support for stroke listcerts|listcacerts|listall and left|rightca=
[strongswan.git] / src / stroke / stroke.c
1 /* Stroke for charon is the counterpart to whack from pluto
2 * Copyright (C) 2006 Martin Willi - Hochschule fuer Technik Rapperswil
3 *
4 * This program is free software; you can redistribute it and/or modify it
5 * under the terms of the GNU General Public License as published by the
6 * Free Software Foundation; either version 2 of the License, or (at your
7 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
8 *
9 * This program is distributed in the hope that it will be useful, but
10 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
11 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
12 * for more details.
13 */
14
15 #include <stdlib.h>
16 #include <sys/types.h>
17 #include <sys/stat.h>
18 #include <sys/socket.h>
19 #include <sys/un.h>
20 #include <sys/fcntl.h>
21 #include <unistd.h>
22 #include <dirent.h>
23 #include <errno.h>
24 #include <stdio.h>
25 #include <linux/stddef.h>
26
27 #include <types.h>
28
29 #include "stroke.h"
30 #include "stroke_keywords.h"
31
32 struct stroke_token {
33 char *name;
34 stroke_keyword_t kw;
35 };
36
37 static char* push_string(stroke_msg_t *msg, char *string)
38 {
39 u_int string_start = msg->length;
40
41 if (string == NULL || msg->length + strlen(string) >= sizeof(stroke_msg_t))
42 {
43 return NULL;
44 }
45 else
46 {
47 msg->length += strlen(string) + 1;
48 strcpy((char*)msg + string_start, string);
49 return (char*)string_start;
50 }
51 }
52
53 static int send_stroke_msg (stroke_msg_t *msg)
54 {
55 struct sockaddr_un ctl_addr = { AF_UNIX, STROKE_SOCKET };
56 int sock;
57 char buffer[64];
58 int byte_count;
59
60 sock = socket(AF_UNIX, SOCK_STREAM, 0);
61 if (sock < 0)
62 {
63 fprintf(stderr, "Opening unix socket %s: %s\n", STROKE_SOCKET, strerror(errno));
64 return -1;
65 }
66 if (connect(sock, (struct sockaddr *)&ctl_addr,
67 offsetof(struct sockaddr_un, sun_path) + strlen(ctl_addr.sun_path)) < 0)
68 {
69 fprintf(stderr, "Connect to socket failed: %s\n", strerror(errno));
70 close(sock);
71 return -1;
72 }
73
74 /* send message */
75 if (write(sock, msg, msg->length) != msg->length)
76 {
77 fprintf(stderr, "writing to socket failed: %s\n", strerror(errno));
78 close(sock);
79 return -1;
80 }
81
82 while ((byte_count = read(sock, buffer, sizeof(buffer)-1)) > 0)
83 {
84 buffer[byte_count] = '\0';
85 printf("%s", buffer);
86 }
87 if (byte_count < 0)
88 {
89 fprintf(stderr, "reading from socket failed: %s\n", strerror(errno));
90 }
91
92 close(sock);
93 return 0;
94 }
95
96 static int add_connection(char *name,
97 char *my_id, char *other_id,
98 char *my_addr, char *other_addr,
99 char *my_net, char *other_net,
100 u_int my_netmask, u_int other_netmask)
101 {
102 stroke_msg_t msg;
103
104 msg.length = offsetof(stroke_msg_t, buffer);
105 msg.type = STR_ADD_CONN;
106
107 msg.add_conn.name = push_string(&msg, name);
108 msg.add_conn.ikev2 = 1;
109
110 msg.add_conn.rekey.ipsec_lifetime = 0;
111 msg.add_conn.rekey.ike_lifetime = 0;
112 msg.add_conn.rekey.margin = 0;
113 msg.add_conn.rekey.tries = 0;
114 msg.add_conn.rekey.fuzz = 0;
115
116 msg.add_conn.me.id = push_string(&msg, my_id);
117 msg.add_conn.me.address = push_string(&msg, my_addr);
118 msg.add_conn.me.subnet = push_string(&msg, my_net);
119 msg.add_conn.me.subnet_mask = my_netmask;
120 msg.add_conn.me.cert = NULL;
121 msg.add_conn.me.ca = NULL;
122 msg.add_conn.me.sendcert = CERT_SEND_IF_ASKED;
123
124 msg.add_conn.other.id = push_string(&msg, other_id);
125 msg.add_conn.other.address = push_string(&msg, other_addr);
126 msg.add_conn.other.subnet = push_string(&msg, other_net);
127 msg.add_conn.other.subnet_mask = other_netmask;
128 msg.add_conn.other.cert = NULL;
129 msg.add_conn.other.ca = NULL;
130 msg.add_conn.other.sendcert = CERT_SEND_IF_ASKED;
131
132 return send_stroke_msg(&msg);
133 }
134
135 static int del_connection(char *name)
136 {
137 stroke_msg_t msg;
138
139 msg.length = offsetof(stroke_msg_t, buffer);
140 msg.type = STR_DEL_CONN;
141 msg.initiate.name = push_string(&msg, name);
142 return send_stroke_msg(&msg);
143 }
144
145 static int initiate_connection(char *name)
146 {
147 stroke_msg_t msg;
148
149 msg.length = offsetof(stroke_msg_t, buffer);
150 msg.type = STR_INITIATE;
151 msg.initiate.name = push_string(&msg, name);
152 return send_stroke_msg(&msg);
153 }
154
155 static int terminate_connection(char *name)
156 {
157 stroke_msg_t msg;
158
159 msg.type = STR_TERMINATE;
160 msg.length = offsetof(stroke_msg_t, buffer);
161 msg.initiate.name = push_string(&msg, name);
162 return send_stroke_msg(&msg);
163 }
164
165 static int show_status(stroke_keyword_t kw, char *connection)
166 {
167 stroke_msg_t msg;
168
169 msg.type = (kw == STROKE_STATUS)? STR_STATUS:STR_STATUS_ALL;
170 msg.length = offsetof(stroke_msg_t, buffer);
171 msg.status.name = push_string(&msg, connection);
172 return send_stroke_msg(&msg);
173 }
174
175 static int list_flags[] = {
176 LIST_CERTS,
177 LIST_CACERTS,
178 LIST_CRLS,
179 LIST_ALL
180 };
181
182 static int list(stroke_keyword_t kw, bool utc)
183 {
184 stroke_msg_t msg;
185
186 msg.type = STR_LIST;
187 msg.length = offsetof(stroke_msg_t, buffer);
188 msg.list.utc = utc;
189 msg.list.flags = list_flags[kw - STROKE_LIST_FIRST];
190 return send_stroke_msg(&msg);
191 }
192
193 static int set_logtype(char *context, char *type, int enable)
194 {
195 stroke_msg_t msg;
196
197 msg.type = STR_LOGTYPE;
198 msg.length = offsetof(stroke_msg_t, buffer);
199 msg.logtype.context = push_string(&msg, context);
200 msg.logtype.type = push_string(&msg, type);
201 msg.logtype.enable = enable;
202 return send_stroke_msg(&msg);
203 }
204
205 static int set_loglevel(char *context, u_int level)
206 {
207 stroke_msg_t msg;
208
209 msg.type = STR_LOGLEVEL;
210 msg.length = offsetof(stroke_msg_t, buffer);
211 msg.loglevel.context = push_string(&msg, context);
212 msg.loglevel.level = level;
213 return send_stroke_msg(&msg);
214 }
215
216 static void exit_error(char *error)
217 {
218 if (error)
219 {
220 fprintf(stderr, "%s\n", error);
221 }
222 exit(-1);
223 }
224
225 static void exit_usage(char *error)
226 {
227 printf("Usage:\n");
228 printf(" Add a connection:\n");
229 printf(" stroke add NAME MY_ID OTHER_ID MY_ADDR OTHER_ADDR\\\n");
230 printf(" MY_NET OTHER_NET MY_NETBITS OTHER_NETBITS\n");
231 printf(" where: ID is any IKEv2 ID \n");
232 printf(" ADDR is a IPv4 address\n");
233 printf(" NET is a IPv4 address of the subnet to tunnel\n");
234 printf(" NETBITS is the size of the subnet, as the \"24\" in 192.168.0.0/24\n");
235 printf(" Delete a connection:\n");
236 printf(" stroke delete NAME\n");
237 printf(" where: NAME is a connection name added with \"stroke add\"\n");
238 printf(" Initiate a connection:\n");
239 printf(" stroke up NAME\n");
240 printf(" where: NAME is a connection name added with \"stroke add\"\n");
241 printf(" Terminate a connection:\n");
242 printf(" stroke down NAME\n");
243 printf(" where: NAME is a connection name added with \"stroke add\"\n");
244 printf(" Set logtype for a logging context:\n");
245 printf(" stroke logtype CONTEXT TYPE ENABLE\n");
246 printf(" where: CONTEXT is PARSR|GNRAT|IKESA|SAMGR|CHDSA|MESSG|TPOOL|WORKR|SCHED|\n");
247 printf(" SENDR|RECVR|SOCKT|TESTR|DAEMN|CONFG|ENCPL|PAYLD\n");
248 printf(" TYPE is CONTROL|ERROR|AUDIT|RAW|PRIVATE\n");
249 printf(" ENABLE is 0|1\n");
250 printf(" Set loglevel for a logging context:\n");
251 printf(" stroke loglevel CONTEXT LEVEL\n");
252 printf(" where: CONTEXT is PARSR|GNRAT|IKESA|SAMGR|CHDSA|MESSG|TPOOL|WORKR|SCHED|\n");
253 printf(" SENDR|RECVR|SOCKT|TESTR|DAEMN|CONFG|ENCPL|PAYLD\n");
254 printf(" LEVEL is 0|1|2|3\n");
255 printf(" Show connection status:\n");
256 printf(" stroke status\n");
257 printf(" Show list of locally loaded certificates:\n");
258 printf(" stroke listcerts\n");
259 exit_error(error);
260 }
261
262 int main(int argc, char *argv[])
263 {
264 const stroke_token_t *token;
265 int res = 0;
266
267 if (argc < 2)
268 {
269 exit_usage(NULL);
270 }
271
272 token = in_word_set(argv[1], strlen(argv[1]));
273
274 if (token == NULL)
275 {
276 exit_usage("unknown keyword");
277 }
278
279 switch (token->kw)
280 {
281 case STROKE_ADD:
282 if (argc < 11)
283 {
284 exit_usage("\"add\" needs more parameters...");
285 }
286 res = add_connection(argv[2],
287 argv[3], argv[4],
288 argv[5], argv[6],
289 argv[7], argv[8],
290 atoi(argv[9]), atoi(argv[10]));
291 break;
292 case STROKE_DELETE:
293 case STROKE_DEL:
294 if (argc < 3)
295 {
296 exit_usage("\"delete\" needs a connection name");
297 }
298 res = del_connection(argv[2]);
299 break;
300 case STROKE_UP:
301 if (argc < 3)
302 {
303 exit_usage("\"up\" needs a connection name");
304 }
305 res = initiate_connection(argv[2]);
306 break;
307 case STROKE_DOWN:
308 if (argc < 3)
309 {
310 exit_usage("\"down\" needs a connection name");
311 }
312 res = terminate_connection(argv[2]);
313 break;
314 case STROKE_LOGTYPE:
315 if (argc < 5)
316 {
317 exit_usage("\"logtype\" needs more parameters...");
318 }
319 res = set_logtype(argv[2], argv[3], atoi(argv[4]));
320 break;
321 case STROKE_LOGLEVEL:
322 if (argc < 4)
323 {
324 exit_usage("\"logtype\" needs more parameters...");
325 }
326 res = set_loglevel(argv[2], atoi(argv[3]));
327 break;
328 case STROKE_STATUS:
329 case STROKE_STATUSALL:
330 res = show_status(token->kw, argc > 2 ? argv[2] : NULL);
331 break;
332 case STROKE_LIST_CERTS:
333 case STROKE_LIST_CACERTS:
334 case STROKE_LIST_CRLS:
335 case STROKE_LIST_ALL:
336 res = list(token->kw, argc > 2 && streq(argv[2], "--utc"));
337 break;
338 default:
339 exit_usage(NULL);
340 }
341 return res;
342 }