ike_response_format.c
void ikeFreeKeContext(IkeKeContext *keContext)
Release key exchange context.
Definition: ike_key_exchange.c:69
Diffie-Hellman key exchange.
error_t ikeSendErrorResponse(IkeContext *context, uint8_t *message, size_t length)
Send INFORMATIONAL response (outside of an IKE SA)
Definition: ike_response_format.c:485
void ikeInitKeContext(IkeKeContext *keContext)
Initialize key exchange context.
Definition: ike_key_exchange.c:50
error_t ikeFormatNoncePayload(IkeSaEntry *sa, IkeChildSaEntry *childSa, uint8_t *p, size_t *written, uint8_t **nextPayload)
Format Nonce payload.
Definition: ike_payload_format.c:951
Helper functions for IKEv2.
error_t ikeComputeSharedSecret(IkeKeContext *keContext, uint8_t *output, size_t *outputLen)
Compute shared secret.
Definition: ike_key_exchange.c:166
IKE payload formatting.
@ IKE_NOTIFY_MSG_TYPE_NO_PROPOSAL_CHOSEN
Definition: ike.h:1189
error_t ikeFormatCreateChildSaResponse(IkeSaEntry *sa, uint8_t *p, size_t *length)
Format CREATE_CHILD_SA response.
Definition: ike_response_format.c:826
error_t ikeGenerateSaSpi(IkeSaEntry *sa, uint8_t *spi)
Generate a new IKE SA SPI.
Definition: ike_misc.c:632
IKE message encryption.
error_t ikeSendInfoResponse(IkeSaEntry *sa)
Send INFORMATIONAL response.
Definition: ike_response_format.c:415
error_t ikeFormatChildSaPayload(IkeChildSaEntry *childSa, uint8_t *p, size_t *written, uint8_t **nextPayload)
Format Security Association payload (AH or ESP protocol)
Definition: ike_payload_format.c:242
error_t ikeFormatAuthPayload(IkeSaEntry *sa, const IkeIdPayload *idPayload, uint8_t *p, size_t *written, uint8_t **nextPayload)
Format Authentication payload.
Definition: ike_payload_format.c:898
IKEv2 finite state machine.
@ IKE_NOTIFY_MSG_TYPE_SIGNATURE_HASH_ALGORITHMS
Definition: ike.h:1255
@ IKE_NOTIFY_MSG_TYPE_NAT_DETECTION_SOURCE_IP
Definition: ike.h:1212
error_t ikeFormatSaPayload(IkeSaEntry *sa, const uint8_t *spi, uint8_t *p, size_t *written, uint8_t **nextPayload)
Format Security Association payload (IKE protocol)
Definition: ike_payload_format.c:61
@ IKE_NOTIFY_MSG_TYPE_NAT_DETECTION_DESTINATION_IP
Definition: ike.h:1213
void ikeChangeSaState(IkeSaEntry *sa, IkeSaState newState)
Update IKE SA state.
Definition: ike_fsm.c:53
@ IKE_NOTIFY_MSG_TYPE_FAILED_CP_REQUIRED
Definition: ike.h:1195
error_t socketSendMsg(Socket *socket, const SocketMsg *message, uint_t flags)
Send a message to a connectionless socket.
Definition: socket.c:1664
Data logging functions for debugging purpose (IKEv2)
error_t ikeSendIkeAuthResponse(IkeSaEntry *sa)
Send IKE_AUTH response.
Definition: ike_response_format.c:228
error_t ikeFormatInfoResponse(IkeSaEntry *sa, uint8_t *p, size_t *length)
Format INFORMATIONAL response.
Definition: ike_response_format.c:949
error_t ikeFormatIkeSaInitResponse(IkeSaEntry *sa, uint8_t *p, size_t *length)
Format IKE_SA_INIT response.
Definition: ike_response_format.c:533
error_t ikeFormatIkeAuthResponse(IkeSaEntry *sa, uint8_t *p, size_t *length)
Format IKE_AUTH response.
Definition: ike_response_format.c:695
Key material generation.
error_t ikeFormatNotifyPayload(IkeSaEntry *sa, IkeChildSaEntry *childSa, IkeNotifyMsgType notifyMsgType, uint8_t *p, size_t *written, uint8_t **nextPayload)
Format Notify payload.
Definition: ike_payload_format.c:1039
IKE response formatting.
void ikeDeleteDuplicateSaEntries(IkeSaEntry *sa)
Delete an duplicate IKE Security Associations.
Definition: ike_misc.c:408
error_t ikeFormatKePayload(IkeKeContext *keContext, uint8_t *p, size_t *written, uint8_t **nextPayload)
Format Key Exchange payload.
Definition: ike_payload_format.c:488
error_t ikeSendCreateChildSaResponse(IkeSaEntry *sa)
Send CREATE_CHILD_SA response.
Definition: ike_response_format.c:371
error_t ikeFormatTsiPayload(IkeChildSaEntry *childSa, uint8_t *p, size_t *written, uint8_t **nextPayload)
Format Traffic Selector payload (initiator)
Definition: ike_payload_format.c:1493
void ikeDeleteChildSaEntry(IkeChildSaEntry *childSa)
Delete a Child Security Association.
Definition: ike_misc.c:560
error_t ikeSendIkeSaInitResponse(IkeSaEntry *sa)
Send IKE_SA_INIT response.
Definition: ike_response_format.c:112
error_t ikeFormatIdPayload(IkeSaEntry *sa, uint8_t *p, size_t *written, uint8_t **nextPayload)
Format Identification payload.
Definition: ike_payload_format.c:543
error_t ikeFormatCertPayloads(IkeSaEntry *sa, uint8_t *p, size_t *written, uint8_t **nextPayload)
Format Certificate payloads.
Definition: ike_payload_format.c:646
void ikeChangeChildSaState(IkeChildSaEntry *childSa, IkeChildSaState newState)
Update Child SA state.
Definition: ike_fsm.c:110
IKEv2 (Internet Key Exchange Protocol)
error_t ikeCreateIpsecSaPair(IkeChildSaEntry *childSa)
Create AH or ESP SA pair.
Definition: ike_misc.c:1467
error_t ikeGenerateKeyPair(IkeKeContext *keContext, const PrngAlgo *prngAlgo, void *prngContext)
Key pair generation.
Definition: ike_key_exchange.c:91
@ IKE_NOTIFY_MSG_TYPE_UNSUPPORTED_CRITICAL_PAYLOAD
Definition: ike.h:1183
error_t ikeGenerateChildSaKeyMaterial(IkeChildSaEntry *childSa)
Generate keying material for the Child SA.
Definition: ike_key_material.c:262
error_t ikeEncryptMessage(IkeSaEntry *sa, uint8_t *message, size_t *messageLen)
Encrypt an outgoing IKE message.
Definition: ike_message_encrypt.c:55
error_t ikeFormatIkeSaRekeyResponse(IkeSaEntry *sa, uint8_t *p, size_t *length, uint8_t **nextPayload)
Format IKE SA rekeying response.
Definition: ike_response_format.c:1317
error_t ikeFormatChildSaCreateResponse(IkeSaEntry *sa, uint8_t *p, size_t *length, uint8_t **nextPayload)
Format Child SA creation/rekeying response.
Definition: ike_response_format.c:1202
error_t ikeFormatErrorResponse(IkeHeader *requestHeader, uint8_t *p, size_t *length)
Format INFORMATIONAL response (outside of an IKE SA)
Definition: ike_response_format.c:1126
error_t ikeGenerateSaKeyMaterial(IkeSaEntry *sa, IkeSaEntry *oldSa)
Generate keying material for the IKE SA.
Definition: ike_key_material.c:54
@ IKE_NOTIFY_MSG_TYPE_INTERNAL_ADDRESS_FAILURE
Definition: ike.h:1194
@ IKE_NOTIFY_MSG_TYPE_USE_TRANSPORT_MODE
Definition: ike.h:1215
error_t ikeGenerateNonce(IkeContext *context, uint8_t *nonce, size_t *length)
Generate a new nonce.
Definition: ike_misc.c:792
@ IKE_NOTIFY_MSG_TYPE_SINGLE_PAIR_REQUIRED
Definition: ike.h:1192
@ IKE_NOTIFY_MSG_TYPE_INVALID_MAJOR_VERSION
Definition: ike.h:1185
void ikeDumpMessage(const uint8_t *message, size_t length)
Dump IKE message.
Definition: ike_debug.c:425
error_t ikeSendResponse(IkeContext *context, const uint8_t *message, size_t length)
Send IKE response.
Definition: ike_response_format.c:58
error_t ikeFormatCertReqPayload(IkeSaEntry *sa, uint8_t *p, size_t *written, uint8_t **nextPayload)
Format Certificate Request payload.
Definition: ike_payload_format.c:800
error_t ikeFormatTsrPayload(IkeChildSaEntry *childSa, uint8_t *p, size_t *written, uint8_t **nextPayload)
Format Traffic Selector payload (responder)
Definition: ike_payload_format.c:1631
Debugging facilities.
