Commit Graph
322 Commits
Author SHA1 Message Date
Martin Willi c64a4b4f8e Implemented post-authentication certificate handling for IKEv1 2012-03-20 17:31:13 +01:00
Martin Willi 9ad5b8fa95 Cleanup CERT payload constructors 2012-03-20 17:31:13 +01:00
Martin Willi 0bcdb8e571 Implemented pre-authentication certificate handling for IKEv1 2012-03-20 17:31:13 +01:00
Martin Willi 8c33850615 Added task types for IKEv1 certificate handling 2012-03-20 17:31:13 +01:00
Martin Willi 6ccabe2561 Reverted ike_cert tasks to IKEv2 only, we use dedicated IKEv1 tasks 2012-03-20 17:31:13 +01:00
Tobias Brunner 9f80110bc6 Install SAs with UDP encapsulation during Quick Mode. 2012-03-20 17:31:13 +01:00
Martin Willi aaa8f88906 Fix support for plain RSA authentication in IKEv1, both as initiator and responder 2012-03-20 17:31:13 +01:00
Martin Willi a974700fc0 Fix referencing of multiple CERTREQ payload with IKEv1, other cleanups 2012-03-20 17:31:12 +01:00
Clavister OpenSource d82a68642d XAUTH additions for certificates. 2012-03-20 17:31:12 +01:00
Clavister OpenSource a874a1f50b signature payload handling. 2012-03-20 17:31:12 +01:00
Clavister OpenSource 8ad5cd1f6c certificate tasks added to passive list for responder 2012-03-20 17:31:12 +01:00
Clavister OpenSource 7d9269bfce certificate handling for XAuth responder. 2012-03-20 17:31:11 +01:00
Clavister OpenSource a846be3116 keymat: derive_ike_keys updated with XAUTH RSA:s 2012-03-20 17:31:11 +01:00
Clavister OpenSource 07abb470c6 IKEv1: Added basic support for INFORMATIONAL exchange types, and for NOTIFY_V1 messages in the 3rd message in quick_mode. 2012-03-20 17:31:11 +01:00
Tobias Brunner 8cb6f4f979 Don't stop processing tasks if one returns SUCCESS.
Only send a response if at least one of the tasks requires it.
2012-03-20 17:31:11 +01:00
Clavister OpenSource 4394d96844 IKEv1 XAuth: Added a "NULL" XAuth plugin which sends a hardcoded user/pass, and blindly accepts whatever user/pass is sent it. Changed the xauth_request task to use this new plugin. Add --enable-xauth-null to your configure line to build with the new plugin. 2012-03-20 17:31:11 +01:00
Clavister OpenSource 9c5366446a IKEv1 XAuth: Added plugin support for XAuth, which allows us to have plugins to talk to servers with different quirks for XAuth authentication. 2012-03-20 17:31:11 +01:00
Tobias Brunner 3bf0be6b08 Add NAT-OA payloads during Quick Mode if transport mode is used.
We don't parse them currently, as the Linux kernel does not need them to fix
the IP header checksum.
2012-03-20 17:31:11 +01:00
Tobias Brunner 29b0cb328a Negotiate UDP encapsulation during Quick Mode if NAT is detected. 2012-03-20 17:31:10 +01:00
Tobias Brunner 1cc4ec46cf Task added for IKEv1 NAT detection.
There is already support for both Main and Aggressive Mode.
2012-03-20 17:31:10 +01:00
Tobias Brunner 61e2a1ad8a Create negotiated hasher earlier during Main Mode so it is available for building NAT-D payloads. 2012-03-20 17:31:10 +01:00
Tobias Brunner 4ace4daf0c Added a function to keymat_v1 to create the hasher earlier than during key derivation.
The negotiated hasher is also used to generate NAT-D payloads.
2012-03-20 17:31:10 +01:00
Clavister OpenSource c5dc9d3383 IKEv1 XAuth: Moving the state change to IKE_CONNECTED until after XAuth exchanges are complete. 2012-03-20 17:31:10 +01:00
Clavister OpenSource 02c36eeb86 IKEv1 XAuth: Adding "initiate" flag parameter to the initiate_xauth method, signalling whether or not to call the task_manager->initiate method after queueing the task. 2012-03-20 17:31:10 +01:00
Tobias Brunner 06d29be714 Handle IKEv1 NAT-T vendor ID payload (only RFC 3947 for now). 2012-03-20 17:31:10 +01:00
Tobias Brunner 1e97783c99 Added payloads for IKEv1 NAT-Traversal negotiation. 2012-03-20 17:31:09 +01:00
Clavister OpenSource 3fa8db8b59 IKEv1 XAuth: Clean up debug prints in xauth_request task. 2012-03-20 17:31:09 +01:00
Clavister OpenSource 735fa3e5b9 IKEv1 XAuth: Remove XAuth task from the passive task list for ID_PROT. 2012-03-20 17:31:09 +01:00
Clavister OpenSource 0ea77083bb Revert "IKEv1 XAuth: Added new MIGRATE status type to status_t."
This reverts commit b57df8310a867a0a65abf17279bf1b6e6bb2f5d3.

Conflicts:

	src/libcharon/sa/task_manager_v1.c
2012-03-20 17:31:09 +01:00
Clavister OpenSource c961d110ab IKEv1 XAuth + CfgMode: Added ability to process CfgMode messages in the xauth task. Migrated away from using the MIGRATE method to switch queues. 2012-03-20 17:31:09 +01:00
Clavister OpenSource ef2eac7fb0 IKEv1 XAuth: Change the main_mode task to use the new initiate_xauth job instead of the old MIGRATE method. 2012-03-20 17:31:09 +01:00
Clavister OpenSource 56fb0f0b3a IKEv1 XAuth: Added XAuthResp authentication modes. 2012-03-20 17:31:09 +01:00
Clavister OpenSource 65359ccbbc IKEv1 XAuth: Add "initiate xauth" method, which adds the xauth task into the queue for initiation. 2012-03-20 17:31:09 +01:00
Tobias Brunner 9eefb5f9b4 Use quiet generator when creating IKEv1 message hashes.
This avoids cluttering the log with duplicate log messages when
generating and especially confusing log messages when parsing
authenticated messages.
2012-03-20 17:31:09 +01:00
Tobias Brunner 4cfd0db854 Respond with NO_PROPOSAL_CHOSEN, if we don't find an ike_cfg. 2012-03-20 17:31:09 +01:00
Tobias Brunner 6be8d33daa Don't respond to malformed INFORMATIONAL_V1 messages with another INFORMATIONAL_V1 exchange. 2012-03-20 17:31:08 +01:00
Tobias Brunner 37639e94fb Handle invalid IKEv1 hashes more specifically. 2012-03-20 17:31:08 +01:00
Tobias Brunner 29a5e0707e Handle unsupported IKEv1 exchange types more specifically. 2012-03-20 17:31:08 +01:00
Tobias Brunner b235e69cde Send an INFORMATIONAL message on IKEv1 parse errors. 2012-03-20 17:31:08 +01:00
Tobias Brunner 983e852af8 Handle INFORMATIONAL_V1 messages when no keys have been derived yet.
This allows to gracefully process the INFORMATIONAL_V1 message rules which
require the payloads to be encrypted and thus the exchange to be
authenticated with a HASH payload.  If such an exchange is now initiated
before the ISAKMP_SA is established, the message is simply sent unencrypted
and without HASH payload.
2012-03-20 17:31:08 +01:00
Tobias Brunner e6732003f4 Error reporting for invalid IKEv2 responses fixed. 2012-03-20 17:31:08 +01:00
Tobias Brunner 7519106d07 Set request flag to proper value for IKEv1 messages before parsing them. 2012-03-20 17:31:08 +01:00
Tobias Brunner 1960312cfd Avoid parsing retransmits we already responded to.
Decryption will fail as we already moved the IV when we sent the
response. Without this change, encrypted retransmits would have been
discarded during parsing already.
2012-03-20 17:31:08 +01:00
Tobias Brunner 68c6863bbb Moved main part of message processing to task managers.
This will allow individual error handling for each IKE version and should
allow better handling of IKEv1 retransmits.
2012-03-20 17:31:08 +01:00
Tobias Brunner 44ff1153e8 Addded ike_sa_t.set_statistic to set timestamps from task manager. 2012-03-20 17:31:08 +01:00
Clavister OpenSource 52ac2cebe2 IKEv1 XAuth: Fix XAuth task so that it reinitiates. 2012-03-20 17:31:07 +01:00
Clavister OpenSource e63cb7f816 Revert "IKEv1 XAuth: Temporarilty add an "initiate_later" flag to the task manager. When set to TRUE it will cause "initiate" to be called when the current process_response call is finished. This change should be reverted once we have a better method in place."
This reverts commit c6c28f4ac522dd8afb457847bca79eee77f78706.

Revert "IKEv1 XAuth: Added temporary "initiate_xauth" public method to ike_sa_t.  This allows us to initiate an XAuth password authentication exchange after responding to the final message of Main Mode.  This change should be reverted once we have a better method to initiate this exchange."

This reverts commit 5529dc50477e25df9dd5f3c442bb1521c0baf225.
2012-03-20 17:31:07 +01:00
Clavister OpenSource 2c49c53186 IKEv1 XAuth: Fix main mode to work with XAuth PSK. 2012-03-20 17:31:07 +01:00
Martin Willi a2f8fc9711 Use a dedicated IKEv1 vendor ID task to fix using IKEv2 payloads in IKEv1 2012-03-20 17:31:07 +01:00
Martin Willi abf9784786 Pass concrete auth_method to key derivation, as we have that as a responder 2012-03-20 17:30:53 +01:00