1 /* $NetBSD: remoteconf.h,v 1.7 2006/10/03 08:01:56 vanhu Exp $ */
3 /* Id: remoteconf.h,v 1.26 2006/05/06 15:52:44 manubsd Exp */
6 * Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project.
9 * Redistribution and use in source and binary forms, with or without
10 * modification, are permitted provided that the following conditions
12 * 1. Redistributions of source code must retain the above copyright
13 * notice, this list of conditions and the following disclaimer.
14 * 2. Redistributions in binary form must reproduce the above copyright
15 * notice, this list of conditions and the following disclaimer in the
16 * documentation and/or other materials provided with the distribution.
17 * 3. Neither the name of the project nor the names of its contributors
18 * may be used to endorse or promote products derived from this software
19 * without specific prior written permission.
21 * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
22 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
23 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
24 * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
25 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
26 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
27 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
28 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
29 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
30 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
37 /* remote configuration */
39 #include <sys/queue.h>
42 #include "isakmp_var.h"
43 #include "isakmp_xauth.h"
45 #include <CoreFoundation/CFData.h>
46 #include "algorithm.h"
51 time_t lifetime
; /* for isakmp/ipsec */
52 int lifebyte
; /* for isakmp/ipsec */
53 struct secprotospec
*spspec
; /* the head is always current spec. */
54 struct proposalspec
*next
; /* the tail is the most prefered. */
55 struct proposalspec
*prev
;
61 int strength
; /* for isakmp/ipsec */
62 int encklen
; /* for isakmp/ipsec */
63 time_t lifetime
; /* for isakmp */
64 int lifebyte
; /* for isakmp */
65 int proto_id
; /* for ipsec (isakmp?) */
66 int ipsec_level
; /* for ipsec */
67 int encmode
; /* for ipsec */
68 int vendorid
; /* for isakmp */
70 struct sockaddr_storage
*remote
;
71 int algclass
[MAXALGCLASS
];
73 struct secprotospec
*next
; /* the tail is the most prefiered. */
74 struct secprotospec
*prev
;
75 struct proposalspec
*back
;
86 DPD_ALGO_INBOUND_DETECT
,
87 DPD_ALGO_BLACKHOLE_DETECT
,
93 struct sockaddr_storage
*remote
; /* remote IP address */
94 int remote_prefix
; /* allows subnet for remote address */
95 /* if family is AF_UNSPEC, that is
96 * for anonymous configuration. */
98 struct etypes
*etypes
; /* exchange type list. the head
99 * is a type to be sent first. */
100 int doitype
; /* doi type */
101 int sittype
; /* situation type */
103 int idvtype
; /* my identifier type */
104 vchar_t
*idv
; /* my identifier */
105 vchar_t
*key
; /* my pre-shared key */
106 struct genlist
*idvl_p
; /* peer's identifiers list */
108 int identity_in_keychain
; /* cert and private key is in the keychain */
109 vchar_t
*keychainCertRef
; /* peristant keychain ref for cert */
110 int secrettype
; /* type of secret [use, key, keychain] */
111 vchar_t
*shared_secret
; /* shared secret */
112 vchar_t
*open_dir_auth_group
; /* group to be used to authorize user */
114 int certtype
; /* certificate type if need */
115 int getcert_method
; /* the way to get peer's certificate */
116 int cacerttype
; /* CA type is needed */
117 int send_cert
; /* send to CERT or not */
118 int send_cr
; /* send to CR or not */
119 int verify_cert
; /* verify a CERT strictly */
120 int cert_verification
; /* openssl or security framework */
121 int cert_verification_option
; /* nothing, peers identifier, or open_dir */
122 int verify_identifier
; /* vefify the peer's identifier */
123 int nonce_size
; /* the number of bytes of nonce */
124 int passive
; /* never initiate */
125 int ike_frag
; /* IKE fragmentation */
126 int esp_frag
; /* ESP fragmentation */
127 int mode_cfg
; /* Gets config through mode config */
128 int support_proxy
; /* support mip6/proxy */
129 #define GENERATE_POLICY_NONE 0
130 #define GENERATE_POLICY_REQUIRE 1
131 #define GENERATE_POLICY_UNIQUE 2
132 int gen_policy
; /* generate policy if no policy found */
133 int ini_contact
; /* initial contact */
134 int pcheck_level
; /* level of propocl checking */
135 int nat_traversal
; /* NAT-Traversal */
136 int natt_multiple_user
; /* special handling of multiple users behind a nat - for VPN server */
137 int natt_keepalive
; /* do we need to send natt keep alive */
138 int dh_group
; /* use it when only aggressive mode */
139 struct dhgroup
*dhgrp
; /* use it when only aggressive mode */
140 /* above two can't be defined by user*/
142 int retry_counter
; /* times to retry. */
143 int retry_interval
; /* interval each retry. */
144 /* above 2 values are copied from localconf. */
146 int dpd
; /* Negociate DPD support ? */
147 int dpd_retry
; /* in seconds */
148 int dpd_interval
; /* in seconds */
151 int idle_timeout
; /* in seconds */
152 int idle_timeout_dir
; /* direction to check */
154 int ph1id
; /* ph1id to be matched with sainfo sections */
156 int weak_phase1_check
; /* act on unencrypted deletions ? */
158 struct isakmpsa
*proposal
; /* proposal list */
159 struct remoteconf
*inherited_from
; /* the original rmconf
162 struct proposalspec
*prhead
;
165 struct xauth_rmconf
*xauth
;
167 int initiate_ph1rekey
;
168 int in_list
; // in the linked list
169 int refcount
; // ref count - in use
172 struct sockaddr_storage
*forced_local
; /* forced local IP address */
174 TAILQ_ENTRY(remoteconf
) chain
; /* next remote conf */
179 /* ISAKMP SA specification */
192 int dh_group
; /* don't use it if aggressive mode */
193 struct dhgroup
*dhgrp
; /* don't use it if aggressive mode */
197 struct isakmpsa
*next
; /* next transform */
198 struct remoteconf
*rmconf
; /* backpointer to remoteconf */
202 int idtype
; /* identifier type */
203 vchar_t
*id
; /* identifier */
206 typedef struct remoteconf
*(rmconf_func_t
) (struct remoteconf
*rmconf
, void *data
);
208 extern struct remoteconf
*getrmconf (struct sockaddr_storage
*);
209 extern struct remoteconf
*getrmconf_strict
210 (struct sockaddr_storage
*remote
, int allow_anon
);
212 extern int no_remote_configs (int);
213 extern struct remoteconf
*copyrmconf (struct sockaddr_storage
*);
214 extern struct remoteconf
*create_rmconf (void);
215 extern void retain_rmconf(struct remoteconf
*);
216 extern void release_rmconf(struct remoteconf
*);
217 extern struct remoteconf
*duprmconf (struct remoteconf
*);
218 extern void delrmconf (struct remoteconf
*);
219 extern void delisakmpsa (struct isakmpsa
*);
220 extern void deletypes (struct etypes
*);
221 extern struct etypes
* dupetypes (struct etypes
*);
222 extern void insrmconf (struct remoteconf
*);
223 extern void remrmconf (struct remoteconf
*);
224 extern void flushrmconf (void);
225 extern void initrmconf (void);
226 extern struct etypes
*check_etypeok
227 (struct remoteconf
*, u_int8_t
);
228 extern struct remoteconf
*foreachrmconf (rmconf_func_t rmconf_func
,
231 extern struct isakmpsa
*newisakmpsa (void);
232 extern struct isakmpsa
*dupisakmpsa (struct isakmpsa
*);
234 extern void insisakmpsa (struct isakmpsa
*, struct remoteconf
*);
236 extern void dumprmconf (void);
238 extern struct idspec
*newidspec (void);
240 #endif /* _REMOTECONF_H */