22163aefd35f892758cade82ac427be1e94e6711
[strongswan.git] / src / libimcv / plugins / imv_test / imv_test.c
1 /*
2 * Copyright (C) 2011 Andreas Steffen, HSR Hochschule fuer Technik Rapperswil
3 *
4 * This program is free software; you can redistribute it and/or modify it
5 * under the terms of the GNU General Public License as published by the
6 * Free Software Foundation; either version 2 of the License, or (at your
7 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
8 *
9 * This program is distributed in the hope that it will be useful, but
10 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
11 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
12 * for more details.
13 */
14
15 #include "imv_test_state.h"
16
17 #include <imv/imv_agent.h>
18 #include <pa_tnc/pa_tnc_msg.h>
19 #include <ietf/ietf_attr.h>
20 #include <ietf/ietf_attr_pa_tnc_error.h>
21 #include <ita/ita_attr_command.h>
22
23 #include <tncif_names.h>
24 #include <tncif_pa_subtypes.h>
25
26 #include <pen/pen.h>
27 #include <debug.h>
28
29 /* IMV definitions */
30
31 static const char imv_name[] = "Test";
32
33 #define IMV_VENDOR_ID PEN_ITA
34 #define IMV_SUBTYPE PA_SUBTYPE_ITA_TEST
35
36 static imv_agent_t *imv_test;
37
38 /**
39 * see section 3.7.1 of TCG TNC IF-IMV Specification 1.2
40 */
41 TNC_Result TNC_IMV_Initialize(TNC_IMVID imv_id,
42 TNC_Version min_version,
43 TNC_Version max_version,
44 TNC_Version *actual_version)
45 {
46 if (imv_test)
47 {
48 DBG1(DBG_IMV, "IMV \"%s\" has already been initialized", imv_name);
49 return TNC_RESULT_ALREADY_INITIALIZED;
50 }
51 imv_test = imv_agent_create(imv_name, IMV_VENDOR_ID, IMV_SUBTYPE,
52 imv_id, actual_version);
53 if (!imv_test)
54 {
55 return TNC_RESULT_FATAL;
56 }
57 if (min_version > TNC_IFIMV_VERSION_1 || max_version < TNC_IFIMV_VERSION_1)
58 {
59 DBG1(DBG_IMV, "no common IF-IMV version");
60 return TNC_RESULT_NO_COMMON_VERSION;
61 }
62 return TNC_RESULT_SUCCESS;
63 }
64
65 /**
66 * see section 3.7.2 of TCG TNC IF-IMV Specification 1.2
67 */
68 TNC_Result TNC_IMV_NotifyConnectionChange(TNC_IMVID imv_id,
69 TNC_ConnectionID connection_id,
70 TNC_ConnectionState new_state)
71 {
72 imv_state_t *state;
73 imv_test_state_t *test_state;
74 TNC_Result result;
75 int rounds;
76
77 if (!imv_test)
78 {
79 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
80 return TNC_RESULT_NOT_INITIALIZED;
81 }
82 switch (new_state)
83 {
84 case TNC_CONNECTION_STATE_CREATE:
85 state = imv_test_state_create(connection_id);
86 return imv_test->create_state(imv_test, state);
87 case TNC_CONNECTION_STATE_DELETE:
88 return imv_test->delete_state(imv_test, connection_id);
89 case TNC_CONNECTION_STATE_HANDSHAKE:
90 /* get updated IMV state */
91 result = imv_test->change_state(imv_test, connection_id,
92 new_state, &state);
93 if (result != TNC_RESULT_SUCCESS)
94 {
95 return TNC_RESULT_FATAL;
96 }
97 test_state = (imv_test_state_t*)state;
98
99 /* set the number of measurement rounds */
100 rounds = lib->settings->get_int(lib->settings,
101 "libimcv.plugins.imv-test.rounds", 0);
102 test_state->set_rounds(test_state, rounds);
103 return TNC_RESULT_SUCCESS;
104 default:
105 return imv_test->change_state(imv_test, connection_id,
106 new_state, NULL);
107 }
108 }
109
110 static TNC_Result send_message(TNC_ConnectionID connection_id)
111 {
112 pa_tnc_msg_t *msg;
113 pa_tnc_attr_t *attr;
114 TNC_Result result;
115
116 attr = ita_attr_command_create("repeat");
117 msg = pa_tnc_msg_create();
118 msg->add_attribute(msg, attr);
119 msg->build(msg);
120 result = imv_test->send_message(imv_test, connection_id,
121 msg->get_encoding(msg));
122 msg->destroy(msg);
123
124 return result;
125 }
126
127 /**
128 * see section 3.7.3 of TCG TNC IF-IMV Specification 1.2
129 */
130 TNC_Result TNC_IMV_ReceiveMessage(TNC_IMVID imv_id,
131 TNC_ConnectionID connection_id,
132 TNC_BufferReference msg,
133 TNC_UInt32 msg_len,
134 TNC_MessageType msg_type)
135 {
136 pa_tnc_msg_t *pa_tnc_msg;
137 pa_tnc_attr_t *attr;
138 imv_state_t *state;
139 imv_test_state_t *imv_test_state;
140 enumerator_t *enumerator;
141 TNC_Result result;
142 bool fatal_error = FALSE, retry = FALSE;
143
144 if (!imv_test)
145 {
146 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
147 return TNC_RESULT_NOT_INITIALIZED;
148 }
149
150 /* get current IMV state */
151 if (!imv_test->get_state(imv_test, connection_id, &state))
152 {
153 return TNC_RESULT_FATAL;
154 }
155
156 /* parse received PA-TNC message and automatically handle any errors */
157 result = imv_test->receive_message(imv_test, connection_id,
158 chunk_create(msg, msg_len), msg_type,
159 &pa_tnc_msg);
160
161 /* no parsed PA-TNC attributes available if an error occurred */
162 if (!pa_tnc_msg)
163 {
164 return result;
165 }
166
167 /* analyze PA-TNC attributes */
168 enumerator = pa_tnc_msg->create_attribute_enumerator(pa_tnc_msg);
169 while (enumerator->enumerate(enumerator, &attr))
170 {
171 if (attr->get_vendor_id(attr) == PEN_IETF &&
172 attr->get_type(attr) == IETF_ATTR_PA_TNC_ERROR)
173 {
174 ietf_attr_pa_tnc_error_t *error_attr;
175 pa_tnc_error_code_t error_code;
176 chunk_t msg_info, attr_info;
177
178 error_attr = (ietf_attr_pa_tnc_error_t*)attr;
179 error_code = error_attr->get_error_code(error_attr);
180 msg_info = error_attr->get_msg_info(error_attr);
181
182 DBG1(DBG_IMV, "received PA-TNC error '%N' concerning message %#B",
183 pa_tnc_error_code_names, error_code, &msg_info);
184 switch (error_code)
185 {
186 case PA_ERROR_ATTR_TYPE_NOT_SUPPORTED:
187 attr_info = error_attr->get_attr_info(error_attr);
188 DBG1(DBG_IMV, " unsupported attribute %#B", &attr_info);
189 break;
190 default:
191 break;
192 }
193 fatal_error = TRUE;
194 }
195 else if (attr->get_vendor_id(attr) == PEN_ITA &&
196 attr->get_type(attr) == ITA_ATTR_COMMAND)
197 {
198 ita_attr_command_t *ita_attr;
199 char *command;
200
201 ita_attr = (ita_attr_command_t*)attr;
202 command = ita_attr->get_command(ita_attr);
203
204 if (streq(command, "allow"))
205 {
206 state->set_recommendation(state,
207 TNC_IMV_ACTION_RECOMMENDATION_ALLOW,
208 TNC_IMV_EVALUATION_RESULT_COMPLIANT);
209 }
210 else if (streq(command, "isolate"))
211 {
212 state->set_recommendation(state,
213 TNC_IMV_ACTION_RECOMMENDATION_ISOLATE,
214 TNC_IMV_EVALUATION_RESULT_NONCOMPLIANT_MINOR);
215 }
216 else if (streq(command, "block") || streq(command, "none"))
217 {
218 state->set_recommendation(state,
219 TNC_IMV_ACTION_RECOMMENDATION_NO_ACCESS,
220 TNC_IMV_EVALUATION_RESULT_NONCOMPLIANT_MAJOR);
221 }
222 else if (streq(command, "retry"))
223 {
224 retry = TRUE;
225 }
226 else
227 {
228 DBG1(DBG_IMV, "unsupported ITA Command '%s'", command);
229 state->set_recommendation(state,
230 TNC_IMV_ACTION_RECOMMENDATION_NO_RECOMMENDATION,
231 TNC_IMV_EVALUATION_RESULT_ERROR);
232 }
233 }
234 }
235 enumerator->destroy(enumerator);
236 pa_tnc_msg->destroy(pa_tnc_msg);
237
238 if (fatal_error)
239 {
240 state->set_recommendation(state,
241 TNC_IMV_ACTION_RECOMMENDATION_NO_RECOMMENDATION,
242 TNC_IMV_EVALUATION_RESULT_ERROR);
243 return imv_test->provide_recommendation(imv_test, connection_id);
244 }
245
246 /* request a handshake retry ? */
247 if (retry)
248 {
249 return imv_test->request_handshake_retry(imv_id, connection_id,
250 TNC_RETRY_REASON_IMV_SERIOUS_EVENT);
251 }
252
253 /* repeat the measurement ? */
254 imv_test_state = (imv_test_state_t*)state;
255 if (imv_test_state->another_round(imv_test_state))
256 {
257 return send_message(connection_id);
258 }
259
260 return imv_test->provide_recommendation(imv_test, connection_id);
261 }
262
263 /**
264 * see section 3.7.4 of TCG TNC IF-IMV Specification 1.2
265 */
266 TNC_Result TNC_IMV_SolicitRecommendation(TNC_IMVID imv_id,
267 TNC_ConnectionID connection_id)
268 {
269 if (!imv_test)
270 {
271 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
272 return TNC_RESULT_NOT_INITIALIZED;
273 }
274 return imv_test->provide_recommendation(imv_test, connection_id);
275 }
276
277 /**
278 * see section 3.7.5 of TCG TNC IF-IMV Specification 1.2
279 */
280 TNC_Result TNC_IMV_BatchEnding(TNC_IMVID imv_id,
281 TNC_ConnectionID connection_id)
282 {
283 if (!imv_test)
284 {
285 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
286 return TNC_RESULT_NOT_INITIALIZED;
287 }
288 return TNC_RESULT_SUCCESS;
289 }
290
291 /**
292 * see section 3.7.6 of TCG TNC IF-IMV Specification 1.2
293 */
294 TNC_Result TNC_IMV_Terminate(TNC_IMVID imv_id)
295 {
296 if (!imv_test)
297 {
298 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
299 return TNC_RESULT_NOT_INITIALIZED;
300 }
301 imv_test->destroy(imv_test);
302 imv_test = NULL;
303
304 return TNC_RESULT_SUCCESS;
305 }
306
307 /**
308 * see section 4.2.8.1 of TCG TNC IF-IMV Specification 1.2
309 */
310 TNC_Result TNC_IMV_ProvideBindFunction(TNC_IMVID imv_id,
311 TNC_TNCS_BindFunctionPointer bind_function)
312 {
313 if (!imv_test)
314 {
315 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
316 return TNC_RESULT_NOT_INITIALIZED;
317 }
318 return imv_test->bind_functions(imv_test, bind_function);
319 }