1d678f1e5dcd87d399f0f755617b638ec7a009a6
[strongswan.git] / src / libcharon / plugins / load_tester / load_tester_config.c
1 /*
2 * Copyright (C) 2008 Martin Willi
3 * Hochschule fuer Technik Rapperswil
4 *
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; either version 2 of the License, or (at your
8 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
9 *
10 * This program is distributed in the hope that it will be useful, but
11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
13 * for more details.
14 */
15
16 #include "load_tester_config.h"
17
18 #include <daemon.h>
19 #include <hydra.h>
20 #include <attributes/mem_pool.h>
21
22 typedef struct private_load_tester_config_t private_load_tester_config_t;
23
24 /**
25 * Private data of an load_tester_config_t object
26 */
27 struct private_load_tester_config_t {
28
29 /**
30 * Public part
31 */
32 load_tester_config_t public;
33
34 /**
35 * peer config
36 */
37 peer_cfg_t *peer_cfg;
38
39 /**
40 * virtual IP, if any
41 */
42 host_t *vip;
43
44 /**
45 * Initiator address
46 */
47 char *initiator;
48
49 /**
50 * Responder address
51 */
52 char *responder;
53
54 /**
55 * IP address pool
56 */
57 char *pool;
58
59 /**
60 * IKE proposal
61 */
62 proposal_t *proposal;
63
64 /**
65 * Authentication method(s) to use/expect from initiator
66 */
67 char *initiator_auth;
68
69 /**
70 * Authentication method(s) use/expected from responder
71 */
72 char *responder_auth;
73
74 /**
75 * Initiator ID to enforce
76 */
77 char *initiator_id;
78
79 /**
80 * Initiator ID to to match against as responder
81 */
82 char *initiator_match;
83
84 /**
85 * Responder ID to enforce
86 */
87 char *responder_id;
88
89 /**
90 * Traffic Selector on initiator side, as proposed from initiator
91 */
92 char *initiator_tsi;
93
94 /**
95 * Traffic Selector on responder side, as proposed from initiator
96 */
97 char *initiator_tsr;
98
99 /**
100 * Traffic Selector on initiator side, as narrowed by responder
101 */
102 char *responder_tsi;
103
104 /**
105 * Traffic Selector on responder side, as narrowed by responder
106 */
107 char *responder_tsr;
108
109 /**
110 * IKE_SA rekeying delay
111 */
112 u_int ike_rekey;
113
114 /**
115 * CHILD_SA rekeying delay
116 */
117 u_int child_rekey;
118
119 /**
120 * DPD check delay
121 */
122 u_int dpd_delay;
123
124 /**
125 * DPD timeout (IKEv1 only)
126 */
127 u_int dpd_timeout;
128
129 /**
130 * incremental numbering of generated configs
131 */
132 u_int num;
133
134 /**
135 * Dynamic source port, if used
136 */
137 u_int16_t port;
138
139 /**
140 * IKE version to use for load testing
141 */
142 ike_version_t version;
143
144 /**
145 * List of pools to allocate external addresses dynamically, as mem_pool_t
146 */
147 linked_list_t *pools;
148
149 /**
150 * Address prefix to use when installing dynamic addresses
151 */
152 int prefix;
153 };
154
155 /**
156 * Load external addresses to use, if any
157 */
158 static void load_addrs(private_load_tester_config_t *this)
159 {
160 enumerator_t *enumerator;
161 host_t *net;
162 int bits;
163 char *iface, *cidr;
164 mem_pool_t *pool;
165
166
167 this->prefix = lib->settings->get_int(lib->settings,
168 "%s.plugins.load-tester.addrs_prefix", 16, charon->name);
169 enumerator = lib->settings->create_key_value_enumerator(lib->settings,
170 "%s.plugins.load-tester.addrs", charon->name);
171 while (enumerator->enumerate(enumerator, &iface, &cidr))
172 {
173 net = host_create_from_subnet(cidr, &bits);
174 if (net)
175 {
176 DBG1(DBG_CFG, "loaded load-tester addresses %s", cidr);
177 pool = mem_pool_create(iface, net, bits);
178 net->destroy(net);
179 this->pools->insert_last(this->pools, pool);
180 }
181 else
182 {
183 DBG1(DBG_CFG, "parsing load-tester addresses %s failed", cidr);
184 }
185 }
186 enumerator->destroy(enumerator);
187 }
188
189 /**
190 * Generate auth config from string
191 */
192 static void generate_auth_cfg(private_load_tester_config_t *this, char *str,
193 peer_cfg_t *peer_cfg, bool local, int num)
194 {
195 enumerator_t *enumerator;
196 auth_cfg_t *auth;
197 identification_t *id;
198 auth_class_t class;
199 eap_type_t type;
200 char buf[128];
201 int rnd = 0;
202
203 enumerator = enumerator_create_token(str, "|", " ");
204 while (enumerator->enumerate(enumerator, &str))
205 {
206 id = NULL;
207 auth = auth_cfg_create();
208 rnd++;
209
210 if (this->initiator_id)
211 {
212 if (this->initiator_match && (!local && !num))
213 { /* as responder, use the secified identity that matches
214 * all used initiator identities, if given. */
215 snprintf(buf, sizeof(buf), this->initiator_match, rnd);
216 id = identification_create_from_string(buf);
217 }
218 else if ((local && num) || (!local && !num))
219 { /* as initiator, create peer specific identities */
220 snprintf(buf, sizeof(buf), this->initiator_id, num, rnd);
221 id = identification_create_from_string(buf);
222 }
223 }
224 if (this->responder_id)
225 {
226 if ((local && !num) || (!local && num))
227 {
228 snprintf(buf, sizeof(buf), this->responder_id, num, rnd);
229 id = identification_create_from_string(buf);
230 }
231 }
232
233 if (streq(str, "psk"))
234 { /* PSK authentication, use FQDNs */
235 class = AUTH_CLASS_PSK;
236 if (!id)
237 {
238 if ((local && !num) || (!local && num))
239 {
240 id = identification_create_from_string("srv.strongswan.org");
241 }
242 else if (local)
243 {
244 snprintf(buf, sizeof(buf), "c%d-r%d.strongswan.org",
245 num, rnd);
246 id = identification_create_from_string(buf);
247 }
248 else
249 {
250 id = identification_create_from_string("*.strongswan.org");
251 }
252 }
253 }
254 else if (strneq(str, "eap", strlen("eap")))
255 { /* EAP authentication, use a NAI */
256 class = AUTH_CLASS_EAP;
257 if (*(str + strlen("eap")) == '-')
258 {
259 type = eap_type_from_string(str + strlen("eap-"));
260 if (type)
261 {
262 auth->add(auth, AUTH_RULE_EAP_TYPE, type);
263 }
264 }
265 if (!id)
266 {
267 if (local && num)
268 {
269 snprintf(buf, sizeof(buf), "1%.10d%.4d@strongswan.org",
270 num, rnd);
271 id = identification_create_from_string(buf);
272 }
273 else
274 {
275 id = identification_create_from_encoding(ID_ANY, chunk_empty);
276 }
277 }
278 }
279 else
280 {
281 if (!streq(str, "pubkey"))
282 {
283 DBG1(DBG_CFG, "invalid authentication: '%s', fallback to pubkey",
284 str);
285 }
286 /* certificate authentication, use distinguished names */
287 class = AUTH_CLASS_PUBKEY;
288 if (!id)
289 {
290 if ((local && !num) || (!local && num))
291 {
292 id = identification_create_from_string(
293 "CN=srv, OU=load-test, O=strongSwan");
294 }
295 else if (local)
296 {
297 snprintf(buf, sizeof(buf),
298 "CN=c%d-r%d, OU=load-test, O=strongSwan", num, rnd);
299 id = identification_create_from_string(buf);
300 }
301 else
302 {
303 id = identification_create_from_string(
304 "CN=*, OU=load-test, O=strongSwan");
305 }
306 }
307 }
308 auth->add(auth, AUTH_RULE_AUTH_CLASS, class);
309 auth->add(auth, AUTH_RULE_IDENTITY, id);
310 peer_cfg->add_auth_cfg(peer_cfg, auth, local);
311 }
312 enumerator->destroy(enumerator);
313 }
314
315 /**
316 * Add a TS from a string to a child_cfg
317 */
318 static void add_ts(char *string, child_cfg_t *cfg, bool local)
319 {
320 traffic_selector_t *ts;
321
322 if (string)
323 {
324 ts = traffic_selector_create_from_cidr(string, 0, 0);
325 if (!ts)
326 {
327 DBG1(DBG_CFG, "parsing TS string '%s' failed", string);
328 }
329 }
330 else
331 {
332 ts = traffic_selector_create_dynamic(0, 0, 65535);
333 }
334 if (ts)
335 {
336 cfg->add_traffic_selector(cfg, local, ts);
337 }
338 }
339
340 /**
341 * Allocate and install a dynamic external address to use
342 */
343 static host_t *allocate_addr(private_load_tester_config_t *this, uint num)
344 {
345 enumerator_t *pools, *addrs;
346 mem_pool_t *pool;
347 host_t *addr, *iface = NULL, *found = NULL, *requested;
348 identification_t *id;
349 char *name, buf[32];
350
351 requested = host_create_any(AF_INET);
352 snprintf(buf, sizeof(buf), "ext-%d", num);
353 id = identification_create_from_string(buf);
354 pools = this->pools->create_enumerator(this->pools);
355 while (!found && pools->enumerate(pools, &pool))
356 {
357 addrs = hydra->kernel_interface->create_address_enumerator(
358 hydra->kernel_interface, ADDR_TYPE_REGULAR);
359 while (!found && addrs->enumerate(addrs, &addr))
360 {
361 if (hydra->kernel_interface->get_interface(hydra->kernel_interface,
362 addr, &name))
363 {
364 if (streq(pool->get_name(pool), name))
365 {
366 found = pool->acquire_address(pool, id, requested,
367 MEM_POOL_NEW);
368 if (found)
369 {
370 iface = addr->clone(addr);
371 }
372 }
373 free(name);
374 }
375 }
376 addrs->destroy(addrs);
377 }
378 pools->destroy(pools);
379 requested->destroy(requested);
380 id->destroy(id);
381
382 if (!found)
383 {
384 DBG1(DBG_CFG, "no interface found to install load-tester IP");
385 return NULL;
386 }
387 if (hydra->kernel_interface->add_ip(hydra->kernel_interface,
388 found, this->prefix, iface) != SUCCESS)
389 {
390 DBG1(DBG_CFG, "installing load-tester IP %H failed", found);
391 iface->destroy(iface);
392 found->destroy(found);
393 return NULL;
394 }
395 DBG1(DBG_CFG, "installed load-tester IP %H", found);
396 iface->destroy(iface);
397 return found;
398 }
399
400 /**
401 * Generate a new initiator config, num = 0 for responder config
402 */
403 static peer_cfg_t* generate_config(private_load_tester_config_t *this, uint num)
404 {
405 ike_cfg_t *ike_cfg;
406 child_cfg_t *child_cfg;
407 peer_cfg_t *peer_cfg;
408 proposal_t *proposal;
409 char local[32], *remote;
410 host_t *addr;
411 lifetime_cfg_t lifetime = {
412 .time = {
413 .life = this->child_rekey * 2,
414 .rekey = this->child_rekey,
415 .jitter = 0
416 }
417 };
418
419 if (num)
420 { /* initiator */
421 if (this->pools->get_count(this->pools))
422 { /* using dynamically installed external addresses */
423 addr = allocate_addr(this, num);
424 if (!addr)
425 {
426 DBG1(DBG_CFG, "allocating external address failed");
427 return NULL;
428 }
429 snprintf(local, sizeof(local), "%H", addr);
430 addr->destroy(addr);
431 }
432 else
433 {
434 snprintf(local, sizeof(local), "%s", this->initiator);
435 }
436 remote = this->responder;
437 }
438 else
439 {
440 snprintf(local, sizeof(local), "%s", this->responder);
441 remote = this->initiator;
442 }
443
444 if (this->port && num)
445 {
446 ike_cfg = ike_cfg_create(this->version, TRUE, FALSE,
447 local, FALSE, this->port + num - 1,
448 remote, FALSE, IKEV2_NATT_PORT);
449 }
450 else
451 {
452 ike_cfg = ike_cfg_create(this->version, TRUE, FALSE,
453 local, FALSE,
454 charon->socket->get_port(charon->socket, FALSE),
455 remote, FALSE, IKEV2_UDP_PORT);
456 }
457 ike_cfg->add_proposal(ike_cfg, this->proposal->clone(this->proposal));
458 peer_cfg = peer_cfg_create("load-test", ike_cfg,
459 CERT_SEND_IF_ASKED, UNIQUE_NO, 1, /* keytries */
460 this->ike_rekey, 0, /* rekey, reauth */
461 0, this->ike_rekey, /* jitter, overtime */
462 FALSE, FALSE, /* mobike, aggressive mode */
463 this->dpd_delay, /* dpd_delay */
464 this->dpd_timeout, /* dpd_timeout */
465 FALSE, NULL, NULL);
466 if (this->vip)
467 {
468 peer_cfg->add_virtual_ip(peer_cfg, this->vip->clone(this->vip));
469 }
470 if (this->pool)
471 {
472 peer_cfg->add_pool(peer_cfg, this->pool);
473 }
474 if (num)
475 { /* initiator */
476 generate_auth_cfg(this, this->initiator_auth, peer_cfg, TRUE, num);
477 generate_auth_cfg(this, this->responder_auth, peer_cfg, FALSE, num);
478 }
479 else
480 { /* responder */
481 generate_auth_cfg(this, this->responder_auth, peer_cfg, TRUE, num);
482 generate_auth_cfg(this, this->initiator_auth, peer_cfg, FALSE, num);
483 }
484
485 child_cfg = child_cfg_create("load-test", &lifetime, NULL, TRUE, MODE_TUNNEL,
486 ACTION_NONE, ACTION_NONE, ACTION_NONE, FALSE,
487 0, 0, NULL, NULL, 0);
488 proposal = proposal_create_from_string(PROTO_ESP, "aes128-sha1");
489 child_cfg->add_proposal(child_cfg, proposal);
490
491 if (num)
492 { /* initiator */
493 add_ts(this->initiator_tsi, child_cfg, TRUE);
494 add_ts(this->initiator_tsr, child_cfg, FALSE);
495 }
496 else
497 { /* responder */
498 add_ts(this->responder_tsr, child_cfg, TRUE);
499 add_ts(this->responder_tsi, child_cfg, FALSE);
500 }
501 peer_cfg->add_child_cfg(peer_cfg, child_cfg);
502 return peer_cfg;
503 }
504
505 METHOD(backend_t, create_peer_cfg_enumerator, enumerator_t*,
506 private_load_tester_config_t *this,
507 identification_t *me, identification_t *other)
508 {
509 return enumerator_create_single(this->peer_cfg, NULL);
510 }
511
512 METHOD(backend_t, create_ike_cfg_enumerator, enumerator_t*,
513 private_load_tester_config_t *this, host_t *me, host_t *other)
514 {
515 ike_cfg_t *ike_cfg;
516
517 ike_cfg = this->peer_cfg->get_ike_cfg(this->peer_cfg);
518 return enumerator_create_single(ike_cfg, NULL);
519 }
520
521 METHOD(backend_t, get_peer_cfg_by_name, peer_cfg_t*,
522 private_load_tester_config_t *this, char *name)
523 {
524 if (streq(name, "load-test"))
525 {
526 return generate_config(this, this->num++);
527 }
528 return NULL;
529 }
530
531 METHOD(load_tester_config_t, delete_ip, void,
532 private_load_tester_config_t *this, host_t *ip)
533 {
534 mem_pool_t *pool;
535 enumerator_t *pools, *leases;
536 identification_t *id, *found = FALSE;
537 host_t *host;
538 bool online;
539
540 /* find identity for this IP, so we can call release_address() */
541 pools = this->pools->create_enumerator(this->pools);
542 while (pools->enumerate(pools, &pool))
543 {
544 leases = pool->create_lease_enumerator(pool);
545 while (leases->enumerate(leases, &id, &host, &online))
546 {
547 if (online && host->ip_equals(host, ip))
548 {
549 found = id->clone(id);
550 }
551 }
552 leases->destroy(leases);
553 if (found)
554 {
555 if (pool->release_address(pool, ip, found))
556 {
557 hydra->kernel_interface->del_ip(hydra->kernel_interface,
558 ip, this->prefix);
559 }
560 found->destroy(found);
561 break;
562 }
563 }
564 pools->destroy(pools);
565 }
566
567
568 METHOD(load_tester_config_t, destroy, void,
569 private_load_tester_config_t *this)
570 {
571 this->pools->destroy_offset(this->pools, offsetof(mem_pool_t, destroy));
572 this->peer_cfg->destroy(this->peer_cfg);
573 DESTROY_IF(this->proposal);
574 DESTROY_IF(this->vip);
575 free(this);
576 }
577
578 /**
579 * Described in header.
580 */
581 load_tester_config_t *load_tester_config_create()
582 {
583 private_load_tester_config_t *this;
584
585 INIT(this,
586 .public = {
587 .backend = {
588 .create_peer_cfg_enumerator = _create_peer_cfg_enumerator,
589 .create_ike_cfg_enumerator = _create_ike_cfg_enumerator,
590 .get_peer_cfg_by_name = _get_peer_cfg_by_name,
591 },
592 .delete_ip = _delete_ip,
593 .destroy = _destroy,
594 },
595 .pools = linked_list_create(),
596 .num = 1,
597 );
598
599 if (lib->settings->get_bool(lib->settings,
600 "%s.plugins.load-tester.request_virtual_ip", FALSE, charon->name))
601 {
602 this->vip = host_create_from_string("0.0.0.0", 0);
603 }
604 this->pool = lib->settings->get_str(lib->settings,
605 "%s.plugins.load-tester.pool", NULL, charon->name);
606 this->initiator = lib->settings->get_str(lib->settings,
607 "%s.plugins.load-tester.initiator", "0.0.0.0", charon->name);
608 this->responder = lib->settings->get_str(lib->settings,
609 "%s.plugins.load-tester.responder", "127.0.0.1", charon->name);
610
611 this->proposal = proposal_create_from_string(PROTO_IKE,
612 lib->settings->get_str(lib->settings,
613 "%s.plugins.load-tester.proposal", "aes128-sha1-modp768",
614 charon->name));
615 if (!this->proposal)
616 { /* fallback */
617 this->proposal = proposal_create_from_string(PROTO_IKE,
618 "aes128-sha1-modp768");
619 }
620 this->ike_rekey = lib->settings->get_int(lib->settings,
621 "%s.plugins.load-tester.ike_rekey", 0, charon->name);
622 this->child_rekey = lib->settings->get_int(lib->settings,
623 "%s.plugins.load-tester.child_rekey", 600, charon->name);
624 this->dpd_delay = lib->settings->get_int(lib->settings,
625 "%s.plugins.load-tester.dpd_delay", 0, charon->name);
626 this->dpd_timeout = lib->settings->get_int(lib->settings,
627 "%s.plugins.load-tester.dpd_timeout", 0, charon->name);
628
629 this->initiator_auth = lib->settings->get_str(lib->settings,
630 "%s.plugins.load-tester.initiator_auth", "pubkey", charon->name);
631 this->responder_auth = lib->settings->get_str(lib->settings,
632 "%s.plugins.load-tester.responder_auth", "pubkey", charon->name);
633 this->initiator_id = lib->settings->get_str(lib->settings,
634 "%s.plugins.load-tester.initiator_id", NULL, charon->name);
635 this->initiator_match = lib->settings->get_str(lib->settings,
636 "%s.plugins.load-tester.initiator_match", NULL, charon->name);
637 this->responder_id = lib->settings->get_str(lib->settings,
638 "%s.plugins.load-tester.responder_id", NULL, charon->name);
639
640 this->initiator_tsi = lib->settings->get_str(lib->settings,
641 "%s.plugins.load-tester.initiator_tsi", NULL, charon->name);
642 this->responder_tsi =lib->settings->get_str(lib->settings,
643 "%s.plugins.load-tester.responder_tsi",
644 this->initiator_tsi, charon->name);
645 this->initiator_tsr = lib->settings->get_str(lib->settings,
646 "%s.plugins.load-tester.initiator_tsr", NULL, charon->name);
647 this->responder_tsr =lib->settings->get_str(lib->settings,
648 "%s.plugins.load-tester.responder_tsr",
649 this->initiator_tsr, charon->name);
650
651 this->port = lib->settings->get_int(lib->settings,
652 "%s.plugins.load-tester.dynamic_port", 0, charon->name);
653 this->version = lib->settings->get_int(lib->settings,
654 "%s.plugins.load-tester.version", IKE_ANY, charon->name);
655
656 load_addrs(this);
657
658 this->peer_cfg = generate_config(this, 0);
659
660 return &this->public;
661 }
662