ike_response_parse.c
int_t ikeCompareChildSaNonces(IkeChildSaEntry *childSa1, IkeChildSaEntry *childSa2)
Compare Child SA nonces.
Definition: ike_misc.c:1422
error_t ikeSendIkeSaInitRequest(IkeSaEntry *sa)
Send IKE_SA_INIT request.
Definition: ike_request_format.c:103
void ikeFreeKeContext(IkeKeContext *keContext)
Release key exchange context.
Definition: ike_key_exchange.c:69
error_t ikeParseIdPayload(IkeSaEntry *sa, const IkeIdPayload *idPayload)
Parse Identification payload.
Definition: ike_payload_parse.c:456
Diffie-Hellman key exchange.
void ikeInitKeContext(IkeKeContext *keContext)
Initialize key exchange context.
Definition: ike_key_exchange.c:50
Authentication of the IKE SA.
Helper functions for IKEv2.
error_t ikeComputeSharedSecret(IkeKeContext *keContext, uint8_t *output, size_t *outputLen)
Compute shared secret.
Definition: ike_key_exchange.c:166
const IkeNotifyPayload * initialContactNotify
Definition: ike_payload_parse.h:65
int_t ikeCompareSaNonces(IkeSaEntry *sa1, IkeSaEntry *sa2)
Compare IKE SA nonces.
Definition: ike_misc.c:1376
error_t ikeParseCookieNotification(IkeSaEntry *sa, const IkeNotifyPayload *notifyPayload)
Parse COOKIE notification.
Definition: ike_payload_parse.c:602
IpsecPadEntry * ipsecFindPadEntry(IpsecContext *context, uint8_t idType, const uint8_t *id, size_t idLen)
Find PAD entry that matches the specified identification data.
Definition: ipsec_misc.c:254
const IkeNotifyPayload * natDetectSrcIpNotify
Definition: ike_payload_parse.h:71
error_t ikeCheckTs(IkeChildSaEntry *childSa, const IkeTsPayload *tsiPayload, const IkeTsPayload *tsrPayload, bool_t rekey)
Check whether the selected traffic selectors are acceptable.
Definition: ike_misc.c:1046
@ IKE_NOTIFY_MSG_TYPE_NO_PROPOSAL_CHOSEN
Definition: ike.h:1189
const IkeNotifyPayload * errorNotify
Definition: ike_payload_parse.h:74
error_t ikeCheckCriticalPayloads(const uint8_t *message, size_t length, uint8_t *unsupportedCriticalPayload)
Check whether the message contains an unsupported critical payload.
Definition: ike_payload_parse.c:1406
const IkeNotifyPayload * cookieNotify
Definition: ike_payload_parse.h:62
const IkePayloadHeader * ikeGetPayload(const uint8_t *message, size_t length, uint8_t type, uint_t index)
Search an IKE message for a given payload type.
Definition: ike_payload_parse.c:1161
error_t ikeCheckSaProposal(IkeSaEntry *sa, const IkeSaPayload *payload)
Check whether the selected proposal is acceptable (IKE protocol)
Definition: ike_algorithms.c:1915
error_t ikeParseNoncePayload(const IkeNoncePayload *noncePayload, uint8_t *nonce, size_t *nonceLen)
Parse Nonce payload.
Definition: ike_payload_parse.c:525
IKEv2 finite state machine.
IKE response parsing.
error_t ikeParseSignHashAlgosNotification(IkeSaEntry *sa, const IkeNotifyPayload *notifyPayload)
Parse SIGNATURE_HASH_ALGORITHMS notification.
Definition: ike_payload_parse.c:636
error_t ikeProcessSaDeleteEvent(IkeSaEntry *sa)
Handle IKE SA deletion event.
Definition: ike_fsm.c:802
error_t ikeParseCreateChildSaResponse(IkeSaEntry *sa, const uint8_t *message, size_t length)
Parse incoming CREATE_CHILD_SA response.
Definition: ike_response_parse.c:518
error_t ikeParseKePayload(IkeKeContext *keContext, const IkeKePayload *kePayload)
Parse Key Exchange payload.
Definition: ike_payload_parse.c:416
void ikeChangeSaState(IkeSaEntry *sa, IkeSaState newState)
Update IKE SA state.
Definition: ike_fsm.c:53
@ IKE_NOTIFY_MSG_TYPE_FAILED_CP_REQUIRED
Definition: ike.h:1195
error_t ikeParseNatDetectDestIpNotification(IkeSaEntry *sa, const IkeNotifyPayload *notifyPayload)
Parse NAT_DETECTION_DESTINATION_IP notification.
Definition: ike_payload_parse.c:784
Key material generation.
error_t ikeSendInfoRequest(IkeSaEntry *sa)
Send INFORMATIONAL request.
Definition: ike_request_format.c:311
Helper routines for IPsec.
error_t ikeParseCertificateChain(IkeSaEntry *sa, IpsecPadEntry *padEntry, const uint8_t *message, size_t length)
Parse certificate chain.
Definition: ike_certificate.c:450
const IkeNotifyPayload * natDetectDestIpNotify
Definition: ike_payload_parse.h:72
error_t ikeProcessChildSaCreateResponse(IkeSaEntry *sa, IkeMessagePayloads *payloads)
Process Child SA creation response.
Definition: ike_response_parse.c:794
error_t ikeParseInfoResponse(IkeSaEntry *sa, const uint8_t *message, size_t length)
Parse incoming INFORMATIONAL response.
Definition: ike_response_parse.c:591
error_t ikeSendIkeAuthRequest(IkeSaEntry *sa)
Send IKE_AUTH request.
Definition: ike_request_format.c:147
error_t ikeVerifyAuth(IkeSaEntry *sa, IpsecPadEntry *padEntry, const IkeIdPayload *idPayload, const IkeCertPayload *certPayload, const IkeAuthPayload *authPayload)
Verify signature or MAC.
Definition: ike_auth.c:138
error_t ikeParseNatDetectSrcIpNotification(IkeSaEntry *sa, const uint8_t *message, size_t length)
Parse NAT_DETECTION_SOURCE_IP notification.
Definition: ike_payload_parse.c:690
void ikeDeleteDuplicateSaEntries(IkeSaEntry *sa)
Delete an duplicate IKE Security Associations.
Definition: ike_misc.c:408
void ikeDeleteChildSaEntry(IkeChildSaEntry *childSa)
Delete a Child Security Association.
Definition: ike_misc.c:560
error_t ikeCheckNonceLength(IkeSaEntry *sa, size_t nonceLen)
Check the length of the nonce.
Definition: ike_misc.c:1238
error_t ikeParseInvalidKePayloadNotification(IkeKeContext *keContext, const IkeNotifyPayload *notifyPayload)
Parse INVALID_KE_PAYLOAD notification.
Definition: ike_payload_parse.c:561
void ikeInheritChildSas(IkeSaEntry *newSa, IkeSaEntry *oldSa)
Move inherited Child SAs.
Definition: ike_misc.c:597
error_t ikeProcessInitialChildSaCreateResponse(IkeSaEntry *sa, IkeMessagePayloads *payloads)
Process initial Child SA creation response.
Definition: ike_response_parse.c:699
void ikeChangeChildSaState(IkeChildSaEntry *childSa, IkeChildSaState newState)
Update Child SA state.
Definition: ike_fsm.c:110
error_t ikeProcessChildSaRekeyResponse(IkeSaEntry *sa, IkeMessagePayloads *payloads)
Process Child SA rekeying response.
Definition: ike_response_parse.c:1011
error_t ikeParseSaPayload(const IkeSaPayload *saPayload)
Parse Security Association payload.
Definition: ike_payload_parse.c:165
error_t ikeSendCreateChildSaRequest(IkeSaEntry *sa)
Send CREATE_CHILD_SA request.
Definition: ike_request_format.c:241
IKEv2 (Internet Key Exchange Protocol)
error_t ikeCreateIpsecSaPair(IkeChildSaEntry *childSa)
Create AH or ESP SA pair.
Definition: ike_misc.c:1467
@ IKE_NOTIFY_MSG_TYPE_INVALID_KE_PAYLOAD
Definition: ike.h:1190
IKE payload parsing.
void ikeParseIkeMessagePayloads(const uint8_t *message, size_t length, IkeMessagePayloads *payloads)
Parse IKE message payloads.
Definition: ike_payload_parse.c:59
error_t ikeGenerateKeyPair(IkeKeContext *keContext, const PrngAlgo *prngAlgo, void *prngContext)
Key pair generation.
Definition: ike_key_exchange.c:91
error_t ikeGenerateChildSaKeyMaterial(IkeChildSaEntry *childSa)
Generate keying material for the Child SA.
Definition: ike_key_material.c:262
error_t ikeParseIkeSaInitResponse(IkeSaEntry *sa, const uint8_t *message, size_t length)
Parse incoming IKE_SA_INIT response.
Definition: ike_response_parse.c:61
error_t ikeGenerateSaKeyMaterial(IkeSaEntry *sa, IkeSaEntry *oldSa)
Generate keying material for the IKE SA.
Definition: ike_key_material.c:54
const IkeNotifyPayload * signHashAlgosNotify
Definition: ike_payload_parse.h:68
error_t ikeParseIkeAuthResponse(IkeSaEntry *sa, const uint8_t *message, size_t length)
Parse incoming IKE_AUTH response.
Definition: ike_response_parse.c:316
error_t ikeParseCertReqPayload(IkeSaEntry *sa, const IkeCertReqPayload *certReqPayload)
Parse Certificate Request payload.
Definition: ike_payload_parse.c:491
X.509 certificate handling.
@ IKE_NOTIFY_MSG_TYPE_INTERNAL_ADDRESS_FAILURE
Definition: ike.h:1194
const IkeNotifyPayload * useTransportModeNotify
Definition: ike_payload_parse.h:59
@ IKE_NOTIFY_MSG_TYPE_SINGLE_PAIR_REQUIRED
Definition: ike.h:1192
error_t ikeParseDeletePayload(IkeSaEntry *sa, const IkeDeletePayload *deletePayload, bool_t response)
Parse Delete payload.
Definition: ike_payload_parse.c:856
error_t ikeProcessChildSaDeleteEvent(IkeChildSaEntry *childSa)
Handle Child SA deletion event.
Definition: ike_fsm.c:1090
error_t ikeCheckChildSaProposal(IkeChildSaEntry *childSa, const IkeSaPayload *payload)
Check whether the selected proposal is acceptable (AH or ESP protocol)
Definition: ike_algorithms.c:2051
IKEv2 algorithm negotiation.
Debugging facilities.
error_t ikeProcessIkeSaRekeyResponse(IkeSaEntry *sa, IkeMessagePayloads *payloads)
Process IKE SA rekeying response.
Definition: ike_response_parse.c:1261
IKE request formatting.
