run, bool, - private_auth_filter_t *this, fast_request_t *request, char *controller, - char *action, char *p2, char *p3, char *p4, char *p5) -{ - if (this->user->get_user(this->user)) - { - enumerator_t *query; - char *login; - - query = this->db->query(this->db, "SELECT login FROM user WHERE id = ?", - DB_INT, this->user->get_user(this->user), - DB_TEXT); - if (query && query->enumerate(query, &login)) - { - request->set(request, "login", login); - query->destroy(query); - return TRUE; - } - DESTROY_IF(query); - this->user->set_user(this->user, 0); - } - if (controller && streq(controller, "user") && action && - (streq(action, "add") || streq(action, "login") || streq(action, "help"))) - { /* add/login allowed */ - return TRUE; - } - request->redirect(request, "user/login"); - return FALSE; -} - -METHOD(fast_filter_t, destroy, void, - private_auth_filter_t *this) -{ - free(this); -} - -/* - * see header file - */ -fast_filter_t *auth_filter_create(user_t *user, database_t *db) -{ - private_auth_filter_t *this; - - INIT(this, - .public = { - .filter = { - .destroy = _destroy, - .run = _run, - }, - }, - .user = user, - .db = db, - ); - - return &this->public.filter; -} diff --git a/src/medsrv/filter/auth_filter.h b/src/medsrv/filter/auth_filter.h deleted file mode 100644 index e0cca0a88..000000000 --- a/src/medsrv/filter/auth_filter.h +++ /dev/null @@ -1,49 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * Copyright (C) 2008 Philip Boetschi, Adrian Doerig - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup auth_filter_server auth_filter - * @{ @ingroup medsrv - */ - -#ifndef AUTH_FILTER_H_ -#define AUTH_FILTER_H_ - -#include -#include - -#include "user.h" - -typedef struct auth_filter_t auth_filter_t; - -/** - * Authentication/Authorization filter. - */ -struct auth_filter_t { - - /** - * Implements filter_t interface. - */ - fast_filter_t filter; -}; - -/** - * Create a auth_filter instance. - */ -fast_filter_t *auth_filter_create(user_t *user, database_t *db); - -#endif /** AUTH_FILTER_H_ @}*/ diff --git a/src/medsrv/main.c b/src/medsrv/main.c deleted file mode 100644 index fe0d8a4c7..000000000 --- a/src/medsrv/main.c +++ /dev/null @@ -1,79 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * Copyright (C) 2008 Philip Boetschi, Adrian Doerig - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include - -#include -#include -#include - -#include "filter/auth_filter.h" -#include "controller/user_controller.h" -#include "controller/peer_controller.h" - -int main(int arc, char *argv[]) -{ - fast_dispatcher_t *dispatcher; - database_t *db; - char *socket; - bool debug; - char *uri; - int timeout, threads; - - library_init(NULL, "medsrv"); - if (!lib->plugins->load(lib->plugins, - lib->settings->get_str(lib->settings, "medsrv.load", PLUGINS))) - { - return 1; - } - - socket = lib->settings->get_str(lib->settings, "medsrv.socket", NULL); - debug = lib->settings->get_bool(lib->settings, "medsrv.debug", FALSE); - timeout = lib->settings->get_time(lib->settings, "medsrv.timeout", 900); - threads = lib->settings->get_int(lib->settings, "medsrv.threads", 5); - uri = lib->settings->get_str(lib->settings, "medsrv.database", NULL); - if (uri == NULL) - { - fprintf(stderr, "database URI medsrv.database not defined.\n"); - return 1; - } - - db = lib->db->create(lib->db, uri); - if (db == NULL) - { - fprintf(stderr, "opening database failed.\n"); - return 1; - } - - dispatcher = fast_dispatcher_create(socket, debug, timeout, - (fast_context_constructor_t)user_create, db); - dispatcher->add_filter(dispatcher, - (fast_filter_constructor_t)auth_filter_create, db); - dispatcher->add_controller(dispatcher, - (fast_controller_constructor_t)user_controller_create, db); - dispatcher->add_controller(dispatcher, - (fast_controller_constructor_t)peer_controller_create, db); - - dispatcher->run(dispatcher, threads); - - dispatcher->waitsignal(dispatcher); - dispatcher->destroy(dispatcher); - db->destroy(db); - - library_deinit(); - return 0; -} diff --git a/src/medsrv/templates/footer.cs b/src/medsrv/templates/footer.cs deleted file mode 100644 index 9b151ee89..000000000 --- a/src/medsrv/templates/footer.cs +++ /dev/null @@ -1,4 +0,0 @@ - - - - diff --git a/src/medsrv/templates/header.cs b/src/medsrv/templates/header.cs deleted file mode 100644 index cb21bb06a..000000000 --- a/src/medsrv/templates/header.cs +++ /dev/null @@ -1,31 +0,0 @@ - - - - strongSwan Mediation Service - - - - - - -
- - - -

Mediation Service

-
- -
-
-
diff --git a/src/medsrv/templates/peer/add.cs b/src/medsrv/templates/peer/add.cs deleted file mode 100644 index 1e4f10f30..000000000 --- a/src/medsrv/templates/peer/add.cs +++ /dev/null @@ -1,24 +0,0 @@ - -
- -
- - - - - - - - - - - - - - -
- - -
-
- diff --git a/src/medsrv/templates/peer/edit.cs b/src/medsrv/templates/peer/edit.cs deleted file mode 100644 index ac4a2e11f..000000000 --- a/src/medsrv/templates/peer/edit.cs +++ /dev/null @@ -1,25 +0,0 @@ - -
- -
- - - - - - - - - - - - - - -
- - - -
-
- diff --git a/src/medsrv/templates/peer/list.cs b/src/medsrv/templates/peer/list.cs deleted file mode 100644 index 205452641..000000000 --- a/src/medsrv/templates/peer/list.cs +++ /dev/null @@ -1,28 +0,0 @@ - -
- 0 ?> - - - - - - - - - - - -
AliasKey Identifier
- - - -
- -No peers defined. - -
-
- -
-
- diff --git a/src/medsrv/templates/static/favicon.ico b/src/medsrv/templates/static/favicon.ico deleted file mode 100644 index d00459196..000000000 Binary files a/src/medsrv/templates/static/favicon.ico and /dev/null differ diff --git a/src/medsrv/templates/static/strongswan.png b/src/medsrv/templates/static/strongswan.png deleted file mode 100644 index 869188cdf..000000000 Binary files a/src/medsrv/templates/static/strongswan.png and /dev/null differ diff --git a/src/medsrv/templates/static/style.css b/src/medsrv/templates/static/style.css deleted file mode 100644 index cb7f30398..000000000 --- a/src/medsrv/templates/static/style.css +++ /dev/null @@ -1,128 +0,0 @@ - -body { - font-family: Verdana, Arial, Helvetica, sans-serif; - color: #230100; - background-color: #f7f4d3; - margin: 0; -} - -.content { -} - -.content > * { - background-color: #e5bf5e; - border: solid 2px; - padding: 1em 1em 1em 1em; - margin: 1em; - text-align: left; -} - -textarea, select, input { - background-color: #ffec9e; - border: 1px solid; - padding: 1px 3px 1px 3px; -} - -table.user input[type="text"], table.user input[type="password"] { - width: 15em; -} - -table.peer textarea { - height: 20em; - width: 42.3em; - -} - -table.peer input[type="text"] { - width: 38em; -} - -.menu { - text-align: right; - background-color: #e5bf5e; - padding: 3px; - border-bottom: solid 2px; -} - -a { - color: black; - text-decoration: none; -} - -a:hover { - text-decoration: underline; -} - -h1 { - margin-top: 1.5em; - font-size: 2.1em; - white-space: nowrap; -} - -hr { - border: solid 1px; -} - -a img { - border: none; -} - -.center { - text-align: center; -} - -.left { - text-align: left; -} - -.right { - text-align: right; -} - -.fleft { - margin-right: 2em; - float: left; -} - -.fright { - float: left; -} - -.cleft { - clear:left; -} - -.cright { - clear:right; -} - -.both { - clear:both; -} - -.error { - color: #dd0000; -} - -table.list * { - padding: 0px 1em 0px 0.2em; -} - -table.list tr td, table.list tr th { - border: solid 1px; - border-color: black; -} - -table.list tr th { - background-color: #ffec9e; -} - -table.list tr:nth-child(odd) td { - background-color: #f2cd6f; -} - -table.list tr td a { - text-decoration: none; - display: inline-block; - width: 100%; -} diff --git a/src/medsrv/templates/user/add.cs b/src/medsrv/templates/user/add.cs deleted file mode 100644 index 82442c543..000000000 --- a/src/medsrv/templates/user/add.cs +++ /dev/null @@ -1,28 +0,0 @@ - -
- -
- - - - - - - - - - - - - - - - - - -
min. characters
- - -
-
- diff --git a/src/medsrv/templates/user/edit.cs b/src/medsrv/templates/user/edit.cs deleted file mode 100644 index de311cd3d..000000000 --- a/src/medsrv/templates/user/edit.cs +++ /dev/null @@ -1,35 +0,0 @@ - -
- -
- - - - - - - - - - - - - - - - - - - - - - - - -
min. characters
- - - -
-
- diff --git a/src/medsrv/templates/user/help.cs b/src/medsrv/templates/user/help.cs deleted file mode 100644 index 58615c14a..000000000 --- a/src/medsrv/templates/user/help.cs +++ /dev/null @@ -1,34 +0,0 @@ - -
-

strongSwan Mediation Service web frontend

-

This web application builds the end user front end for a Mediation Service -as defined in the - -IKEv2 Mediation Extension draft.

-

Mediation connection

-

The authentication between Mediation Server and connecting clients is based -on RSA public keys. The identities used for IKEv2 are the public key identifier -of each clients key, encapsulated in a ID_KEY_ID identity.

-

The public key of this Mediation Server is:

-
-----BEGIN PUBLIC KEY-----
-MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzZRsIp99UrIdoctThOfc
-r2Up92BTSlY1Xv1J6Hqcbx3dX/MDvX60nCPeA63Eh0VvQetfkpR73I/42+RD+NES
-4NosmBRefE0c0Vzd0IV39NTz0KLh2jwIyUzYGXWHUZMeepckzEPXOhG44XaiaLTN
-u/OZXLCXI6vJv8R3wl5xSkZhqEwHi+dATYmGvlXyBDfjprJ4o8yJrsCFlB8aGq+v
-SyKuFG/kaE1VZ9wwZYoyCH0BuYUVBwyxZTMRy2EC+CqDxjjCp5mF27lgB1Lpy8Jy
-AUpcVHtKtZEww6lIZYv/eUtvICz5WTn/pzsQUh8FwGDOyxX4WX7ZXXK55AXuMfG1
-2QIDAQAB
------END PUBLIC KEY-----
-

The Mediation Server is reachable at mediation.strongswan.org.

-The mediation server allows connections from all registered peers.

-

Mediated connections

-

The authentication between mediated clients is done between clients, they -can use own keys or the same keys as defined for authentication of the -mediation connection. -

-
- -
-
-
- diff --git a/src/medsrv/templates/user/login.cs b/src/medsrv/templates/user/login.cs deleted file mode 100644 index fbf5b8bd7..000000000 --- a/src/medsrv/templates/user/login.cs +++ /dev/null @@ -1,23 +0,0 @@ - -
- -
- - - - - - - - - - - - - -
- - -
-
- diff --git a/src/medsrv/user.c b/src/medsrv/user.c deleted file mode 100644 index 3907870e6..000000000 --- a/src/medsrv/user.c +++ /dev/null @@ -1,73 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "user.h" - -typedef struct private_user_t private_user_t; - -/** - * private data of user - */ -struct private_user_t { - - /** - * public functions - */ - user_t public; - - /** - * user id, if we are logged in; otherwise 0 - */ - u_int user; -}; - -METHOD(user_t, set_user, void, - private_user_t *this, u_int id) -{ - this->user = id; -} - -METHOD(user_t, get_user, u_int, - private_user_t *this) -{ - return this->user; -} - -METHOD(fast_context_t, destroy, void, - private_user_t *this) -{ - free(this); -} - -/* - * see header file - */ -user_t *user_create(void *param) -{ - private_user_t *this; - - INIT(this, - .public = { - .set_user = _set_user, - .get_user = _get_user, - .context = { - .destroy = _destroy, - }, - }, - ); - - return &this->public; -} diff --git a/src/medsrv/user.h b/src/medsrv/user.h deleted file mode 100644 index 85d22d1a7..000000000 --- a/src/medsrv/user.h +++ /dev/null @@ -1,58 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup medsrv medsrv - * - * @defgroup user user - * @{ @ingroup medsrv - */ - -#ifndef USER_H_ -#define USER_H_ - -#include -#include - -typedef struct user_t user_t; - -/** - * Per session context. Contains user user state and data. - */ -struct user_t { - - /** - * implements context_t interface - */ - fast_context_t context; - - /** - * Set the user ID of the logged in user. - */ - void (*set_user)(user_t *this, u_int id); - - /** - * Get the user ID of the logged in user. - */ - u_int (*get_user)(user_t *this); -}; - -/** - * Create a user instance. - */ -user_t *user_create(void *param); - -#endif /** USER_H_ @} */ diff --git a/testing/tests/p2pnat/medsrv-psk/description.txt b/testing/tests/p2pnat/different-nats/description.txt similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/description.txt rename to testing/tests/p2pnat/different-nats/description.txt diff --git a/testing/tests/p2pnat/medsrv-psk/evaltest.dat b/testing/tests/p2pnat/different-nats/evaltest.dat similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/evaltest.dat rename to testing/tests/p2pnat/different-nats/evaltest.dat diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/alice/etc/iptables.rules b/testing/tests/p2pnat/different-nats/hosts/alice/etc/iptables.rules similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/alice/etc/iptables.rules rename to testing/tests/p2pnat/different-nats/hosts/alice/etc/iptables.rules diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/alice/etc/strongswan.conf b/testing/tests/p2pnat/different-nats/hosts/alice/etc/strongswan.conf similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/alice/etc/strongswan.conf rename to testing/tests/p2pnat/different-nats/hosts/alice/etc/strongswan.conf diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/alice/etc/swanctl/swanctl.conf b/testing/tests/p2pnat/different-nats/hosts/alice/etc/swanctl/swanctl.conf similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/alice/etc/swanctl/swanctl.conf rename to testing/tests/p2pnat/different-nats/hosts/alice/etc/swanctl/swanctl.conf diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/bob/etc/iptables.rules b/testing/tests/p2pnat/different-nats/hosts/bob/etc/iptables.rules similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/bob/etc/iptables.rules rename to testing/tests/p2pnat/different-nats/hosts/bob/etc/iptables.rules diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/bob/etc/strongswan.conf b/testing/tests/p2pnat/different-nats/hosts/bob/etc/strongswan.conf similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/bob/etc/strongswan.conf rename to testing/tests/p2pnat/different-nats/hosts/bob/etc/strongswan.conf diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/bob/etc/swanctl/swanctl.conf b/testing/tests/p2pnat/different-nats/hosts/bob/etc/swanctl/swanctl.conf similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/bob/etc/swanctl/swanctl.conf rename to testing/tests/p2pnat/different-nats/hosts/bob/etc/swanctl/swanctl.conf diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/carol/etc/iptables.rules b/testing/tests/p2pnat/different-nats/hosts/carol/etc/iptables.rules similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/carol/etc/iptables.rules rename to testing/tests/p2pnat/different-nats/hosts/carol/etc/iptables.rules diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/carol/etc/strongswan.conf b/testing/tests/p2pnat/different-nats/hosts/carol/etc/strongswan.conf similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/carol/etc/strongswan.conf rename to testing/tests/p2pnat/different-nats/hosts/carol/etc/strongswan.conf diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/carol/etc/swanctl/swanctl.conf b/testing/tests/p2pnat/different-nats/hosts/carol/etc/swanctl/swanctl.conf similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/carol/etc/swanctl/swanctl.conf rename to testing/tests/p2pnat/different-nats/hosts/carol/etc/swanctl/swanctl.conf diff --git a/testing/tests/p2pnat/medsrv-psk/posttest.dat b/testing/tests/p2pnat/different-nats/posttest.dat similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/posttest.dat rename to testing/tests/p2pnat/different-nats/posttest.dat diff --git a/testing/tests/p2pnat/medsrv-psk/pretest.dat b/testing/tests/p2pnat/different-nats/pretest.dat similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/pretest.dat rename to testing/tests/p2pnat/different-nats/pretest.dat diff --git a/testing/tests/p2pnat/medsrv-psk/test.conf b/testing/tests/p2pnat/different-nats/test.conf similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/test.conf rename to testing/tests/p2pnat/different-nats/test.conf