added support for leftsendcert= and left|rightca= parameters
[strongswan.git] / src / stroke / stroke.c
1 /* Stroke for charon is the counterpart to whack from pluto
2 * Copyright (C) 2006 Martin Willi - Hochschule fuer Technik Rapperswil
3 *
4 * This program is free software; you can redistribute it and/or modify it
5 * under the terms of the GNU General Public License as published by the
6 * Free Software Foundation; either version 2 of the License, or (at your
7 * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
8 *
9 * This program is distributed in the hope that it will be useful, but
10 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
11 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
12 * for more details.
13 */
14
15 #include <stdlib.h>
16 #include <sys/types.h>
17 #include <sys/stat.h>
18 #include <sys/socket.h>
19 #include <sys/un.h>
20 #include <sys/fcntl.h>
21 #include <unistd.h>
22 #include <dirent.h>
23 #include <errno.h>
24 #include <stdio.h>
25 #include <linux/stddef.h>
26
27 #include <types.h>
28
29 #include "stroke.h"
30
31 #define streq(a, b) (strcmp((a), (b)) == 0) /* clearer shorthand */
32
33 static char* push_string(stroke_msg_t *msg, char *string)
34 {
35 u_int string_start = msg->length;
36
37 if (string == NULL || msg->length + strlen(string) >= sizeof(stroke_msg_t))
38 {
39 return NULL;
40 }
41 else
42 {
43 msg->length += strlen(string) + 1;
44 strcpy((char*)msg + string_start, string);
45 return (char*)string_start;
46 }
47 }
48
49 static int send_stroke_msg (stroke_msg_t *msg)
50 {
51 struct sockaddr_un ctl_addr = { AF_UNIX, STROKE_SOCKET };
52 int sock;
53 char buffer[64];
54 int byte_count;
55
56 sock = socket(AF_UNIX, SOCK_STREAM, 0);
57 if (sock < 0)
58 {
59 fprintf(stderr, "Opening unix socket %s: %s\n", STROKE_SOCKET, strerror(errno));
60 return -1;
61 }
62 if (connect(sock, (struct sockaddr *)&ctl_addr,
63 offsetof(struct sockaddr_un, sun_path) + strlen(ctl_addr.sun_path)) < 0)
64 {
65 fprintf(stderr, "Connect to socket failed: %s\n", strerror(errno));
66 close(sock);
67 return -1;
68 }
69
70 /* send message */
71 if (write(sock, msg, msg->length) != msg->length)
72 {
73 fprintf(stderr, "writing to socket failed: %s\n", strerror(errno));
74 close(sock);
75 return -1;
76 }
77
78 while ((byte_count = read(sock, buffer, sizeof(buffer)-1)) > 0)
79 {
80 buffer[byte_count] = '\0';
81 printf("%s", buffer);
82 }
83 if (byte_count < 0)
84 {
85 fprintf(stderr, "reading from socket failed: %s\n", strerror(errno));
86 }
87
88 close(sock);
89 return 0;
90 }
91
92 static int add_connection(char *name,
93 char *my_id, char *other_id,
94 char *my_addr, char *other_addr,
95 char *my_net, char *other_net,
96 u_int my_netmask, u_int other_netmask)
97 {
98 stroke_msg_t msg;
99
100 msg.length = offsetof(stroke_msg_t, buffer);
101 msg.type = STR_ADD_CONN;
102
103 msg.add_conn.name = push_string(&msg, name);
104 msg.add_conn.ikev2 = 1;
105
106 msg.add_conn.me.id = push_string(&msg, my_id);
107 msg.add_conn.me.address = push_string(&msg, my_addr);
108 msg.add_conn.me.subnet = push_string(&msg, my_net);
109 msg.add_conn.me.subnet_mask = my_netmask;
110 msg.add_conn.me.cert = NULL;
111 msg.add_conn.me.ca = NULL;
112 msg.add_conn.me.sendcert = CERT_SEND_IF_ASKED;
113
114 msg.add_conn.other.id = push_string(&msg, other_id);
115 msg.add_conn.other.address = push_string(&msg, other_addr);
116 msg.add_conn.other.subnet = push_string(&msg, other_net);
117 msg.add_conn.other.subnet_mask = other_netmask;
118 msg.add_conn.other.cert = NULL;
119 msg.add_conn.other.ca = NULL;
120 msg.add_conn.other.sendcert = CERT_SEND_IF_ASKED;
121
122 return send_stroke_msg(&msg);
123 }
124
125 static int del_connection(char *name)
126 {
127 stroke_msg_t msg;
128
129 msg.length = offsetof(stroke_msg_t, buffer);
130 msg.type = STR_DEL_CONN;
131 msg.initiate.name = push_string(&msg, name);
132 return send_stroke_msg(&msg);
133 }
134
135 static int initiate_connection(char *name)
136 {
137 stroke_msg_t msg;
138
139 msg.length = offsetof(stroke_msg_t, buffer);
140 msg.type = STR_INITIATE;
141 msg.initiate.name = push_string(&msg, name);
142 return send_stroke_msg(&msg);
143 }
144
145 static int terminate_connection(char *name)
146 {
147 stroke_msg_t msg;
148
149 msg.type = STR_TERMINATE;
150 msg.length = offsetof(stroke_msg_t, buffer);
151 msg.initiate.name = push_string(&msg, name);
152 return send_stroke_msg(&msg);
153 }
154
155 static int show_status(char *mode, char *connection)
156 {
157 stroke_msg_t msg;
158
159 if (strcmp(mode, "statusall") == 0)
160 msg.type = STR_STATUS_ALL;
161 else
162 msg.type = STR_STATUS;
163
164 msg.length = offsetof(stroke_msg_t, buffer);
165 msg.status.name = push_string(&msg, connection);
166 return send_stroke_msg(&msg);
167 }
168
169 static int list_certs(void)
170 {
171 stroke_msg_t msg;
172
173 msg.type = STR_LIST_CERTS;
174 msg.length = offsetof(stroke_msg_t, buffer);
175 return send_stroke_msg(&msg);
176 }
177
178 static int set_logtype(char *context, char *type, int enable)
179 {
180 stroke_msg_t msg;
181
182 msg.type = STR_LOGTYPE;
183 msg.length = offsetof(stroke_msg_t, buffer);
184 msg.logtype.context = push_string(&msg, context);
185 msg.logtype.type = push_string(&msg, type);
186 msg.logtype.enable = enable;
187 return send_stroke_msg(&msg);
188 }
189
190 static int set_loglevel(char *context, u_int level)
191 {
192 stroke_msg_t msg;
193
194 msg.type = STR_LOGLEVEL;
195 msg.length = offsetof(stroke_msg_t, buffer);
196 msg.loglevel.context = push_string(&msg, context);
197 msg.loglevel.level = level;
198 return send_stroke_msg(&msg);
199 }
200
201 static void exit_error(char *error)
202 {
203 if (error)
204 {
205 fprintf(stderr, "%s\n", error);
206 }
207 exit(-1);
208 }
209
210 static void exit_usage(char *error)
211 {
212 printf("Usage:\n");
213 printf(" Add a connection:\n");
214 printf(" stroke add NAME MY_ID OTHER_ID MY_ADDR OTHER_ADDR\\\n");
215 printf(" MY_NET OTHER_NET MY_NETBITS OTHER_NETBITS\n");
216 printf(" where: ID is any IKEv2 ID \n");
217 printf(" ADDR is a IPv4 address\n");
218 printf(" NET is a IPv4 address of the subnet to tunnel\n");
219 printf(" NETBITS is the size of the subnet, as the \"24\" in 192.168.0.0/24\n");
220 printf(" Delete a connection:\n");
221 printf(" stroke delete NAME\n");
222 printf(" where: NAME is a connection name added with \"stroke add\"\n");
223 printf(" Initiate a connection:\n");
224 printf(" stroke up NAME\n");
225 printf(" where: NAME is a connection name added with \"stroke add\"\n");
226 printf(" Terminate a connection:\n");
227 printf(" stroke down NAME\n");
228 printf(" where: NAME is a connection name added with \"stroke add\"\n");
229 printf(" Set logtype for a logging context:\n");
230 printf(" stroke logtype CONTEXT TYPE ENABLE\n");
231 printf(" where: CONTEXT is PARSR|GNRAT|IKESA|SAMGR|CHDSA|MESSG|TPOOL|WORKR|SCHED|\n");
232 printf(" SENDR|RECVR|SOCKT|TESTR|DAEMN|CONFG|ENCPL|PAYLD\n");
233 printf(" TYPE is CONTROL|ERROR|AUDIT|RAW|PRIVATE\n");
234 printf(" ENABLE is 0|1\n");
235 printf(" Set loglevel for a logging context:\n");
236 printf(" stroke loglevel CONTEXT LEVEL\n");
237 printf(" where: CONTEXT is PARSR|GNRAT|IKESA|SAMGR|CHDSA|MESSG|TPOOL|WORKR|SCHED|\n");
238 printf(" SENDR|RECVR|SOCKT|TESTR|DAEMN|CONFG|ENCPL|PAYLD\n");
239 printf(" LEVEL is 0|1|2|3\n");
240 printf(" Show connection status:\n");
241 printf(" stroke status\n");
242 printf(" Show list of locally loaded certificates:\n");
243 printf(" stroke listcerts\n");
244 exit_error(error);
245 }
246
247 int main(int argc, char *argv[])
248 {
249 int res = 0;
250 char *op;
251
252 if (argc < 2)
253 {
254 exit_usage(NULL);
255 }
256
257 op = argv[1];
258
259 if (streq(op, "status") || streq(op, "statusall"))
260 {
261 res = show_status(op, argc > 2 ? argv[2] : NULL);
262 }
263 else if (streq(op, "listcerts") || streq(op, "listall"))
264 {
265 res = list_certs();
266 }
267 else if (streq(op, "up"))
268 {
269 if (argc < 3)
270 {
271 exit_usage("\"up\" needs a connection name");
272 }
273 res = initiate_connection(argv[2]);
274 }
275 else if (streq(op, "down"))
276 {
277 if (argc < 3)
278 {
279 exit_usage("\"down\" needs a connection name");
280 }
281 res = terminate_connection(argv[2]);
282 }
283 else if (streq(op, "add"))
284 {
285 if (argc < 11)
286 {
287 exit_usage("\"add\" needs more parameters...");
288 }
289 res = add_connection(argv[2],
290 argv[3], argv[4],
291 argv[5], argv[6],
292 argv[7], argv[8],
293 atoi(argv[9]), atoi(argv[10]));
294 }
295 else if (streq(op, "delete"))
296 {
297 if (argc < 3)
298 {
299 exit_usage("\"delete\" needs a connection name");
300 }
301 res = del_connection(argv[2]);
302 }
303 else if (streq(op, "logtype"))
304 {
305 if (argc < 5)
306 {
307 exit_usage("\"logtype\" needs more parameters...");
308 }
309 res = set_logtype(argv[2], argv[3], atoi(argv[4]));
310 }
311 else if (streq(op, "loglevel"))
312 {
313 if (argc < 4)
314 {
315 exit_usage("\"logtype\" needs more parameters...");
316 }
317 res = set_loglevel(argv[2], atoi(argv[3]));
318 }
319 else
320 {
321 exit_usage(NULL);
322 }
323
324 return res;
325 }