ike_request_parse.c
error_t ikeParseIdPayload(IkeSaEntry *sa, const IkeIdPayload *idPayload)
Parse Identification payload.
Definition: ike_payload_parse.c:456
Diffie-Hellman key exchange.
Authentication of the IKE SA.
Helper functions for IKEv2.
error_t ikeComputeSharedSecret(IkeKeContext *keContext, uint8_t *output, size_t *outputLen)
Compute shared secret.
Definition: ike_key_exchange.c:166
const IkeNotifyPayload * initialContactNotify
Definition: ike_payload_parse.h:65
error_t ikeRetransmitResponse(IkeSaEntry *sa)
Retransmit IKE response message.
Definition: ike_misc.c:117
error_t ikeParseCookieNotification(IkeSaEntry *sa, const IkeNotifyPayload *notifyPayload)
Parse COOKIE notification.
Definition: ike_payload_parse.c:602
IpsecPadEntry * ipsecFindPadEntry(IpsecContext *context, uint8_t idType, const uint8_t *id, size_t idLen)
Find PAD entry that matches the specified identification data.
Definition: ipsec_misc.c:254
@ IKE_NOTIFY_MSG_TYPE_CHILD_SA_NOT_FOUND
Definition: ike.h:1202
const IkeNotifyPayload * natDetectSrcIpNotify
Definition: ike_payload_parse.h:71
@ IKE_NOTIFY_MSG_TYPE_NO_PROPOSAL_CHOSEN
Definition: ike.h:1189
void ikeProcessInitialChildSaCreateRequest(IkeSaEntry *sa, IkeMessagePayloads *payloads)
Process initial Child SA creation request.
Definition: ike_request_parse.c:750
const IkeNotifyPayload * errorNotify
Definition: ike_payload_parse.h:74
error_t ikeCheckCriticalPayloads(const uint8_t *message, size_t length, uint8_t *unsupportedCriticalPayload)
Check whether the message contains an unsupported critical payload.
Definition: ike_payload_parse.c:1406
const IkeNotifyPayload * cookieNotify
Definition: ike_payload_parse.h:62
error_t ikeGenerateSaSpi(IkeSaEntry *sa, uint8_t *spi)
Generate a new IKE SA SPI.
Definition: ike_misc.c:632
error_t ikeParseInfoRequest(IkeSaEntry *sa, const uint8_t *message, size_t length)
Parse incoming INFORMATIONAL request.
Definition: ike_request_parse.c:649
const IkePayloadHeader * ikeGetPayload(const uint8_t *message, size_t length, uint8_t type, uint_t index)
Search an IKE message for a given payload type.
Definition: ike_payload_parse.c:1161
error_t ikeParseNoncePayload(const IkeNoncePayload *noncePayload, uint8_t *nonce, size_t *nonceLen)
Parse Nonce payload.
Definition: ike_payload_parse.c:525
error_t ikeSendInfoResponse(IkeSaEntry *sa)
Send INFORMATIONAL response.
Definition: ike_response_format.c:415
IkeChildSaEntry * ikeCreateChildSaEntry(IkeContext *context)
Create a new Child Security Association.
Definition: ike_misc.c:451
IKE request parsing.
error_t ikeSelectChildSaProposal(IkeChildSaEntry *childSa, const IkeSaPayload *payload)
Select a single proposal (AH or ESP protocol)
Definition: ike_algorithms.c:1877
void ikeProcessIkeSaRekeyRequest(IkeSaEntry *sa, IkeMessagePayloads *payloads)
Process IKE SA rekeying request.
Definition: ike_request_parse.c:1218
error_t ikeSelectTs(IkeChildSaEntry *childSa, const IkeTsPayload *tsiPayload, const IkeTsPayload *tsrPayload)
Traffic selector selection.
Definition: ike_misc.c:904
IKEv2 finite state machine.
error_t ikeParseSignHashAlgosNotification(IkeSaEntry *sa, const IkeNotifyPayload *notifyPayload)
Parse SIGNATURE_HASH_ALGORITHMS notification.
Definition: ike_payload_parse.c:636
error_t ikeParseKePayload(IkeKeContext *keContext, const IkeKePayload *kePayload)
Parse Key Exchange payload.
Definition: ike_payload_parse.c:416
void ikeChangeSaState(IkeSaEntry *sa, IkeSaState newState)
Update IKE SA state.
Definition: ike_fsm.c:53
error_t ikeParseNatDetectDestIpNotification(IkeSaEntry *sa, const IkeNotifyPayload *notifyPayload)
Parse NAT_DETECTION_DESTINATION_IP notification.
Definition: ike_payload_parse.c:784
IkeSaEntry * ikeCreateSaEntry(IkeContext *context)
Create a new IKE Security Association.
Definition: ike_misc.c:185
error_t ikeSendIkeAuthResponse(IkeSaEntry *sa)
Send IKE_AUTH response.
Definition: ike_response_format.c:228
Key material generation.
Helper routines for IPsec.
error_t ikeParseCertificateChain(IkeSaEntry *sa, IpsecPadEntry *padEntry, const uint8_t *message, size_t length)
Parse certificate chain.
Definition: ike_certificate.c:450
void ikeProcessChildSaRekeyRequest(IkeSaEntry *sa, IkeMessagePayloads *payloads)
Process Child SA rekeying request.
Definition: ike_request_parse.c:1148
const IkeNotifyPayload * natDetectDestIpNotify
Definition: ike_payload_parse.h:72
IkeChildSaEntry * ikeFindChildSaEntry(IkeSaEntry *sa, uint8_t protocolId, const uint8_t *spi)
Find an Child SA that matches the specified SPI.
Definition: ike_misc.c:518
IKE response formatting.
error_t ikeVerifyAuth(IkeSaEntry *sa, IpsecPadEntry *padEntry, const IkeIdPayload *idPayload, const IkeCertPayload *certPayload, const IkeAuthPayload *authPayload)
Verify signature or MAC.
Definition: ike_auth.c:138
error_t ikeParseNatDetectSrcIpNotification(IkeSaEntry *sa, const uint8_t *message, size_t length)
Parse NAT_DETECTION_SOURCE_IP notification.
Definition: ike_payload_parse.c:690
error_t ikeSendCreateChildSaResponse(IkeSaEntry *sa)
Send CREATE_CHILD_SA response.
Definition: ike_response_format.c:371
error_t ikeParseIkeSaInitRequest(IkeContext *context, const uint8_t *message, size_t length)
Parse incoming IKE_SA_INIT request.
Definition: ike_request_parse.c:61
void ikeDeleteChildSaEntry(IkeChildSaEntry *childSa)
Delete a Child Security Association.
Definition: ike_misc.c:560
error_t ikeCheckNonceLength(IkeSaEntry *sa, size_t nonceLen)
Check the length of the nonce.
Definition: ike_misc.c:1238
error_t ikeSendIkeSaInitResponse(IkeSaEntry *sa)
Send IKE_SA_INIT response.
Definition: ike_response_format.c:112
void ikeInheritChildSas(IkeSaEntry *newSa, IkeSaEntry *oldSa)
Move inherited Child SAs.
Definition: ike_misc.c:597
void ikeChangeChildSaState(IkeChildSaEntry *childSa, IkeChildSaState newState)
Update Child SA state.
Definition: ike_fsm.c:110
error_t ikeParseSaPayload(const IkeSaPayload *saPayload)
Parse Security Association payload.
Definition: ike_payload_parse.c:165
IKEv2 (Internet Key Exchange Protocol)
error_t ikeCreateIpsecSaPair(IkeChildSaEntry *childSa)
Create AH or ESP SA pair.
Definition: ike_misc.c:1467
error_t ikeSelectSaProposal(IkeSaEntry *sa, const IkeSaPayload *payload, size_t spiSize)
Select a single proposal (IKE protocol)
Definition: ike_algorithms.c:1741
@ IKE_NOTIFY_MSG_TYPE_INVALID_KE_PAYLOAD
Definition: ike.h:1190
IKE payload parsing.
void ikeParseIkeMessagePayloads(const uint8_t *message, size_t length, IkeMessagePayloads *payloads)
Parse IKE message payloads.
Definition: ike_payload_parse.c:59
error_t ikeGenerateKeyPair(IkeKeContext *keContext, const PrngAlgo *prngAlgo, void *prngContext)
Key pair generation.
Definition: ike_key_exchange.c:91
@ IKE_NOTIFY_MSG_TYPE_UNSUPPORTED_CRITICAL_PAYLOAD
Definition: ike.h:1183
error_t ikeGenerateChildSaKeyMaterial(IkeChildSaEntry *childSa)
Generate keying material for the Child SA.
Definition: ike_key_material.c:262
void ikeProcessChildSaCreateRequest(IkeSaEntry *sa, IkeChildSaEntry *oldChildSa, IkeMessagePayloads *payloads)
Process Child SA creation request.
Definition: ike_request_parse.c:872
error_t ikeGenerateSaKeyMaterial(IkeSaEntry *sa, IkeSaEntry *oldSa)
Generate keying material for the IKE SA.
Definition: ike_key_material.c:54
const IkeNotifyPayload * signHashAlgosNotify
Definition: ike_payload_parse.h:68
error_t ikeGenerateChildSaSpi(IkeChildSaEntry *childSa, uint8_t *spi)
Generate a new Child SA SPI.
Definition: ike_misc.c:718
error_t ikeParseCreateChildSaRequest(IkeSaEntry *sa, const uint8_t *message, size_t length)
Parse incoming CREATE_CHILD_SA request.
Definition: ike_request_parse.c:549
error_t ikeParseCertReqPayload(IkeSaEntry *sa, const IkeCertReqPayload *certReqPayload)
Parse Certificate Request payload.
Definition: ike_payload_parse.c:491
X.509 certificate handling.
const IkeNotifyPayload * useTransportModeNotify
Definition: ike_payload_parse.h:59
IkeSaEntry * ikeFindHalfOpenSaEntry(IkeContext *context, const IkeHeader *ikeHeader, const IkeNoncePayload *noncePayload)
Find an half-open IKE SA that matches an incoming IKE_SA_INIT request.
Definition: ike_misc.c:293
error_t ikeGenerateNonce(IkeContext *context, uint8_t *nonce, size_t *length)
Generate a new nonce.
Definition: ike_misc.c:792
error_t ikeParseIkeAuthRequest(IkeSaEntry *sa, const uint8_t *message, size_t length)
Parse incoming IKE_AUTH request.
Definition: ike_request_parse.c:387
error_t ikeParseDeletePayload(IkeSaEntry *sa, const IkeDeletePayload *deletePayload, bool_t response)
Parse Delete payload.
Definition: ike_payload_parse.c:856
const IkeNotifyPayload * rekeySaNotify
Definition: ike_payload_parse.h:60
IKEv2 algorithm negotiation.
Debugging facilities.
