From ba2201edf07eaa6502a8687051a93a2947962213 Mon Sep 17 00:00:00 2001 From: Martin Willi Date: Wed, 3 Aug 2011 15:16:41 +0200 Subject: [PATCH] Added plugin stub of certexpire plugin --- configure.in | 4 ++ src/libcharon/Makefile.am | 7 +++ src/libcharon/plugins/certexpire/Makefile.am | 16 ++++++ .../plugins/certexpire/certexpire_plugin.c | 63 ++++++++++++++++++++++ .../plugins/certexpire/certexpire_plugin.h | 42 +++++++++++++++ 5 files changed, 132 insertions(+) create mode 100644 src/libcharon/plugins/certexpire/Makefile.am create mode 100644 src/libcharon/plugins/certexpire/certexpire_plugin.c create mode 100644 src/libcharon/plugins/certexpire/certexpire_plugin.h diff --git a/configure.in b/configure.in index 2de37bb..d38b0fa 100644 --- a/configure.in +++ b/configure.in @@ -183,6 +183,7 @@ ARG_ENABL_SET([maemo], [enable Maemo specific plugin.]) ARG_ENABL_SET([nm], [enable NetworkManager plugin.]) ARG_ENABL_SET([ha], [enable high availability cluster plugin.]) ARG_ENABL_SET([whitelist], [enable peer identity whitelisting plugin.]) +ARG_ENABL_SET([certexpire], [enable CSV export of expiration dates of used certificates.]) ARG_ENABL_SET([led], [enable plugin to control LEDs on IKEv2 activity using the Linux kernel LED subsystem.]) ARG_ENABL_SET([duplicheck], [advanced duplicate checking plugin using liveness checks.]) ARG_ENABL_SET([coupling], [enable IKEv2 plugin to couple peer certificates permanently to authentication.]) @@ -817,6 +818,7 @@ ADD_PLUGIN([dhcp], [c libcharon]) ADD_PLUGIN([android], [c libcharon]) ADD_PLUGIN([ha], [c libcharon]) ADD_PLUGIN([whitelist], [c libcharon]) +ADD_PLUGIN([certexpire], [c libcharon]) ADD_PLUGIN([led], [c libcharon]) ADD_PLUGIN([duplicheck], [c libcharon]) ADD_PLUGIN([coupling], [c libcharon]) @@ -899,6 +901,7 @@ AM_CONDITIONAL(USE_UNIT_TESTS, test x$unit_tester = xtrue) AM_CONDITIONAL(USE_LOAD_TESTER, test x$load_tester = xtrue) AM_CONDITIONAL(USE_HA, test x$ha = xtrue) AM_CONDITIONAL(USE_WHITELIST, test x$whitelist = xtrue) +AM_CONDITIONAL(USE_CERTEXPIRE, test x$certexpire = xtrue) AM_CONDITIONAL(USE_LED, test x$led = xtrue) AM_CONDITIONAL(USE_DUPLICHECK, test x$duplicheck = xtrue) AM_CONDITIONAL(USE_COUPLING, test x$coupling = xtrue) @@ -1103,6 +1106,7 @@ AC_OUTPUT( src/libcharon/plugins/uci/Makefile src/libcharon/plugins/ha/Makefile src/libcharon/plugins/whitelist/Makefile + src/libcharon/plugins/certexpire/Makefile src/libcharon/plugins/led/Makefile src/libcharon/plugins/duplicheck/Makefile src/libcharon/plugins/coupling/Makefile diff --git a/src/libcharon/Makefile.am b/src/libcharon/Makefile.am index 42c02db..7b46186 100644 --- a/src/libcharon/Makefile.am +++ b/src/libcharon/Makefile.am @@ -431,6 +431,13 @@ if MONOLITHIC endif endif +if USE_CERTEXPIRE + SUBDIRS += plugins/certexpire +if MONOLITHIC + libcharon_la_LIBADD += plugins/certexpire/libstrongswan-certexpire.la +endif +endif + if USE_LED SUBDIRS += plugins/led if MONOLITHIC diff --git a/src/libcharon/plugins/certexpire/Makefile.am b/src/libcharon/plugins/certexpire/Makefile.am new file mode 100644 index 0000000..806cb94 --- /dev/null +++ b/src/libcharon/plugins/certexpire/Makefile.am @@ -0,0 +1,16 @@ + +INCLUDES = -I$(top_srcdir)/src/libstrongswan -I$(top_srcdir)/src/libhydra \ + -I$(top_srcdir)/src/libcharon + +AM_CFLAGS = -rdynamic \ + -DIPSEC_PIDDIR=\"${piddir}\" + +if MONOLITHIC +noinst_LTLIBRARIES = libstrongswan-certexpire.la +else +plugin_LTLIBRARIES = libstrongswan-certexpire.la +endif + +libstrongswan_certexpire_la_SOURCES = certexpire_plugin.h certexpire_plugin.c + +libstrongswan_certexpire_la_LDFLAGS = -module -avoid-version diff --git a/src/libcharon/plugins/certexpire/certexpire_plugin.c b/src/libcharon/plugins/certexpire/certexpire_plugin.c new file mode 100644 index 0000000..8f92b58 --- /dev/null +++ b/src/libcharon/plugins/certexpire/certexpire_plugin.c @@ -0,0 +1,63 @@ +/* + * Copyright (C) 2011 Martin Willi + * Copyright (C) 2011 revosec AG + * + * This program is free software; you can redistribute it and/or modify it + * under the terms of the GNU General Public License as published by the + * Free Software Foundation; either version 2 of the License, or (at your + * option) any later version. See . + * + * This program is distributed in the hope that it will be useful, but + * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY + * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License + * for more details. + */ + +#include "certexpire_plugin.h" + +#include + +typedef struct private_certexpire_plugin_t private_certexpire_plugin_t; + +/** + * Private data of certexpire plugin + */ +struct private_certexpire_plugin_t { + + /** + * Implements plugin interface + */ + certexpire_plugin_t public; +}; + +METHOD(plugin_t, get_name, char*, + private_certexpire_plugin_t *this) +{ + return "certexpire"; +} + +METHOD(plugin_t, destroy, void, + private_certexpire_plugin_t *this) +{ + free(this); +} + +/** + * Plugin constructor + */ +plugin_t *certexpire_plugin_create() +{ + private_certexpire_plugin_t *this; + + INIT(this, + .public = { + .plugin = { + .get_name = _get_name, + .reload = (void*)return_false, + .destroy = _destroy, + }, + }, + ); + + return &this->public.plugin; +} diff --git a/src/libcharon/plugins/certexpire/certexpire_plugin.h b/src/libcharon/plugins/certexpire/certexpire_plugin.h new file mode 100644 index 0000000..bcb5606 --- /dev/null +++ b/src/libcharon/plugins/certexpire/certexpire_plugin.h @@ -0,0 +1,42 @@ +/* + * Copyright (C) 2011 Martin Willi + * Copyright (C) 2011 revosec AG + * + * This program is free software; you can redistribute it and/or modify it + * under the terms of the GNU General Public License as published by the + * Free Software Foundation; either version 2 of the License, or (at your + * option) any later version. See . + * + * This program is distributed in the hope that it will be useful, but + * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY + * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License + * for more details. + */ + +/** + * @defgroup certexpire certexpire + * @ingroup cplugins + * + * @defgroup certexpire_plugin certexpire_plugin + * @{ @ingroup certexpire + */ + +#ifndef CERTEXPIRE_PLUGIN_H_ +#define CERTEXPIRE_PLUGIN_H_ + +#include + +typedef struct certexpire_plugin_t certexpire_plugin_t; + +/** + * Plugin exporting expiration dates of used certificates to CSV files. + */ +struct certexpire_plugin_t { + + /** + * Implements plugin interface. + */ + plugin_t plugin; +}; + +#endif /** CERTEXPIRE_PLUGIN_H_ @}*/ -- 2.7.4