added HA resync option to (re-)integrate nodes to a cluster
[strongswan.git] / src / charon / plugins / ha_sync / ha_sync_message.h
1 /*
2 * Copyright (C) 2008 Martin Willi
3 * Hochschule fuer Technik Rapperswil
4 *
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; either version 2 of the License, or (at your
8 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
13 * for more details.
14 *
15 * $Id$
16 */
17
18 /**
19 * @defgroup ha_sync_message ha_sync_message
20 * @{ @ingroup ha_sync
21 */
22
23 #ifndef HA_SYNC_MESSAGE_H_
24 #define HA_SYNC_MESSAGE_H_
25
26 #include <library.h>
27 #include <utils/host.h>
28 #include <utils/identification.h>
29 #include <sa/ike_sa_id.h>
30 #include <config/traffic_selector.h>
31
32 /**
33 * Protocol version of this implementation
34 */
35 #define HA_SYNC_MESSAGE_VERSION 1
36
37 typedef struct ha_sync_message_t ha_sync_message_t;
38 typedef enum ha_sync_message_type_t ha_sync_message_type_t;
39 typedef enum ha_sync_message_attribute_t ha_sync_message_attribute_t;
40 typedef union ha_sync_message_value_t ha_sync_message_value_t;
41
42 /**
43 * Type of a sync message
44 */
45 enum ha_sync_message_type_t {
46 /** add a completely new IKE_SA */
47 HA_SYNC_IKE_ADD = 1,
48 /** update an existing IKE_SA (message IDs, address update, ...) */
49 HA_SYNC_IKE_UPDATE,
50 /** delete an existing IKE_SA */
51 HA_SYNC_IKE_DELETE,
52 /** add a new CHILD_SA */
53 HA_SYNC_CHILD_ADD,
54 /** delete an existing CHILD_SA */
55 HA_SYNC_CHILD_DELETE,
56 };
57
58 /**
59 * Type of attributes contained in a message
60 */
61 enum ha_sync_message_attribute_t {
62 /** ike_sa_id_t*, to identify IKE_SA */
63 HA_SYNC_IKE_ID = 1,
64 /** ike_Sa_id_t*, identifies IKE_SA which gets rekeyed */
65 HA_SYNC_IKE_REKEY_ID,
66 /** identification_t*, local identity */
67 HA_SYNC_LOCAL_ID,
68 /** identification_t*, remote identity */
69 HA_SYNC_REMOTE_ID,
70 /** identification_t*, EAP identity */
71 HA_SYNC_EAP_ID,
72 /** host_t*, local address */
73 HA_SYNC_LOCAL_ADDR,
74 /** host_t*, remote address */
75 HA_SYNC_REMOTE_ADDR,
76 /** char*, name of configuration */
77 HA_SYNC_CONFIG_NAME,
78 /** u_int32_t, bitset of ike_condition_t */
79 HA_SYNC_CONDITIONS,
80 /** u_int32_t, bitset of ike_extension_t */
81 HA_SYNC_EXTENSIONS,
82 /** host_t*, local virtual IP */
83 HA_SYNC_LOCAL_VIP,
84 /** host_t*, remote virtual IP */
85 HA_SYNC_REMOTE_VIP,
86 /** host_t*, additional MOBIKE peer address */
87 HA_SYNC_ADDITIONAL_ADDR,
88 /** chunk_t, initiators nonce */
89 HA_SYNC_NONCE_I,
90 /** chunk_t, responders nonce */
91 HA_SYNC_NONCE_R,
92 /** chunk_t, diffie hellman shared secret */
93 HA_SYNC_SECRET,
94 /** chunk_t, SKd of old SA if rekeying */
95 HA_SYNC_OLD_SKD,
96 /** u_int16_t, pseudo random function */
97 HA_SYNC_ALG_PRF,
98 /** u_int16_t, old pseudo random function if rekeying */
99 HA_SYNC_ALG_OLD_PRF,
100 /** u_int16_t, encryption algorithm */
101 HA_SYNC_ALG_ENCR,
102 /** u_int16_t, encryption key size in bytes */
103 HA_SYNC_ALG_ENCR_LEN,
104 /** u_int16_t, integrity protection algorithm */
105 HA_SYNC_ALG_INTEG,
106 /** u_int8_t, IPsec mode, TUNNEL|TRANSPORT|... */
107 HA_SYNC_IPSEC_MODE,
108 /** u_int8_t, IPComp protocol */
109 HA_SYNC_IPCOMP,
110 /** u_int32_t, inbound security parameter index */
111 HA_SYNC_INBOUND_SPI,
112 /** u_int32_t, outbound security parameter index */
113 HA_SYNC_OUTBOUND_SPI,
114 /** u_int16_t, inbound security parameter index */
115 HA_SYNC_INBOUND_CPI,
116 /** u_int16_t, outbound security parameter index */
117 HA_SYNC_OUTBOUND_CPI,
118 /** traffic_selector_t*, local traffic selector */
119 HA_SYNC_LOCAL_TS,
120 /** traffic_selector_t*, remote traffic selector */
121 HA_SYNC_REMOTE_TS,
122 /** u_int32_t, initiating message ID */
123 HA_SYNC_INITIATE_MID,
124 /** u_int32_t, responding message ID */
125 HA_SYNC_RESPOND_MID,
126 };
127
128 /**
129 * Union to enumerate typed attributes in a message
130 */
131 union ha_sync_message_value_t {
132 u_int8_t u8;
133 u_int16_t u16;
134 u_int32_t u32;
135 char *str;
136 chunk_t chunk;
137 ike_sa_id_t *ike_sa_id;
138 identification_t *id;
139 host_t *host;
140 traffic_selector_t *ts;
141 };
142
143 /**
144 * Abstracted message passed between nodes in a HA cluster.
145 */
146 struct ha_sync_message_t {
147
148 /**
149 * Get the type of the message.
150 *
151 * @return message type
152 */
153 ha_sync_message_type_t (*get_type)(ha_sync_message_t *this);
154
155 /**
156 * Add an attribute to a message.
157 *
158 * @param attribute attribute type to add
159 * @param ... attribute specific data
160 */
161 void (*add_attribute)(ha_sync_message_t *this,
162 ha_sync_message_attribute_t attribute, ...);
163
164 /**
165 * Create an enumerator over all attributes in a message.
166 *
167 * @return enumerator over attribute, ha_sync_message_value_t
168 */
169 enumerator_t* (*create_attribute_enumerator)(ha_sync_message_t *this);
170
171 /**
172 * Get the message in a encoded form.
173 *
174 * @return chunk pointing to internal data
175 */
176 chunk_t (*get_encoding)(ha_sync_message_t *this);
177
178 /**
179 * Destroy a ha_sync_message_t.
180 */
181 void (*destroy)(ha_sync_message_t *this);
182 };
183
184 /**
185 * Create a new ha_sync_message instance, ready for adding attributes
186 *
187 * @param version protocol version to create a message from
188 * @param type type of the message
189 */
190 ha_sync_message_t *ha_sync_message_create(ha_sync_message_type_t type);
191
192 /**
193 * Create a ha_sync_message from encoded data.
194 *
195 * @param data encoded message data
196 */
197 ha_sync_message_t *ha_sync_message_parse(chunk_t data);
198
199 #endif /* HA_SYNC_MESSAGE_ @}*/