]> git.saurik.com Git - apple/network_cmds.git/blob - racoon.tproj/isakmp_newg.c
network_cmds-245.19.tar.gz
[apple/network_cmds.git] / racoon.tproj / isakmp_newg.c
1 /* $KAME: isakmp_newg.c,v 1.10 2002/09/27 05:55:52 itojun Exp $ */
2
3 /*
4 * Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project.
5 * All rights reserved.
6 *
7 * Redistribution and use in source and binary forms, with or without
8 * modification, are permitted provided that the following conditions
9 * are met:
10 * 1. Redistributions of source code must retain the above copyright
11 * notice, this list of conditions and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in the
14 * documentation and/or other materials provided with the distribution.
15 * 3. Neither the name of the project nor the names of its contributors
16 * may be used to endorse or promote products derived from this software
17 * without specific prior written permission.
18 *
19 * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
20 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
21 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
22 * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
23 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
24 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
25 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
26 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
27 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
28 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
29 * SUCH DAMAGE.
30 */
31
32 #include <sys/types.h>
33 #include <sys/param.h>
34
35 #include <stdlib.h>
36 #include <stdio.h>
37 #include <string.h>
38 #include <errno.h>
39
40 #include "var.h"
41 #include "misc.h"
42 #include "vmbuf.h"
43 #include "plog.h"
44 #include "sockmisc.h"
45 #include "debug.h"
46
47 #include "schedule.h"
48 #include "cfparse.h"
49 #include "isakmp_var.h"
50 #include "isakmp.h"
51 #include "isakmp_newg.h"
52 #include "oakley.h"
53 #include "ipsec_doi.h"
54 #include "crypto_openssl.h"
55 #include "handler.h"
56 #include "pfkey.h"
57 #include "admin.h"
58 #include "str2val.h"
59 #include "vendorid.h"
60
61 /*
62 * New group mode as responder
63 */
64 int
65 isakmp_newgroup_r(iph1, msg)
66 struct ph1handle *iph1;
67 vchar_t *msg;
68 {
69 #if 0
70 struct isakmp *isakmp = (struct isakmp *)msg->v;
71 struct isakmp_pl_hash *hash = NULL;
72 struct isakmp_pl_sa *sa = NULL;
73 int error = -1;
74 vchar_t *buf;
75 struct oakley_sa *osa;
76 int len;
77
78 /* validate the type of next payload */
79 /*
80 * ISAKMP_ETYPE_NEWGRP,
81 * ISAKMP_NPTYPE_HASH, (ISAKMP_NPTYPE_VID), ISAKMP_NPTYPE_SA,
82 * ISAKMP_NPTYPE_NONE
83 */
84 {
85 vchar_t *pbuf = NULL;
86 struct isakmp_parse_t *pa;
87
88 if ((pbuf = isakmp_parse(msg)) == NULL)
89 goto end;
90
91 for (pa = (struct isakmp_parse_t *)pbuf->v;
92 pa->type != ISAKMP_NPTYPE_NONE;
93 pa++) {
94
95 switch (pa->type) {
96 case ISAKMP_NPTYPE_HASH:
97 if (hash) {
98 isakmp_info_send_n1(iph1, ISAKMP_NTYPE_INVALID_PAYLOAD_TYPE, NULL);
99 plog(LLV_ERROR, LOCATION, iph1->remote,
100 "received multiple payload type %d.\n",
101 pa->type);
102 vfree(pbuf);
103 goto end;
104 }
105 hash = (struct isakmp_pl_hash *)pa->ptr;
106 break;
107 case ISAKMP_NPTYPE_SA:
108 if (sa) {
109 isakmp_info_send_n1(iph1, ISAKMP_NTYPE_INVALID_PAYLOAD_TYPE, NULL);
110 plog(LLV_ERROR, LOCATION, iph1->remote,
111 "received multiple payload type %d.\n",
112 pa->type);
113 vfree(pbuf);
114 goto end;
115 }
116 sa = (struct isakmp_pl_sa *)pa->ptr;
117 break;
118 case ISAKMP_NPTYPE_VID:
119 (void)check_vendorid(pa->ptr);
120 break;
121 default:
122 isakmp_info_send_n1(iph1, ISAKMP_NTYPE_INVALID_PAYLOAD_TYPE, NULL);
123 plog(LLV_ERROR, LOCATION, iph1->remote,
124 "ignore the packet, "
125 "received unexpecting payload type %d.\n",
126 pa->type);
127 vfree(pbuf);
128 goto end;
129 }
130 }
131 vfree(pbuf);
132
133 if (!hash || !sa) {
134 isakmp_info_send_n1(iph1, ISAKMP_NTYPE_INVALID_PAYLOAD_TYPE, NULL);
135 plog(LLV_ERROR, LOCATION, iph1->remote,
136 "no HASH, or no SA payload.\n");
137 goto end;
138 }
139 }
140
141 /* validate HASH */
142 {
143 char *r_hash;
144 vchar_t *my_hash = NULL;
145 int result;
146
147 plog(LLV_DEBUG, LOCATION, NULL, "validate HASH\n");
148
149 len = sizeof(isakmp->msgid) + ntohs(sa->h.len);
150 buf = vmalloc(len);
151 if (buf == NULL) {
152 plog(LLV_ERROR, LOCATION, NULL,
153 "failed to get buffer to send.\n");
154 goto end;
155 }
156 memcpy(buf->v, &isakmp->msgid, sizeof(isakmp->msgid));
157 memcpy(buf->v + sizeof(isakmp->msgid), sa, ntohs(sa->h.len));
158
159 plog(LLV_DEBUG, LOCATION, NULL, "hash source\n");
160 plogdump(LLV_DEBUG, buf->v, buf->l);
161
162 my_hash = isakmp_prf(iph1->skeyid_a, buf, iph1);
163 vfree(buf);
164 if (my_hash == NULL)
165 goto end;
166
167 plog(LLV_DEBUG, LOCATION, NULL, "hash result\n");
168 plogdump(LLV_DEBUG, my_hash->v, my_hash->l);
169
170 r_hash = (char *)hash + sizeof(*hash);
171
172 plog(LLV_DEBUG, LOCATION, NULL, "original hash\n"));
173 plogdump(LLV_DEBUG, r_hash, ntohs(hash->h.len) - sizeof(*hash)));
174
175 result = memcmp(my_hash->v, r_hash, my_hash->l);
176 vfree(my_hash);
177
178 if (result) {
179 plog(LLV_ERROR, LOCATION, iph1->remote,
180 "HASH mismatch.\n");
181 isakmp_info_send_n1(iph1, ISAKMP_NTYPE_INVALID_HASH_INFORMATION, NULL);
182 goto end;
183 }
184 }
185
186 /* check SA payload and get new one for use */
187 buf = ipsecdoi_get_proposal((struct ipsecdoi_sa *)sa,
188 OAKLEY_NEWGROUP_MODE);
189 if (buf == NULL) {
190 isakmp_info_send_n1(iph1, ISAKMP_NTYPE_ATTRIBUTES_NOT_SUPPORTED, NULL);
191 goto end;
192 }
193
194 /* save sa parameters */
195 osa = ipsecdoi_get_oakley(buf);
196 if (osa == NULL) {
197 isakmp_info_send_n1(iph1, ISAKMP_NTYPE_ATTRIBUTES_NOT_SUPPORTED, NULL);
198 goto end;
199 }
200 vfree(buf);
201
202 switch (osa->dhgrp) {
203 case OAKLEY_ATTR_GRP_DESC_MODP768:
204 case OAKLEY_ATTR_GRP_DESC_MODP1024:
205 case OAKLEY_ATTR_GRP_DESC_MODP1536:
206 /*XXX*/
207 default:
208 isakmp_info_send_n1(iph1, ISAKMP_NTYPE_ATTRIBUTES_NOT_SUPPORTED, NULL);
209 plog(LLV_ERROR, LOCATION, NULL,
210 "dh group %d isn't supported.\n", osa->dhgrp);
211 goto end;
212 }
213
214 plog(LLV_INFO, LOCATION, iph1->remote,
215 "got new dh group %s.\n", isakmp_pindex(&iph1->index, 0));
216
217 error = 0;
218
219 end:
220 if (error) {
221 if (iph1 != NULL)
222 (void)isakmp_free_ph1(iph1);
223 }
224 return error;
225 #endif
226 return 0;
227 }
228