Tobias Brunner
1960312cfd
Avoid parsing retransmits we already responded to.
...
Decryption will fail as we already moved the IV when we sent the
response. Without this change, encrypted retransmits would have been
discarded during parsing already.
2012-03-20 17:31:08 +01:00
Tobias Brunner
68c6863bbb
Moved main part of message processing to task managers.
...
This will allow individual error handling for each IKE version and should
allow better handling of IKEv1 retransmits.
2012-03-20 17:31:08 +01:00
Tobias Brunner
44ff1153e8
Addded ike_sa_t.set_statistic to set timestamps from task manager.
2012-03-20 17:31:08 +01:00
Tobias Brunner
38d189eee9
Compiler warning fixed in prf_plus_t.
2012-03-20 17:31:07 +01:00
Tobias Brunner
fd24c700fb
Use proper enum types in proposal_substructure.
2012-03-20 17:31:07 +01:00
Clavister OpenSource
52ac2cebe2
IKEv1 XAuth: Fix XAuth task so that it reinitiates.
2012-03-20 17:31:07 +01:00
Clavister OpenSource
e63cb7f816
Revert "IKEv1 XAuth: Temporarilty add an "initiate_later" flag to the task manager. When set to TRUE it will cause "initiate" to be called when the current process_response call is finished. This change should be reverted once we have a better method in place."
...
This reverts commit c6c28f4ac522dd8afb457847bca79eee77f78706.
Revert "IKEv1 XAuth: Added temporary "initiate_xauth" public method to ike_sa_t. This allows us to initiate an XAuth password authentication exchange after responding to the final message of Main Mode. This change should be reverted once we have a better method to initiate this exchange."
This reverts commit 5529dc50477e25df9dd5f3c442bb1521c0baf225.
2012-03-20 17:31:07 +01:00
Clavister OpenSource
2c49c53186
IKEv1 XAuth: Fix main mode to work with XAuth PSK.
2012-03-20 17:31:07 +01:00
Martin Willi
a2f8fc9711
Use a dedicated IKEv1 vendor ID task to fix using IKEv2 payloads in IKEv1
2012-03-20 17:31:07 +01:00
Martin Willi
abf9784786
Pass concrete auth_method to key derivation, as we have that as a responder
2012-03-20 17:30:53 +01:00
Martin Willi
b4e815354c
Map auth_class to auth method and IKEv1 proposal attribute
2012-03-20 17:30:53 +01:00
Martin Willi
eeca2af81c
Removed obsolete transform attribute setters
2012-03-20 17:30:53 +01:00
Martin Willi
914ec2dbf2
Implemented IKEv1 attribute encoding in SA payload
2012-03-20 17:30:53 +01:00
Martin Willi
fbebc2a068
Implemented encoding of additional IKEv1 proposal attributes
2012-03-20 17:30:53 +01:00
Martin Willi
cd0017d452
Exchange IKEv1 ESP SA proposal information
2012-03-20 17:30:53 +01:00
Martin Willi
132d5c56de
Exchange IKEv1 SA specific proposal data with SA payload
2012-03-20 17:30:52 +01:00
Martin Willi
e174e0d445
Added not-yet used sa_payload parameters used in IKEv1
2012-03-20 17:30:52 +01:00
Martin Willi
d08269c700
Added a get_rekey/reauth_time() jitter parameter to get time without randomization
2012-03-20 17:30:52 +01:00
Clavister OpenSource
b03c700d08
IKEv1 XAuth: Changed the xauth_request task to use the new MIGRATE status.
2012-03-20 17:30:52 +01:00
Clavister OpenSource
b94f248ea9
IKEv1 XAuth: Added new MIGRATE status type to status_t.
...
When a task returns this status from a build or process method, it is a signal to the task manager that it should treat it as if the task returned SUCCESS.
Additionally it will migrate all remaining tasks from the current queue to a different one, calling swap_initiator for each applicable task.
Finally, the task manager will call "initiate", if applicable, to kick off tasks in the "queued_tasks" queue.
Task queue relocation mapping:
passive_tasks moves to queued_tasks (which is then fed to active by the initiate call).
active_tasks moves to passive_tasks
2012-03-20 17:30:52 +01:00
Clavister OpenSource
46897273d7
IKEv1 XAuth: Added new "swap_initiator" method to the standard task_t interface. This is needed for when we move a task from the passive queue to the active one. I'm not a huge fan of this method of doing things. Perhaps we should change task_t to have build_i, build_r, process_i, and process_r methods, and call the appropriate one from the task manager, since we have these methods for most tasks anyways.
2012-03-20 17:30:52 +01:00
Clavister OpenSource
cc50df9e6c
IKEv1 XAuth: XAuthInitPreShared working for XAuth initiator (Main Mode responder). Creates USER/PASS request, retrieves the result and sends status.
2012-03-20 17:30:52 +01:00
Clavister OpenSource
2d97ec0d35
IKEv1 XAuth: Added ability to initiate the XAuth transactions under a flag, default not to initiate XAuth.
2012-03-20 17:30:52 +01:00
Clavister OpenSource
8b30286fcf
IKEv1 XAuth: Add XAUTH authentication types to the enum. Added the ability to switch between hardcoded PSK and XAUTH_INIT_PSK authentications using a flag, default to PSK.
2012-03-20 17:30:52 +01:00
Clavister OpenSource
ece4ed3fcd
IKEv1 ConfigMode: Fix configuration_attribute encoding rules for IKEv1 to use the attribute type instead of the internal only payload type.
2012-03-20 17:30:52 +01:00
Clavister OpenSource
0b6811b4a7
IKEv1 ConfigMode: Fixed cp_payload to use CONFIGURATION_ATTRIBUTE_V1 in all appropriate places, so the parsing is done correctly.
2012-03-20 17:30:51 +01:00
Clavister OpenSource
01685247b0
IKEv1 XAuth: Added ike_vendor task to the ID_PROT exchange type processing. We need to process vendor payloads to check to see if our peer understands XAuth before using any of these payload types.
2012-03-20 17:30:51 +01:00
Clavister OpenSource
e3bb68841a
IKEv1 XAuth: Added temporary "initiate_xauth" public method to ike_sa_t. This allows us to initiate an XAuth password authentication exchange after responding to the final message of Main Mode. This change should be reverted once we have a better method to initiate this exchange.
2012-03-20 17:30:51 +01:00
Clavister OpenSource
adf7b76f4c
IKEv1 XAuth: Temporarilty add an "initiate_later" flag to the task manager. When set to TRUE it will cause "initiate" to be called when the current process_response call is finished. This change should be reverted once we have a better method in place.
2012-03-20 17:30:51 +01:00
Martin Willi
9cc38c8efb
Use quick mode task initiator flag instead of passing it as parameter
2012-03-20 17:30:51 +01:00
Martin Willi
4e0bc9af22
Add quick mode ID payloads only if establishing a non-host2host tunnel
2012-03-20 17:30:51 +01:00
Martin Willi
c4b8539f93
Refactored traffic selector handling in quick mode
2012-03-20 17:30:51 +01:00
Martin Willi
818330aafe
Refactored NONCE payload handling in quick mode
2012-03-20 17:30:51 +01:00
Tobias Brunner
78f7728c30
No need to build a HASH payload in XAUTH task.
...
It gets added automatically when the message is generated.
2012-03-20 17:30:51 +01:00
Martin Willi
c4c5950458
Create host-to-host traffic selectors if quick mode identities missing
2012-03-20 17:30:51 +01:00
Tobias Brunner
97265a8927
Removed redundant '=>' when logging binary data in parser and generator.
2012-03-20 17:30:51 +01:00
Tobias Brunner
f4e21faa98
Fixed encryption of IKEv2 messages.
2012-03-20 17:30:50 +01:00
Martin Willi
d020d4d695
Print message payload names after prepending IKEv1 HASH payload
2012-03-20 17:30:50 +01:00
Martin Willi
da063ec95e
Fixed task_manager_v1 compiler warnings
2012-03-20 17:30:50 +01:00
Martin Willi
3e246c4883
Generate a new mid only after we start a new task (and exchange)
2012-03-20 17:30:50 +01:00
Martin Willi
a7910b1c6e
Derive IKEv1 CHILD_SA keymat twice, once for each IPsec SA
2012-03-20 17:30:50 +01:00
Martin Willi
85f5c478bf
Fix seed construction for IKEv1 key derivation
2012-03-20 17:30:50 +01:00
Martin Willi
9cc8bd4fd2
Use a dedicated message hash to detect IKEv1 retransmissions
2012-03-20 17:30:50 +01:00
Martin Willi
7a7f486df6
Include hardcoded tunnel mode attribute in porposal, remove ESN attribute
2012-03-20 17:30:50 +01:00
Tobias Brunner
cd200cb821
Authenticate and verify Phase 2 IKEv1 messages with appropriate hashes.
2012-03-20 17:30:50 +01:00
Tobias Brunner
1e5dd62bb2
Fixed verification of DELETE_V1 payloads.
2012-03-20 17:30:50 +01:00
Tobias Brunner
f3cc8589b1
Fixed header length calculation of DELETE payload.
2012-03-20 17:30:50 +01:00
Tobias Brunner
d6cec44b24
Fixed conftests after extending CERT payload.
2012-03-20 17:30:50 +01:00
Martin Willi
b6016fcab3
Fixed a config reference leak in IKEv2 initiate
2012-03-20 17:30:49 +01:00
Martin Willi
384c1a32a2
XAUTH is initiated based on configuration, no need to call externally
2012-03-20 17:30:49 +01:00