send TCG_PTS_TPM_VERS_NOT_SUPPORTED error code
[strongswan.git] / src / libimcv / plugins / imv_test / imv_test.c
1 /*
2 * Copyright (C) 2011 Andreas Steffen, HSR Hochschule fuer Technik Rapperswil
3 *
4 * This program is free software; you can redistribute it and/or modify it
5 * under the terms of the GNU General Public License as published by the
6 * Free Software Foundation; either version 2 of the License, or (at your
7 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
8 *
9 * This program is distributed in the hope that it will be useful, but
10 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
11 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
12 * for more details.
13 */
14
15 #include "imv_test_state.h"
16
17 #include <imv/imv_agent.h>
18 #include <pa_tnc/pa_tnc_msg.h>
19 #include <ietf/ietf_attr.h>
20 #include <ietf/ietf_attr_pa_tnc_error.h>
21 #include <ita/ita_attr.h>
22 #include <ita/ita_attr_command.h>
23
24 #include <tncif_names.h>
25 #include <tncif_pa_subtypes.h>
26
27 #include <pen/pen.h>
28 #include <debug.h>
29
30 /* IMV definitions */
31
32 static const char imv_name[] = "Test";
33
34 #define IMV_VENDOR_ID PEN_ITA
35 #define IMV_SUBTYPE PA_SUBTYPE_ITA_TEST
36
37 static imv_agent_t *imv_test;
38
39 /**
40 * see section 3.7.1 of TCG TNC IF-IMV Specification 1.2
41 */
42 TNC_Result TNC_IMV_Initialize(TNC_IMVID imv_id,
43 TNC_Version min_version,
44 TNC_Version max_version,
45 TNC_Version *actual_version)
46 {
47 if (imv_test)
48 {
49 DBG1(DBG_IMV, "IMV \"%s\" has already been initialized", imv_name);
50 return TNC_RESULT_ALREADY_INITIALIZED;
51 }
52 imv_test = imv_agent_create(imv_name, IMV_VENDOR_ID, IMV_SUBTYPE,
53 imv_id, actual_version);
54 if (!imv_test)
55 {
56 return TNC_RESULT_FATAL;
57 }
58 if (min_version > TNC_IFIMV_VERSION_1 || max_version < TNC_IFIMV_VERSION_1)
59 {
60 DBG1(DBG_IMV, "no common IF-IMV version");
61 return TNC_RESULT_NO_COMMON_VERSION;
62 }
63 return TNC_RESULT_SUCCESS;
64 }
65
66 /**
67 * see section 3.7.2 of TCG TNC IF-IMV Specification 1.2
68 */
69 TNC_Result TNC_IMV_NotifyConnectionChange(TNC_IMVID imv_id,
70 TNC_ConnectionID connection_id,
71 TNC_ConnectionState new_state)
72 {
73 imv_state_t *state;
74 imv_test_state_t *test_state;
75 TNC_Result result;
76 int rounds;
77
78 if (!imv_test)
79 {
80 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
81 return TNC_RESULT_NOT_INITIALIZED;
82 }
83 switch (new_state)
84 {
85 case TNC_CONNECTION_STATE_CREATE:
86 state = imv_test_state_create(connection_id);
87 return imv_test->create_state(imv_test, state);
88 case TNC_CONNECTION_STATE_DELETE:
89 return imv_test->delete_state(imv_test, connection_id);
90 case TNC_CONNECTION_STATE_HANDSHAKE:
91 /* get updated IMV state */
92 result = imv_test->change_state(imv_test, connection_id,
93 new_state, &state);
94 if (result != TNC_RESULT_SUCCESS)
95 {
96 return result;
97 }
98 test_state = (imv_test_state_t*)state;
99
100 /* set the number of measurement rounds */
101 rounds = lib->settings->get_int(lib->settings,
102 "libimcv.plugins.imv-test.rounds", 0);
103 test_state->set_rounds(test_state, rounds);
104 return TNC_RESULT_SUCCESS;
105 default:
106 return imv_test->change_state(imv_test, connection_id,
107 new_state, NULL);
108 }
109 }
110
111 static TNC_Result send_message(TNC_ConnectionID connection_id)
112 {
113 pa_tnc_msg_t *msg;
114 pa_tnc_attr_t *attr;
115 TNC_Result result;
116
117 attr = ita_attr_command_create("repeat");
118 msg = pa_tnc_msg_create();
119 msg->add_attribute(msg, attr);
120 msg->build(msg);
121 result = imv_test->send_message(imv_test, connection_id,
122 msg->get_encoding(msg));
123 msg->destroy(msg);
124
125 return result;
126 }
127
128 /**
129 * see section 3.7.3 of TCG TNC IF-IMV Specification 1.2
130 */
131 TNC_Result TNC_IMV_ReceiveMessage(TNC_IMVID imv_id,
132 TNC_ConnectionID connection_id,
133 TNC_BufferReference msg,
134 TNC_UInt32 msg_len,
135 TNC_MessageType msg_type)
136 {
137 pa_tnc_msg_t *pa_tnc_msg;
138 pa_tnc_attr_t *attr;
139 imv_state_t *state;
140 imv_test_state_t *imv_test_state;
141 enumerator_t *enumerator;
142 TNC_Result result;
143 bool fatal_error = FALSE, retry = FALSE;
144
145 if (!imv_test)
146 {
147 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
148 return TNC_RESULT_NOT_INITIALIZED;
149 }
150
151 /* get current IMV state */
152 if (!imv_test->get_state(imv_test, connection_id, &state))
153 {
154 return TNC_RESULT_FATAL;
155 }
156
157 /* parse received PA-TNC message and automatically handle any errors */
158 result = imv_test->receive_message(imv_test, connection_id,
159 chunk_create(msg, msg_len), msg_type,
160 &pa_tnc_msg);
161
162 /* no parsed PA-TNC attributes available if an error occurred */
163 if (!pa_tnc_msg)
164 {
165 return result;
166 }
167
168 /* analyze PA-TNC attributes */
169 enumerator = pa_tnc_msg->create_attribute_enumerator(pa_tnc_msg);
170 while (enumerator->enumerate(enumerator, &attr))
171 {
172 if (attr->get_vendor_id(attr) == PEN_IETF &&
173 attr->get_type(attr) == IETF_ATTR_PA_TNC_ERROR)
174 {
175 ietf_attr_pa_tnc_error_t *error_attr;
176 pa_tnc_error_code_t error_code;
177 chunk_t msg_info, attr_info;
178 u_int32_t offset;
179
180 error_attr = (ietf_attr_pa_tnc_error_t*)attr;
181 error_code = error_attr->get_error_code(error_attr);
182 msg_info = error_attr->get_msg_info(error_attr);
183
184 DBG1(DBG_IMV, "received PA-TNC error '%N' concerning message %#B",
185 pa_tnc_error_code_names, error_code, &msg_info);
186 switch (error_code)
187 {
188 case PA_ERROR_INVALID_PARAMETER:
189 offset = error_attr->get_offset(error_attr);
190 DBG1(DBG_IMV, " occurred at offset of %u bytes", offset);
191 break;
192 case PA_ERROR_ATTR_TYPE_NOT_SUPPORTED:
193 attr_info = error_attr->get_attr_info(error_attr);
194 DBG1(DBG_IMV, " unsupported attribute %#B", &attr_info);
195 break;
196 default:
197 break;
198 }
199 fatal_error = TRUE;
200 }
201 else if (attr->get_vendor_id(attr) == PEN_ITA &&
202 attr->get_type(attr) == ITA_ATTR_COMMAND)
203 {
204 ita_attr_command_t *ita_attr;
205 char *command;
206
207 ita_attr = (ita_attr_command_t*)attr;
208 command = ita_attr->get_command(ita_attr);
209
210 if (streq(command, "allow"))
211 {
212 state->set_recommendation(state,
213 TNC_IMV_ACTION_RECOMMENDATION_ALLOW,
214 TNC_IMV_EVALUATION_RESULT_COMPLIANT);
215 }
216 else if (streq(command, "isolate"))
217 {
218 state->set_recommendation(state,
219 TNC_IMV_ACTION_RECOMMENDATION_ISOLATE,
220 TNC_IMV_EVALUATION_RESULT_NONCOMPLIANT_MINOR);
221 }
222 else if (streq(command, "block") || streq(command, "none"))
223 {
224 state->set_recommendation(state,
225 TNC_IMV_ACTION_RECOMMENDATION_NO_ACCESS,
226 TNC_IMV_EVALUATION_RESULT_NONCOMPLIANT_MAJOR);
227 }
228 else if (streq(command, "retry"))
229 {
230 retry = TRUE;
231 }
232 else
233 {
234 DBG1(DBG_IMV, "unsupported ITA Command '%s'", command);
235 state->set_recommendation(state,
236 TNC_IMV_ACTION_RECOMMENDATION_NO_RECOMMENDATION,
237 TNC_IMV_EVALUATION_RESULT_ERROR);
238 }
239 }
240 }
241 enumerator->destroy(enumerator);
242 pa_tnc_msg->destroy(pa_tnc_msg);
243
244 if (fatal_error)
245 {
246 state->set_recommendation(state,
247 TNC_IMV_ACTION_RECOMMENDATION_NO_RECOMMENDATION,
248 TNC_IMV_EVALUATION_RESULT_ERROR);
249 return imv_test->provide_recommendation(imv_test, connection_id);
250 }
251
252 /* request a handshake retry ? */
253 if (retry)
254 {
255 return imv_test->request_handshake_retry(imv_id, connection_id,
256 TNC_RETRY_REASON_IMV_SERIOUS_EVENT);
257 }
258
259 /* repeat the measurement ? */
260 imv_test_state = (imv_test_state_t*)state;
261 if (imv_test_state->another_round(imv_test_state))
262 {
263 return send_message(connection_id);
264 }
265
266 return imv_test->provide_recommendation(imv_test, connection_id);
267 }
268
269 /**
270 * see section 3.7.4 of TCG TNC IF-IMV Specification 1.2
271 */
272 TNC_Result TNC_IMV_SolicitRecommendation(TNC_IMVID imv_id,
273 TNC_ConnectionID connection_id)
274 {
275 if (!imv_test)
276 {
277 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
278 return TNC_RESULT_NOT_INITIALIZED;
279 }
280 return imv_test->provide_recommendation(imv_test, connection_id);
281 }
282
283 /**
284 * see section 3.7.5 of TCG TNC IF-IMV Specification 1.2
285 */
286 TNC_Result TNC_IMV_BatchEnding(TNC_IMVID imv_id,
287 TNC_ConnectionID connection_id)
288 {
289 if (!imv_test)
290 {
291 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
292 return TNC_RESULT_NOT_INITIALIZED;
293 }
294 return TNC_RESULT_SUCCESS;
295 }
296
297 /**
298 * see section 3.7.6 of TCG TNC IF-IMV Specification 1.2
299 */
300 TNC_Result TNC_IMV_Terminate(TNC_IMVID imv_id)
301 {
302 if (!imv_test)
303 {
304 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
305 return TNC_RESULT_NOT_INITIALIZED;
306 }
307 imv_test->destroy(imv_test);
308 imv_test = NULL;
309
310 return TNC_RESULT_SUCCESS;
311 }
312
313 /**
314 * see section 4.2.8.1 of TCG TNC IF-IMV Specification 1.2
315 */
316 TNC_Result TNC_IMV_ProvideBindFunction(TNC_IMVID imv_id,
317 TNC_TNCS_BindFunctionPointer bind_function)
318 {
319 if (!imv_test)
320 {
321 DBG1(DBG_IMV, "IMV \"%s\" has not been initialized", imv_name);
322 return TNC_RESULT_NOT_INITIALIZED;
323 }
324 return imv_test->bind_functions(imv_test, bind_function);
325 }