Tobias Brunner
29a5e0707e
Handle unsupported IKEv1 exchange types more specifically.
2012-03-20 17:31:08 +01:00
Tobias Brunner
983e852af8
Handle INFORMATIONAL_V1 messages when no keys have been derived yet.
...
This allows to gracefully process the INFORMATIONAL_V1 message rules which
require the payloads to be encrypted and thus the exchange to be
authenticated with a HASH payload. If such an exchange is now initiated
before the ISAKMP_SA is established, the message is simply sent unencrypted
and without HASH payload.
2012-03-20 17:31:08 +01:00
Tobias Brunner
fd24c700fb
Use proper enum types in proposal_substructure.
2012-03-20 17:31:07 +01:00
Martin Willi
b4e815354c
Map auth_class to auth method and IKEv1 proposal attribute
2012-03-20 17:30:53 +01:00
Martin Willi
eeca2af81c
Removed obsolete transform attribute setters
2012-03-20 17:30:53 +01:00
Martin Willi
914ec2dbf2
Implemented IKEv1 attribute encoding in SA payload
2012-03-20 17:30:53 +01:00
Martin Willi
fbebc2a068
Implemented encoding of additional IKEv1 proposal attributes
2012-03-20 17:30:53 +01:00
Martin Willi
e174e0d445
Added not-yet used sa_payload parameters used in IKEv1
2012-03-20 17:30:52 +01:00
Clavister OpenSource
8b30286fcf
IKEv1 XAuth: Add XAUTH authentication types to the enum. Added the ability to switch between hardcoded PSK and XAUTH_INIT_PSK authentications using a flag, default to PSK.
2012-03-20 17:30:52 +01:00
Clavister OpenSource
ece4ed3fcd
IKEv1 ConfigMode: Fix configuration_attribute encoding rules for IKEv1 to use the attribute type instead of the internal only payload type.
2012-03-20 17:30:52 +01:00
Clavister OpenSource
0b6811b4a7
IKEv1 ConfigMode: Fixed cp_payload to use CONFIGURATION_ATTRIBUTE_V1 in all appropriate places, so the parsing is done correctly.
2012-03-20 17:30:51 +01:00
Tobias Brunner
97265a8927
Removed redundant '=>' when logging binary data in parser and generator.
2012-03-20 17:30:51 +01:00
Tobias Brunner
f4e21faa98
Fixed encryption of IKEv2 messages.
2012-03-20 17:30:50 +01:00
Martin Willi
d020d4d695
Print message payload names after prepending IKEv1 HASH payload
2012-03-20 17:30:50 +01:00
Martin Willi
7a7f486df6
Include hardcoded tunnel mode attribute in porposal, remove ESN attribute
2012-03-20 17:30:50 +01:00
Tobias Brunner
cd200cb821
Authenticate and verify Phase 2 IKEv1 messages with appropriate hashes.
2012-03-20 17:30:50 +01:00
Tobias Brunner
1e5dd62bb2
Fixed verification of DELETE_V1 payloads.
2012-03-20 17:30:50 +01:00
Tobias Brunner
f3cc8589b1
Fixed header length calculation of DELETE payload.
2012-03-20 17:30:50 +01:00
Tobias Brunner
d6cec44b24
Fixed conftests after extending CERT payload.
2012-03-20 17:30:50 +01:00
Martin Willi
017d98bf39
Merged IKEv1 attribute payload/data into configuration payload/attribute
2012-03-20 17:30:49 +01:00
Clavister OpenSource
c71760570e
IKEv1 ConfigMode: Added the payload handlers for attribute_payload and data_attribute payload types.
2012-03-20 17:30:49 +01:00
Clavister OpenSource
54a8a94fa9
IKEv1 ConfigMode: Added TRANSACTION exchange type. Added attribute_payload (IKEv2 equiv cp_payload) and data_attribute (IKEv2 equiv configuration_attribute) payload types. Did not combine with IKEv2 because it wasn't trivial to do so. This might be a task worth investigating in the future, because there is a decent amount of shared code here.
2012-03-20 17:30:49 +01:00
Clavister OpenSource
9769b76cab
Updated the CERT payload to work for both IKEv1 and IKEv2.
2012-03-20 17:30:49 +01:00
Martin Willi
d50152a70b
Parse proposal substructure with multiple IKEv1 transforms to multiple proposals
2012-03-20 17:30:49 +01:00
Martin Willi
62a27ba347
Encode multiple IKEv1 proposals in a single transform substructure
2012-03-20 17:30:48 +01:00
Martin Willi
f9450fc9f7
Remove public sa_payload.add_proposal() method
2012-03-20 17:30:48 +01:00
Martin Willi
cd89f1a074
Only add the first algorithm of a kind to IKEv1 transforms
2012-03-20 17:30:48 +01:00
Martin Willi
f5c0096086
Hardcode some SA lifetimes until we can configure them dynamically
2012-03-20 17:30:48 +01:00
Tobias Brunner
4c6dfbb26b
Added missing comma after ME_CONNECT declaration.
2012-03-20 17:30:48 +01:00
Tobias Brunner
8c5e78ae4f
Fixed creation of endpoint notifies.
2012-03-20 17:30:48 +01:00
Tobias Brunner
21da1087a5
Fixed diagram of IKEv1 encrypted "payload".
2012-03-20 17:30:47 +01:00
Martin Willi
cc9629d87c
Partially implemented IKEv1 ESP proposal en-/decoding
2012-03-20 17:30:47 +01:00
Martin Willi
e1f9d6476e
Register HASH_V1 in payload factory
2012-03-20 17:30:46 +01:00
Martin Willi
7fcd26f4fc
Fix payload length of id_payload created from a traffic selector
2012-03-20 17:30:46 +01:00
Tobias Brunner
42a69b05ab
String for ENCRYPTED_DATA fixed.
2012-03-20 17:30:46 +01:00
Tobias Brunner
780ce7724d
Strings for ENCRYPTED_V1 payload added.
2012-03-20 17:30:46 +01:00
Tobias Brunner
d66199884f
Set flags on message according to IKE version when parsing header.
2012-03-20 17:30:46 +01:00
Tobias Brunner
c92f2cf36d
Encrypt IKEv1 messages.
2012-03-20 17:30:46 +01:00
Tobias Brunner
477e856a15
Decrypt IKEv1 messages.
2012-03-20 17:30:46 +01:00
Tobias Brunner
6f5f8ee4b5
Use modified encryption payload to encrypt/decrypt complete IKEv1 messages.
2012-03-20 17:30:46 +01:00
Tobias Brunner
0cec72df40
Provide keymat_t to message_t to encrypt/decrypt data.
2012-03-20 17:30:45 +01:00
Tobias Brunner
50d493808c
Avoid compiler warnings due to extended enums.
2012-03-20 17:30:45 +01:00
Martin Willi
3bd5fcc832
Print message ID as unsigned integer
2012-03-20 17:30:45 +01:00
Martin Willi
9e40e3e9fa
Added message encoding rules for quick mode
2012-03-20 17:30:45 +01:00
Martin Willi
cbb6d765bc
Fixed length calculation of delete payload
2012-03-20 17:30:44 +01:00
Martin Willi
4ea258538e
Update header length after each parsed rule, as it might change when parsing SPI size
2012-03-20 17:30:44 +01:00
Martin Willi
5789320f5c
Fix rule selection in transform substructure
2012-03-20 17:30:44 +01:00
Martin Willi
5f1aef65ce
Fixed proposal numbering check in sa_payload
2012-03-20 17:30:44 +01:00
Martin Willi
c311d22d0f
Don't clone chunk in message.get_packet_data
2012-03-20 17:30:44 +01:00
Martin Willi
31fc14e394
Verify IKEv1 nonce size, send 32 byte nonces
2012-03-20 17:30:44 +01:00