- state ike_sa_init_responded implemented (has some memleaks)
[strongswan.git] / Source / charon / config / configuration_manager.c
1 /**
2 * @file configuration.c
3 *
4 * @brief Configuration class used to store IKE_SA-configurations.
5 *
6 * Object of this type represents the configuration for all IKE_SA's and their child_sa's.
7 *
8 */
9
10 /*
11 * Copyright (C) 2005 Jan Hutter, Martin Willi
12 * Hochschule fuer Technik Rapperswil
13 *
14 * This program is free software; you can redistribute it and/or modify it
15 * under the terms of the GNU General Public License as published by the
16 * Free Software Foundation; either version 2 of the License, or (at your
17 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
18 *
19 * This program is distributed in the hope that it will be useful, but
20 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
21 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
22 * for more details.
23 */
24
25 #include <stdlib.h>
26
27 #include "configuration_manager.h"
28
29 #include <types.h>
30 #include <daemon.h>
31 #include <utils/allocator.h>
32
33 typedef struct configuration_entry_t configuration_entry_t;
34
35 /* A configuration entry combines a configuration name with a init and sa
36 * configuration represented as init_config_t and sa_config_t objects.
37 */
38 struct configuration_entry_t {
39
40 /**
41 * Configuration name.
42 *
43 */
44 char *name;
45
46 /**
47 * Configuration for IKE_SA_INIT exchange.
48 */
49 init_config_t *init_config;
50
51 /**
52 * Configuration for all phases after IKE_SA_INIT exchange.
53 */
54 sa_config_t *sa_config;
55
56 /**
57 * Destroys a configuration_entry_t
58 *
59 *
60 * @param this calling object
61 */
62 void (*destroy) (configuration_entry_t *this);
63 };
64
65 static void configuration_entry_destroy (configuration_entry_t *this)
66 {
67 allocator_free(this->name);
68 allocator_free(this);
69 }
70
71 /**
72 * Creates a configuration_entry_t object
73 *
74 * @param name name of the configuration entry (gets copied)
75 * @param init_config object of type init_config_t
76 * @param sa_config object of type sa_config_t
77 */
78 configuration_entry_t * configuration_entry_create(char * name, init_config_t * init_config, sa_config_t * sa_config)
79 {
80 configuration_entry_t *entry = allocator_alloc_thing(configuration_entry_t);
81
82 /* functions */
83 entry->destroy = configuration_entry_destroy;
84
85 /* private data */
86 entry->init_config = init_config;
87 entry->sa_config = sa_config;
88 entry->name = allocator_alloc(strlen(name) + 1);
89 strcpy(entry->name,name);
90 return entry;
91 }
92
93
94 typedef struct private_configuration_manager_t private_configuration_manager_t;
95
96 /**
97 * Private data of an configuration_t object
98 */
99 struct private_configuration_manager_t {
100
101 /**
102 * Public part of configuration manager.
103 */
104 configuration_manager_t public;
105
106 /**
107 * Holding all configurations.
108 */
109 linked_list_t *configurations;
110
111 /**
112 * Holding all init_configs.
113 */
114 linked_list_t *init_configs;
115
116 /**
117 * Holding all init_configs.
118 */
119 linked_list_t *sa_configs;
120
121
122 /**
123 * Assigned logger object.
124 */
125 logger_t *logger;
126
127 /**
128 * Load default configuration
129 *
130 *
131 * @param this calling object
132 * @param name name for the configuration
133 * @param init_config init_config_t object
134 * @param sa_config sa_config_t object
135 */
136 void (*add_new_configuration) (private_configuration_manager_t *this, char *name, init_config_t *init_config, sa_config_t *sa_config);
137
138 /**
139 * Load default configuration
140 *
141 *
142 * @param this calling object
143 */
144 void (*load_default_config) (private_configuration_manager_t *this);
145 };
146
147 /**
148 * Implementation of private_configuration_manager_t.load_default_config.
149 */
150 static void load_default_config (private_configuration_manager_t *this)
151 {
152 init_config_t *init_config1, *init_config2, *init_config3;
153 ike_proposal_t proposals[2];
154 child_proposal_t child_proposals[1];
155 sa_config_t *sa_config1, *sa_config2, *sa_config3;
156 traffic_selector_t *ts;
157
158 init_config1 = init_config_create("152.96.193.131","152.96.193.131",IKEV2_UDP_PORT,IKEV2_UDP_PORT);
159 init_config2 = init_config_create("152.96.193.131","152.96.193.130",IKEV2_UDP_PORT,IKEV2_UDP_PORT);
160 init_config3 = init_config_create("0.0.0.0","127.0.0.1",IKEV2_UDP_PORT,IKEV2_UDP_PORT);
161 ts = traffic_selector_create_from_string(1, TS_IPV4_ADDR_RANGE, "0.0.0.0", 0, "255.255.255.255", 65535);
162
163
164 proposals[0].encryption_algorithm = ENCR_AES_CBC;
165 proposals[0].encryption_algorithm_key_length = 16;
166 proposals[0].integrity_algorithm = AUTH_HMAC_MD5_96;
167 proposals[0].integrity_algorithm_key_length = 16;
168 proposals[0].pseudo_random_function = PRF_HMAC_MD5;
169 proposals[0].pseudo_random_function_key_length = 16;
170 proposals[0].diffie_hellman_group = MODP_1024_BIT;
171
172 proposals[1] = proposals[0];
173 proposals[1].integrity_algorithm = AUTH_HMAC_SHA1_96;
174 proposals[1].integrity_algorithm_key_length = 20;
175 proposals[1].pseudo_random_function = PRF_HMAC_SHA1;
176 proposals[1].pseudo_random_function_key_length = 20;
177
178 init_config1->add_proposal(init_config1,1,proposals[0]);
179 init_config1->add_proposal(init_config1,1,proposals[1]);
180 init_config2->add_proposal(init_config2,1,proposals[0]);
181 init_config2->add_proposal(init_config2,1,proposals[1]);
182 init_config3->add_proposal(init_config3,1,proposals[0]);
183 init_config3->add_proposal(init_config3,1,proposals[1]);
184
185 sa_config1 = sa_config_create(ID_IPV4_ADDR, "152.96.193.131",
186 ID_IPV4_ADDR, "152.96.193.130",
187 SHARED_KEY_MESSAGE_INTEGRITY_CODE);
188
189 sa_config1->add_traffic_selector_initiator(sa_config1,ts);
190 sa_config1->add_traffic_selector_responder(sa_config1,ts);
191
192 sa_config2 = sa_config_create(ID_IPV4_ADDR, "152.96.193.130",
193 ID_IPV4_ADDR, "152.96.193.131",
194 SHARED_KEY_MESSAGE_INTEGRITY_CODE);
195
196 sa_config2->add_traffic_selector_initiator(sa_config2,ts);
197 sa_config2->add_traffic_selector_responder(sa_config2,ts);
198
199 sa_config3 = sa_config_create(ID_IPV4_ADDR, "127.0.0.1",
200 ID_IPV4_ADDR, "127.0.0.1",
201 SHARED_KEY_MESSAGE_INTEGRITY_CODE);
202
203 sa_config3->add_traffic_selector_initiator(sa_config3,ts);
204 sa_config3->add_traffic_selector_responder(sa_config3,ts);
205
206 ts->destroy(ts);
207
208 /* ah and esp prop */
209 child_proposals[0].ah.is_set = TRUE;
210 child_proposals[0].ah.integrity_algorithm = AUTH_HMAC_MD5_96;
211 child_proposals[0].ah.integrity_algorithm_key_size = 16;
212 child_proposals[0].ah.diffie_hellman_group = MODP_1024_BIT;
213 child_proposals[0].ah.extended_sequence_numbers = NO_EXT_SEQ_NUMBERS;
214
215 child_proposals[0].esp.is_set = TRUE;
216 child_proposals[0].esp.diffie_hellman_group = MODP_1024_BIT;
217 child_proposals[0].esp.encryption_algorithm = ENCR_AES_CBC;
218 child_proposals[0].esp.encryption_algorithm_key_size = 16;
219 child_proposals[0].esp.integrity_algorithm = AUTH_UNDEFINED;
220 child_proposals[0].esp.extended_sequence_numbers = NO_EXT_SEQ_NUMBERS;
221 child_proposals[0].esp.spi[0] = 2;
222 child_proposals[0].esp.spi[1] = 2;
223 child_proposals[0].esp.spi[2] = 2;
224 child_proposals[0].esp.spi[3] = 2;
225
226 sa_config1->add_proposal(sa_config1, &child_proposals[0]);
227 sa_config2->add_proposal(sa_config2, &child_proposals[0]);
228 sa_config3->add_proposal(sa_config3, &child_proposals[0]);
229
230 this->add_new_configuration(this,"pinflb31",init_config1,sa_config2);
231 this->add_new_configuration(this,"pinflb30",init_config2,sa_config1);
232 this->add_new_configuration(this,"localhost",init_config3,sa_config3);
233
234 }
235
236 /**
237 * Implementation of configuration_manager_t.get_init_config_for_host.
238 */
239 static status_t get_init_config_for_host (private_configuration_manager_t *this, host_t *my_host, host_t *other_host,init_config_t **init_config)
240 {
241 iterator_t *iterator;
242 status_t status = NOT_FOUND;
243
244 iterator = this->configurations->create_iterator(this->configurations,TRUE);
245
246 while (iterator->has_next(iterator))
247 {
248 configuration_entry_t *entry;
249 host_t *config_my_host;
250 host_t *config_other_host;
251
252 iterator->current(iterator,(void **) &entry);
253
254 config_my_host = entry->init_config->get_my_host(entry->init_config);
255 config_other_host = entry->init_config->get_other_host(entry->init_config);
256
257 /* first check if ip is equal */
258 if(config_other_host->ip_is_equal(config_other_host,other_host))
259 {
260 /* could be right one, check my_host for default route*/
261 if (config_my_host->is_default_route(config_my_host))
262 {
263 *init_config = entry->init_config;
264 status = SUCCESS;
265 break;
266 }
267 /* check now if host informations are the same */
268 else if (config_my_host->ip_is_equal(config_my_host,my_host))
269 {
270 *init_config = entry->init_config;
271 status = SUCCESS;
272 break;
273 }
274
275 }
276 /* Then check for wildcard hosts!
277 * TODO
278 * actually its only checked if other host with default route can be found! */
279 else if (config_other_host->is_default_route(config_other_host))
280 {
281 /* could be right one, check my_host for default route*/
282 if (config_my_host->is_default_route(config_my_host))
283 {
284 *init_config = entry->init_config;
285 status = SUCCESS;
286 break;
287 }
288 /* check now if host informations are the same */
289 else if (config_my_host->ip_is_equal(config_my_host,my_host))
290 {
291 *init_config = entry->init_config;
292 status = SUCCESS;
293 break;
294 }
295 }
296 }
297
298 iterator->destroy(iterator);
299
300 return status;
301 }
302
303 /**
304 * Implementation of configuration_manager_t.get_init_config_for_name.
305 */
306 static status_t get_init_config_for_name (private_configuration_manager_t *this, char *name, init_config_t **init_config)
307 {
308 iterator_t *iterator;
309 status_t status = NOT_FOUND;
310
311 iterator = this->configurations->create_iterator(this->configurations,TRUE);
312
313 while (iterator->has_next(iterator))
314 {
315 configuration_entry_t *entry;
316 iterator->current(iterator,(void **) &entry);
317
318 if (strcmp(entry->name,name) == 0)
319 {
320
321 /* found configuration */
322 *init_config = entry->init_config;
323 status = SUCCESS;
324 break;
325 }
326 }
327
328 iterator->destroy(iterator);
329
330 return status;
331 }
332
333 /**
334 * Implementation of configuration_manager_t.get_sa_config_for_name.
335 */
336 static status_t get_sa_config_for_name (private_configuration_manager_t *this, char *name, sa_config_t **sa_config)
337 {
338 iterator_t *iterator;
339 status_t status = NOT_FOUND;
340
341 iterator = this->configurations->create_iterator(this->configurations,TRUE);
342
343 while (iterator->has_next(iterator))
344 {
345 configuration_entry_t *entry;
346 iterator->current(iterator,(void **) &entry);
347
348 if (strcmp(entry->name,name) == 0)
349 {
350 /* found configuration */
351 *sa_config = entry->sa_config;
352 status = SUCCESS;
353 break;
354 }
355 }
356
357 iterator->destroy(iterator);
358
359 return status;
360 }
361
362 /**
363 * Implementation of configuration_manager_t.get_sa_config_for_init_config_and_id.
364 */
365 static status_t get_sa_config_for_init_config_and_id (private_configuration_manager_t *this, init_config_t *init_config, identification_t *other_id, identification_t *my_id,sa_config_t **sa_config)
366 {
367 iterator_t *iterator;
368 status_t status = NOT_FOUND;
369
370 iterator = this->configurations->create_iterator(this->configurations,TRUE);
371
372 while (iterator->has_next(iterator))
373 {
374 configuration_entry_t *entry;
375 iterator->current(iterator,(void **) &entry);
376
377 if (entry->init_config == init_config)
378 {
379 identification_t *config_my_id = entry->sa_config->get_my_id(entry->sa_config);
380 identification_t *config_other_id = entry->sa_config->get_other_id(entry->sa_config);
381
382 /* host informations seem to be the same */
383 if (config_other_id->equals(config_other_id,other_id))
384 {
385 /* other ids seems to match */
386
387 if (my_id == NULL)
388 {
389 /* first matching one is selected */
390
391 /* TODO priorize found entries */
392 *sa_config = entry->sa_config;
393 status = SUCCESS;
394 break;
395 }
396
397 if (config_my_id->equals(config_my_id,my_id))
398 {
399 *sa_config = entry->sa_config;
400 status = SUCCESS;
401 break;
402 }
403
404 }
405 }
406 }
407
408 iterator->destroy(iterator);
409
410 return status;
411 }
412
413 /**
414 * Implementation of private_configuration_manager_t.add_new_configuration.
415 */
416 static void add_new_configuration (private_configuration_manager_t *this, char *name, init_config_t *init_config, sa_config_t *sa_config)
417 {
418 iterator_t *iterator;
419 bool found;
420
421 iterator = this->init_configs->create_iterator(this->init_configs,TRUE);
422 found = FALSE;
423 while (iterator->has_next(iterator))
424 {
425 init_config_t *found_init_config;
426 iterator->current(iterator,(void **) &found_init_config);
427 if (init_config == found_init_config)
428 {
429 found = TRUE;
430 break;
431 }
432 }
433 iterator->destroy(iterator);
434 if (!found)
435 {
436 this->init_configs->insert_first(this->init_configs,init_config);
437 }
438
439 iterator = this->sa_configs->create_iterator(this->sa_configs,TRUE);
440 found = FALSE;
441 while (iterator->has_next(iterator))
442 {
443 sa_config_t *found_sa_config;
444 iterator->current(iterator,(void **) &found_sa_config);
445 if (sa_config == found_sa_config)
446 {
447 found = TRUE;
448 break;
449 }
450 }
451 iterator->destroy(iterator);
452 if (!found)
453 {
454 this->sa_configs->insert_first(this->sa_configs,sa_config);
455 }
456
457 this->configurations->insert_first(this->configurations,configuration_entry_create(name,init_config,sa_config));
458 }
459
460 /**
461 * Implementation of configuration_manager_t.destroy.
462 */
463 static void destroy(private_configuration_manager_t *this)
464 {
465 this->logger->log(this->logger,CONTROL | MORE, "Going to destroy configuration manager ");
466
467 while (this->configurations->get_count(this->configurations) > 0)
468 {
469 configuration_entry_t *entry;
470 this->configurations->remove_first(this->configurations,(void **) &entry);
471 entry->destroy(entry);
472 }
473 /* todo delete all config objects */
474
475 this->configurations->destroy(this->configurations);
476
477 while (this->sa_configs->get_count(this->sa_configs) > 0)
478 {
479 sa_config_t *sa_config;
480 this->sa_configs->remove_first(this->sa_configs,(void **) &sa_config);
481 sa_config->destroy(sa_config);
482 }
483
484 this->sa_configs->destroy(this->sa_configs);
485
486 while (this->init_configs->get_count(this->init_configs) > 0)
487 {
488 init_config_t *init_config;
489 this->init_configs->remove_first(this->init_configs,(void **) &init_config);
490 init_config->destroy(init_config);
491 }
492 this->init_configs->destroy(this->init_configs);
493
494 this->logger->log(this->logger,CONTROL | MOST, "Destroy assigned logger");
495 charon->logger_manager->destroy_logger(charon->logger_manager,this->logger);
496 allocator_free(this);
497 }
498
499 /*
500 * Described in header-file
501 */
502 configuration_manager_t *configuration_manager_create()
503 {
504 private_configuration_manager_t *this = allocator_alloc_thing(private_configuration_manager_t);
505
506 /* public functions */
507 this->public.destroy = (void(*)(configuration_manager_t*))destroy;
508 this->public.get_init_config_for_name = (status_t (*) (configuration_manager_t *, char *, init_config_t **)) get_init_config_for_name;
509 this->public.get_init_config_for_host = (status_t (*) (configuration_manager_t *, host_t *, host_t *,init_config_t **)) get_init_config_for_host;
510 this->public.get_sa_config_for_name =(status_t (*) (configuration_manager_t *, char *, sa_config_t **)) get_sa_config_for_name;
511 this->public.get_sa_config_for_init_config_and_id =(status_t (*) (configuration_manager_t *, init_config_t *, identification_t *, identification_t *,sa_config_t **)) get_sa_config_for_init_config_and_id;
512
513 /* private functions */
514 this->load_default_config = load_default_config;
515 this->add_new_configuration = add_new_configuration;
516
517 /* private variables */
518 this->logger = charon->logger_manager->create_logger(charon->logger_manager,CONFIGURATION_MANAGER,NULL);
519 this->configurations = linked_list_create();
520 this->sa_configs = linked_list_create();
521 this->init_configs = linked_list_create();
522
523 this->load_default_config(this);
524
525 return (&this->public);
526 }