d2e50c7801716095cf495e499d5500202e2b0568
[strongswan.git] / Source / charon / config / connections / connection.c
1 /**
2 * @file connection.c
3 *
4 * @brief Implementation of connection_t.
5 *
6 */
7
8 /*
9 * Copyright (C) 2005 Jan Hutter, Martin Willi
10 * Hochschule fuer Technik Rapperswil
11 *
12 * This program is free software; you can redistribute it and/or modify it
13 * under the terms of the GNU General Public License as published by the
14 * Free Software Foundation; either version 2 of the License, or (at your
15 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
16 *
17 * This program is distributed in the hope that it will be useful, but
18 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
19 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
20 * for more details.
21 */
22
23 #include "connection.h"
24
25 #include <utils/linked_list.h>
26 #include <utils/logger.h>
27
28 /**
29 * String mappings for auth_method_t.
30 */
31 mapping_t auth_method_m[] = {
32 {RSA_DIGITAL_SIGNATURE, "RSA"},
33 {SHARED_KEY_MESSAGE_INTEGRITY_CODE, "SHARED_KEY"},
34 {DSS_DIGITAL_SIGNATURE, "DSS"},
35 {MAPPING_END, NULL}
36 };
37
38
39 typedef struct private_connection_t private_connection_t;
40
41 /**
42 * Private data of an connection_t object
43 */
44 struct private_connection_t {
45
46 /**
47 * Public part
48 */
49 connection_t public;
50
51 /**
52 * ID of us
53 */
54 identification_t *my_id;
55
56 /**
57 * ID of remote peer
58 */
59 identification_t *other_id;
60
61 /**
62 * Host information of my host.
63 */
64 host_t *my_host;
65
66 /**
67 * Host information of other host.
68 */
69 host_t *other_host;
70
71 /**
72 * Method to use for own authentication data
73 */
74 auth_method_t auth_method;
75
76 /**
77 * Supported proposals
78 */
79 linked_list_t *proposals;
80 };
81
82 /**
83 * Implementation of connection_t.get_my_id.
84 */
85 static identification_t *get_my_id (private_connection_t *this)
86 {
87 return this->my_id;
88 }
89
90 /**
91 * Implementation of connection_t.get_other_id.
92 */
93 static identification_t *get_other_id(private_connection_t *this)
94 {
95 return this->other_id;
96 }
97
98 /**
99 * Implementation of connection_t.get_my_host.
100 */
101 static host_t * get_my_host (private_connection_t *this)
102 {
103 return this->my_host;
104 }
105
106 /**
107 * Implementation of connection_t.update_my_host.
108 */
109 static void update_my_host(private_connection_t *this, host_t *my_host)
110 {
111 this->my_host->destroy(this->my_host);
112 this->my_host = my_host;
113 }
114
115 /**
116 * Implementation of connection_t.update_other_host.
117 */
118 static void update_other_host(private_connection_t *this, host_t *other_host)
119 {
120 this->other_host->destroy(this->other_host);
121 this->other_host = other_host;
122 }
123
124 /**
125 * Implementation of connection_t.get_other_host.
126 */
127 static host_t * get_other_host (private_connection_t *this)
128 {
129 return this->other_host;
130 }
131
132 /**
133 * Implementation of connection_t.get_proposals.
134 */
135 static linked_list_t* get_proposals (private_connection_t *this)
136 {
137 return this->proposals;
138 }
139
140 /**
141 * Implementation of connection_t.select_proposal.
142 */
143 static proposal_t *select_proposal(private_connection_t *this, linked_list_t *proposals)
144 {
145 iterator_t *stored_iter, *supplied_iter;
146 proposal_t *stored, *supplied, *selected;
147
148 stored_iter = this->proposals->create_iterator(this->proposals, TRUE);
149 supplied_iter = proposals->create_iterator(proposals, TRUE);
150
151 /* compare all stored proposals with all supplied. Stored ones are preferred. */
152 while (stored_iter->has_next(stored_iter))
153 {
154 supplied_iter->reset(supplied_iter);
155 stored_iter->current(stored_iter, (void**)&stored);
156
157 while (supplied_iter->has_next(supplied_iter))
158 {
159 supplied_iter->current(supplied_iter, (void**)&supplied);
160 selected = stored->select(stored, supplied);
161 if (selected)
162 {
163 /* they match, return */
164 stored_iter->destroy(stored_iter);
165 supplied_iter->destroy(supplied_iter);
166 return selected;
167 }
168 }
169 }
170
171 /* no proposal match :-(, will result in a NO_PROPOSAL_CHOSEN... */
172 stored_iter->destroy(stored_iter);
173 supplied_iter->destroy(supplied_iter);
174
175 return NULL;
176 }
177
178 /**
179 * Implementation of connection_t.add_proposal.
180 */
181 static void add_proposal (private_connection_t *this, proposal_t *proposal)
182 {
183 this->proposals->insert_last(this->proposals, proposal);
184 }
185
186 /**
187 * Implementation of connection_t.auth_method_t.
188 */
189 static auth_method_t get_auth_method(private_connection_t *this)
190 {
191 return this->auth_method;
192 }
193
194 /**
195 * Implementation of connection_t.get_dh_group.
196 */
197 static diffie_hellman_group_t get_dh_group(private_connection_t *this)
198 {
199 iterator_t *iterator;
200 proposal_t *proposal;
201 algorithm_t *algo;
202
203 iterator = this->proposals->create_iterator(this->proposals, TRUE);
204 while (iterator->has_next(iterator))
205 {
206 iterator->current(iterator, (void**)&proposal);
207 proposal->get_algorithm(proposal, PROTO_IKE, DIFFIE_HELLMAN_GROUP, &algo);
208 if (algo)
209 {
210 iterator->destroy(iterator);
211 return algo->algorithm;
212 }
213 }
214 iterator->destroy(iterator);
215 return MODP_UNDEFINED;
216 }
217
218 /**
219 * Implementation of connection_t.check_dh_group.
220 */
221 static bool check_dh_group(private_connection_t *this, diffie_hellman_group_t dh_group)
222 {
223 iterator_t *prop_iter, *alg_iter;
224 proposal_t *proposal;
225 algorithm_t *algo;
226
227 prop_iter = this->proposals->create_iterator(this->proposals, TRUE);
228 while (prop_iter->has_next(prop_iter))
229 {
230 prop_iter->current(prop_iter, (void**)&proposal);
231 alg_iter = proposal->create_algorithm_iterator(proposal, PROTO_IKE, DIFFIE_HELLMAN_GROUP);
232 while (alg_iter->has_next(alg_iter))
233 {
234 alg_iter->current(alg_iter, (void**)&algo);
235 if (algo->algorithm == dh_group)
236 {
237 prop_iter->destroy(prop_iter);
238 alg_iter->destroy(alg_iter);
239 return TRUE;
240 }
241 }
242 }
243 prop_iter->destroy(prop_iter);
244 alg_iter->destroy(alg_iter);
245 return FALSE;
246 }
247
248 /**
249 * Implementation of connection_t.clone.
250 */
251 static connection_t *clone(private_connection_t *this)
252 {
253 iterator_t *iterator;
254 proposal_t *proposal;
255 private_connection_t *clone = (private_connection_t*)connection_create(
256 this->my_host->clone(this->my_host),
257 this->other_host->clone(this->other_host),
258 this->my_id->clone(this->my_id),
259 this->other_id->clone(this->other_id),
260 this->auth_method);
261
262 /* clone all proposals */
263 iterator = this->proposals->create_iterator(this->proposals, TRUE);
264 while (iterator->has_next(iterator))
265 {
266 iterator->current(iterator, (void**)&proposal);
267 proposal = proposal->clone(proposal);
268 clone->proposals->insert_last(clone->proposals, (void*)proposal);
269 }
270 iterator->destroy(iterator);
271
272 return &clone->public;
273 }
274
275 /**
276 * Implementation of connection_t.destroy.
277 */
278 static void destroy (private_connection_t *this)
279 {
280 proposal_t *proposal;
281
282 while (this->proposals->remove_last(this->proposals, (void**)&proposal) == SUCCESS)
283 {
284 proposal->destroy(proposal);
285 }
286 this->proposals->destroy(this->proposals);
287
288 this->my_host->destroy(this->my_host);
289 this->other_host->destroy(this->other_host);
290 this->my_id->destroy(this->my_id);
291 this->other_id->destroy(this->other_id);
292 free(this);
293 }
294
295 /**
296 * Described in header.
297 */
298 connection_t * connection_create(host_t *my_host, host_t *other_host, identification_t *my_id, identification_t *other_id, auth_method_t auth_method)
299 {
300 private_connection_t *this = malloc_thing(private_connection_t);
301
302 /* public functions */
303 this->public.get_my_id = (identification_t*(*)(connection_t*))get_my_id;
304 this->public.get_other_id = (identification_t*(*)(connection_t*))get_other_id;
305 this->public.get_my_host = (host_t*(*)(connection_t*))get_my_host;
306 this->public.update_my_host = (void(*)(connection_t*,host_t*))update_my_host;
307 this->public.update_other_host = (void(*)(connection_t*,host_t*))update_other_host;
308 this->public.get_other_host = (host_t*(*)(connection_t*))get_other_host;
309 this->public.get_proposals = (linked_list_t*(*)(connection_t*))get_proposals;
310 this->public.select_proposal = (proposal_t*(*)(connection_t*,linked_list_t*))select_proposal;
311 this->public.add_proposal = (void(*)(connection_t*, proposal_t*)) add_proposal;
312 this->public.get_auth_method = (auth_method_t(*)(connection_t*)) get_auth_method;
313 this->public.get_dh_group = (diffie_hellman_group_t(*)(connection_t*)) get_dh_group;
314 this->public.check_dh_group = (bool(*)(connection_t*,diffie_hellman_group_t)) check_dh_group;
315 this->public.clone = (connection_t*(*)(connection_t*))clone;
316 this->public.destroy = (void(*)(connection_t*))destroy;
317
318 /* private variables */
319 this->my_host = my_host;
320 this->other_host = other_host;
321 this->my_id = my_id;
322 this->other_id = other_id;
323 this->auth_method = auth_method;
324
325 this->proposals = linked_list_create();
326
327 return (&this->public);
328 }