added a "purgeike" command to stroke, deleting all IKE_SAs without a CHILD_SA
[strongswan.git] / src / stroke / stroke.c
1 /* Stroke for charon is the counterpart to whack from pluto
2 * Copyright (C) 2007 Tobias Brunner
3 * Copyright (C) 2006 Martin Willi
4 * Hochschule fuer Technik Rapperswil
5 *
6 * This program is free software; you can redistribute it and/or modify it
7 * under the terms of the GNU General Public License as published by the
8 * Free Software Foundation; either version 2 of the License, or (at your
9 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
10 *
11 * This program is distributed in the hope that it will be useful, but
12 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
13 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
14 * for more details.
15 */
16
17 #include <stdlib.h>
18 #include <sys/types.h>
19 #include <sys/stat.h>
20 #include <sys/socket.h>
21 #include <sys/un.h>
22 #include <sys/fcntl.h>
23 #include <unistd.h>
24 #include <dirent.h>
25 #include <errno.h>
26 #include <stdio.h>
27 #include <stddef.h>
28 #include <string.h>
29
30 #include "stroke_msg.h"
31 #include "stroke_keywords.h"
32
33 struct stroke_token {
34 char *name;
35 stroke_keyword_t kw;
36 };
37
38 static char* push_string(stroke_msg_t *msg, char *string)
39 {
40 unsigned long string_start = msg->length;
41
42 if (string == NULL || msg->length + strlen(string) >= sizeof(stroke_msg_t))
43 {
44 return NULL;
45 }
46 else
47 {
48 msg->length += strlen(string) + 1;
49 strcpy((char*)msg + string_start, string);
50 return (char*)string_start;
51 }
52 }
53
54 static int send_stroke_msg (stroke_msg_t *msg)
55 {
56 struct sockaddr_un ctl_addr;
57 int sock;
58 char buffer[64];
59 int byte_count;
60
61 ctl_addr.sun_family = AF_UNIX;
62 strcpy(ctl_addr.sun_path, STROKE_SOCKET);
63
64 msg->output_verbosity = 1; /* CONTROL */
65
66 sock = socket(AF_UNIX, SOCK_STREAM, 0);
67 if (sock < 0)
68 {
69 fprintf(stderr, "Opening unix socket %s: %s\n", STROKE_SOCKET, strerror(errno));
70 return -1;
71 }
72 if (connect(sock, (struct sockaddr *)&ctl_addr,
73 offsetof(struct sockaddr_un, sun_path) + strlen(ctl_addr.sun_path)) < 0)
74 {
75 fprintf(stderr, "Connect to socket failed: %s\n", strerror(errno));
76 close(sock);
77 return -1;
78 }
79
80 /* send message */
81 if (write(sock, msg, msg->length) != msg->length)
82 {
83 fprintf(stderr, "writing to socket failed: %s\n", strerror(errno));
84 close(sock);
85 return -1;
86 }
87
88 while ((byte_count = read(sock, buffer, sizeof(buffer)-1)) > 0)
89 {
90 buffer[byte_count] = '\0';
91 printf("%s", buffer);
92 }
93 if (byte_count < 0)
94 {
95 fprintf(stderr, "reading from socket failed: %s\n", strerror(errno));
96 }
97
98 close(sock);
99 return 0;
100 }
101
102 static int add_connection(char *name,
103 char *my_id, char *other_id,
104 char *my_addr, char *other_addr,
105 char *my_nets, char *other_nets)
106 {
107 stroke_msg_t msg;
108
109 memset(&msg, 0, sizeof(msg));
110 msg.length = offsetof(stroke_msg_t, buffer);
111 msg.type = STR_ADD_CONN;
112
113 msg.add_conn.name = push_string(&msg, name);
114 msg.add_conn.ikev2 = 1;
115 msg.add_conn.auth_method = 2;
116 msg.add_conn.mode = 1;
117 msg.add_conn.mobike = 1;
118 msg.add_conn.dpd.action = 1;
119
120 msg.add_conn.me.id = push_string(&msg, my_id);
121 msg.add_conn.me.address = push_string(&msg, my_addr);
122 msg.add_conn.me.subnets = push_string(&msg, my_nets);
123 msg.add_conn.me.sendcert = 1;
124
125 msg.add_conn.other.id = push_string(&msg, other_id);
126 msg.add_conn.other.address = push_string(&msg, other_addr);
127 msg.add_conn.other.subnets = push_string(&msg, other_nets);
128 msg.add_conn.other.sendcert = 1;
129
130 return send_stroke_msg(&msg);
131 }
132
133 static int del_connection(char *name)
134 {
135 stroke_msg_t msg;
136
137 msg.length = offsetof(stroke_msg_t, buffer);
138 msg.type = STR_DEL_CONN;
139 msg.initiate.name = push_string(&msg, name);
140 return send_stroke_msg(&msg);
141 }
142
143 static int initiate_connection(char *name)
144 {
145 stroke_msg_t msg;
146
147 msg.length = offsetof(stroke_msg_t, buffer);
148 msg.type = STR_INITIATE;
149 msg.initiate.name = push_string(&msg, name);
150 return send_stroke_msg(&msg);
151 }
152
153 static int terminate_connection(char *name)
154 {
155 stroke_msg_t msg;
156
157 msg.type = STR_TERMINATE;
158 msg.length = offsetof(stroke_msg_t, buffer);
159 msg.initiate.name = push_string(&msg, name);
160 return send_stroke_msg(&msg);
161 }
162
163 static int terminate_connection_srcip(char *start, char *end)
164 {
165 stroke_msg_t msg;
166
167 msg.type = STR_TERMINATE_SRCIP;
168 msg.length = offsetof(stroke_msg_t, buffer);
169 msg.terminate_srcip.start = push_string(&msg, start);
170 msg.terminate_srcip.end = push_string(&msg, end);
171 return send_stroke_msg(&msg);
172 }
173
174 static int route_connection(char *name)
175 {
176 stroke_msg_t msg;
177
178 msg.type = STR_ROUTE;
179 msg.length = offsetof(stroke_msg_t, buffer);
180 msg.route.name = push_string(&msg, name);
181 return send_stroke_msg(&msg);
182 }
183
184 static int unroute_connection(char *name)
185 {
186 stroke_msg_t msg;
187
188 msg.type = STR_UNROUTE;
189 msg.length = offsetof(stroke_msg_t, buffer);
190 msg.unroute.name = push_string(&msg, name);
191 return send_stroke_msg(&msg);
192 }
193
194 static int show_status(stroke_keyword_t kw, char *connection)
195 {
196 stroke_msg_t msg;
197
198 msg.type = (kw == STROKE_STATUS)? STR_STATUS:STR_STATUS_ALL;
199 msg.length = offsetof(stroke_msg_t, buffer);
200 msg.status.name = push_string(&msg, connection);
201 return send_stroke_msg(&msg);
202 }
203
204 static int list_flags[] = {
205 LIST_PUBKEYS,
206 LIST_CERTS,
207 LIST_CACERTS,
208 LIST_OCSPCERTS,
209 LIST_AACERTS,
210 LIST_ACERTS,
211 LIST_GROUPS,
212 LIST_CAINFOS,
213 LIST_CRLS,
214 LIST_OCSP,
215 LIST_ALGS,
216 LIST_ALL
217 };
218
219 static int list(stroke_keyword_t kw, int utc)
220 {
221 stroke_msg_t msg;
222
223 msg.type = STR_LIST;
224 msg.length = offsetof(stroke_msg_t, buffer);
225 msg.list.utc = utc;
226 msg.list.flags = list_flags[kw - STROKE_LIST_FIRST];
227 return send_stroke_msg(&msg);
228 }
229
230 static int reread_flags[] = {
231 REREAD_SECRETS,
232 REREAD_CACERTS,
233 REREAD_OCSPCERTS,
234 REREAD_AACERTS,
235 REREAD_ACERTS,
236 REREAD_CRLS,
237 REREAD_ALL
238 };
239
240 static int reread(stroke_keyword_t kw)
241 {
242 stroke_msg_t msg;
243
244 msg.type = STR_REREAD;
245 msg.length = offsetof(stroke_msg_t, buffer);
246 msg.reread.flags = reread_flags[kw - STROKE_REREAD_FIRST];
247 return send_stroke_msg(&msg);
248 }
249
250 static int purge_flags[] = {
251 PURGE_OCSP,
252 PURGE_IKE,
253 };
254
255 static int purge(stroke_keyword_t kw)
256 {
257 stroke_msg_t msg;
258
259 msg.type = STR_PURGE;
260 msg.length = offsetof(stroke_msg_t, buffer);
261 msg.purge.flags = purge_flags[kw - STROKE_PURGE_FIRST];
262 return send_stroke_msg(&msg);
263 }
264
265 static int leases(stroke_keyword_t kw, char *pool, char *address)
266 {
267
268 stroke_msg_t msg;
269
270 msg.type = STR_LEASES;
271 msg.length = offsetof(stroke_msg_t, buffer);
272 msg.leases.pool = push_string(&msg, pool);
273 msg.leases.address = push_string(&msg, address);
274 return send_stroke_msg(&msg);
275 }
276
277 static int set_loglevel(char *type, u_int level)
278 {
279 stroke_msg_t msg;
280
281 msg.type = STR_LOGLEVEL;
282 msg.length = offsetof(stroke_msg_t, buffer);
283 msg.loglevel.type = push_string(&msg, type);
284 msg.loglevel.level = level;
285 return send_stroke_msg(&msg);
286 }
287
288 static void exit_error(char *error)
289 {
290 if (error)
291 {
292 fprintf(stderr, "%s\n", error);
293 }
294 exit(-1);
295 }
296
297 static void exit_usage(char *error)
298 {
299 printf("Usage:\n");
300 printf(" Add a connection:\n");
301 printf(" stroke add NAME MY_ID OTHER_ID MY_ADDR OTHER_ADDR\\\n");
302 printf(" MY_NET OTHER_NET MY_NETBITS OTHER_NETBITS\n");
303 printf(" where: ID is any IKEv2 ID \n");
304 printf(" ADDR is a IPv4 address\n");
305 printf(" NET is a IPv4 subnet in CIDR notation\n");
306 printf(" Delete a connection:\n");
307 printf(" stroke delete NAME\n");
308 printf(" where: NAME is a connection name added with \"stroke add\"\n");
309 printf(" Initiate a connection:\n");
310 printf(" stroke up NAME\n");
311 printf(" where: NAME is a connection name added with \"stroke add\"\n");
312 printf(" Terminate a connection:\n");
313 printf(" stroke down NAME\n");
314 printf(" where: NAME is a connection name added with \"stroke add\"\n");
315 printf(" Terminate a connection by remote srcip:\n");
316 printf(" stroke down-srcip START [END]\n");
317 printf(" where: START and optional END define the clients source IP\n");
318 printf(" Set loglevel for a logging type:\n");
319 printf(" stroke loglevel TYPE LEVEL\n");
320 printf(" where: TYPE is any|dmn|mgr|ike|chd|job|cfg|knl|net|enc|lib\n");
321 printf(" LEVEL is -1|0|1|2|3|4\n");
322 printf(" Show connection status:\n");
323 printf(" stroke status\n");
324 printf(" Show list of authority and attribute certificates:\n");
325 printf(" stroke listcacerts|listocspcerts|listaacerts|listacerts\n");
326 printf(" Show list of end entity certificates, ca info records and crls:\n");
327 printf(" stroke listcerts|listcainfos|listcrls|listall\n");
328 printf(" Show list of supported algorithms:\n");
329 printf(" stroke listalgs\n");
330 printf(" Reload authority and attribute certificates:\n");
331 printf(" stroke rereadcacerts|rereadocspcerts|rereadaacerts|rereadacerts\n");
332 printf(" Reload secrets and crls:\n");
333 printf(" stroke rereadsecrets|rereadcrls|rereadall\n");
334 printf(" Purge ocsp cache entries:\n");
335 printf(" stroke purgeocsp\n");
336 printf(" Purge IKE_SAs without a CHILD_SA:\n");
337 printf(" stroke purgeike\n");
338 printf(" Show leases of a pool:\n");
339 printf(" stroke leases [POOL [ADDRESS]]\n");
340 exit_error(error);
341 }
342
343 int main(int argc, char *argv[])
344 {
345 const stroke_token_t *token;
346 int res = 0;
347
348 if (argc < 2)
349 {
350 exit_usage(NULL);
351 }
352
353 token = in_word_set(argv[1], strlen(argv[1]));
354
355 if (token == NULL)
356 {
357 exit_usage("unknown keyword");
358 }
359
360 switch (token->kw)
361 {
362 case STROKE_ADD:
363 if (argc < 11)
364 {
365 exit_usage("\"add\" needs more parameters...");
366 }
367 res = add_connection(argv[2],
368 argv[3], argv[4],
369 argv[5], argv[6],
370 argv[7], argv[8]);
371 break;
372 case STROKE_DELETE:
373 case STROKE_DEL:
374 if (argc < 3)
375 {
376 exit_usage("\"delete\" needs a connection name");
377 }
378 res = del_connection(argv[2]);
379 break;
380 case STROKE_UP:
381 if (argc < 3)
382 {
383 exit_usage("\"up\" needs a connection name");
384 }
385 res = initiate_connection(argv[2]);
386 break;
387 case STROKE_DOWN:
388 if (argc < 3)
389 {
390 exit_usage("\"down\" needs a connection name");
391 }
392 res = terminate_connection(argv[2]);
393 break;
394 case STROKE_DOWN_SRCIP:
395 if (argc < 3)
396 {
397 exit_usage("\"down-srcip\" needs start and optional end address");
398 }
399 res = terminate_connection_srcip(argv[2], argc > 3 ? argv[3] : NULL);
400 break;
401 case STROKE_ROUTE:
402 if (argc < 3)
403 {
404 exit_usage("\"route\" needs a connection name");
405 }
406 res = route_connection(argv[2]);
407 break;
408 case STROKE_UNROUTE:
409 if (argc < 3)
410 {
411 exit_usage("\"unroute\" needs a connection name");
412 }
413 res = unroute_connection(argv[2]);
414 break;
415 case STROKE_LOGLEVEL:
416 if (argc < 4)
417 {
418 exit_usage("\"logtype\" needs more parameters...");
419 }
420 res = set_loglevel(argv[2], atoi(argv[3]));
421 break;
422 case STROKE_STATUS:
423 case STROKE_STATUSALL:
424 res = show_status(token->kw, argc > 2 ? argv[2] : NULL);
425 break;
426 case STROKE_LIST_PUBKEYS:
427 case STROKE_LIST_CERTS:
428 case STROKE_LIST_CACERTS:
429 case STROKE_LIST_OCSPCERTS:
430 case STROKE_LIST_AACERTS:
431 case STROKE_LIST_ACERTS:
432 case STROKE_LIST_CAINFOS:
433 case STROKE_LIST_CRLS:
434 case STROKE_LIST_OCSP:
435 case STROKE_LIST_ALGS:
436 case STROKE_LIST_ALL:
437 res = list(token->kw, argc > 2 && strcmp(argv[2], "--utc") == 0);
438 break;
439 case STROKE_REREAD_SECRETS:
440 case STROKE_REREAD_CACERTS:
441 case STROKE_REREAD_OCSPCERTS:
442 case STROKE_REREAD_AACERTS:
443 case STROKE_REREAD_ACERTS:
444 case STROKE_REREAD_CRLS:
445 case STROKE_REREAD_ALL:
446 res = reread(token->kw);
447 break;
448 case STROKE_PURGE_OCSP:
449 case STROKE_PURGE_IKE:
450 res = purge(token->kw);
451 break;
452 case STROKE_LEASES:
453 res = leases(token->kw, argc > 2 ? argv[2] : NULL,
454 argc > 3 ? argv[3] : NULL);
455 break;
456 default:
457 exit_usage(NULL);
458 }
459 return res;
460 }