From ac690f1a5e3a1ea5982340331dd24072450fc821 Mon Sep 17 00:00:00 2001 From: Tobias Brunner Date: Fri, 24 Jul 2026 14:21:44 +0200 Subject: [PATCH] medsrv/medcli: Remove prototypical medsrv web application and plugins This was from a student project that has never been developed further. And similar to the manager web application it lacks all sorts of modern standards. So just remove it and the two plugins it relied on. The test scenario is renamed to avoid confusion (neither of the two p2pnat scenarios uses medsrv/medcli). --- conf/Makefile.am | 1 - conf/options/medsrv.opt | 27 -- configure.ac | 57 +-- scripts/test.sh | 2 +- src/Makefile.am | 4 - src/libcharon/Makefile.am | 14 - src/libcharon/plugins/medcli/Makefile.am | 20 - src/libcharon/plugins/medcli/medcli_config.c | 434 ------------------ src/libcharon/plugins/medcli/medcli_config.h | 54 --- src/libcharon/plugins/medcli/medcli_creds.c | 242 ---------- src/libcharon/plugins/medcli/medcli_creds.h | 54 --- .../plugins/medcli/medcli_listener.c | 132 ------ .../plugins/medcli/medcli_listener.h | 54 --- src/libcharon/plugins/medcli/medcli_plugin.c | 147 ------ src/libcharon/plugins/medcli/medcli_plugin.h | 43 -- src/libcharon/plugins/medcli/mysql.sql | 32 -- src/libcharon/plugins/medsrv/Makefile.am | 19 - src/libcharon/plugins/medsrv/medsrv_config.c | 161 ------- src/libcharon/plugins/medsrv/medsrv_config.h | 54 --- src/libcharon/plugins/medsrv/medsrv_creds.c | 163 ------- src/libcharon/plugins/medsrv/medsrv_creds.h | 54 --- src/libcharon/plugins/medsrv/medsrv_plugin.c | 137 ------ src/libcharon/plugins/medsrv/medsrv_plugin.h | 43 -- src/libcharon/plugins/medsrv/mysql.sql | 21 - src/libcharon/plugins/medsrv/test.sql | 9 - src/medsrv/.gitignore | 1 - src/medsrv/Makefile.am | 45 -- src/medsrv/controller/peer_controller.c | 380 --------------- src/medsrv/controller/peer_controller.h | 49 -- src/medsrv/controller/user_controller.c | 367 --------------- src/medsrv/controller/user_controller.h | 49 -- src/medsrv/filter/auth_filter.c | 99 ---- src/medsrv/filter/auth_filter.h | 49 -- src/medsrv/main.c | 79 ---- src/medsrv/templates/footer.cs | 4 - src/medsrv/templates/header.cs | 31 -- src/medsrv/templates/peer/add.cs | 24 - src/medsrv/templates/peer/edit.cs | 25 - src/medsrv/templates/peer/list.cs | 28 -- src/medsrv/templates/static/favicon.ico | Bin 894 -> 0 bytes src/medsrv/templates/static/strongswan.png | Bin 19837 -> 0 bytes src/medsrv/templates/static/style.css | 128 ------ src/medsrv/templates/user/add.cs | 28 -- src/medsrv/templates/user/edit.cs | 35 -- src/medsrv/templates/user/help.cs | 34 -- src/medsrv/templates/user/login.cs | 23 - src/medsrv/user.c | 73 --- src/medsrv/user.h | 58 --- .../description.txt | 0 .../evaltest.dat | 0 .../hosts/alice/etc/iptables.rules | 0 .../hosts/alice/etc/strongswan.conf | 0 .../hosts/alice/etc/swanctl/swanctl.conf | 0 .../hosts/bob/etc/iptables.rules | 0 .../hosts/bob/etc/strongswan.conf | 0 .../hosts/bob/etc/swanctl/swanctl.conf | 0 .../hosts/carol/etc/iptables.rules | 0 .../hosts/carol/etc/strongswan.conf | 0 .../hosts/carol/etc/swanctl/swanctl.conf | 0 .../posttest.dat | 0 .../pretest.dat | 0 .../{medsrv-psk => different-nats}/test.conf | 0 62 files changed, 19 insertions(+), 3568 deletions(-) delete mode 100644 conf/options/medsrv.opt delete mode 100644 src/libcharon/plugins/medcli/Makefile.am delete mode 100644 src/libcharon/plugins/medcli/medcli_config.c delete mode 100644 src/libcharon/plugins/medcli/medcli_config.h delete mode 100644 src/libcharon/plugins/medcli/medcli_creds.c delete mode 100644 src/libcharon/plugins/medcli/medcli_creds.h delete mode 100644 src/libcharon/plugins/medcli/medcli_listener.c delete mode 100644 src/libcharon/plugins/medcli/medcli_listener.h delete mode 100644 src/libcharon/plugins/medcli/medcli_plugin.c delete mode 100644 src/libcharon/plugins/medcli/medcli_plugin.h delete mode 100644 src/libcharon/plugins/medcli/mysql.sql delete mode 100644 src/libcharon/plugins/medsrv/Makefile.am delete mode 100644 src/libcharon/plugins/medsrv/medsrv_config.c delete mode 100644 src/libcharon/plugins/medsrv/medsrv_config.h delete mode 100644 src/libcharon/plugins/medsrv/medsrv_creds.c delete mode 100644 src/libcharon/plugins/medsrv/medsrv_creds.h delete mode 100644 src/libcharon/plugins/medsrv/medsrv_plugin.c delete mode 100644 src/libcharon/plugins/medsrv/medsrv_plugin.h delete mode 100644 src/libcharon/plugins/medsrv/mysql.sql delete mode 100644 src/libcharon/plugins/medsrv/test.sql delete mode 100644 src/medsrv/.gitignore delete mode 100644 src/medsrv/Makefile.am delete mode 100644 src/medsrv/controller/peer_controller.c delete mode 100644 src/medsrv/controller/peer_controller.h delete mode 100644 src/medsrv/controller/user_controller.c delete mode 100644 src/medsrv/controller/user_controller.h delete mode 100644 src/medsrv/filter/auth_filter.c delete mode 100644 src/medsrv/filter/auth_filter.h delete mode 100644 src/medsrv/main.c delete mode 100644 src/medsrv/templates/footer.cs delete mode 100644 src/medsrv/templates/header.cs delete mode 100644 src/medsrv/templates/peer/add.cs delete mode 100644 src/medsrv/templates/peer/edit.cs delete mode 100644 src/medsrv/templates/peer/list.cs delete mode 100644 src/medsrv/templates/static/favicon.ico delete mode 100644 src/medsrv/templates/static/strongswan.png delete mode 100644 src/medsrv/templates/static/style.css delete mode 100644 src/medsrv/templates/user/add.cs delete mode 100644 src/medsrv/templates/user/edit.cs delete mode 100644 src/medsrv/templates/user/help.cs delete mode 100644 src/medsrv/templates/user/login.cs delete mode 100644 src/medsrv/user.c delete mode 100644 src/medsrv/user.h rename testing/tests/p2pnat/{medsrv-psk => different-nats}/description.txt (100%) rename testing/tests/p2pnat/{medsrv-psk => different-nats}/evaltest.dat (100%) rename testing/tests/p2pnat/{medsrv-psk => different-nats}/hosts/alice/etc/iptables.rules (100%) rename testing/tests/p2pnat/{medsrv-psk => different-nats}/hosts/alice/etc/strongswan.conf (100%) rename testing/tests/p2pnat/{medsrv-psk => different-nats}/hosts/alice/etc/swanctl/swanctl.conf (100%) rename testing/tests/p2pnat/{medsrv-psk => different-nats}/hosts/bob/etc/iptables.rules (100%) rename testing/tests/p2pnat/{medsrv-psk => different-nats}/hosts/bob/etc/strongswan.conf (100%) rename testing/tests/p2pnat/{medsrv-psk => different-nats}/hosts/bob/etc/swanctl/swanctl.conf (100%) rename testing/tests/p2pnat/{medsrv-psk => different-nats}/hosts/carol/etc/iptables.rules (100%) rename testing/tests/p2pnat/{medsrv-psk => different-nats}/hosts/carol/etc/strongswan.conf (100%) rename testing/tests/p2pnat/{medsrv-psk => different-nats}/hosts/carol/etc/swanctl/swanctl.conf (100%) rename testing/tests/p2pnat/{medsrv-psk => different-nats}/posttest.dat (100%) rename testing/tests/p2pnat/{medsrv-psk => different-nats}/pretest.dat (100%) rename testing/tests/p2pnat/{medsrv-psk => different-nats}/test.conf (100%) diff --git a/conf/Makefile.am b/conf/Makefile.am index 6fefbf630..d2601b677 100644 --- a/conf/Makefile.am +++ b/conf/Makefile.am @@ -20,7 +20,6 @@ options = \ options/imcv.opt \ options/imv_policy_manager.opt \ options/iptfs.opt \ - options/medsrv.opt \ options/pki.opt \ options/pool.opt \ options/starter.opt \ diff --git a/conf/options/medsrv.opt b/conf/options/medsrv.opt deleted file mode 100644 index f673b7e03..000000000 --- a/conf/options/medsrv.opt +++ /dev/null @@ -1,27 +0,0 @@ -medsrv.database = - Mediation server database URI. If it contains a password, make - sure to adjust the permissions of the config file accordingly. - -medsrv.debug = no - Debugging in mediation server web application. - -medsrv.dpd = 5m - DPD timeout to use in mediation server plugin. - -medsrv.load = - Plugins to load in mediation server plugin. - -medsrv.password_length = 6 - Minimum password length required for mediation server user accounts. - -medsrv.rekey = 20m - Rekeying time on mediation connections in mediation server plugin. - -medsrv.socket = - Run Mediation server web application statically on socket. - -medsrv.threads = 5 - Number of thread for mediation service web application. - -medsrv.timeout = 15m - Session timeout for mediation service. diff --git a/configure.ac b/configure.ac index 2c7dc637a..66be9fab7 100644 --- a/configure.ac +++ b/configure.ac @@ -290,8 +290,6 @@ ARG_ENABL_SET([conftest], [enforce Suite B conformance test framework.]) ARG_ENABL_SET([fast], [enable libfast (FastCGI Application Server w/ templates.]) ARG_ENABL_SET([fuzzing], [enable fuzzing scripts (found in directory fuzz).]) ARG_ENABL_SET([libipsec], [enable user space IPsec implementation.]) -ARG_ENABL_SET([medcli], [enable mediation client configuration database plugin.]) -ARG_ENABL_SET([medsrv], [enable mediation server web frontend and daemon plugin.]) ARG_ENABL_SET([nm], [enable NetworkManager backend.]) ARG_DISBL_SET([pki], [disable pki certificate utility.]) ARG_DISBL_SET([scripts], [disable additional utilities (found in directory scripts).]) @@ -473,15 +471,6 @@ if test x$tnccs_11 = xtrue -o x$tnc_ifmap = xtrue; then xml=true fi -if test x$medsrv = xtrue; then - mediation=true - fast=true -fi - -if test x$medcli = xtrue; then - mediation=true -fi - if test x$ruby_gems_install = xtrue; then ruby_gems=true fi @@ -1528,7 +1517,6 @@ pool_plugins= attest_plugins= pki_plugins= scripts_plugins= -medsrv_plugins= nm_plugins= cmd_plugins= aikgen_plugins= @@ -1548,26 +1536,26 @@ ADD_PLUGIN([unbound], [s charon scripts]) ADD_PLUGIN([ldap], [s charon pki scripts nm cmd]) ADD_PLUGIN([pkcs11], [s charon pki nm cmd]) ADD_PLUGIN([tpm], [p charon pki nm cmd]) -ADD_PLUGIN([aesni], [s charon swanctl pki scripts medsrv attest nm cmd aikgen]) +ADD_PLUGIN([aesni], [s charon swanctl pki scripts attest nm cmd aikgen]) ADD_PLUGIN([aes], [s charon swanctl pki scripts nm cmd]) ADD_PLUGIN([des], [s charon swanctl pki scripts nm cmd]) ADD_PLUGIN([blowfish], [s charon swanctl pki scripts nm cmd]) ADD_PLUGIN([rc2], [s charon swanctl pki scripts nm cmd]) -ADD_PLUGIN([sha2], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fc]) -ADD_PLUGIN([sha3], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fc]) -ADD_PLUGIN([sha1], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fc]) +ADD_PLUGIN([sha2], [s charon swanctl pki scripts attest nm cmd aikgen fc]) +ADD_PLUGIN([sha3], [s charon swanctl pki scripts attest nm cmd aikgen fc]) +ADD_PLUGIN([sha1], [s charon swanctl pki scripts attest nm cmd aikgen fc]) ADD_PLUGIN([md4], [s charon swanctl pki nm cmd]) ADD_PLUGIN([md5], [s charon swanctl pki scripts attest nm cmd aikgen]) -ADD_PLUGIN([mgf1], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fc]) -ADD_PLUGIN([rdrand], [s charon swanctl pki scripts medsrv attest nm cmd aikgen]) -ADD_PLUGIN([random], [s charon swanctl pki scripts medsrv attest nm cmd aikgen]) +ADD_PLUGIN([mgf1], [s charon swanctl pki scripts attest nm cmd aikgen fc]) +ADD_PLUGIN([rdrand], [s charon swanctl pki scripts attest nm cmd aikgen]) +ADD_PLUGIN([random], [s charon swanctl pki scripts attest nm cmd aikgen]) ADD_PLUGIN([nonce], [s charon nm cmd aikgen]) ADD_PLUGIN([x509], [s charon swanctl pki scripts attest nm cmd aikgen fd fc]) ADD_PLUGIN([revocation], [s charon pki nm cmd]) ADD_PLUGIN([constraints], [s charon pki nm cmd]) ADD_PLUGIN([acert], [s charon]) ADD_PLUGIN([pubkey], [s charon swanctl pki cmd aikgen]) -ADD_PLUGIN([pkcs1], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fd fc]) +ADD_PLUGIN([pkcs1], [s charon swanctl pki scripts attest nm cmd aikgen fd fc]) ADD_PLUGIN([pkcs7], [s charon swanctl pki scripts nm cmd]) ADD_PLUGIN([pkcs12], [s charon swanctl pki scripts cmd]) ADD_PLUGIN([pgp], [s charon]) @@ -1575,16 +1563,16 @@ ADD_PLUGIN([dnskey], [s charon swanctl pki]) ADD_PLUGIN([sshkey], [s charon swanctl pki nm cmd]) ADD_PLUGIN([dnscert], [c charon]) ADD_PLUGIN([ipseckey], [c charon]) -ADD_PLUGIN([pem], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fd fc]) +ADD_PLUGIN([pem], [s charon swanctl pki scripts attest nm cmd aikgen fd fc]) ADD_PLUGIN([padlock], [s charon]) -ADD_PLUGIN([openssl], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fd]) -ADD_PLUGIN([wolfssl], [s charon swanctl pki scripts medsrv attest nm cmd aikgen]) -ADD_PLUGIN([gcrypt], [s charon swanctl pki scripts medsrv attest nm cmd aikgen]) -ADD_PLUGIN([botan], [s charon swanctl pki scripts medsrv attest nm cmd aikgen]) -ADD_PLUGIN([pkcs8], [s charon swanctl pki scripts medsrv attest nm cmd]) -ADD_PLUGIN([af-alg], [s charon swanctl pki scripts medsrv attest nm cmd aikgen]) +ADD_PLUGIN([openssl], [s charon swanctl pki scripts attest nm cmd aikgen fd]) +ADD_PLUGIN([wolfssl], [s charon swanctl pki scripts attest nm cmd aikgen]) +ADD_PLUGIN([gcrypt], [s charon swanctl pki scripts attest nm cmd aikgen]) +ADD_PLUGIN([botan], [s charon swanctl pki scripts attest nm cmd aikgen]) +ADD_PLUGIN([pkcs8], [s charon swanctl pki scripts attest nm cmd]) +ADD_PLUGIN([af-alg], [s charon swanctl pki scripts attest nm cmd aikgen]) ADD_PLUGIN([fips-prf], [s charon nm cmd]) -ADD_PLUGIN([gmp], [s charon swanctl pki scripts medsrv attest nm cmd aikgen fc]) +ADD_PLUGIN([gmp], [s charon swanctl pki scripts attest nm cmd aikgen fc]) ADD_PLUGIN([curve25519], [s charon swanctl pki scripts nm cmd]) ADD_PLUGIN([agent], [s charon nm cmd]) ADD_PLUGIN([keychain], [s charon cmd]) @@ -1602,8 +1590,8 @@ ADD_PLUGIN([curl], [s charon pki scripts nm cmd]) ADD_PLUGIN([files], [s charon pki scripts nm cmd]) ADD_PLUGIN([winhttp], [s charon pki scripts]) ADD_PLUGIN([soup], [s charon pki scripts nm cmd]) -ADD_PLUGIN([mysql], [s charon pki pool medsrv attest]) -ADD_PLUGIN([sqlite], [s charon pki pool medsrv attest]) +ADD_PLUGIN([mysql], [s charon pki pool attest]) +ADD_PLUGIN([sqlite], [s charon pki pool attest]) ADD_PLUGIN([openxpki], [s pki]) ADD_PLUGIN([attr], [c charon]) ADD_PLUGIN([attr-sql], [c charon]) @@ -1659,8 +1647,6 @@ ADD_PLUGIN([tnc-tnccs], [t charon]) ADD_PLUGIN([tnccs-20], [t charon]) ADD_PLUGIN([tnccs-11], [t charon]) ADD_PLUGIN([tnccs-dynamic], [t charon]) -ADD_PLUGIN([medsrv], [c charon]) -ADD_PLUGIN([medcli], [c charon]) ADD_PLUGIN([dhcp], [c charon]) ADD_PLUGIN([osx-attr], [c charon cmd]) ADD_PLUGIN([p-cscf], [c charon cmd]) @@ -1687,7 +1673,6 @@ AC_SUBST(pool_plugins) AC_SUBST(attest_plugins) AC_SUBST(pki_plugins) AC_SUBST(scripts_plugins) -AC_SUBST(medsrv_plugins) AC_SUBST(nm_plugins) AC_SUBST(cmd_plugins) AC_SUBST(aikgen_plugins) @@ -1770,8 +1755,6 @@ AM_CONDITIONAL(USE_ML, test x$ml = xtrue) # ---------------- AM_CONDITIONAL(USE_STROKE, test x$stroke = xtrue) AM_CONDITIONAL(USE_VICI, test x$vici = xtrue) -AM_CONDITIONAL(USE_MEDSRV, test x$medsrv = xtrue) -AM_CONDITIONAL(USE_MEDCLI, test x$medcli = xtrue) AM_CONDITIONAL(USE_OSX_ATTR, test x$osx_attr = xtrue) AM_CONDITIONAL(USE_P_CSCF, test x$p_cscf = xtrue) AM_CONDITIONAL(USE_ANDROID_DNS, test x$android_dns = xtrue) @@ -1975,7 +1958,6 @@ AM_COND_IF([USE_IMCV], [strongswan_options=${strongswan_options}" imcv imv_polic AM_COND_IF([USE_IMC_SWIMA], [strongswan_options=${strongswan_options}" sw-collector"]) AM_COND_IF([USE_IMV_SWIMA], [strongswan_options=${strongswan_options}" sec-updater"]) AM_COND_IF([USE_LIBTNCCS], [strongswan_options=${strongswan_options}" tnc"]) -AM_COND_IF([USE_MEDSRV], [strongswan_options=${strongswan_options}" medsrv"]) AM_COND_IF([USE_CMD], [strongswan_options=${strongswan_options}" charon-cmd"]) AM_COND_IF([USE_NM], [strongswan_options=${strongswan_options}" charon-nm"]) AM_COND_IF([USE_PKI], [strongswan_options=${strongswan_options}" pki"]) @@ -2132,8 +2114,6 @@ AC_CONFIG_FILES([ src/libcharon/plugins/sql/Makefile src/libcharon/plugins/dnscert/Makefile src/libcharon/plugins/ipseckey/Makefile - src/libcharon/plugins/medsrv/Makefile - src/libcharon/plugins/medcli/Makefile src/libcharon/plugins/addrblock/Makefile src/libcharon/plugins/unity/Makefile src/libcharon/plugins/ha/Makefile @@ -2183,7 +2163,6 @@ AC_CONFIG_FILES([ src/pki/man/Makefile src/pool/Makefile src/libfast/Makefile - src/medsrv/Makefile src/checksum/Makefile src/conftest/Makefile src/pt-tls-client/Makefile diff --git a/scripts/test.sh b/scripts/test.sh index 74c540e92..d3489d43b 100755 --- a/scripts/test.sh +++ b/scripts/test.sh @@ -304,7 +304,7 @@ all|alpine|codeql|coverage|sonarcloud|no-dbg|no-testable-ke) # no TrouSerS either CONFIG="$CONFIG --disable-tss-trousers --disable-aikgen" # and no Clearsilver - CONFIG="$CONFIG --disable-fast --disable-medsrv" + CONFIG="$CONFIG --disable-fast" fi if test "$1" = "build-deps"; then build_botan diff --git a/src/Makefile.am b/src/Makefile.am index f74c9010d..3a94b37a7 100644 --- a/src/Makefile.am +++ b/src/Makefile.am @@ -91,10 +91,6 @@ if USE_FAST SUBDIRS += libfast endif -if USE_MEDSRV - SUBDIRS += medsrv -endif - if USE_ATTR_SQL SUBDIRS += pool else diff --git a/src/libcharon/Makefile.am b/src/libcharon/Makefile.am index 38364595a..c6707ae3f 100644 --- a/src/libcharon/Makefile.am +++ b/src/libcharon/Makefile.am @@ -502,20 +502,6 @@ if MONOLITHIC endif endif -if USE_MEDSRV - SUBDIRS += plugins/medsrv -if MONOLITHIC - libcharon_la_LIBADD += plugins/medsrv/libstrongswan-medsrv.la -endif -endif - -if USE_MEDCLI - SUBDIRS += plugins/medcli -if MONOLITHIC - libcharon_la_LIBADD += plugins/medcli/libstrongswan-medcli.la -endif -endif - if USE_DHCP SUBDIRS += plugins/dhcp if MONOLITHIC diff --git a/src/libcharon/plugins/medcli/Makefile.am b/src/libcharon/plugins/medcli/Makefile.am deleted file mode 100644 index 0408c8963..000000000 --- a/src/libcharon/plugins/medcli/Makefile.am +++ /dev/null @@ -1,20 +0,0 @@ -AM_CPPFLAGS = \ - -I$(top_srcdir)/src/libstrongswan \ - -I$(top_srcdir)/src/libcharon - -AM_CFLAGS = \ - $(PLUGIN_CFLAGS) - -if MONOLITHIC -noinst_LTLIBRARIES = libstrongswan-medcli.la -else -plugin_LTLIBRARIES = libstrongswan-medcli.la -endif - -libstrongswan_medcli_la_SOURCES = \ - medcli_plugin.h medcli_plugin.c \ - medcli_creds.h medcli_creds.c \ - medcli_config.h medcli_config.c \ - medcli_listener.h medcli_listener.c - -libstrongswan_medcli_la_LDFLAGS = -module -avoid-version diff --git a/src/libcharon/plugins/medcli/medcli_config.c b/src/libcharon/plugins/medcli/medcli_config.c deleted file mode 100644 index 59a9358a1..000000000 --- a/src/libcharon/plugins/medcli/medcli_config.c +++ /dev/null @@ -1,434 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#define _GNU_SOURCE -#include - -#include "medcli_config.h" - -#include -#include - -typedef struct private_medcli_config_t private_medcli_config_t; - -/** - * Name of the mediation connection - */ -#define MEDIATION_CONN_NAME "medcli-mediation" - -/** - * Private data of an medcli_config_t object - */ -struct private_medcli_config_t { - - /** - * Public part - */ - medcli_config_t public; - - /** - * database connection - */ - database_t *db; - - /** - * rekey time - */ - int rekey; - - /** - * dpd delay - */ - int dpd; - - /** - * default ike config - */ - ike_cfg_t *ike; -}; - -/** - * create a traffic selector from a CIDR notation string - */ -static traffic_selector_t *ts_from_string(char *str) -{ - if (str) - { - traffic_selector_t *ts; - - ts = traffic_selector_create_from_cidr(str, 0, 0, 65535); - if (ts) - { - return ts; - } - } - return traffic_selector_create_dynamic(0, 0, 65535); -} - -/** - * Build a mediation config - */ -static peer_cfg_t *build_mediation_config(private_medcli_config_t *this, - peer_cfg_create_t *defaults) -{ - enumerator_t *e; - auth_cfg_t *auth; - ike_cfg_t *ike_cfg; - peer_cfg_t *med_cfg; - ike_cfg_create_t ike = { - .version = IKEV2, - .local = "0.0.0.0", - .local_port = charon->socket->get_port(charon->socket, FALSE), - .remote_port = IKEV2_UDP_PORT, - .no_certreq = TRUE, - }; - peer_cfg_create_t peer = *defaults; - chunk_t me, other; - - /* query mediation server config: - * - build ike_cfg/peer_cfg for mediation connection on-the-fly - */ - e = this->db->query(this->db, - "SELECT Address, ClientConfig.KeyId, MediationServerConfig.KeyId " - "FROM MediationServerConfig JOIN ClientConfig", - DB_TEXT, DB_BLOB, DB_BLOB); - if (!e || !e->enumerate(e, &ike.remote, &me, &other)) - { - DESTROY_IF(e); - return NULL; - } - ike_cfg = ike_cfg_create(&ike); - ike_cfg->add_proposal(ike_cfg, proposal_create_default(PROTO_IKE)); - ike_cfg->add_proposal(ike_cfg, proposal_create_default_aead(PROTO_IKE)); - - peer.mediation = TRUE; - med_cfg = peer_cfg_create(MEDIATION_CONN_NAME, ike_cfg, &peer); - e->destroy(e); - - auth = auth_cfg_create(); - auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY); - auth->add(auth, AUTH_RULE_IDENTITY, - identification_create_from_encoding(ID_KEY_ID, me)); - med_cfg->add_auth_cfg(med_cfg, auth, TRUE); - auth = auth_cfg_create(); - auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY); - auth->add(auth, AUTH_RULE_IDENTITY, - identification_create_from_encoding(ID_KEY_ID, other)); - med_cfg->add_auth_cfg(med_cfg, auth, FALSE); - return med_cfg; -} - -METHOD(backend_t, get_peer_cfg_by_name, peer_cfg_t*, - private_medcli_config_t *this, char *name) -{ - enumerator_t *e; - auth_cfg_t *auth; - peer_cfg_t *peer_cfg; - child_cfg_t *child_cfg; - chunk_t me, other; - char *local_net, *remote_net; - peer_cfg_create_t peer = { - .cert_policy = CERT_NEVER_SEND, - .unique = UNIQUE_REPLACE, - .keyingtries = 1, - .rekey_time = this->rekey * 60, - .jitter_time = this->rekey * 5, - .over_time = this->rekey * 3, - .dpd = this->dpd, - }; - child_cfg_create_t child = { - .lifetime = { - .time = { - .life = this->rekey * 60 + this->rekey, - .rekey = this->rekey, - .jitter = this->rekey - }, - }, - .mode = MODE_TUNNEL, - }; - - if (streq(name, "medcli-mediation")) - { - return build_mediation_config(this, &peer); - } - - /* query mediated config: - * - use any-any ike_cfg - * - build peer_cfg on-the-fly using med_cfg - * - add a child_cfg - */ - e = this->db->query(this->db, - "SELECT ClientConfig.KeyId, Connection.KeyId, " - "Connection.LocalSubnet, Connection.RemoteSubnet " - "FROM ClientConfig JOIN Connection " - "WHERE Active AND Alias = ?", DB_TEXT, name, - DB_BLOB, DB_BLOB, DB_TEXT, DB_TEXT); - if (!e || !e->enumerate(e, &me, &other, &local_net, &remote_net)) - { - DESTROY_IF(e); - return NULL; - } - peer.mediated_by = MEDIATION_CONN_NAME; - peer.peer_id = identification_create_from_encoding(ID_KEY_ID, other); - peer_cfg = peer_cfg_create(name, this->ike->get_ref(this->ike), &peer); - - auth = auth_cfg_create(); - auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY); - auth->add(auth, AUTH_RULE_IDENTITY, - identification_create_from_encoding(ID_KEY_ID, me)); - peer_cfg->add_auth_cfg(peer_cfg, auth, TRUE); - auth = auth_cfg_create(); - auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY); - auth->add(auth, AUTH_RULE_IDENTITY, - identification_create_from_encoding(ID_KEY_ID, other)); - peer_cfg->add_auth_cfg(peer_cfg, auth, FALSE); - - child_cfg = child_cfg_create(name, &child); - child_cfg->add_proposal(child_cfg, proposal_create_default_aead(PROTO_ESP)); - child_cfg->add_proposal(child_cfg, proposal_create_default(PROTO_ESP)); - child_cfg->add_traffic_selector(child_cfg, TRUE, ts_from_string(local_net)); - child_cfg->add_traffic_selector(child_cfg, FALSE, ts_from_string(remote_net)); - peer_cfg->add_child_cfg(peer_cfg, child_cfg); - e->destroy(e); - return peer_cfg; -} - -METHOD(backend_t, create_ike_cfg_enumerator, enumerator_t*, - private_medcli_config_t *this, host_t *me, host_t *other) -{ - return enumerator_create_single(this->ike, NULL); -} - -typedef struct { - /** implements enumerator */ - enumerator_t public; - /** inner SQL enumerator */ - enumerator_t *inner; - /** currently enumerated peer config */ - peer_cfg_t *current; - /** ike cfg to use in peer cfg */ - ike_cfg_t *ike; - /** rekey time */ - int rekey; - /** dpd time */ - int dpd; -} peer_enumerator_t; - -METHOD(enumerator_t, peer_enumerator_enumerate, bool, - peer_enumerator_t *this, va_list args) -{ - char *name, *local_net, *remote_net; - chunk_t me, other; - peer_cfg_t **cfg; - child_cfg_t *child_cfg; - auth_cfg_t *auth; - peer_cfg_create_t peer = { - .cert_policy = CERT_NEVER_SEND, - .unique = UNIQUE_REPLACE, - .keyingtries = 1, - .rekey_time = this->rekey * 60, - .jitter_time = this->rekey * 5, - .over_time = this->rekey * 3, - .dpd = this->dpd, - }; - child_cfg_create_t child = { - .lifetime = { - .time = { - .life = this->rekey * 60 + this->rekey, - .rekey = this->rekey, - .jitter = this->rekey - }, - }, - .mode = MODE_TUNNEL, - }; - - VA_ARGS_VGET(args, cfg); - - DESTROY_IF(this->current); - if (!this->inner->enumerate(this->inner, &name, &me, &other, - &local_net, &remote_net)) - { - this->current = NULL; - return FALSE; - } - this->current = peer_cfg_create(name, this->ike->get_ref(this->ike), &peer); - - auth = auth_cfg_create(); - auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY); - auth->add(auth, AUTH_RULE_IDENTITY, - identification_create_from_encoding(ID_KEY_ID, me)); - this->current->add_auth_cfg(this->current, auth, TRUE); - auth = auth_cfg_create(); - auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY); - auth->add(auth, AUTH_RULE_IDENTITY, - identification_create_from_encoding(ID_KEY_ID, other)); - this->current->add_auth_cfg(this->current, auth, FALSE); - - child_cfg = child_cfg_create(name, &child); - child_cfg->add_proposal(child_cfg, proposal_create_default_aead(PROTO_ESP)); - child_cfg->add_proposal(child_cfg, proposal_create_default(PROTO_ESP)); - child_cfg->add_traffic_selector(child_cfg, TRUE, ts_from_string(local_net)); - child_cfg->add_traffic_selector(child_cfg, FALSE, ts_from_string(remote_net)); - this->current->add_child_cfg(this->current, child_cfg); - *cfg = this->current; - return TRUE; -} - -METHOD(enumerator_t, peer_enumerator_destroy, void, - peer_enumerator_t *this) -{ - DESTROY_IF(this->current); - this->inner->destroy(this->inner); - free(this); -} - -METHOD(backend_t, create_peer_cfg_enumerator, enumerator_t*, - private_medcli_config_t *this, identification_t *me, - identification_t *other) -{ - peer_enumerator_t *e; - - INIT(e, - .public = { - .enumerate = enumerator_enumerate_default, - .venumerate = _peer_enumerator_enumerate, - .destroy = _peer_enumerator_destroy, - }, - .ike = this->ike, - .rekey = this->rekey, - .dpd = this->dpd, - ); - - /* filter on IDs: NULL or ANY or matching KEY_ID */ - e->inner = this->db->query(this->db, - "SELECT Alias, ClientConfig.KeyId, Connection.KeyId, " - "Connection.LocalSubnet, Connection.RemoteSubnet " - "FROM ClientConfig JOIN Connection " - "WHERE Active AND " - "(? OR ClientConfig.KeyId = ?) AND (? OR Connection.KeyId = ?)", - DB_INT, me == NULL || me->get_type(me) == ID_ANY, - DB_BLOB, me && me->get_type(me) == ID_KEY_ID ? - me->get_encoding(me) : chunk_empty, - DB_INT, other == NULL || other->get_type(other) == ID_ANY, - DB_BLOB, other && other->get_type(other) == ID_KEY_ID ? - other->get_encoding(other) : chunk_empty, - DB_TEXT, DB_BLOB, DB_BLOB, DB_TEXT, DB_TEXT); - if (!e->inner) - { - free(e); - return NULL; - } - return &e->public; -} - -/** - * initiate a peer config - */ -static job_requeue_t initiate_config(peer_cfg_t *peer_cfg) -{ - enumerator_t *enumerator; - child_cfg_t *child_cfg = NULL; - - enumerator = peer_cfg->create_child_cfg_enumerator(peer_cfg); - enumerator->enumerate(enumerator, &child_cfg); - if (child_cfg) - { - child_cfg->get_ref(child_cfg); - peer_cfg->get_ref(peer_cfg); - enumerator->destroy(enumerator); - charon->controller->initiate(charon->controller, peer_cfg, child_cfg, - NULL, NULL, 0, 0, FALSE); - } - else - { - enumerator->destroy(enumerator); - } - return JOB_REQUEUE_NONE; -} - -/** - * schedule initiation of all "active" connections - */ -static void schedule_autoinit(private_medcli_config_t *this) -{ - enumerator_t *e; - char *name; - - e = this->db->query(this->db, "SELECT Alias FROM Connection WHERE Active", - DB_TEXT); - if (e) - { - while (e->enumerate(e, &name)) - { - peer_cfg_t *peer_cfg; - - peer_cfg = get_peer_cfg_by_name(this, name); - if (peer_cfg) - { - /* schedule asynchronous initiation job */ - lib->processor->queue_job(lib->processor, - (job_t*)callback_job_create( - (callback_job_cb_t)initiate_config, - peer_cfg, (void*)peer_cfg->destroy, NULL)); - } - } - e->destroy(e); - } -} - -METHOD(medcli_config_t, destroy, void, - private_medcli_config_t *this) -{ - this->ike->destroy(this->ike); - free(this); -} - -/** - * Described in header. - */ -medcli_config_t *medcli_config_create(database_t *db) -{ - private_medcli_config_t *this; - ike_cfg_create_t ike = { - .version = IKEV2, - .local = "0.0.0.0", - .local_port = charon->socket->get_port(charon->socket, FALSE), - .remote = "0.0.0.0", - .remote_port = IKEV2_UDP_PORT, - .no_certreq = TRUE, - }; - - INIT(this, - .public = { - .backend = { - .create_peer_cfg_enumerator = _create_peer_cfg_enumerator, - .create_ike_cfg_enumerator = _create_ike_cfg_enumerator, - .get_peer_cfg_by_name = _get_peer_cfg_by_name, - }, - .destroy = _destroy, - }, - .db = db, - .rekey = lib->settings->get_time(lib->settings, "medcli.rekey", 1200), - .dpd = lib->settings->get_time(lib->settings, "medcli.dpd", 300), - .ike = ike_cfg_create(&ike), - ); - this->ike->add_proposal(this->ike, proposal_create_default(PROTO_IKE)); - this->ike->add_proposal(this->ike, proposal_create_default_aead(PROTO_IKE)); - - schedule_autoinit(this); - - return &this->public; -} diff --git a/src/libcharon/plugins/medcli/medcli_config.h b/src/libcharon/plugins/medcli/medcli_config.h deleted file mode 100644 index a22b2cf92..000000000 --- a/src/libcharon/plugins/medcli/medcli_config.h +++ /dev/null @@ -1,54 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup medcli_config_i medcli_config - * @{ @ingroup medcli - */ - -#ifndef MEDCLI_CONFIG_H_ -#define MEDCLI_CONFIG_H_ - -#include -#include - -typedef struct medcli_config_t medcli_config_t; - -/** - * Mediation client configuration backend. - */ -struct medcli_config_t { - - /** - * Implements backend_t interface - */ - backend_t backend; - - /** - * Destroy the backend. - */ - void (*destroy)(medcli_config_t *this); -}; - -/** - * Create a medcli_config backend instance. - * - * @param db underlying database - * @return backend instance - */ -medcli_config_t *medcli_config_create(database_t *db); - -#endif /** MEDCLI_CONFIG_H_ @}*/ diff --git a/src/libcharon/plugins/medcli/medcli_creds.c b/src/libcharon/plugins/medcli/medcli_creds.c deleted file mode 100644 index dc61cc5a7..000000000 --- a/src/libcharon/plugins/medcli/medcli_creds.c +++ /dev/null @@ -1,242 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "medcli_creds.h" - -#include -#include -#include - -typedef struct private_medcli_creds_t private_medcli_creds_t; - -/** - * Private data of an medcli_creds_t object - */ -struct private_medcli_creds_t { - - /** - * Public part - */ - medcli_creds_t public; - - /** - * underlying database handle - */ - database_t *db; -}; - -/** - * enumerator over private keys - */ -typedef struct { - /** implements enumerator */ - enumerator_t public; - /** inner SQL enumerator */ - enumerator_t *inner; - /** currently enumerated private key */ - private_key_t *current; -} private_enumerator_t; - -METHOD(enumerator_t, private_enumerator_enumerate, bool, - private_enumerator_t *this, va_list args) -{ - private_key_t **key; - chunk_t chunk; - - VA_ARGS_VGET(args, key); - - DESTROY_IF(this->current); - while (this->inner->enumerate(this->inner, &chunk)) - { - this->current = lib->creds->create(lib->creds, CRED_PRIVATE_KEY, KEY_RSA, - BUILD_BLOB_ASN1_DER, chunk, - BUILD_END); - if (this->current) - { - *key = this->current; - return TRUE; - } - } - this->current = NULL; - return FALSE; -} - -METHOD(enumerator_t, private_enumerator_destroy, void, - private_enumerator_t *this) -{ - DESTROY_IF(this->current); - this->inner->destroy(this->inner); - free(this); -} - -METHOD(credential_set_t, create_private_enumerator, enumerator_t*, - private_medcli_creds_t *this, key_type_t type, identification_t *id) -{ - private_enumerator_t *e; - - if ((type != KEY_RSA && type != KEY_ANY) || - id == NULL || id->get_type(id) != ID_KEY_ID) - { - DBG1(DBG_CFG, "%N - %Y", key_type_names, type, id); - return NULL; - } - - INIT(e, - .public = { - .enumerate = enumerator_enumerate_default, - .venumerate = _private_enumerator_enumerate, - .destroy = _private_enumerator_destroy, - }, - ); - e->inner = this->db->query(this->db, - "SELECT PrivateKey FROM ClientConfig WHERE KeyId = ?", - DB_BLOB, id->get_encoding(id), - DB_BLOB); - if (!e->inner) - { - free(e); - return NULL; - } - return &e->public; -} - -/** - * enumerator over certificates - */ -typedef struct { - /** implements enumerator */ - enumerator_t public; - /** inner SQL enumerator */ - enumerator_t *inner; - /** currently enumerated cert */ - certificate_t *current; - /** type of requested key */ - key_type_t type; -} cert_enumerator_t; - -METHOD(enumerator_t, cert_enumerator_enumerate, bool, - cert_enumerator_t *this, va_list args) -{ - certificate_t **cert; - public_key_t *public; - chunk_t chunk; - - VA_ARGS_VGET(args, cert); - - DESTROY_IF(this->current); - while (this->inner->enumerate(this->inner, &chunk)) - { - public = lib->creds->create(lib->creds, CRED_PUBLIC_KEY, KEY_ANY, - BUILD_BLOB_ASN1_DER, chunk, - BUILD_END); - if (public) - { - if (this->type == KEY_ANY || this->type == public->get_type(public)) - { - this->current = lib->creds->create(lib->creds, - CRED_CERTIFICATE, CERT_TRUSTED_PUBKEY, - BUILD_PUBLIC_KEY, public, BUILD_END); - public->destroy(public); - if (this->current) - { - *cert = this->current; - return TRUE; - } - } - else - { - public->destroy(public); - } - } - } - this->current = NULL; - return FALSE; -} - -METHOD(enumerator_t, cert_enumerator_destroy, void, - cert_enumerator_t *this) -{ - DESTROY_IF(this->current); - this->inner->destroy(this->inner); - free(this); -} - -METHOD(credential_set_t, create_cert_enumerator, enumerator_t*, - private_medcli_creds_t *this, certificate_type_t cert, key_type_t key, - identification_t *id, bool trusted) -{ - cert_enumerator_t *e; - - if ((cert != CERT_TRUSTED_PUBKEY && cert != CERT_ANY) || - id == NULL || id->get_type(id) != ID_KEY_ID) - { - return NULL; - } - - INIT(e, - .public = { - .enumerate = enumerator_enumerate_default, - .venumerate = _cert_enumerator_enumerate, - .destroy = _cert_enumerator_destroy, - }, - .type = key, - ); - e->inner = this->db->query(this->db, - "SELECT PublicKey FROM ClientConfig WHERE KeyId = ? UNION " - "SELECT PublicKey FROM MediationServerConfig WHERE KeyId = ? UNION " - "SELECT PublicKey FROM Connection WHERE KeyId = ?", - DB_BLOB, id->get_encoding(id), - DB_BLOB, id->get_encoding(id), - DB_BLOB, id->get_encoding(id), - DB_BLOB); - if (!e->inner) - { - free(e); - return NULL; - } - return &e->public; -} - -METHOD(medcli_creds_t, destroy, void, - private_medcli_creds_t *this) -{ - free(this); -} - -/** - * Described in header. - */ -medcli_creds_t *medcli_creds_create(database_t *db) -{ - private_medcli_creds_t *this; - - INIT(this, - .public = { - .set = { - .create_private_enumerator = _create_private_enumerator, - .create_cert_enumerator = _create_cert_enumerator, - .create_shared_enumerator = (void*)return_null, - .create_cdp_enumerator = (void*)return_null, - .cache_cert = (void*)nop, - }, - .destroy = _destroy, - }, - .db = db, - ); - - return &this->public; -} - diff --git a/src/libcharon/plugins/medcli/medcli_creds.h b/src/libcharon/plugins/medcli/medcli_creds.h deleted file mode 100644 index dc39a9e13..000000000 --- a/src/libcharon/plugins/medcli/medcli_creds.h +++ /dev/null @@ -1,54 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup medcli_creds_i medcli_creds - * @{ @ingroup medcli - */ - -#ifndef MEDCLI_CREDS_H_ -#define MEDCLI_CREDS_H_ - -#include -#include - -typedef struct medcli_creds_t medcli_creds_t; - -/** - * Mediation client credentials database. - */ -struct medcli_creds_t { - - /** - * Implements credential_set_t interface - */ - credential_set_t set; - - /** - * Destroy the credentials database. - */ - void (*destroy)(medcli_creds_t *this); -}; - -/** - * Create the medcli credential set. - * - * @param database underlying database - * @return credential set implementation on that database - */ -medcli_creds_t *medcli_creds_create(database_t *database); - -#endif /** MEDCLI_CREDS_H_ @}*/ diff --git a/src/libcharon/plugins/medcli/medcli_listener.c b/src/libcharon/plugins/medcli/medcli_listener.c deleted file mode 100644 index 27debb096..000000000 --- a/src/libcharon/plugins/medcli/medcli_listener.c +++ /dev/null @@ -1,132 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "medcli_listener.h" - -#include -#include - -typedef struct private_medcli_listener_t private_medcli_listener_t; -typedef enum mediated_state_t mediated_state_t; - -/** - * state of a mediated connection - */ -enum mediated_state_t { - STATE_DOWN = 1, - STATE_CONNECTING = 2, - STATE_UP = 3, -}; - -/** - * Private data of an medcli_listener_t object - */ -struct private_medcli_listener_t { - - /** - * Public part - */ - medcli_listener_t public; - - /** - * underlying database handle - */ - database_t *db; -}; - -/** - * Update connection status in the database - */ -static void set_state(private_medcli_listener_t *this, char *alias, - mediated_state_t state) -{ - this->db->execute(this->db, NULL, - "UPDATE Connection SET Status = ? WHERE Alias = ?", - DB_UINT, state, DB_TEXT, alias); -} - -METHOD(listener_t, ike_state_change, bool, - private_medcli_listener_t *this, ike_sa_t *ike_sa, ike_sa_state_t state) -{ - if (ike_sa) - { - switch (state) - { - case IKE_CONNECTING: - set_state(this, ike_sa->get_name(ike_sa), STATE_CONNECTING); - break; - case IKE_DESTROYING: - set_state(this, ike_sa->get_name(ike_sa), STATE_DOWN); - default: - break; - } - } - return TRUE; -} - -METHOD(listener_t, child_state_change, bool, - private_medcli_listener_t *this, ike_sa_t *ike_sa, child_sa_t *child_sa, - child_sa_state_t state) -{ - if (ike_sa && child_sa) - { - switch (state) - { - case CHILD_INSTALLED: - set_state(this, child_sa->get_name(child_sa), STATE_UP); - break; - case CHILD_DESTROYING: - set_state(this, child_sa->get_name(child_sa), STATE_DOWN); - break; - default: - break; - } - } - return TRUE; -} - -METHOD(medcli_listener_t, destroy, void, - private_medcli_listener_t *this) -{ - this->db->execute(this->db, NULL, "UPDATE Connection SET Status = ?", - DB_UINT, STATE_DOWN); - free(this); -} - -/** - * Described in header. - */ -medcli_listener_t *medcli_listener_create(database_t *db) -{ - private_medcli_listener_t *this; - - INIT(this, - .public = { - .listener = { - .ike_state_change = _ike_state_change, - .child_state_change = _child_state_change, - }, - .destroy = _destroy, - }, - .db = db, - ); - - db->execute(db, NULL, "UPDATE Connection SET Status = ?", - DB_UINT, STATE_DOWN); - - return &this->public; -} - diff --git a/src/libcharon/plugins/medcli/medcli_listener.h b/src/libcharon/plugins/medcli/medcli_listener.h deleted file mode 100644 index 8fb611266..000000000 --- a/src/libcharon/plugins/medcli/medcli_listener.h +++ /dev/null @@ -1,54 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup medcli_listener_i medcli_listener - * @{ @ingroup medcli - */ - -#ifndef MEDCLI_LISTENER_H_ -#define MEDCLI_LISTENER_H_ - -#include -#include - -typedef struct medcli_listener_t medcli_listener_t; - -/** - * Mediation client listener, writes connection status to database - */ -struct medcli_listener_t { - - /** - * Implements bus_listener_t interface - */ - listener_t listener; - - /** - * Destroy the credentials database. - */ - void (*destroy)(medcli_listener_t *this); -}; - -/** - * Create the medcli credential set. - * - * @param database underlying database - * @return listener - */ -medcli_listener_t *medcli_listener_create(database_t *database); - -#endif /** MEDCLI_LISTENER_H_ @}*/ diff --git a/src/libcharon/plugins/medcli/medcli_plugin.c b/src/libcharon/plugins/medcli/medcli_plugin.c deleted file mode 100644 index b5cbe7da3..000000000 --- a/src/libcharon/plugins/medcli/medcli_plugin.c +++ /dev/null @@ -1,147 +0,0 @@ -/* - * Copyright (C) 2013 Tobias Brunner - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "medcli_plugin.h" - -#include "medcli_creds.h" -#include "medcli_config.h" -#include "medcli_listener.h" - -#include - -typedef struct private_medcli_plugin_t private_medcli_plugin_t; - -/** - * private data of medcli plugin - */ -struct private_medcli_plugin_t { - - /** - * implements plugin interface - */ - medcli_plugin_t public; - - /** - * database connection instance - */ - database_t *db; - - /** - * medcli credential set instance - */ - medcli_creds_t *creds; - - /** - * medcli config database - */ - medcli_config_t *config; - - /** - * Listener to update database connection state - */ - medcli_listener_t *listener; -}; - -METHOD(plugin_t, get_name, char*, - private_medcli_plugin_t *this) -{ - return "medcli"; -} - -/** - * Connect to database - */ -static bool open_database(private_medcli_plugin_t *this, - plugin_feature_t *feature, bool reg, void *cb_data) -{ - if (reg) - { - char *uri; - - uri = lib->settings->get_str(lib->settings, - "medcli.database", NULL); - if (!uri) - { - DBG1(DBG_CFG, "mediation client database URI not defined, skipped"); - return FALSE; - } - - this->db = lib->db->create(lib->db, uri); - if (this->db == NULL) - { - DBG1(DBG_CFG, "opening mediation client database failed"); - return FALSE; - } - - this->creds = medcli_creds_create(this->db); - this->config = medcli_config_create(this->db); - this->listener = medcli_listener_create(this->db); - - lib->credmgr->add_set(lib->credmgr, &this->creds->set); - charon->backends->add_backend(charon->backends, &this->config->backend); - charon->bus->add_listener(charon->bus, &this->listener->listener); - } - else - { - charon->bus->remove_listener(charon->bus, &this->listener->listener); - charon->backends->remove_backend(charon->backends, &this->config->backend); - lib->credmgr->remove_set(lib->credmgr, &this->creds->set); - this->listener->destroy(this->listener); - this->config->destroy(this->config); - this->creds->destroy(this->creds); - this->db->destroy(this->db); - } - return TRUE; -} - -METHOD(plugin_t, get_features, int, - private_medcli_plugin_t *this, plugin_feature_t *features[]) -{ - static plugin_feature_t f[] = { - PLUGIN_CALLBACK((plugin_feature_callback_t)open_database, NULL), - PLUGIN_PROVIDE(CUSTOM, "medcli"), - PLUGIN_DEPENDS(DATABASE, DB_ANY), - }; - *features = f; - return countof(f); -} - -METHOD(plugin_t, destroy, void, - private_medcli_plugin_t *this) -{ - free(this); -} - -/* - * see header file - */ -PLUGIN_DEFINE(medcli) -{ - private_medcli_plugin_t *this; - - INIT(this, - .public = { - .plugin = { - .get_name = _get_name, - .get_features = _get_features, - .destroy = _destroy, - }, - }, - ); - - return &this->public.plugin; -} diff --git a/src/libcharon/plugins/medcli/medcli_plugin.h b/src/libcharon/plugins/medcli/medcli_plugin.h deleted file mode 100644 index a3dabc503..000000000 --- a/src/libcharon/plugins/medcli/medcli_plugin.h +++ /dev/null @@ -1,43 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup medcli medcli - * @ingroup cplugins - * - * @defgroup medcli_plugin medcli_plugin - * @{ @ingroup medcli - */ - -#ifndef MEDCLI_PLUGIN_H_ -#define MEDCLI_PLUGIN_H_ - -#include - -typedef struct medcli_plugin_t medcli_plugin_t; - -/** - * Mediation client database plugin. - */ -struct medcli_plugin_t { - - /** - * implements plugin interface - */ - plugin_t plugin; -}; - -#endif /** MEDCLI_PLUGIN_H_ @}*/ diff --git a/src/libcharon/plugins/medcli/mysql.sql b/src/libcharon/plugins/medcli/mysql.sql deleted file mode 100644 index 0107ad35a..000000000 --- a/src/libcharon/plugins/medcli/mysql.sql +++ /dev/null @@ -1,32 +0,0 @@ - -CREATE TABLE `ClientConfig` ( - `IdClientConfig` int(11) NOT NULL, - `KeyId` varbinary(20) NOT NULL, - `PublicKey` blob NOT NULL, - `PrivateKey` blob NOT NULL, - PRIMARY KEY (`IdClientConfig`) -); - - -CREATE TABLE `MediationServerConfig` ( - `IdMediationServerConfig` int(11) NOT NULL, - `Address` varchar(200) NOT NULL, - `KeyId` varbinary(20) NOT NULL, - `PublicKey` blob NOT NULL, - PRIMARY KEY (`IdMediationServerConfig`) -); - - -CREATE TABLE `Connection` ( - `IdConnection` int(11) NOT NULL auto_increment, - `Active` tinyint(1) NOT NULL, - `Alias` varchar(50) NOT NULL, - `KeyId` varbinary(20) NOT NULL, - `PublicKey` blob NOT NULL, - `LocalSubnet` varchar(20), - `RemoteSubnet` varchar(20), - `Status` int(11) NOT NULL, - PRIMARY KEY (`IdConnection`), - UNIQUE (`Alias`), - UNIQUE (`KeyId`) -); diff --git a/src/libcharon/plugins/medsrv/Makefile.am b/src/libcharon/plugins/medsrv/Makefile.am deleted file mode 100644 index 1d1cb4465..000000000 --- a/src/libcharon/plugins/medsrv/Makefile.am +++ /dev/null @@ -1,19 +0,0 @@ -AM_CPPFLAGS = \ - -I$(top_srcdir)/src/libstrongswan \ - -I$(top_srcdir)/src/libcharon - -AM_CFLAGS = \ - $(PLUGIN_CFLAGS) - -if MONOLITHIC -noinst_LTLIBRARIES = libstrongswan-medsrv.la -else -plugin_LTLIBRARIES = libstrongswan-medsrv.la -endif - -libstrongswan_medsrv_la_SOURCES = \ - medsrv_plugin.h medsrv_plugin.c \ - medsrv_creds.h medsrv_creds.c \ - medsrv_config.h medsrv_config.c - -libstrongswan_medsrv_la_LDFLAGS = -module -avoid-version diff --git a/src/libcharon/plugins/medsrv/medsrv_config.c b/src/libcharon/plugins/medsrv/medsrv_config.c deleted file mode 100644 index 4dd69f2d4..000000000 --- a/src/libcharon/plugins/medsrv/medsrv_config.c +++ /dev/null @@ -1,161 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include - -#include "medsrv_config.h" - -#include - -typedef struct private_medsrv_config_t private_medsrv_config_t; - -/** - * Private data of an medsrv_config_t object - */ -struct private_medsrv_config_t { - - /** - * Public part - */ - medsrv_config_t public; - - /** - * database connection - */ - database_t *db; - - /** - * rekey time - */ - int rekey; - - /** - * dpd delay - */ - int dpd; - - /** - * default ike config - */ - ike_cfg_t *ike; -}; - -METHOD(backend_t, get_peer_cfg_by_name, peer_cfg_t*, - private_medsrv_config_t *this, char *name) -{ - return NULL; -} - -METHOD(backend_t, create_ike_cfg_enumerator, enumerator_t*, - private_medsrv_config_t *this, host_t *me, host_t *other) -{ - return enumerator_create_single(this->ike, NULL); -} - -METHOD(backend_t, create_peer_cfg_enumerator, enumerator_t*, - private_medsrv_config_t *this, identification_t *me, - identification_t *other) -{ - enumerator_t *e; - - if (!me || !other || other->get_type(other) != ID_KEY_ID) - { - return NULL; - } - e = this->db->query(this->db, - "SELECT CONCAT(peer.alias, CONCAT('@', user.login)) FROM " - "peer JOIN user ON peer.user = user.id " - "WHERE peer.keyid = ?", DB_BLOB, other->get_encoding(other), - DB_TEXT); - if (e) - { - peer_cfg_t *peer_cfg; - auth_cfg_t *auth; - char *name; - - if (e->enumerate(e, &name)) - { - peer_cfg_create_t peer = { - .cert_policy = CERT_NEVER_SEND, - .unique = UNIQUE_REPLACE, - .keyingtries = 1, - .rekey_time = this->rekey * 60, - .jitter_time = this->rekey * 5, - .over_time = this->rekey * 3, - .dpd = this->dpd, - .mediation = TRUE, - }; - peer_cfg = peer_cfg_create(name, this->ike->get_ref(this->ike), - &peer); - e->destroy(e); - - auth = auth_cfg_create(); - auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY); - auth->add(auth, AUTH_RULE_IDENTITY, me->clone(me)); - peer_cfg->add_auth_cfg(peer_cfg, auth, TRUE); - auth = auth_cfg_create(); - auth->add(auth, AUTH_RULE_AUTH_CLASS, AUTH_CLASS_PUBKEY); - auth->add(auth, AUTH_RULE_IDENTITY, other->clone(other)); - peer_cfg->add_auth_cfg(peer_cfg, auth, FALSE); - - return enumerator_create_single(peer_cfg, (void*)peer_cfg->destroy); - } - e->destroy(e); - } - return NULL; -} - -METHOD(medsrv_config_t, destroy, void, - private_medsrv_config_t *this) -{ - this->ike->destroy(this->ike); - free(this); -} - -/** - * Described in header. - */ -medsrv_config_t *medsrv_config_create(database_t *db) -{ - private_medsrv_config_t *this; - ike_cfg_create_t ike = { - .version = IKEV2, - .local = "0.0.0.0", - .local_port = charon->socket->get_port(charon->socket, FALSE), - .remote = "0.0.0.0", - .remote_port = IKEV2_UDP_PORT, - .no_certreq = TRUE, - }; - - INIT(this, - .public = { - .backend = { - .create_peer_cfg_enumerator = _create_peer_cfg_enumerator, - .create_ike_cfg_enumerator = _create_ike_cfg_enumerator, - .get_peer_cfg_by_name = _get_peer_cfg_by_name, - }, - .destroy = _destroy, - }, - .db = db, - .rekey = lib->settings->get_time(lib->settings, "medsrv.rekey", 1200), - .dpd = lib->settings->get_time(lib->settings, "medsrv.dpd", 300), - .ike = ike_cfg_create(&ike), - ); - this->ike->add_proposal(this->ike, proposal_create_default(PROTO_IKE)); - this->ike->add_proposal(this->ike, proposal_create_default_aead(PROTO_IKE)); - - return &this->public; -} diff --git a/src/libcharon/plugins/medsrv/medsrv_config.h b/src/libcharon/plugins/medsrv/medsrv_config.h deleted file mode 100644 index 37545e65f..000000000 --- a/src/libcharon/plugins/medsrv/medsrv_config.h +++ /dev/null @@ -1,54 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup medsrv_config_i medsrv_config - * @{ @ingroup medsrv_p - */ - -#ifndef MEDSRV_CONFIG_H_ -#define MEDSRV_CONFIG_H_ - -#include -#include - -typedef struct medsrv_config_t medsrv_config_t; - -/** - * Mediation server configuration backend. - */ -struct medsrv_config_t { - - /** - * Implements backend_t interface - */ - backend_t backend; - - /** - * Destroy the backend. - */ - void (*destroy)(medsrv_config_t *this); -}; - -/** - * Create a medsrv_config backend instance. - * - * @param db underlying database - * @return backend instance - */ -medsrv_config_t *medsrv_config_create(database_t *db); - -#endif /** MEDSRV_CONFIG_H_ @}*/ diff --git a/src/libcharon/plugins/medsrv/medsrv_creds.c b/src/libcharon/plugins/medsrv/medsrv_creds.c deleted file mode 100644 index c415aaedf..000000000 --- a/src/libcharon/plugins/medsrv/medsrv_creds.c +++ /dev/null @@ -1,163 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "medsrv_creds.h" - -#include -#include -#include - -typedef struct private_medsrv_creds_t private_medsrv_creds_t; - -/** - * Private data of an medsrv_creds_t object - */ -struct private_medsrv_creds_t { - - /** - * Public part - */ - medsrv_creds_t public; - - /** - * underlying database handle - */ - database_t *db; -}; - -/** - * enumerator over certificates - */ -typedef struct { - /** implements enumerator */ - enumerator_t public; - /** inner SQL enumerator */ - enumerator_t *inner; - /** currently enumerated cert */ - certificate_t *current; - /** type of requested key */ - key_type_t type; -} cert_enumerator_t; - -METHOD(enumerator_t, cert_enumerator_enumerate, bool, - cert_enumerator_t *this, va_list args) -{ - certificate_t *trusted, **cert; - public_key_t *public; - chunk_t chunk; - - VA_ARGS_VGET(args, cert); - - DESTROY_IF(this->current); - while (this->inner->enumerate(this->inner, &chunk)) - { - public = lib->creds->create(lib->creds, CRED_PUBLIC_KEY, KEY_ANY, - BUILD_BLOB_ASN1_DER, chunk, - BUILD_END); - if (public) - { - if (this->type == KEY_ANY || this->type == public->get_type(public)) - { - trusted = lib->creds->create(lib->creds, - CRED_CERTIFICATE, CERT_TRUSTED_PUBKEY, - BUILD_PUBLIC_KEY, public, BUILD_END); - public->destroy(public); - if (trusted) - { - *cert = this->current = trusted; - return TRUE; - } - } - else - { - public->destroy(public); - } - } - } - this->current = NULL; - return FALSE; -} - -METHOD(enumerator_t, cert_enumerator_destroy, void, - cert_enumerator_t *this) -{ - DESTROY_IF(this->current); - this->inner->destroy(this->inner); - free(this); -} - -METHOD(credential_set_t, create_cert_enumerator, enumerator_t*, - private_medsrv_creds_t *this, certificate_type_t cert, key_type_t key, - identification_t *id, bool trusted) -{ - cert_enumerator_t *e; - - if ((cert != CERT_TRUSTED_PUBKEY && cert != CERT_ANY) || - id == NULL || id->get_type(id) != ID_KEY_ID) - { - return NULL; - } - - INIT(e, - .public = { - .enumerate = enumerator_enumerate_default, - .venumerate = _cert_enumerator_enumerate, - .destroy = _cert_enumerator_destroy, - }, - .type = key, - .inner = this->db->query(this->db, - "SELECT public_key FROM peer WHERE keyid = ?", - DB_BLOB, id->get_encoding(id), - DB_BLOB), - ); - if (!e->inner) - { - free(e); - return NULL; - } - return &e->public; -} - -METHOD(medsrv_creds_t, destroy, void, - private_medsrv_creds_t *this) -{ - free(this); -} - -/** - * Described in header. - */ -medsrv_creds_t *medsrv_creds_create(database_t *db) -{ - private_medsrv_creds_t *this; - - INIT(this, - .public = { - .set = { - .create_private_enumerator = (void*)return_null, - .create_cert_enumerator = _create_cert_enumerator, - .create_shared_enumerator = (void*)return_null, - .create_cdp_enumerator = (void*)return_null, - .cache_cert = (void*)nop, - }, - .destroy = _destroy, - }, - .db = db, - ); - - return &this->public; -} - diff --git a/src/libcharon/plugins/medsrv/medsrv_creds.h b/src/libcharon/plugins/medsrv/medsrv_creds.h deleted file mode 100644 index 21c7ac111..000000000 --- a/src/libcharon/plugins/medsrv/medsrv_creds.h +++ /dev/null @@ -1,54 +0,0 @@ -/* - * Copyright (C) 2007-2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup medsrv_creds_i medsrv_creds - * @{ @ingroup medsrv_p - */ - -#ifndef MEDSRV_CREDS_H_ -#define MEDSRV_CREDS_H_ - -#include -#include - -typedef struct medsrv_creds_t medsrv_creds_t; - -/** - * Mediation credentials database. - */ -struct medsrv_creds_t { - - /** - * Implements credential_set_t interface - */ - credential_set_t set; - - /** - * Destroy the credentials database. - */ - void (*destroy)(medsrv_creds_t *this); -}; - -/** - * Create the medsrv credentials db. - * - * @param database underlying database - * @return credential set implementation on that database - */ -medsrv_creds_t *medsrv_creds_create(database_t *database); - -#endif /** MEDSRV_CREDS_H_ @}*/ diff --git a/src/libcharon/plugins/medsrv/medsrv_plugin.c b/src/libcharon/plugins/medsrv/medsrv_plugin.c deleted file mode 100644 index 2ffd5e5f1..000000000 --- a/src/libcharon/plugins/medsrv/medsrv_plugin.c +++ /dev/null @@ -1,137 +0,0 @@ -/* - * Copyright (C) 2013 Tobias Brunner - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "medsrv_plugin.h" - -#include "medsrv_creds.h" -#include "medsrv_config.h" - -#include - -typedef struct private_medsrv_plugin_t private_medsrv_plugin_t; - -/** - * private data of medsrv plugin - */ -struct private_medsrv_plugin_t { - - /** - * implements plugin interface - */ - medsrv_plugin_t public; - - /** - * database connection instance - */ - database_t *db; - - /** - * medsrv credential set instance - */ - medsrv_creds_t *creds; - - /** - * medsrv config database - */ - medsrv_config_t *config; -}; - -METHOD(plugin_t, get_name, char*, - private_medsrv_plugin_t *this) -{ - return "medsrv"; -} - -/** - * Connect to database - */ -static bool open_database(private_medsrv_plugin_t *this, - plugin_feature_t *feature, bool reg, void *cb_data) -{ - if (reg) - { - char *uri; - - uri = lib->settings->get_str(lib->settings, - "medsrv.database", NULL); - if (!uri) - { - DBG1(DBG_CFG, "mediation database URI not defined, skipped"); - return FALSE; - } - - this->db = lib->db->create(lib->db, uri); - if (this->db == NULL) - { - DBG1(DBG_CFG, "opening mediation server database failed"); - return FALSE; - } - - this->creds = medsrv_creds_create(this->db); - this->config = medsrv_config_create(this->db); - - lib->credmgr->add_set(lib->credmgr, &this->creds->set); - charon->backends->add_backend(charon->backends, &this->config->backend); - } - else - { - charon->backends->remove_backend(charon->backends, &this->config->backend); - lib->credmgr->remove_set(lib->credmgr, &this->creds->set); - this->config->destroy(this->config); - this->creds->destroy(this->creds); - this->db->destroy(this->db); - } - return TRUE; -} - -METHOD(plugin_t, get_features, int, - private_medsrv_plugin_t *this, plugin_feature_t *features[]) -{ - static plugin_feature_t f[] = { - PLUGIN_CALLBACK((plugin_feature_callback_t)open_database, NULL), - PLUGIN_PROVIDE(CUSTOM, "medsrv"), - PLUGIN_DEPENDS(DATABASE, DB_ANY), - }; - *features = f; - return countof(f); -} - -METHOD(plugin_t, destroy, void, - private_medsrv_plugin_t *this) -{ - free(this); -} - -/* - * see header file - */ -PLUGIN_DEFINE(medsrv) -{ - private_medsrv_plugin_t *this; - - INIT(this, - .public = { - .plugin = { - .get_name = _get_name, - .get_features = _get_features, - .destroy = _destroy, - }, - }, - ); - - return &this->public.plugin; -} diff --git a/src/libcharon/plugins/medsrv/medsrv_plugin.h b/src/libcharon/plugins/medsrv/medsrv_plugin.h deleted file mode 100644 index e2c63bbe4..000000000 --- a/src/libcharon/plugins/medsrv/medsrv_plugin.h +++ /dev/null @@ -1,43 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup medsrv_p medsrv - * @ingroup cplugins - * - * @defgroup medsrv_plugin medsrv_plugin - * @{ @ingroup medsrv_p - */ - -#ifndef MEDSRV_PLUGIN_H_ -#define MEDSRV_PLUGIN_H_ - -#include - -typedef struct medsrv_plugin_t medsrv_plugin_t; - -/** - * Mediation server database plugin. - */ -struct medsrv_plugin_t { - - /** - * implements plugin interface - */ - plugin_t plugin; -}; - -#endif /** MEDSRV_PLUGIN_H_ @}*/ diff --git a/src/libcharon/plugins/medsrv/mysql.sql b/src/libcharon/plugins/medsrv/mysql.sql deleted file mode 100644 index eb9f57772..000000000 --- a/src/libcharon/plugins/medsrv/mysql.sql +++ /dev/null @@ -1,21 +0,0 @@ - -CREATE TABLE IF NOT EXISTS `peer` ( - `id` int(10) unsigned NOT NULL auto_increment, - `user` int(10) unsigned NOT NULL, - `alias` varchar(30) NOT NULL, - `keyid` varbinary(20) NOT NULL, - `public_key` blob, - PRIMARY KEY (`id`), - UNIQUE KEY (`user`,`alias`), - UNIQUE KEY (`keyid`), - KEY (`user`) -) ENGINE=MyISAM DEFAULT CHARSET=utf8 COLLATE=utf8_unicode_ci; - -CREATE TABLE IF NOT EXISTS `user` ( - `id` int(10) unsigned NOT NULL auto_increment, - `login` varchar(30) NOT NULL, - `password` varbinary(20) NOT NULL, - PRIMARY KEY (`id`), - UNIQUE KEY (`login`) -) ENGINE=MyISAM DEFAULT CHARSET=utf8 COLLATE=utf8_unicode_ci; - diff --git a/src/libcharon/plugins/medsrv/test.sql b/src/libcharon/plugins/medsrv/test.sql deleted file mode 100644 index cd964300d..000000000 --- a/src/libcharon/plugins/medsrv/test.sql +++ /dev/null @@ -1,9 +0,0 @@ - -INSERT INTO `Peer` ( - `IdPeer`, `IdUser`, `Alias`, `KeyId`, `PublicKey` -) VALUES ( - 1, 0, 'sidv150', - X'ed90e64feca21f4b6897992422e0de21b9d62629', - X'30820122300d06092a864886f70d01010105000382010f003082010a0282010100cd946c229f7d52b21da1cb5384e7dcaf6529f760534a56355efd49e87a9c6f1ddd5ff303bd7eb49c23de03adc487456f41eb5f92947bdc8ff8dbe443f8d112e0da2c98145e7c4d1cd15cddd08577f4d4f3d0a2e1da3c08c94cd819758751931e7a9724cc43d73a11b8e176a268b4cdbbf3995cb09723abc9bfc477c25e714a4661a84c078be7404d8986be55f20437e3a6b278a3cc89aec085941f1a1aafaf4b22ae146fe4684d5567dc30658a32087d01b98515070cb1653311cb6102f82a83c638c2a79985dbb9600752e9cbc272014a5c547b4ab59130c3a948658bff794b6f202cf95939ffa73b10521f05c060cecb15f8597ed95d72b9e405ee31f1b5d90203010001' -); - diff --git a/src/medsrv/.gitignore b/src/medsrv/.gitignore deleted file mode 100644 index ab09bc87f..000000000 --- a/src/medsrv/.gitignore +++ /dev/null @@ -1 +0,0 @@ -medsrv.fcgi diff --git a/src/medsrv/Makefile.am b/src/medsrv/Makefile.am deleted file mode 100644 index bee7ae1f0..000000000 --- a/src/medsrv/Makefile.am +++ /dev/null @@ -1,45 +0,0 @@ -medsrvdir = ${ipsecdir}/medsrv - -medsrv_PROGRAMS = medsrv.fcgi - -medsrv_fcgi_SOURCES = user.h user.c \ -main.c filter/auth_filter.c filter/auth_filter.h \ -controller/user_controller.c controller/user_controller.h \ -controller/peer_controller.c controller/peer_controller.h - -medsrv_fcgi_LDADD = $(top_builddir)/src/libstrongswan/libstrongswan.la $(top_builddir)/src/libfast/libfast.la -main.o : $(top_builddir)/config.status - -AM_CPPFLAGS = \ - -I$(top_srcdir)/src/libstrongswan \ - -I$(top_srcdir)/src/libfast \ - -DIPSECDIR=\"${ipsecdir}\" \ - -DIPSEC_PIDDIR=\"${piddir}\" \ - -DPLUGINS=\""${medsrv_plugins}\"" - -AM_CFLAGS = \ - $(PLUGIN_CFLAGS) - -# Don't forget to add templates to EXTRA_DIST !!! How to automate? -medsrv_templatesdir = ${medsrvdir}/templates -medsrv_templates_DATA = templates/header.cs templates/footer.cs - -medsrv_templates_userdir = ${medsrv_templatesdir}/user -medsrv_templates_user_DATA = templates/user/add.cs templates/user/edit.cs \ -templates/user/login.cs templates/user/help.cs - -medsrv_templates_peerdir = ${medsrv_templatesdir}/peer -medsrv_templates_peer_DATA = templates/peer/add.cs templates/peer/edit.cs \ -templates/peer/list.cs - -medsrv_templates_staticdir = ${medsrv_templatesdir}/static -medsrv_templates_static_DATA = templates/header.cs templates/footer.cs \ -templates/static/style.css templates/static/strongswan.png \ -templates/static/favicon.ico - -EXTRA_DIST = templates/header.cs templates/footer.cs \ -templates/static/style.css templates/static/strongswan.png \ -templates/static/favicon.ico \ -templates/peer/add.cs templates/peer/edit.cs templates/peer/list.cs \ -templates/user/login.cs templates/user/add.cs templates/user/edit.cs \ -templates/user/help.cs diff --git a/src/medsrv/controller/peer_controller.c b/src/medsrv/controller/peer_controller.c deleted file mode 100644 index 9fa02a207..000000000 --- a/src/medsrv/controller/peer_controller.c +++ /dev/null @@ -1,380 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * Copyright (C) 2008 Philip Boetschi, Adrian Doerig - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#define _GNU_SOURCE -#include - -#include "peer_controller.h" - -#include -#include -#include -#include -#include -#include - -typedef struct private_peer_controller_t private_peer_controller_t; - -/** - * private data of the peer_controller - */ -struct private_peer_controller_t { - - /** - * public functions - */ - peer_controller_t public; - - /** - * active user session - */ - user_t *user; - - /** - * underlying database - */ - database_t *db; -}; - -/** - * list the configured peer configs - */ -static void list(private_peer_controller_t *this, fast_request_t *request) -{ - enumerator_t *query; - - query = this->db->query(this->db, - "SELECT id, alias, keyid FROM peer WHERE user = ? ORDER BY alias", - DB_UINT, this->user->get_user(this->user), - DB_UINT, DB_TEXT, DB_BLOB); - - if (query) - { - u_int id; - char *alias; - chunk_t keyid; - identification_t *identifier; - - while (query->enumerate(query, &id, &alias, &keyid)) - { - request->setf(request, "peers.%d.alias=%s", id, alias); - identifier = identification_create_from_encoding(ID_KEY_ID, keyid); - request->setf(request, "peers.%d.identifier=%Y", id, identifier); - identifier->destroy(identifier); - } - query->destroy(query); - } - request->render(request, "templates/peer/list.cs"); -} - -/** - * verify a peer alias - */ -static bool verify_alias(private_peer_controller_t *this, fast_request_t *request, - char *alias) -{ - if (!alias || *alias == '\0') - { - request->setf(request, "error=Alias is missing."); - return FALSE; - } - while (*alias != '\0') - { - switch (*alias) - { - case 'a' ... 'z': - case 'A' ... 'Z': - case '0' ... '9': - case '-': - case '_': - case '@': - case '.': - alias++; - continue; - default: - request->setf(request, "error=Alias invalid, " - "valid characters: A-Z a-z 0-9 - _ @ ."); - return FALSE; - } - } - return TRUE; -} - -/** - * parse and verify a public key - */ -static bool parse_public_key(private_peer_controller_t *this, - fast_request_t *request, char *public_key, - chunk_t *encoding, chunk_t *keyid) -{ - public_key_t *public; - chunk_t blob, id; - - if (!public_key || *public_key == '\0') - { - request->setf(request, "error=Public key is missing."); - return FALSE; - } - blob = chunk_clone(chunk_create(public_key, strlen(public_key))); - public = lib->creds->create(lib->creds, CRED_PUBLIC_KEY, KEY_ANY, - BUILD_BLOB_PEM, blob, - BUILD_END); - chunk_free(&blob); - if (!public) - { - request->setf(request, "error=Parsing public key failed."); - return FALSE; - } - /* TODO: use get_encoding() with an encoding type */ - if (!public->get_fingerprint(public, KEYID_PUBKEY_SHA1, &id) || - !public->get_encoding(public, PUBKEY_SPKI_ASN1_DER, encoding)) - { - request->setf(request, "error=Encoding public key failed."); - return FALSE; - } - *keyid = chunk_clone(id); - public->destroy(public); - return TRUE; -} - -/** - * register a new peer - */ -static void add(private_peer_controller_t *this, fast_request_t *request) -{ - char *alias = "", *public_key = ""; - - if (request->get_query_data(request, "back")) - { - return request->redirect(request, "peer/list"); - } - while (request->get_query_data(request, "add")) - { - chunk_t encoding, keyid; - - alias = request->get_query_data(request, "alias"); - public_key = request->get_query_data(request, "public_key"); - - if (!verify_alias(this, request, alias)) - { - break; - } - if (!parse_public_key(this, request, public_key, &encoding, &keyid)) - { - break; - } - if (this->db->execute(this->db, NULL, - "INSERT INTO peer (user, alias, public_key, keyid) " - "VALUES (?, ?, ?, ?)", - DB_UINT, this->user->get_user(this->user), - DB_TEXT, alias, DB_BLOB, encoding, - DB_BLOB, keyid) <= 0) - { - request->setf(request, "error=Peer already exists."); - free(keyid.ptr); - free(encoding.ptr); - break; - } - free(keyid.ptr); - free(encoding.ptr); - return request->redirect(request, "peer/list"); - } - request->set(request, "alias", alias); - request->set(request, "public_key", public_key); - - return request->render(request, "templates/peer/add.cs"); -} - -/** - * pem encode a public key into an allocated string - */ -static char* pem_encode(chunk_t der) -{ - static const char *begin = "-----BEGIN PUBLIC KEY-----\n"; - static const char *end = "-----END PUBLIC KEY-----"; - size_t len; - char *pem; - chunk_t base64; - int i = 0; - - base64 = chunk_to_base64(der, NULL); - len = strlen(begin) + base64.len + base64.len/64 + strlen(end) + 2; - pem = malloc(len + 1); - - strcpy(pem, begin); - do - { - strncat(pem, base64.ptr + i, 64); - strcat(pem, "\n"); - i += 64; - } - while (i < base64.len - 2); - strcat(pem, end); - - free(base64.ptr); - return pem; -} - -/** - * edit a peer - */ -static void edit(private_peer_controller_t *this, fast_request_t *request, int id) -{ - char *alias = "", *public_key = "", *pem; - chunk_t encoding, keyid; - - if (request->get_query_data(request, "back")) - { - return request->redirect(request, "peer/list"); - } - if (request->get_query_data(request, "delete")) - { - this->db->execute(this->db, NULL, - "DELETE FROM peer WHERE id = ? AND user = ?", - DB_INT, id, DB_UINT, this->user->get_user(this->user)); - return request->redirect(request, "peer/list"); - } - if (request->get_query_data(request, "save")) - { - while (TRUE) - { - alias = request->get_query_data(request, "alias"); - public_key = request->get_query_data(request, "public_key"); - - if (!verify_alias(this, request, alias)) - { - break; - } - if (!parse_public_key(this, request, public_key, &encoding, &keyid)) - { - break; - } - if (this->db->execute(this->db, NULL, - "UPDATE peer SET alias = ?, public_key = ?, keyid = ? " - "WHERE id = ? AND user = ?", - DB_TEXT, alias, DB_BLOB, encoding, DB_BLOB, keyid, - DB_INT, id, DB_UINT, this->user->get_user(this->user)) < 0) - { - request->setf(request, "error=Peer already exists."); - free(keyid.ptr); - free(encoding.ptr); - break; - } - free(keyid.ptr); - free(encoding.ptr); - return request->redirect(request, "peer/list"); - } - } - else - { - enumerator_t *query = this->db->query(this->db, - "SELECT alias, public_key FROM peer WHERE id = ? AND user = ?", - DB_INT, id, DB_UINT, this->user->get_user(this->user), - DB_TEXT, DB_BLOB); - if (query && query->enumerate(query, &alias, &encoding)) - { - alias = strdupa(alias); - pem = pem_encode(encoding); - public_key = strdupa(pem); - free(pem); - } - else - { - return request->redirect(request, "peer/list"); - } - DESTROY_IF(query); - } - request->set(request, "alias", alias); - request->set(request, "public_key", public_key); - return request->render(request, "templates/peer/edit.cs"); -} - -/** - * delete a peer from the database - */ -static void delete(private_peer_controller_t *this, fast_request_t *request, int id) -{ - this->db->execute(this->db, NULL, - "DELETE FROM peer WHERE id = ? AND user = ?", - DB_INT, id, DB_UINT, this->user->get_user(this->user)); -} - -METHOD(fast_controller_t, get_name, char*, - private_peer_controller_t *this) -{ - return "peer"; -} - -METHOD(fast_controller_t, handle, void, - private_peer_controller_t *this, fast_request_t *request, char *action, - char *idstr, char *p3, char *p4, char *p5) -{ - if (action) - { - int id = 0; - if (idstr) - { - id = atoi(idstr); - } - - if (streq(action, "list")) - { - return list(this, request); - } - else if (streq(action, "add")) - { - return add(this, request); - } - else if (streq(action, "edit") && id) - { - return edit(this, request, id); - } - else if (streq(action, "delete") && id) - { - delete(this, request, id); - } - } - request->redirect(request, "peer/list"); -} - -METHOD(fast_controller_t, destroy, void, - private_peer_controller_t *this) -{ - free(this); -} - -/* - * see header file - */ -fast_controller_t *peer_controller_create(user_t *user, database_t *db) -{ - private_peer_controller_t *this; - - INIT(this, - .public = { - .controller = { - .get_name = _get_name, - .handle = _handle, - .destroy = _destroy, - }, - }, - .user = user, - .db = db, - ); - - return &this->public.controller; -} diff --git a/src/medsrv/controller/peer_controller.h b/src/medsrv/controller/peer_controller.h deleted file mode 100644 index fc817d456..000000000 --- a/src/medsrv/controller/peer_controller.h +++ /dev/null @@ -1,49 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * Copyright (C) 2008 Philip Boetschi, Adrian Doerig - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup peer_controller_server peer_controller - * @{ @ingroup medsrv - */ - -#ifndef PEER_CONTROLLER_H_ -#define PEER_CONTROLLER_H_ - -#include - -#include -#include - -typedef struct peer_controller_t peer_controller_t; - -/** - * Peer controller. Manages peers associated to a user. - */ -struct peer_controller_t { - - /** - * Implements controller_t interface. - */ - fast_controller_t controller; -}; - -/** - * Create a peer_controller controller instance. - */ -fast_controller_t *peer_controller_create(user_t *user, database_t *db); - -#endif /** PEER_CONTROLLER_H_ @}*/ diff --git a/src/medsrv/controller/user_controller.c b/src/medsrv/controller/user_controller.c deleted file mode 100644 index d4c20e287..000000000 --- a/src/medsrv/controller/user_controller.c +++ /dev/null @@ -1,367 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * Copyright (C) 2008 Philip Boetschi, Adrian Doerig - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#define _GNU_SOURCE -#include - -#include "user_controller.h" - -#include - -typedef struct private_user_controller_t private_user_controller_t; - -/** - * private data of the user_controller - */ -struct private_user_controller_t { - - /** - * public functions - */ - user_controller_t public; - - /** - * database connection - */ - database_t *db; - - /** - * user session - */ - user_t *user; - - /** - * minimum required password length - */ - u_int password_length; -}; - -/** - * hash the password for database storage - */ -static chunk_t hash_password(char *login, char *password) -{ - hasher_t *hasher; - chunk_t hash, data; - - hasher = lib->crypto->create_hasher(lib->crypto, HASH_SHA1); - if (!hasher) - { - return chunk_empty; - } - data = chunk_cata("cc", chunk_create(login, strlen(login)), - chunk_create(password, strlen(password))); - if (!hasher->allocate_hash(hasher, data, &hash)) - { - hasher->destroy(hasher); - return chunk_empty; - } - hasher->destroy(hasher); - return hash; -} - -/** - * Login a user. - */ -static void login(private_user_controller_t *this, fast_request_t *request) -{ - if (request->get_query_data(request, "submit")) - { - char *login, *password; - - login = request->get_query_data(request, "login"); - password = request->get_query_data(request, "password"); - - if (login && password) - { - enumerator_t *query; - u_int id = 0; - chunk_t hash; - - hash = hash_password(login, password); - query = this->db->query(this->db, - "SELECT id FROM user WHERE login = ? AND password = ?", - DB_TEXT, login, DB_BLOB, hash, DB_UINT); - if (query) - { - query->enumerate(query, &id); - query->destroy(query); - } - free(hash.ptr); - if (id) - { - this->user->set_user(this->user, id); - return request->redirect(request, "peer/list"); - } - } - request->setf(request, "error=Invalid username or password."); - } - request->render(request, "templates/user/login.cs"); -} - -/** - * Logout a user. - */ -static void logout(private_user_controller_t *this, fast_request_t *request) -{ - request->redirect(request, "user/login"); - request->close_session(request); -} - -/** - * verify a user entered username for validity - */ -static bool verify_login(private_user_controller_t *this, - fast_request_t *request, char *login) -{ - if (!login || *login == '\0') - { - request->setf(request, "error=Username is missing."); - return FALSE; - } - while (*login != '\0') - { - switch (*login) - { - case 'a' ... 'z': - case 'A' ... 'Z': - case '0' ... '9': - case '-': - case '_': - case '@': - case '.': - login++; - continue; - default: - request->setf(request, "error=Username invalid, " - "valid characters: A-Z a-z 0-9 - _ @ ."); - return FALSE; - } - } - return TRUE; -} - -/** - * verify a user entered password for validity - */ -static bool verify_password(private_user_controller_t *this, - fast_request_t *request, - char *password, char *confirm) -{ - if (!password || *password == '\0') - { - request->setf(request, "error=Password is missing."); - return FALSE; - } - if (strlen(password) < this->password_length) - { - request->setf(request, "error=Password requires at least %d characters.", - this->password_length); - return FALSE; - } - if (!confirm || !streq(password, confirm)) - { - request->setf(request, "error=Password not confirmed."); - return FALSE; - } - return TRUE; -} - -/** - * Register a user. - */ -static void add(private_user_controller_t *this, fast_request_t *request) -{ - char *login = ""; - - while (request->get_query_data(request, "register")) - { - char *password, *confirm; - chunk_t hash; - u_int id; - - login = request->get_query_data(request, "new_login"); - password = request->get_query_data(request, "new_password"); - confirm = request->get_query_data(request, "confirm_password"); - - if (!verify_login(this, request, login) || - !verify_password(this, request, password, confirm)) - { - break; - } - - hash = hash_password(login, password); - if (!hash.ptr || this->db->execute(this->db, &id, - "INSERT INTO user (login, password) VALUES (?, ?)", - DB_TEXT, login, DB_BLOB, hash) < 0) - { - request->setf(request, "error=Username already exists."); - free(hash.ptr); - break; - } - free(hash.ptr); - this->user->set_user(this->user, id); - return request->redirect(request, "peer/list"); - } - request->set(request, "new_login", login); - request->setf(request, "password_length=%d", this->password_length); - request->render(request, "templates/user/add.cs"); -} - -/** - * Edit the logged in user - */ -static void edit(private_user_controller_t *this, fast_request_t *request) -{ - enumerator_t *query; - char *old_login; - - /* lookup old login */ - query = this->db->query(this->db, "SELECT login FROM user WHERE id = ?", - DB_INT, this->user->get_user(this->user), - DB_TEXT); - if (!query || !query->enumerate(query, &old_login)) - { - DESTROY_IF(query); - request->close_session(request); - return request->redirect(request, "user/login"); - } - old_login = strdupa(old_login); - query->destroy(query); - - /* back pressed */ - if (request->get_query_data(request, "back")) - { - return request->redirect(request, "peer/list"); - } - /* delete pressed */ - if (request->get_query_data(request, "delete")) - { - this->db->execute(this->db, NULL, "DELETE FROM user WHERE id = ?", - DB_UINT, this->user->get_user(this->user)); - this->db->execute(this->db, NULL, - "DELETE FROM peer WHERE user = ?", - DB_UINT, this->user->get_user(this->user)); - return logout(this, request); - } - /* save pressed */ - while (request->get_query_data(request, "save")) - { - char *new_login, *old_pass, *new_pass, *confirm; - chunk_t old_hash, new_hash; - - new_login = request->get_query_data(request, "old_login"); - old_pass = request->get_query_data(request, "old_password"); - new_pass = request->get_query_data(request, "new_password"); - confirm = request->get_query_data(request, "confirm_password"); - - if (!verify_login(this, request, new_login) || - !verify_password(this, request, new_pass, confirm)) - { - old_login = new_login; - break; - } - old_hash = hash_password(old_login, old_pass); - new_hash = hash_password(new_login, new_pass); - - if (this->db->execute(this->db, NULL, - "UPDATE user SET login = ?, password = ? " - "WHERE id = ? AND password = ?", - DB_TEXT, new_login, DB_BLOB, new_hash, - DB_UINT, this->user->get_user(this->user), DB_BLOB, old_hash) <= 0) - { - free(new_hash.ptr); - free(old_hash.ptr); - old_login = new_login; - request->setf(request, "error=Password verification failed."); - break; - } - free(new_hash.ptr); - free(old_hash.ptr); - return request->redirect(request, "peer/list"); - } - /* on error/template rendering */ - request->set(request, "old_login", old_login); - request->setf(request, "password_length=%d", this->password_length); - request->render(request, "templates/user/edit.cs"); -} - -METHOD(fast_controller_t, get_name, char*, - private_user_controller_t *this) -{ - return "user"; -} - -METHOD(fast_controller_t, handle, void, - private_user_controller_t *this, fast_request_t *request, char *action, - char *p2, char *p3, char *p4, char *p5) -{ - if (action) - { - if (streq(action, "add")) - { - return add(this, request); - } - if (streq(action, "login")) - { - return login(this, request); - } - else if (streq(action, "logout")) - { - return logout(this, request); - } - else if (streq(action, "edit")) - { - return edit(this, request); - } - else if (streq(action, "help")) - { - return request->render(request, "templates/user/help.cs"); - } - } - request->redirect(request, "user/login"); -} - -METHOD(fast_controller_t, destroy, void, - private_user_controller_t *this) -{ - free(this); -} - -/* - * see header file - */ -fast_controller_t *user_controller_create(user_t *user, database_t *db) -{ - private_user_controller_t *this; - - INIT(this, - .public = { - .controller = { - .get_name = _get_name, - .handle = _handle, - .destroy = _destroy, - }, - }, - .user = user, - .db = db, - .password_length = lib->settings->get_int(lib->settings, - "medsrv.password_length", 6), - ); - - return &this->public.controller; -} diff --git a/src/medsrv/controller/user_controller.h b/src/medsrv/controller/user_controller.h deleted file mode 100644 index 33e0ec289..000000000 --- a/src/medsrv/controller/user_controller.h +++ /dev/null @@ -1,49 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * Copyright (C) 2008 Philip Boetschi, Adrian Doerig - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup user_controller_server user_controller - * @{ @ingroup medsrv - */ - -#ifndef USER_CONTROLLER_H_ -#define USER_CONTROLLER_H_ - -#include - -#include -#include - -typedef struct user_controller_t user_controller_t; - -/** - * User controller. Register, Login and user management. - */ -struct user_controller_t { - - /** - * Implements controller_t interface. - */ - fast_controller_t controller; -}; - -/** - * Create a user_controller controller instance. - */ -fast_controller_t *user_controller_create(user_t *user, database_t *db); - -#endif /** USER_CONTROLLER_H_ @}*/ diff --git a/src/medsrv/filter/auth_filter.c b/src/medsrv/filter/auth_filter.c deleted file mode 100644 index 20f3ceee4..000000000 --- a/src/medsrv/filter/auth_filter.c +++ /dev/null @@ -1,99 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * Copyright (C) 2008 Philip Boetschi, Adrian Doerig - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "auth_filter.h" - -#include - -typedef struct private_auth_filter_t private_auth_filter_t; - -/** - * private data of auth_filter - */ -struct private_auth_filter_t { - /** - * public functions - */ - auth_filter_t public; - - /** - * user session - */ - user_t *user; - - /** - * database connection - */ - database_t *db; -}; - -METHOD(fast_filter_t, run, bool, - private_auth_filter_t *this, fast_request_t *request, char *controller, - char *action, char *p2, char *p3, char *p4, char *p5) -{ - if (this->user->get_user(this->user)) - { - enumerator_t *query; - char *login; - - query = this->db->query(this->db, "SELECT login FROM user WHERE id = ?", - DB_INT, this->user->get_user(this->user), - DB_TEXT); - if (query && query->enumerate(query, &login)) - { - request->set(request, "login", login); - query->destroy(query); - return TRUE; - } - DESTROY_IF(query); - this->user->set_user(this->user, 0); - } - if (controller && streq(controller, "user") && action && - (streq(action, "add") || streq(action, "login") || streq(action, "help"))) - { /* add/login allowed */ - return TRUE; - } - request->redirect(request, "user/login"); - return FALSE; -} - -METHOD(fast_filter_t, destroy, void, - private_auth_filter_t *this) -{ - free(this); -} - -/* - * see header file - */ -fast_filter_t *auth_filter_create(user_t *user, database_t *db) -{ - private_auth_filter_t *this; - - INIT(this, - .public = { - .filter = { - .destroy = _destroy, - .run = _run, - }, - }, - .user = user, - .db = db, - ); - - return &this->public.filter; -} diff --git a/src/medsrv/filter/auth_filter.h b/src/medsrv/filter/auth_filter.h deleted file mode 100644 index e0cca0a88..000000000 --- a/src/medsrv/filter/auth_filter.h +++ /dev/null @@ -1,49 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * Copyright (C) 2008 Philip Boetschi, Adrian Doerig - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup auth_filter_server auth_filter - * @{ @ingroup medsrv - */ - -#ifndef AUTH_FILTER_H_ -#define AUTH_FILTER_H_ - -#include -#include - -#include "user.h" - -typedef struct auth_filter_t auth_filter_t; - -/** - * Authentication/Authorization filter. - */ -struct auth_filter_t { - - /** - * Implements filter_t interface. - */ - fast_filter_t filter; -}; - -/** - * Create a auth_filter instance. - */ -fast_filter_t *auth_filter_create(user_t *user, database_t *db); - -#endif /** AUTH_FILTER_H_ @}*/ diff --git a/src/medsrv/main.c b/src/medsrv/main.c deleted file mode 100644 index fe0d8a4c7..000000000 --- a/src/medsrv/main.c +++ /dev/null @@ -1,79 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * Copyright (C) 2008 Philip Boetschi, Adrian Doerig - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include - -#include -#include -#include - -#include "filter/auth_filter.h" -#include "controller/user_controller.h" -#include "controller/peer_controller.h" - -int main(int arc, char *argv[]) -{ - fast_dispatcher_t *dispatcher; - database_t *db; - char *socket; - bool debug; - char *uri; - int timeout, threads; - - library_init(NULL, "medsrv"); - if (!lib->plugins->load(lib->plugins, - lib->settings->get_str(lib->settings, "medsrv.load", PLUGINS))) - { - return 1; - } - - socket = lib->settings->get_str(lib->settings, "medsrv.socket", NULL); - debug = lib->settings->get_bool(lib->settings, "medsrv.debug", FALSE); - timeout = lib->settings->get_time(lib->settings, "medsrv.timeout", 900); - threads = lib->settings->get_int(lib->settings, "medsrv.threads", 5); - uri = lib->settings->get_str(lib->settings, "medsrv.database", NULL); - if (uri == NULL) - { - fprintf(stderr, "database URI medsrv.database not defined.\n"); - return 1; - } - - db = lib->db->create(lib->db, uri); - if (db == NULL) - { - fprintf(stderr, "opening database failed.\n"); - return 1; - } - - dispatcher = fast_dispatcher_create(socket, debug, timeout, - (fast_context_constructor_t)user_create, db); - dispatcher->add_filter(dispatcher, - (fast_filter_constructor_t)auth_filter_create, db); - dispatcher->add_controller(dispatcher, - (fast_controller_constructor_t)user_controller_create, db); - dispatcher->add_controller(dispatcher, - (fast_controller_constructor_t)peer_controller_create, db); - - dispatcher->run(dispatcher, threads); - - dispatcher->waitsignal(dispatcher); - dispatcher->destroy(dispatcher); - db->destroy(db); - - library_deinit(); - return 0; -} diff --git a/src/medsrv/templates/footer.cs b/src/medsrv/templates/footer.cs deleted file mode 100644 index 9b151ee89..000000000 --- a/src/medsrv/templates/footer.cs +++ /dev/null @@ -1,4 +0,0 @@ - - - - diff --git a/src/medsrv/templates/header.cs b/src/medsrv/templates/header.cs deleted file mode 100644 index cb21bb06a..000000000 --- a/src/medsrv/templates/header.cs +++ /dev/null @@ -1,31 +0,0 @@ - - - - strongSwan Mediation Service - - - - - - -
- - - -

Mediation Service

-
- -
-
-
diff --git a/src/medsrv/templates/peer/add.cs b/src/medsrv/templates/peer/add.cs deleted file mode 100644 index 1e4f10f30..000000000 --- a/src/medsrv/templates/peer/add.cs +++ /dev/null @@ -1,24 +0,0 @@ - -
- -
- - - - - - - - - - - - - - -
- - -
-
- diff --git a/src/medsrv/templates/peer/edit.cs b/src/medsrv/templates/peer/edit.cs deleted file mode 100644 index ac4a2e11f..000000000 --- a/src/medsrv/templates/peer/edit.cs +++ /dev/null @@ -1,25 +0,0 @@ - -
- -
- - - - - - - - - - - - - - -
- - - -
-
- diff --git a/src/medsrv/templates/peer/list.cs b/src/medsrv/templates/peer/list.cs deleted file mode 100644 index 205452641..000000000 --- a/src/medsrv/templates/peer/list.cs +++ /dev/null @@ -1,28 +0,0 @@ - -
- 0 ?> - - - - - - - - - - - -
AliasKey Identifier
- - - -
- -No peers defined. - -
-
- -
-
- diff --git a/src/medsrv/templates/static/favicon.ico b/src/medsrv/templates/static/favicon.ico deleted file mode 100644 index d004591963d5f531ea7bbf3be030d11360a3fd22..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 894 zcmZQzU<5(|0R|u`!H~hsz#zuJz@P!dKp_SNAO?x!0s&Stbft0)TmpwO*)=e{9Tr#hmAqt;$qe<3tAsCm^y`YcghhV9fZiEbRHOpa0-Gfa>ew zp976DVSH%9bk~&kkb_y0i;Ii1gAb4m6c1E;^5otxWc5uc&rO*g0;Ry{fvv(KKi@z< zKYuIv89)&S!ABR4en(bc7Y8yQj%>w_Cd6eWCnq~-P5=tp@I2bT{wp5!K3d0`8af&p z8g1m37&APw=YM?W08aC*xbAmXAKJ8ObA45>3HwE$`aspEPwxH3YQBTO!)XnVpFMkZ z=FB-at(8Ew@J`T}(wrs*DWc9A%k8fZ42^487I%UFq7pNG5tT-Rd zsQ+;5;!k)K1I@2bcr?waJ-YK1KWZ;NjVoUe GD-Hl6bl2nn diff --git a/src/medsrv/templates/static/strongswan.png b/src/medsrv/templates/static/strongswan.png deleted file mode 100644 index 869188cdf456bdcc3d1821bf8fad639375c7bce8..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 19837 zcmX7w1yCDp*M<|^U4lE57AWo#q_`DY+=B;qcP(19xU{&tyA^kLD^T2_*q8VJH?zsi zW@aaQ_B_Y#YZIxeEQ5(giUt4xFy&;W)L@^#VY?d&66`(Z$65yL1Ia`|Mhfuu-z&GH zC=qr9)j?L<82~`X|8EBZ(lbG@gUBv&N}rGyQL#{fWOYh{MgRacKu${hi^s}Ihx-qT zMOUT=q5F+eF98=j7YS-klpt#H?@8~zCoz2BXVSrfDAabe-Ia^9?JmCv3sK5=cBIJU zm{yrCr2QB5_FA9EUI)l>gYo+JHGN`; z%j~i?MY{0M1iE7!A#0#xtX2+0zQM0abiVM^e1pfhC@zr)`G9FCKzbAKJI1jiC@56s z$-XrNDUz}jp8MZCRtg!Qg@cWe3<1y;VX)hANTn2f9vi$q5$KD-4VRk%)Pw&8)DI-FQ~!)0mVE{sm~VfqW330OBHGE8sPVQj%I7G z=ifg}9wRJ$4a>Jm9x5u%xD>sBrO)aJ&60*SDNU{y)m|c{%`cfE~iSt9gkI zJAi5M;Oge(i;bUOAh?IZ_w|AcL`GqzT=vO1DvH0^mpE?7gvGESjlT;FppMW|FEa!F z2rny*|MzLh8Z$1=02${W8m6Jw&*cHpzcCvr(uEh) z3MIxwtGM>ftK}&f^pZDRk}f2%_G+`nfCzA5(47R38j+j9MO%Vc+b<= zk7P&wBNGv!M+n4-$ z(tFAkFpl%?^WWQVfw14l2JyKFrlKFMeMcF$8)f(puWVH*Q^Xf(*J5Jk9P;i}+0>1} zXoDHtgfeA-Wdi{l1beuYx&{QND(&;s{|rbEVUshO2o-!nBoMpG;Sj*(@Oeq?-d}#Q z>pY(Nn05Q=S)7M#P-3Ud7h_g)M>2X{oJKwnJj(+X+o@hbd z{~+8G_wz0k+2QX;AOSE5_(jroCuGsN2HIjRxfcI23O~45V_}K%=Y^x1Y8THP{~da_ z2ZM?o+{CrY&+ou)Aa}3KH%n}>XZM2<1tGVSt(R|a|0);`x*OsJDYD@z>KNT6Z7jM2 z(1_A_L8kpg+UGiUfW2h6!8WbzS1z*kw8ZBk%ot>TON;>5d9x!fHKjUDwdyWb6WATMAxL-XcOIYD!cvCU-7@##)!M6q$ju1I)1nw>*fi zPOvRaq0&)?M52D*f{HoXh@Z2560`R7JAd?j#Ijo4LuZy!~4j()9xN91m=%*38{18_776sO?3QepO zmnU063zc)RjES*+tuF60F^j7$h(7hQT15YaB;&Xb-bXC5qafl&ayeQS$N z<4vMtfmHsi<1&Y*+usR!)72=ot3Tct;eM8YHy>#IgU*$r}(4TwV%8lJI7OOok$E(ot-p|qsN%kH&|uiB2bEUG4#88 zjQYpgiXF{m*+3Fs_Gq5NIR?$i<>h7Of;rP+6aI{yMIX3#&maGtQ$*~G1+m`yV(4x< z@y)#CU1V%e^RC3a1t>jMK_)wks^5@fce?F;2-~pj!U%azl*;e+^l?=UR0yJ8ZM~x3 zzO7#SS`p{a8f_(`ir9|H21RjbMLP0l5$q-OvWtn?+b`Gd3$aXK`$B)``Z7={cJ%Tg zhhRuOXZ>Ekl>X)3j`B2pp7(E_ac+-7mcgB-lLxzI5n**aP!#S8;oGT{&+GNlqu48! zLe2w@`JWm=rV0xFfzbkk=Ucc~|8VhFh0=r0dYK&Bslvs7h^RP1=xxskf4NY0sOB#$ zkr$s))+LZ#x6>30(;|j8TL=zH+RJJh3JnOMh=K2rh&Bh50mtvPx%xN~v zgVx8y;SuEVWkb$Y7`m}eC4B5D{-zyF-_SaBENBFf0gf`S-9Kl)csCwR)bHgOiMRfC zHIl`(0>9vYE5hv;FWrVve2|NBqJX4+Et{7%G~6_|i+Hi%%(P>E{M}r|<~kyt0+h%7 z-TcFx9!ER(Gv?Scx;#Fvr0Cyj4{gCKuO@L6zzc57sq%-{)M!hx!+&x{8=)SH=2~g- z&Q0*p{64MIn=4DeiX*v&o!uFi+Q@LJ_`_i~|KA1ZEcNVEDT4oB=(|)LQ=&Z_1l84^ z+0p#$Dn3lSU$Il2N*yZ?1VvN21ywod+&xl+wRfPuvw43kjc&u}mc{GxE7c6xQZrz- z`VO;|S_4QdZMzvV9GquB);u-UisFA{_}O#st-rrZIKo;WpVg;)W3bEsYrHiZ*xT8A zZ`!E(yeqN$R5gl@@R=%lZxeFVtS5H{rIo#lQY+`NA_5q^Pd2YxwqY?Juw(59Q4Etc zH|)`!*`Ksb^ttAI`l%Cg{*}4|Dd`+6N2T*PrGp5!Npd+yS?`k9j`XDt&?Ss$aRy4? z-2^{AiVdyxbwv%!bVba};XU8I5>tKfhU9y%8!p_fAJ0d9vNy7F!;gBC**>Q7Vf8L! zMr_oM6(5(^APMDSF+jMw>ryM34$cxQmVc-{W*a(76q&inpMk2m8b@|rnJY$d0= zin6Ju;XNNqJP00wov-tXK}5v8->>)5hVV^)Qkn>UnyCLOXJ`hU&4q4`^7ORS zK+1BVPCV`Wsa1<5Te(23M2n@d!fmDr_uq`MoLzdpo39&BL z1=Rtt3Uv}F+LsRlOxyL(ddIUB;Z$W2lU zl`u}{&`@Sb6r%QcHdO{7oRr&P$buqx`{Xx+Om~>)hDPHDRGU9gz!^je8|v>`c8Ph_ zi!CB))(eh|3O*g9Qs1 z@gl|-cBEy((d>>bU1Rr`5gS`$l{Llw=~xOYn&(M?pY!5Yh;M&){p2oF>ai(zb2j`u zoO_H&eUe!3`-^OcD|%___HRvVX0j(&xss#96YM_yogY|aBSN2odIWu`(9lg#n=t20 z%OE+pr1K0E_1?v}$DtQ_!kH8fSwZLdZQb8#DRmN4j5+fSkoU6G*s_LYq~~ZhcnqYz z8LG)BmlS;TMw)IjtlH9Q$?JEc>HG>`!1Ot%FEn}X5g`8DsgWN>b7wxwZ4Tl-0ZpUd<&E-ox_p9|zP_k{)@2)MzTWcN`+)#SC?L+4%kx;vAKiZ-fMyL; z7Jaw+yp+9Kv3B@*J32LaaVHZxArOMYLK&ydLIjDF3Nqs)p-+@ck)@YK>A~m&9FRwI zm_!FgxKwC-APt+AEt*9Zkv=g^*RlwGkLc&^TbT*S^u!u3z%nXdq}(pm4A`t@ zxT>)CEsIxsEnaBVh1vqx>lX@>u0jU}28y`S#){3f`BocWFd$<|Y8n~i=AOpJc{=Zt zS8jRg&9oiJWh#w@;Q(%@D`q!$cN<8#hE`u68@R44?vnOC7U~aRxQ5ovFM$4e?O5rk zkU0IVDxWcY!*+iaH;zch$v00opJm6GtYwLFX2XvRK>%#t54-9w*zmUO@)sU>a%|qu zs*Pl-mBOOl`uX_5wOBDpO|XLKYw9j9i~sH)DAL)@-GWZpB&kf2lhk~82quuDAU|Zvo$QE z_!18^n6rQ_PfBOH}^kYz?S=;XBx7R0a!K@8~s>K`vi7{w}uGAd1QGA3K z31k%n(TymUfo3u0=l$lO4QZa|9&b~e9rMUuB#=1S%{(`XPP_DYhFSY53YJbsuZ2sJ zYSYL6NHuP2ZibwxHI&3|Y zTWzGe@_nmTv(AoS8PpQP9l+f?(3LWUQIm5Mp*HH5io7Z{Y6D(@;{&36%i3RS16kG z=08Z2FK{wNpy0bm}ZX?|U@jB8DD)?p-PcqBR17V?v8`?}7Ha$BzJ?;3IGr4I4k}jRM{z^Hgii^SOIpEK=c`F&c=E7xv~orhI5xjO^B3(r_|&yb2x1|``1ldw_&Gf2JxIsv_iTN9QQVZ`6QEl#k~8*{4|bljJ{0ZmE2CO*w@ndOk&gsJeBrD~tYN?460-fqf4u`yI~Ft8 z2~tTydgED%tm7gUsv~||2QwfjXCw^xY`O~^IF8mze<13K?>-wD+=JqxXkYX%s(MX_ z#k%#~E&zrbfWJHLHxx4X>vvi<2 z97IgC)1o0bmtWq`Q$!7vS5{WiRPc=KJLPGVu|9Sh@?p?z*!J_O?8?!qPxtd6sT$Ie6T(ky66y?Rvxf_V6JOEj_8lQ z$;Va)PGa<5JQ!i%qXyASq?S<|>{A*`CN_`r4ra@aNQ6Sy7ievD2pi-8T6sv3q2OA* z#fkxw8jcB%E0>hr*iTf<_K-?``0qYQF_F&Vr2ZBY$*n6oAyv4Ohx0m{T)eysS)==B zup&fK=a>R;XH`)qRjx;saeAQG=V|LTHVpe(d%an?r{L2^V#uW#7{vnPU)Aqm^R}O3R9{rF7JGy@0Xq+cN%0Qcy!x{(V1^lAwmo>H2pJnL%Da%D$sWb1lR0>rkIW;T@O4I=Y_z#F6WAwC) z1@$Bl^UNO&RTEA;Q6vc{a)y1709KT5D0QevariKsG!Zc9A+ZdC6cIsaTRL>RRyX{l z93|f!;e%UgED5#pPk(SD0-&qB1U0(yMBAalLy#9F#zgX`DA7A&dd3;@k0BhX(M2^) zTRj#bVd6g&*vXIaU{*6-3#c71Faye98fEm=$|STlSXz>75YtICtN^t4x2=N*?q8%? zh{)i-zthIB*Sf04#l&G{-$k7(8iY?LRC2dhuP94N9QbG)|B-AR0)cc~dbBsGzH48y zyT9as0fT@tOv3(TNW@mBRF_JOkFvpTwgj_BI3KkQ$ zlu@xzrUPT2v3%|#)`mI{yzQ(7^rnd$6cAEXQ&OV(jpLp4Rvyu}4Mla}H^jJf4I$tP z{vKzqUgq`@C49*HhAhQ*BH&Z#&N6BB>PbmkBieh!8e6Zf#OgaM6IVObe8PO-lR4C|P^-tL5~}mtk-Ug4q&gxZ z+)ke+M7Ec+jRn&$_wc_s_YEaIU>QNO2_Hpko}Q(jglGrDENbhD8URWK`zz$FE>zRA zQ(274OXBBM6?F5c^1<1fly(EB?haOisFScH^y)jm`@bLM$o|7$zeRHdv~VI1_YThY zYa0;_K?_($y0b~x9TtTrj52ms3Iu?v@NzL)tCi^+_#onHfCS!gJX>%%kSH-ik+}dr zY9Ne` zMA4)DXNa2&K>@XL9*r`&O$AdBD9p$yCgekHLA}WCEDuXxG>f%tTCkUo%DX)Ta}Bf& zKhE}QI^jelq(_I>wW3N3BcR5qve8KtjiabyRPZ=X%m!Uc4b!gG?9sIVDOnM>qTXd$ ziO>u004xA)}v`I&jqHI8G@nv09;t+b(X$fTzI{3+C==7Afc zXv&%93mcRe(tZbxnsV}4)Gf0{O3|uFy-$|Mbai#b{MTt%xp=HFZeDlRYWGv8f(^E1 z8>Z`eT)Lwlz24_6cDS?sTUv|f&)ES@I`Bv1q>AI^kHYKr6M+Ze(KM*HSj8`x0kR4J zJzy|vOh%OWa`zE^_z>LRpCq{vxe|f{JmR$hji?l$$8Y-lBv7T9FA2sRgY0u(EJNJX z=1uv(@BUD5>Zgx)1-O7-TumYrbgt&QxpAGYReC1j$GV34D4GgqrSYqHDydBaUdT$IzJctF>byID|i3lNA|yiuqa6h zCl1@Bs>yHOD>T}ETyE62;?39>1(jE&fwD10G};vKkkOUK=s}d&b#5P!@)k9gG?FbZ z!BS8pNd=r=Sn@ZX7$6nru_2PP?0W}Y@tu?eDVjmmYLpbXiC-kbL;$J7cx&cvKDfo2 z5^f(HJvYx9!W^JFDw6u~*His6Bv{%6>HO>}Vb@6fp~SwF$)5J-T|XSb2G=p|3z~-R znOzA)uuLzpF5vgyR1XgrR*oh=M(R?(-in*uJ;8~BK7BX_+YaG zVJTxUF%p&%A*|pD=nFc>p*dXHsEpb-ek33dvsy~no`6_L@DPpFjnCI zS%4Jb91}~@kUhenb%b3JAXvjSv-dAnS2t48p#FP0lM2$JEEyMn2eNli3O2xEi6XlW2WHvIDGN4#+kz)quM#f*jd($65 z>3wsJ5zg(y(#x6(;xD;Jh|u-C1)Z2^9}SMJhzPAYSXKo{nN=j!w-78*iA<3^#N*X* zs|hTM$uKg~uM({GG@;Fz7aevU=@AX^t=m1Tu}OEh1x9(n41)r3a?&uFp>1b_4q?jK zl0_7kAm5Vu-P3HNOlFx`aaU#%O-C$I$zW8d6I z7z9mQ=Sqpw(B8>CvGX6Gj-w!>;lXQaA%=oIu*Q4)ipQk^YR4Dmw*27!Q2BgVXQt9huR8Dxb6Z4X z%8m8CjIczNfm>o`44f>Js#Y z_}z#OwUx75iRxA zP(o>EbdGOFel#8})jFF7s~ImO(A-(iQXfxO-U^az(}ItFnZN}!hu7NgMDL_}!%c}h z8O2qk_@AUC#KGDeY+KGP{OYc)-LgI;Wiv!O<_C}aq^Q+Y;mqHT!ix+S9#w$@Al4zO zW-M;`)oM)|hxDKenzhX)>jg;jw+cdAZ5AnR2kOfVr}3X*>KJC%lHEoC-tM#dAqa`3wAw$Q>FBP zsYmM~xEFb&dTV#u58jZB*XUjEU1`6qg6LV6b4?e0o_2ig&IN$pR!Bl7cjHc!bug$t zSxG6BO{QtNqa}L-xJI znz|+;_2wz$$|J=JDSt}V9=ma3b99npkRLKOCB?6LQ&Z++240wYAbMXHKK)}zUM1ei zvbafi!nT>|*t*_mHuZt;(>qeZ`fm?b%dQ{cTX}b+2m-#hN~tIqmrq>I8{>a87dXqt zu2t;fwb_dL$>?Ph8jMJFKkl{k*=`$o7h{ux`(i5~@V#z^SW`(~3wJn~HR%k3B#=W) z*56SeFkJJfD@0WzsU-y1+`T)95_eC=o;0YE-Qc*I86)2dp52KMB0ENRliig{ha#EO z?-WBV+1_cK;hJ1vHezsAmga4sR?5BC$w9>TrQ*L~zk=y| z;1xt0=jbVqxh|?QFm6^z&$AsIIfpL4#C0pq^w$Uvi8zbG!pcKr9oCuN#pOB>e#lvz zU<2Kj_UyxvcW05$B(y$rp(N$_-;8@=rWGGQFP=-b7*BM46N8bZ_> z;!NpxnG_6bSY;1Vo4!wICk7XR5I^ zdGEN!x4W%>VEfD9?|WZdLu}*=sivuMhg4+*x~#1!Vjv29&_Kyz%avX^60?8cFL+m= z{-UOOV!KZ3+Kf;Io9J5ZJv@7r^}YmV^c>-adu`|?_fQM>5Lm(3^fMg72^-17U3_5N zIrm=Awd<2hnT}86R~TGn=@s>dDBC;-&mTM;l4Jgd|k9~$ndGv+4}*1PD?kP zJaKdPrwys%Y%N~Ce`agUXj-s`BFck|omKhasyGssqL3$+mOkHo9DONU1&+H)4~7ht$6*%2lqhLm4sAgmK!`d0X@ zKeif9M(do)n^?!s)2if#@2#^kpK@XS$PoYzTo{#~?51G{sp z4u5v$R^+y#UokY-zim2;ERcqU=;8xTfPwDEAp#r9{!qnF{MCEgZNZG$XFL~oa>yb| zu5!qO1MR$+ zHG-erykv5|Lb|FInJc%e^XA^duX<(Jg)V7NNHx6dn*tqbG>oR*M%fn5AvM`ZkwL$* z1}PT7J_}X^7DFmo=Q;duOTQP!?PalU)=yCFG%&+{RT&jiD?9U!Z*v&QeA>wtApRBH zy*K*ZM!K8HU8|Lbtvd9O;lc;4Ng3j-Wa9iXa*9nXFD4$td4o7y4RuX!tprE_EDcG- z*m9c;k8RpvB%%+_>;dJc3YL!upX$X;DaxMyENiV>x75X_wMR5nQalnuE%81e$diNN zz)l7N1&^~#2SbJCSoZ6Ur=o2_ZSyrCt}pRYN9?^G-*#2*nJ#86Y{>PldgkR%!q~)1 z@*U&+L0mUA$S{( zstwV6(-!w+j^kgMIK&?Lw0^KjHd?9c3Q1)wH&Go^Y(-ed9=>0|k}e+#UmQ`13hIvt zpeG8VN2GS$s7xk`rOMh66}}3~?g?xQH8$s}3{yqpp_5&EKGt`9J`_N<&v7$Uqd}qF z^7bV+1n~%o-6y1$^MZMK2<;44KwdmpMFNOTkqx?aa(V+M3sv;s!$v7$vRfE1c+|1D zgG|Uh(Ovl_$~Y+;t@F8J0mM^oXR!I&h8e37zHo>j&E58B!uP&Zt~yMgmey^!mJt|l z$K2)RV$!~*S(drn>N<*jsO40?NJDBRtB50`4=^O-;Fwb5Z{GXJ^jjZ|T;_*6P;Oei{ zlYwuEo*)?)BxokG2B>?TQHsWs$ey|dn-d&1+@_NyqXf{Q7?N{bKC%*#E2sXI@EQJz ziS?=bNqHGmW~=z?{#|;q3S_$-UO#TF3Qpsm?WQt??>Kpi8X;gKF58=>#2>4PJXrpiDR?QMVp}!X_Rs$YEdDKl@FYGnip$5XEws6+rh``Vb7>lV z-=;0crQYJ;hF?r~g}3GOX0=p=eO~RCP#4I8QJxQ+L3LaezkNoHT~rdlW6{%=G1GH`PR%^vr0$17WHKnJ6!6! zkTrPZ!Us(IzD-ATpm)y(Xucz2{L*`c7M!Lp$vUnpytMs=i$wVkKNeAt+ju3Qlfz`E z%3bS+>?P*s)zfkab#dcc7exc^X70!t;ll=%(cdp5wWN7Hwx^#5N8EI&G)roC8WyNe zL=Lz4_@X!e;JNFo4Z1Y%bzorr%)K3A=eztort~=FhCp5rFVE^Y!L_ZF5?y0Cax-w{ zUA+6bOG--yD1Gc>&YJts%>J#NT*>cpfVk_o03X-z2GwJUbF4?Hj1e!c4eisK2Ks6# zo*^0Dk2o%e7|fD(%5exiK+Jnk++M-<$1l+!9Y?_ngGVij94A_x7qx4@l7rh%_5XMf zQGng{WOU~|!tL0px}&l(3K4p*alS<8vs43XNyOZNHr}QAdtWDhPo{gM7A-kzB;t{uDM=%V&0y)Jkjwa`wmSUZ@BRv`B9bdO_D2S)i;wJ?|sI8^mS-v!BWjf~hmMdRIu8>V%HD{gO z-tvCcKk1Y@zb~}~FZQ2#7_9yCwaO8d$vqi;CGtIL@(G`p?-DajP0(*~8T&?}13h~3 zD_OS5W+gyVVP$2dXnFjTaV}q==B+f_t_js|w0-(uT*imlE#SD*Z-|A7>FVz4+JWEw zJU2Jz?@m6nS!*^*L(_k%bLR0mdMgr_&}XPK;fq$U~#UbXGZLs**47-(G%y zr^EkFmV4HETp1i@+^!B4x$MVR@wsbUwe!xv*|CVQBnIfpKRUGNz3xr_lqs6}oM>Zd z`J0@K?7y#p03ks9`O_|JIIs#MF)%g8T6qSgs8F*PrwK(B(>5>26hfM-E``F$4(-dk z`-nn5#-=-XRHvC%7hE(lyU&+8&<?d#5iC;lG+fZ|MTTrqyO9MOQh6J zQN$q*ZbALRb?3Ri1#IX`HIXS$R~?(Umktcs7;as9tB^Sxvwro2!!+2YXnD6!8pr&0 ze@9xWIJg6#E^vvIb)H}a=*YL+>?Nwau1bbu`GQeud~FK~vgl-D+aac=rtWO1Pt^-e)!W$J=m9ufv1HVR|u#t?nu`8o%U-)&>JR!W3HCyd*)xszv|f z$AcXIse51S0H0m5%?I=_V;@=QOSIZwj=`l#{Lk-8nUmBe6_u1;MwaU=ELPlx4i7DT zV9VYe1QC;wf(azZ-E{d{D0aaS{WHD2VnwrQk{ZIibIfC!i1YxzqmUTyKN{S>hlPjU z>cntunhJ~*Zm2}prD(@+@d2W>e6d4M2(s{=n!E1UeDQTWD5PCnCj=_7W{HLDimeVR zX!Q%Mi>_}+OEnOGEf|9ZXs@hf>$KnOd>a9I>w27b9eQp^rkK4T)BZi0qVH7u8yXoI zX-GmvmGk$4h>h$`Gs9%MDx>fDrS@RlYFtdbdyCK?BJ|=NL#9u6ih2o70{V9!-)YeRUgOEC@KFaTQ>i%FsYU(YQV06Ir{Xm4<-!nz0_!(oB~32JqKpy_72m*#&^(`w>waFkS zY@@ZE*Z?`^NjU1kCDo-yarVJGYz&O&Kd_}w_0YMQ7V#HuN)w;@=4ttKN9JT~bry|^ zE@nFBnn_x|BAicO;<$^jAk?`x~7l;F1Z`NK7p)i)G|Xl(U5& z=g!vKKGA-Ea4h%&@$q?1)2T2IuU~>Ul4pj{7;&nNT&k7a^n`|n?v9(!BIPCwoB9h= zzG2eJFEzgKO^V#F4e3;9v`K3*XN>!8{mHODBbGQhIy&;)?CIoKsg_0qRzUDZNJHuqPJJGFqw~r;G6?-x00L|xlgUlpo6of!Y|J9xX6~d%ru7y!6LZLY0Ff?nn@))M)yu{ayV%dMn z@RLH1ulemfrL!6%-G>=-ewXH)E>=lf8aS71<8-*-o+y(IoFpvY-WPUQE zU?DTA2QJ8ZlTNx{?*D#@jW<|Uy{cjt6VPN$Rb^cT=wx0OnrYJ}%ir!_KT<5)xJ5_c zeTPQEA0io9R!|gZj3HGtq-SS~qEi!3BsSXWdS`2LDLIESTT{4_e(EsKUb1u$j_~cv zsDCsJ`9;;DVYi3;nbn6ZIX}UHk%>v=Y^i3~ZM0TRx6!7>0+xQT7F}UsmE2Ax*nk~rovOx2T3oK_i1IZxz@VWJODfim(Y!b)?I!Dp;ag8GF74kA9K zI&`oi)K(e*ibH9^vLz4_9=h{Z9Mqx$JaihSsxi{$T6(uUyA9wD{vf`x66NE&m+<$0 zgZZ5E=xCPVr|$7jk@q>)c|{GiLhLXSj#)vGi9{A&rWGNAT$oDwkPzt3>fyoB=lFhf znjqwoTPF3VhM=$2RwL{|7yZwkCegNl ze_)Fop=!w=m?#o-{=^0IGH;l4n2SS80+YBQHA@bRi7jPKP4~Lt*i^68YVtCGT*-ju zQE`uM8e039AMmt+ZTo~mddb@K<~!k=+aW;;+wV6D-E6m;Xtx|BtCH$Y%rQhq>2#Dr zl32Vbr!B>LuNx&vnP6L2r^RHp@2NapszMC`;>|(P1ZJZb35&V9hp08j~HMc&4AIjm3`oe`)wEK z0Ats&?K96??HJ_Ot7{$K>#QyrN4HS8psJ1N6jNN~={CKPy@wlYM6!~}0(N7QRZ+q~ zy>Pa06K1rLq7AX*?JRY+nTZwe5uSi?*T~Kk9k#B24K&UzsH#mBH6;aG$@HDvD!N$ZqwSh*N*9rXRpR#$X{Loc5SV$bgCg-na zML_(OV_!{*(Z85+|9i!dl}J<~4jv`=Qd+3;x;Nu#T@4 za`1|e=ImuQ>A@47l$xxDx#*e&OQy4Z`1{?uH&2&VNqcQPl-Gr+iZ=GxLHz#0s<8>bOtYt*SIki`)YOcg{cMFFp* zE3Gz)q{-6PTctyeTw2R?Dv0Q;IBa2xc^#Qw6O2HD<e~` z6D}9^vyy%a_nhtu|8_{{WlV^9*AN)8NJq6RH@ z!-f}za+EHR$}=N&U-^n@u}8Adge<3-;FZuu@Lc7#KR!MdH7pPgYE5o!ZDmmqP9__J zU_Hef3NA_KIn~G1(Sh4%M_i>Xj=|>%jA$4x(XKWEL+AfP?nP(0SLZMueMG&FE1F&r zAU5hlkBwFkC=Bs^tTucprP4sqdcP$0n$3mfci;ejE^um;o5v>9aIlr2w-LFtfn9|H zGgl8!yca$b#Dj9B1Ml*X&=ABa;r4h?ac)?# znc)z`b#hVH^6w-wa!aOHkp2Q3trtse1vu%`3vJVOu4+fKI>t}NG6fE9j1L^%1cVgS z@R*%hF{^X?_p!ncGS9o-HtqM%I-ky*3$2KLPcDJ%EEcf4sO7rZ;i+qgnwQyBmcIrI z$IU+ON?&rIIug^1Lgjaj>xQVmfolduxK=za1?PL8OrAPiNg;u>ssYSC*s$o9^zwteDY zF4(l>e&xZCl(z10*|H_3vQCeJXD^-qdj;!S4Ph(9UyzIIdZ5l?QnVX15BE?G0AO7G z_rCzTH7p-;CJ$7!Qe0D4RPesTb0C|w&3YOy4Cjo=^}Qd!a~25<*CEGd!f*Yic(#Jo zl9<+@P5xUq9G(eZoCqAJzW^Bw=JVV%&64Z7e}UmK*wAWr;-#gf ze>`>S)P1>J?(=hVbKjbonOT)m_Ds{9v@B~uN*Q#!-JdNlFTa&If*{T`HOG{85=3(; z-^dU`MDM)w&Obf);DfnhvG|9DLgCYeLg6z~N+G3ebvm72luD&1EX%q#F*R~pOrNz@ zs=xW0R_QNKc$m5~5U7L#4j=9nzSgV6B+j@TFHV@-Rl-Mm0-p#5j3y_W9ED^sky?Oo z%XNP)H&#fsb!T;T_5AGY?7fcT90LHyaTez1=f9#(UL40w#@MFgIClX+KA)e-=kvK< zuh+$JJ><}SX~7j5!IT*85ZxUhO>lD-ISYsEdKn$Jl_p&1cDvn;YPI@JbAKRDwQ5FO|vYeWQ?)*7-I;6z-NqI z;GA#7aZDSgwinxV-NvO$m%e-a`0-1{V(|+}IMxKf8Dnp{uKUd5;^Hfub2W`sGREp* z7+z$IeSl$RMiIwxi*x>3GMd^Vt;Xt~w0f83kozO48Q(V)#+1M#b%wX@=$DR2130@CBgY5w z^b?`LLrsp2VqeZQqriWr`N5J4uA0-@0GgiXxr>X7Ke_+@`@iHk&dFp3JA@FS=Xpyj zD=ROR%jMaHg@r#;X4ur!)MV1j6LZcRaU8EFpP}7`s%|Y7LTqu)SCZg~lv2h>_uFh& z1sl8h9nay^vD27XzS+^Koh}9;zK(a!Csg=b0M-Gl0;r(MEdN>-&(nKezbx&$dDPE+(RdKP!6QJZ$)9Jn-bhD1Y04vF}1pn56zbqvu4;ps!07Jtdca{}#Nh#+&e6xnE?>`k{MbgBpWBlSNqJFGfz5>^H>x`|Lgnyauh{@X_`~z za`{}TRC>ZN4AXVp7d_AGW|)HvK=dr?%YTg{>p5WNX7AfNqTri&|I+!s=Ahtc5Dnrc z@2LZ>>gfvPuxE`vh={;sL~Gl`)bxmkrstd!fcWGdyVhbEJqYu#X^=PIHN}9)fNGGQ z1`we|F-%QjQ=3xuBD^wk%87wtdF7?N1ep zMFlX^Fbqow5w=>bUoI~%zf3?sG_Sr2#@pZ*%CJt|%sqP#f%hGJu$X{D<*ZcuGi8)% zCGR5xYv?vH3=o|!7f7>$ z&?J(;Fm;cC^eAfs!}H*EN*)R>p(Ugg*s=h^Ga@cR1EVBnk`2IgUH6&k>FF)YvK}%F zV;(?W2*JWIyjrW(URzsRtHyCGiLay%7X`Grj_B26$bHr5k5xX6Y>>mMJIH!_rA`NG=!wIO&*^>&C!1iC`$-J9bm|qwIvACN+a9;QxVU&3 zz`Let79Gc#0#J(M*kO$2$N@457%88ZIt*4F@dq66?S3Wkf##~7gS+uVRNr4k)X~hU zdIF3ZN$R$Ud85o@DTlHI^C zKftJ&5~(tSj8cRwuw-d~IO9H91anzQEvbRdBsQ{0!k4Vq>-Dt1kN(Y^NM4;sN_>d0 zDj++6abN)11PlKj8y`N6TGfZ}iRPdYt4$g)!hmimCI?&z95chG8%4sW`_eLF4-B$T zS=9L z1L+Fhkbr_pLCQOvVgq>_evS7f`9Xx><(u%Ee~YW{y$R2iq=*y)UaJ}biDIy%99LAU z)3qG6FWBLG#)v({i1TqxiNZs5Nl0vh1v2e;Qu~@NuGrHphyQO}!)Hc)-q_*y%jm4q?z&$WB})_3J`&8j#}|C21gc1 z1hT0$fnkbLYR_NSK@1@Hy9m1f3Ags|a5q*Fd2zqhfDSnACLqX~x6(nn(m^+=wd^465fL4s1sDm}rx06$TQ3G)M5e``~N?toJ&+=8I@`Ja3p!YiJyhKn^*8jFUL~9w8!+y`*sBJivGxdqDNQy8?VJt>^WQ#$MDLeS60L)D z!YLXz=kFub9+ZbmCHC6M`@KYa7)Up8(UKJk3Yz4LvA;u34?RF=q)6GJT@1SI0uWYm zWRJPpZ!Mx6MpZVg01_abaJqf%d?^VZ63x%Z{(|@)5z;ft^@31=;rgkM%^ui$TufCR zN;zcPNcSKd1VH2nZKih;(u^!_gJe%@s-%8T1B>225hH_|2-#WskKMZ4dt68(0SGOn z*4tBYzyJZ#EvMp>`h z0J(ODJ*!DfZ`!)0Kyf_>IcqUZT>EV58wCioO}m`~*&mSXwg * { - background-color: #e5bf5e; - border: solid 2px; - padding: 1em 1em 1em 1em; - margin: 1em; - text-align: left; -} - -textarea, select, input { - background-color: #ffec9e; - border: 1px solid; - padding: 1px 3px 1px 3px; -} - -table.user input[type="text"], table.user input[type="password"] { - width: 15em; -} - -table.peer textarea { - height: 20em; - width: 42.3em; - -} - -table.peer input[type="text"] { - width: 38em; -} - -.menu { - text-align: right; - background-color: #e5bf5e; - padding: 3px; - border-bottom: solid 2px; -} - -a { - color: black; - text-decoration: none; -} - -a:hover { - text-decoration: underline; -} - -h1 { - margin-top: 1.5em; - font-size: 2.1em; - white-space: nowrap; -} - -hr { - border: solid 1px; -} - -a img { - border: none; -} - -.center { - text-align: center; -} - -.left { - text-align: left; -} - -.right { - text-align: right; -} - -.fleft { - margin-right: 2em; - float: left; -} - -.fright { - float: left; -} - -.cleft { - clear:left; -} - -.cright { - clear:right; -} - -.both { - clear:both; -} - -.error { - color: #dd0000; -} - -table.list * { - padding: 0px 1em 0px 0.2em; -} - -table.list tr td, table.list tr th { - border: solid 1px; - border-color: black; -} - -table.list tr th { - background-color: #ffec9e; -} - -table.list tr:nth-child(odd) td { - background-color: #f2cd6f; -} - -table.list tr td a { - text-decoration: none; - display: inline-block; - width: 100%; -} diff --git a/src/medsrv/templates/user/add.cs b/src/medsrv/templates/user/add.cs deleted file mode 100644 index 82442c543..000000000 --- a/src/medsrv/templates/user/add.cs +++ /dev/null @@ -1,28 +0,0 @@ - -
- -
- - - - - - - - - - - - - - - - - - -
min. characters
- - -
-
- diff --git a/src/medsrv/templates/user/edit.cs b/src/medsrv/templates/user/edit.cs deleted file mode 100644 index de311cd3d..000000000 --- a/src/medsrv/templates/user/edit.cs +++ /dev/null @@ -1,35 +0,0 @@ - -
- -
- - - - - - - - - - - - - - - - - - - - - - - - -
min. characters
- - - -
-
- diff --git a/src/medsrv/templates/user/help.cs b/src/medsrv/templates/user/help.cs deleted file mode 100644 index 58615c14a..000000000 --- a/src/medsrv/templates/user/help.cs +++ /dev/null @@ -1,34 +0,0 @@ - -
-

strongSwan Mediation Service web frontend

-

This web application builds the end user front end for a Mediation Service -as defined in the - -IKEv2 Mediation Extension draft.

-

Mediation connection

-

The authentication between Mediation Server and connecting clients is based -on RSA public keys. The identities used for IKEv2 are the public key identifier -of each clients key, encapsulated in a ID_KEY_ID identity.

-

The public key of this Mediation Server is:

-
-----BEGIN PUBLIC KEY-----
-MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzZRsIp99UrIdoctThOfc
-r2Up92BTSlY1Xv1J6Hqcbx3dX/MDvX60nCPeA63Eh0VvQetfkpR73I/42+RD+NES
-4NosmBRefE0c0Vzd0IV39NTz0KLh2jwIyUzYGXWHUZMeepckzEPXOhG44XaiaLTN
-u/OZXLCXI6vJv8R3wl5xSkZhqEwHi+dATYmGvlXyBDfjprJ4o8yJrsCFlB8aGq+v
-SyKuFG/kaE1VZ9wwZYoyCH0BuYUVBwyxZTMRy2EC+CqDxjjCp5mF27lgB1Lpy8Jy
-AUpcVHtKtZEww6lIZYv/eUtvICz5WTn/pzsQUh8FwGDOyxX4WX7ZXXK55AXuMfG1
-2QIDAQAB
------END PUBLIC KEY-----
-

The Mediation Server is reachable at mediation.strongswan.org.

-The mediation server allows connections from all registered peers.

-

Mediated connections

-

The authentication between mediated clients is done between clients, they -can use own keys or the same keys as defined for authentication of the -mediation connection. -

-
- -
-
-
- diff --git a/src/medsrv/templates/user/login.cs b/src/medsrv/templates/user/login.cs deleted file mode 100644 index fbf5b8bd7..000000000 --- a/src/medsrv/templates/user/login.cs +++ /dev/null @@ -1,23 +0,0 @@ - -
- -
- - - - - - - - - - - - - -
- - -
-
- diff --git a/src/medsrv/user.c b/src/medsrv/user.c deleted file mode 100644 index 3907870e6..000000000 --- a/src/medsrv/user.c +++ /dev/null @@ -1,73 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -#include "user.h" - -typedef struct private_user_t private_user_t; - -/** - * private data of user - */ -struct private_user_t { - - /** - * public functions - */ - user_t public; - - /** - * user id, if we are logged in; otherwise 0 - */ - u_int user; -}; - -METHOD(user_t, set_user, void, - private_user_t *this, u_int id) -{ - this->user = id; -} - -METHOD(user_t, get_user, u_int, - private_user_t *this) -{ - return this->user; -} - -METHOD(fast_context_t, destroy, void, - private_user_t *this) -{ - free(this); -} - -/* - * see header file - */ -user_t *user_create(void *param) -{ - private_user_t *this; - - INIT(this, - .public = { - .set_user = _set_user, - .get_user = _get_user, - .context = { - .destroy = _destroy, - }, - }, - ); - - return &this->public; -} diff --git a/src/medsrv/user.h b/src/medsrv/user.h deleted file mode 100644 index 85d22d1a7..000000000 --- a/src/medsrv/user.h +++ /dev/null @@ -1,58 +0,0 @@ -/* - * Copyright (C) 2008 Martin Willi - * - * Copyright (C) secunet Security Networks AG - * - * This program is free software; you can redistribute it and/or modify it - * under the terms of the GNU General Public License as published by the - * Free Software Foundation; either version 2 of the License, or (at your - * option) any later version. See . - * - * This program is distributed in the hope that it will be useful, but - * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY - * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License - * for more details. - */ - -/** - * @defgroup medsrv medsrv - * - * @defgroup user user - * @{ @ingroup medsrv - */ - -#ifndef USER_H_ -#define USER_H_ - -#include -#include - -typedef struct user_t user_t; - -/** - * Per session context. Contains user user state and data. - */ -struct user_t { - - /** - * implements context_t interface - */ - fast_context_t context; - - /** - * Set the user ID of the logged in user. - */ - void (*set_user)(user_t *this, u_int id); - - /** - * Get the user ID of the logged in user. - */ - u_int (*get_user)(user_t *this); -}; - -/** - * Create a user instance. - */ -user_t *user_create(void *param); - -#endif /** USER_H_ @} */ diff --git a/testing/tests/p2pnat/medsrv-psk/description.txt b/testing/tests/p2pnat/different-nats/description.txt similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/description.txt rename to testing/tests/p2pnat/different-nats/description.txt diff --git a/testing/tests/p2pnat/medsrv-psk/evaltest.dat b/testing/tests/p2pnat/different-nats/evaltest.dat similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/evaltest.dat rename to testing/tests/p2pnat/different-nats/evaltest.dat diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/alice/etc/iptables.rules b/testing/tests/p2pnat/different-nats/hosts/alice/etc/iptables.rules similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/alice/etc/iptables.rules rename to testing/tests/p2pnat/different-nats/hosts/alice/etc/iptables.rules diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/alice/etc/strongswan.conf b/testing/tests/p2pnat/different-nats/hosts/alice/etc/strongswan.conf similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/alice/etc/strongswan.conf rename to testing/tests/p2pnat/different-nats/hosts/alice/etc/strongswan.conf diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/alice/etc/swanctl/swanctl.conf b/testing/tests/p2pnat/different-nats/hosts/alice/etc/swanctl/swanctl.conf similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/alice/etc/swanctl/swanctl.conf rename to testing/tests/p2pnat/different-nats/hosts/alice/etc/swanctl/swanctl.conf diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/bob/etc/iptables.rules b/testing/tests/p2pnat/different-nats/hosts/bob/etc/iptables.rules similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/bob/etc/iptables.rules rename to testing/tests/p2pnat/different-nats/hosts/bob/etc/iptables.rules diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/bob/etc/strongswan.conf b/testing/tests/p2pnat/different-nats/hosts/bob/etc/strongswan.conf similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/bob/etc/strongswan.conf rename to testing/tests/p2pnat/different-nats/hosts/bob/etc/strongswan.conf diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/bob/etc/swanctl/swanctl.conf b/testing/tests/p2pnat/different-nats/hosts/bob/etc/swanctl/swanctl.conf similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/bob/etc/swanctl/swanctl.conf rename to testing/tests/p2pnat/different-nats/hosts/bob/etc/swanctl/swanctl.conf diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/carol/etc/iptables.rules b/testing/tests/p2pnat/different-nats/hosts/carol/etc/iptables.rules similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/carol/etc/iptables.rules rename to testing/tests/p2pnat/different-nats/hosts/carol/etc/iptables.rules diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/carol/etc/strongswan.conf b/testing/tests/p2pnat/different-nats/hosts/carol/etc/strongswan.conf similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/carol/etc/strongswan.conf rename to testing/tests/p2pnat/different-nats/hosts/carol/etc/strongswan.conf diff --git a/testing/tests/p2pnat/medsrv-psk/hosts/carol/etc/swanctl/swanctl.conf b/testing/tests/p2pnat/different-nats/hosts/carol/etc/swanctl/swanctl.conf similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/hosts/carol/etc/swanctl/swanctl.conf rename to testing/tests/p2pnat/different-nats/hosts/carol/etc/swanctl/swanctl.conf diff --git a/testing/tests/p2pnat/medsrv-psk/posttest.dat b/testing/tests/p2pnat/different-nats/posttest.dat similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/posttest.dat rename to testing/tests/p2pnat/different-nats/posttest.dat diff --git a/testing/tests/p2pnat/medsrv-psk/pretest.dat b/testing/tests/p2pnat/different-nats/pretest.dat similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/pretest.dat rename to testing/tests/p2pnat/different-nats/pretest.dat diff --git a/testing/tests/p2pnat/medsrv-psk/test.conf b/testing/tests/p2pnat/different-nats/test.conf similarity index 100% rename from testing/tests/p2pnat/medsrv-psk/test.conf rename to testing/tests/p2pnat/different-nats/test.conf