#include "config.h"
#include <sys/types.h>
#include <sys/param.h>
#include <stdlib.h>
#include <stdio.h>
#include <string.h>
#include <errno.h>
#include "var.h"
#include "misc.h"
#include "vmbuf.h"
#include "plog.h"
#include "sockmisc.h"
#include "debug.h"
#include "schedule.h"
#include "cfparse_proto.h"
#include "isakmp_var.h"
#include "isakmp.h"
#include "isakmp_newg.h"
#include "oakley.h"
#include "ipsec_doi.h"
#include "crypto_openssl.h"
#include "handler.h"
#include "pfkey.h"
#include "admin.h"
#include "str2val.h"
#include "vendorid.h"
int
isakmp_newgroup_r(iph1, msg)
struct ph1handle *iph1;
vchar_t *msg;
{
#if 0
struct isakmp *isakmp = (struct isakmp *)msg->v;
struct isakmp_pl_hash *hash = NULL;
struct isakmp_pl_sa *sa = NULL;
int error = -1;
vchar_t *buf;
struct oakley_sa *osa;
int len;
{
vchar_t *pbuf = NULL;
struct isakmp_parse_t *pa;
if ((pbuf = isakmp_parse(msg)) == NULL)
goto end;
for (pa = (struct isakmp_parse_t *)pbuf->v;
pa->type != ISAKMP_NPTYPE_NONE;
pa++) {
switch (pa->type) {
case ISAKMP_NPTYPE_HASH:
if (hash) {
isakmp_info_send_n1(iph1, ISAKMP_NTYPE_INVALID_PAYLOAD_TYPE, NULL);
plog(LLV_ERROR, LOCATION, iph1->remote,
"received multiple payload type %d.\n",
pa->type);
vfree(pbuf);
goto end;
}
hash = (struct isakmp_pl_hash *)pa->ptr;
break;
case ISAKMP_NPTYPE_SA:
if (sa) {
isakmp_info_send_n1(iph1, ISAKMP_NTYPE_INVALID_PAYLOAD_TYPE, NULL);
plog(LLV_ERROR, LOCATION, iph1->remote,
"received multiple payload type %d.\n",
pa->type);
vfree(pbuf);
goto end;
}
sa = (struct isakmp_pl_sa *)pa->ptr;
break;
case ISAKMP_NPTYPE_VID:
(void)check_vendorid(pa->ptr);
break;
default:
isakmp_info_send_n1(iph1, ISAKMP_NTYPE_INVALID_PAYLOAD_TYPE, NULL);
plog(LLV_ERROR, LOCATION, iph1->remote,
"ignore the packet, "
"received unexpecting payload type %d.\n",
pa->type);
vfree(pbuf);
goto end;
}
}
vfree(pbuf);
if (!hash || !sa) {
isakmp_info_send_n1(iph1, ISAKMP_NTYPE_INVALID_PAYLOAD_TYPE, NULL);
plog(LLV_ERROR, LOCATION, iph1->remote,
"no HASH, or no SA payload.\n");
goto end;
}
}
{
char *r_hash;
vchar_t *my_hash = NULL;
int result;
plog(LLV_DEBUG, LOCATION, NULL, "validate HASH\n");
len = sizeof(isakmp->msgid) + ntohs(sa->h.len);
buf = vmalloc(len);
if (buf == NULL) {
plog(LLV_ERROR, LOCATION, NULL,
"failed to get buffer to send.\n");
goto end;
}
memcpy(buf->v, &isakmp->msgid, sizeof(isakmp->msgid));
memcpy(buf->v + sizeof(isakmp->msgid), sa, ntohs(sa->h.len));
plog(LLV_DEBUG, LOCATION, NULL, "hash source\n");
plogdump(LLV_DEBUG, buf->v, buf->l);
my_hash = isakmp_prf(iph1->skeyid_a, buf, iph1);
vfree(buf);
if (my_hash == NULL)
goto end;
plog(LLV_DEBUG, LOCATION, NULL, "hash result\n");
plogdump(LLV_DEBUG, my_hash->v, my_hash->l);
r_hash = (char *)hash + sizeof(*hash);
plog(LLV_DEBUG, LOCATION, NULL, "original hash\n"));
plogdump(LLV_DEBUG, r_hash, ntohs(hash->h.len) - sizeof(*hash)));
result = memcmp(my_hash->v, r_hash, my_hash->l);
vfree(my_hash);
if (result) {
plog(LLV_ERROR, LOCATION, iph1->remote,
"HASH mismatch.\n");
isakmp_info_send_n1(iph1, ISAKMP_NTYPE_INVALID_HASH_INFORMATION, NULL);
goto end;
}
}
buf = ipsecdoi_get_proposal((struct ipsecdoi_sa *)sa,
OAKLEY_NEWGROUP_MODE);
if (buf == NULL) {
isakmp_info_send_n1(iph1, ISAKMP_NTYPE_ATTRIBUTES_NOT_SUPPORTED, NULL);
goto end;
}
osa = ipsecdoi_get_oakley(buf);
if (osa == NULL) {
isakmp_info_send_n1(iph1, ISAKMP_NTYPE_ATTRIBUTES_NOT_SUPPORTED, NULL);
goto end;
}
vfree(buf);
switch (osa->dhgrp) {
case OAKLEY_ATTR_GRP_DESC_MODP768:
case OAKLEY_ATTR_GRP_DESC_MODP1024:
case OAKLEY_ATTR_GRP_DESC_MODP1536:
default:
isakmp_info_send_n1(iph1, ISAKMP_NTYPE_ATTRIBUTES_NOT_SUPPORTED, NULL);
plog(LLV_ERROR, LOCATION, NULL,
"dh group %d isn't supported.\n", osa->dhgrp);
goto end;
}
plog(LLV_INFO, LOCATION, iph1->remote,
"got new dh group %s.\n", isakmp_pindex(&iph1->index, 0));
error = 0;
end:
if (error) {
if (iph1 != NULL)
(void)isakmp_free_ph1(iph1);
}
return error;
#endif
return 0;
}