b020fc995e80250a3751c50d5a6cea2e0525aa8e
[strongswan.git] / Source / charon / sa / states / ike_sa_established.c
1 /**
2 * @file ike_sa_established.c
3 *
4 * @brief Implementation of ike_sa_established_t.
5 *
6 */
7
8 /*
9 * Copyright (C) 2005 Jan Hutter, Martin Willi
10 * Hochschule fuer Technik Rapperswil
11 *
12 * This program is free software; you can redistribute it and/or modify it
13 * under the terms of the GNU General Public License as published by the
14 * Free Software Foundation; either version 2 of the License, or (at your
15 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
16 *
17 * This program is distributed in the hope that it will be useful, but
18 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
19 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
20 * for more details.
21 */
22
23 #include "ike_sa_established.h"
24
25 #include <utils/allocator.h>
26 #include <encoding/payloads/delete_payload.h>
27
28
29 typedef struct private_ike_sa_established_t private_ike_sa_established_t;
30
31 /**
32 * Private data of a ike_sa_established_t object.
33 */
34 struct private_ike_sa_established_t {
35 /**
36 * methods of the state_t interface
37 */
38 ike_sa_established_t public;
39
40 /**
41 * Assigned IKE_SA.
42 */
43 protected_ike_sa_t *ike_sa;
44
45 /**
46 * Assigned logger. Use logger of IKE_SA.
47 */
48 logger_t *logger;
49
50 /**
51 * Process received DELETE payload and build DELETE payload for INFORMATIONAL response.
52 *
53 * @param this calling object
54 * @param request DELETE payload received in INFORMATIONAL request
55 * @param response The created DELETE payload is added to this message_t object
56 */
57 status_t (*build_delete_payload) (private_ike_sa_established_t *this, delete_payload_t *request, message_t *response);
58
59 /**
60 * Process a notify payload
61 *
62 * @param this calling object
63 * @param notify_payload notify payload
64 * @param response response message of type INFORMATIONAL
65 *
66 * - SUCCESS
67 * - FAILED
68 * - DELETE_ME
69 */
70 status_t (*process_notify_payload) (private_ike_sa_established_t *this, notify_payload_t *notify_payload,message_t *response);
71 };
72
73 /**
74 * Implements state_t.get_state
75 */
76 static status_t process_message(private_ike_sa_established_t *this, message_t *message)
77 {
78 delete_payload_t *delete_request = NULL;
79 iterator_t *payloads;
80 message_t *response;
81 crypter_t *crypter;
82 signer_t *signer;
83 status_t status;
84
85 if (message->get_exchange_type(message) != INFORMATIONAL)
86 {
87 this->logger->log(this->logger, ERROR | LEVEL1, "Message of type %s not supported in state ike_sa_established",
88 mapping_find(exchange_type_m,message->get_exchange_type(message)));
89 return FAILED;
90 }
91
92 if (!message->get_request(message))
93 {
94 this->logger->log(this->logger, ERROR | LEVEL1, "INFORMATIONAL responses not handled in state ike_sa_established");
95 return FAILED;
96 }
97
98 /* get signer for verification and crypter for decryption */
99 signer = this->ike_sa->get_signer_responder(this->ike_sa);
100 crypter = this->ike_sa->get_crypter_responder(this->ike_sa);
101
102 /* parse incoming message */
103 status = message->parse_body(message, crypter, signer);
104 if (status != SUCCESS)
105 {
106 this->logger->log(this->logger, AUDIT, "INFORMATIONAL request decryption failed. Ignoring message");
107 return status;
108 }
109
110 /* build empty INFORMATIONAL message */
111 this->ike_sa->build_message(this->ike_sa, INFORMATIONAL, FALSE, &response);
112
113 payloads = message->get_payload_iterator(message);
114
115 while (payloads->has_next(payloads))
116 {
117 payload_t *payload;
118 payloads->current(payloads, (void**)&payload);
119
120 switch (payload->get_type(payload))
121 {
122 case NOTIFY:
123 {
124 notify_payload_t *notify_payload = (notify_payload_t *) payload;
125 /* handle the notify directly, abort if no further processing required */
126 status = this->process_notify_payload(this, notify_payload,response);
127 if (status != SUCCESS)
128 {
129 payloads->destroy(payloads);
130 response->destroy(response);
131 return status;
132 }
133 }
134 case DELETE:
135 {
136 delete_request = (delete_payload_t *) payload;
137 }
138 default:
139 {
140 this->logger->log(this->logger, ERROR|LEVEL1, "Ignoring Payload %s (%d)",
141 mapping_find(payload_type_m, payload->get_type(payload)), payload->get_type(payload));
142 break;
143 }
144 }
145 }
146 /* iterator can be destroyed */
147 payloads->destroy(payloads);
148
149 if (delete_request)
150 {
151 status = this->build_delete_payload(this, delete_request, response);
152 if (status == DELETE_ME)
153 {
154 status = this->ike_sa->send_response(this->ike_sa, response);
155 if (status != SUCCESS)
156 {
157 this->logger->log(this->logger, AUDIT, "Unable to send INFORMATIONAL reply");
158 response->destroy(response);
159 return FAILED;
160 }
161 response->destroy(response);
162 return status;
163 }
164 }
165
166
167 status = this->ike_sa->send_response(this->ike_sa, response);
168 /* message can now be sent (must not be destroyed) */
169 if (status != SUCCESS)
170 {
171 this->logger->log(this->logger, AUDIT, "Unable to send INFORMATIONAL reply");
172 response->destroy(response);
173 return FAILED;
174 }
175
176 return SUCCESS;
177 }
178
179 /**
180 * Implementation of private_ike_sa_established_t.build_sa_payload;
181 */
182 static status_t build_delete_payload (private_ike_sa_established_t *this, delete_payload_t *request, message_t *response_message)
183 {
184 delete_payload_t *response;
185 if (request->get_protocol_id(request) == IKE)
186 {
187 this->logger->log(this->logger, AUDIT, "DELETE request for IKE_SA received. Create delete reply.");
188
189 response = delete_payload_create();
190 response->set_protocol_id(response,IKE);
191
192 response_message->add_payload(response_message,(payload_t *)response);
193 /* IKE_SA has to get deleted */
194 return DELETE_ME;
195 }
196
197 this->logger->log(this->logger, AUDIT, "DELETE payload for CHILD_SAs not supported and handled.");
198
199 return SUCCESS;
200 }
201
202 /**
203 * Implementation of private_ike_sa_established_t.process_notify_payload;
204 */
205 static status_t process_notify_payload (private_ike_sa_established_t *this, notify_payload_t *notify_payload, message_t *response)
206 {
207 notify_message_type_t notify_message_type = notify_payload->get_notify_message_type(notify_payload);
208
209 this->logger->log(this->logger, CONTROL|LEVEL1, "Process notify type %s for protocol %s",
210 mapping_find(notify_message_type_m, notify_message_type),
211 mapping_find(protocol_id_m, notify_payload->get_protocol_id(notify_payload)));
212
213 switch (notify_message_type)
214 {
215 default:
216 {
217 this->logger->log(this->logger, AUDIT, "INFORMATIONAL request contained an unknown notify (%d), ignored.", notify_message_type);
218 }
219 }
220
221
222 return SUCCESS;
223 }
224
225 /**
226 * Implementation of state_t.get_state.
227 */
228 static ike_sa_state_t get_state(private_ike_sa_established_t *this)
229 {
230 return IKE_SA_ESTABLISHED;
231 }
232
233 /**
234 * Implementation of state_t.get_state
235 */
236 static void destroy(private_ike_sa_established_t *this)
237 {
238 allocator_free(this);
239 }
240
241 /*
242 * Described in header.
243 */
244 ike_sa_established_t *ike_sa_established_create(protected_ike_sa_t *ike_sa)
245 {
246 private_ike_sa_established_t *this = allocator_alloc_thing(private_ike_sa_established_t);
247
248 /* interface functions */
249 this->public.state_interface.process_message = (status_t (*) (state_t *,message_t *)) process_message;
250 this->public.state_interface.get_state = (ike_sa_state_t (*) (state_t *)) get_state;
251 this->public.state_interface.destroy = (void (*) (state_t *)) destroy;
252
253 /* private functions */
254 this->process_notify_payload = process_notify_payload;
255 this->build_delete_payload = build_delete_payload;
256
257 /* private data */
258 this->ike_sa = ike_sa;
259 this->logger = ike_sa->get_logger(ike_sa);
260
261 return &(this->public);
262 }