ike_response_parse.c
Go to the documentation of this file.
1 /**
2  * @file ike_response_parse.c
3  * @brief IKE response parsing
4  *
5  * @section License
6  *
7  * SPDX-License-Identifier: GPL-2.0-or-later
8  *
9  * Copyright (C) 2022-2026 Oryx Embedded SARL. All rights reserved.
10  *
11  * This file is part of CycloneIPSEC Open.
12  *
13  * This program is free software; you can redistribute it and/or
14  * modify it under the terms of the GNU General Public License
15  * as published by the Free Software Foundation; either version 2
16  * of the License, or (at your option) any later version.
17  *
18  * This program is distributed in the hope that it will be useful,
19  * but WITHOUT ANY WARRANTY; without even the implied warranty of
20  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21  * GNU General Public License for more details.
22  *
23  * You should have received a copy of the GNU General Public License
24  * along with this program; if not, write to the Free Software Foundation,
25  * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
26  *
27  * @author Oryx Embedded SARL (www.oryx-embedded.com)
28  * @version 2.6.6
29  **/
30 
31 //Switch to the appropriate trace level
32 #define TRACE_LEVEL IKE_TRACE_LEVEL
33 
34 //Dependencies
35 #include "ipsec/ipsec_misc.h"
36 #include "ike/ike.h"
37 #include "ike/ike_fsm.h"
38 #include "ike/ike_algorithms.h"
39 #include "ike/ike_request_format.h"
40 #include "ike/ike_response_parse.h"
41 #include "ike/ike_payload_parse.h"
42 #include "ike/ike_auth.h"
43 #include "ike/ike_certificate.h"
44 #include "ike/ike_key_exchange.h"
45 #include "ike/ike_key_material.h"
46 #include "ike/ike_misc.h"
47 #include "debug.h"
48 
49 //Check IKEv2 library configuration
50 #if (IKE_SUPPORT == ENABLED)
51 
52 
53 /**
54  * @brief Parse incoming IKE_SA_INIT response
55  * @param[in] sa Pointer to the IKE SA
56  * @param[in] message Pointer to the received IKE message
57  * @param[in] length Length of the IKE message, in bytes
58  * @return Error code
59  **/
60 
62  size_t length)
63 {
64  error_t error;
65  uint16_t notifyMsgType;
66  const IkeHeader *ikeHeader;
67  IkeMessagePayloads payloads;
68 
69  //Each message begins with the IKE header
70  ikeHeader = (IkeHeader *) message;
71 
72  //Check the state of the IKE SA
73  if(sa->state != IKE_SA_STATE_INIT_RESP)
75 
76  //Save the second message (IKE_SA_INIT response), starting with the first
77  //octet of the first SPI in the header and ending with the last octet of
78  //the last payload
79  sa->responderSaInit = message;
80  sa->responderSaInitLen = length;
81 
82  //Start of exception handling block
83  do
84  {
85  //Payloads sent in IKE response messages must not have the critical flag
86  //set (refer to RFC 7296, section 2.5)
87  error = ikeCheckCriticalPayloads(message, length, NULL);
88  //Any error to report?
89  if(error)
90  break;
91 
92  //Parse IKE message payloads
94 
95  //Error notification received?
96  if(payloads.errorNotify != NULL)
97  {
98  //Types in the range 0-16383 are intended for reporting errors
99  notifyMsgType = ntohs(payloads.errorNotify->notifyMsgType);
100 
101  //Some error notifications such as INVALID_KE_PAYLOAD may lead to a
102  //subsequent successful exchange
104  {
105  IkeContext *context;
106 
107  //Point to the IKE context
108  context = sa->context;
109 
110  //If the initiator guesses wrong, the responder will respond with a
111  //Notify payload of type INVALID_KE_PAYLOAD indicating the selected
112  //group (refer to RFC 7296, section 1.2)
113  error = ikeParseInvalidKePayloadNotification(&sa->keContext,
114  payloads.errorNotify);
115  //Malformed notification?
116  if(error)
117  break;
118 
119  //Reinitialize Diffie-Hellman context
120  ikeFreeKeContext(&sa->keContext);
121  ikeInitKeContext(&sa->keContext);
122 
123  //Generate a new ephemeral key pair
124  error = ikeGenerateKeyPair(&sa->keContext, context->prngAlgo,
125  context->prngContext);
126  //Any error to report?
127  if(error)
128  break;
129 
130  //The initiator must retry the IKE_SA_INIT with the corrected
131  //Diffie-Hellman group (refer to RFC 7296, section 1.2)
132  error = ERROR_RETRY;
133  break;
134  }
135  else
136  {
137  //An implementation receiving an error type that it does not
138  //recognize in a response must assume that the corresponding
139  //request has failed entirely (refer to RFC 7296, section 3.10.1)
140  error = ERROR_UNEXPECTED_STATUS;
141  break;
142  }
143  }
144 
145  //COOKIE notification received?
146  if(payloads.cookieNotify != NULL)
147  {
148  //Save the received cookie
149  error = ikeParseCookieNotification(sa, payloads.cookieNotify);
150  //Malformed notification?
151  if(error)
152  break;
153 
154  //If the IKE_SA_INIT response includes the COOKIE notification, the
155  //initiator must then retry the IKE_SA_INIT request
156  error = ERROR_RETRY;
157  break;
158  }
159 
160  //Mandatory payloads must be included in the received message
161  if(payloads.sa == NULL || payloads.ke == NULL || payloads.nonce == NULL)
162  {
163  error = ERROR_INVALID_MESSAGE;
164  break;
165  }
166 
167  //The responder's SPI must not be zero
168  if(osMemcmp(ikeHeader->responderSpi, IKE_INVALID_SPI, IKE_SPI_SIZE) == 0)
169  {
170  error = ERROR_INVALID_MESSAGE;
171  break;
172  }
173 
174  //Save responder's IKE SPI
175  osMemcpy(sa->responderSpi, ikeHeader->responderSpi, IKE_SPI_SIZE);
176 
177  //Save responder's nonce
178  error = ikeParseNoncePayload(payloads.nonce, sa->responderNonce,
179  &sa->responderNonceLen);
180  //Malformed nonce?
181  if(error)
182  break;
183 
184  //Check the syntax of the SAr payload
185  error = ikeParseSaPayload(payloads.sa);
186  //Malformed SAr payload?
187  if(error)
188  break;
189 
190  //The initiator of an exchange must check that the accepted offer is
191  //consistent with one of its proposals, and if not must terminate the
192  //exchange (refer to RFC 7296, section 3.3.6)
193  error = ikeCheckSaProposal(sa, payloads.sa);
194  //Invalid cryptographic suite?
195  if(error)
196  break;
197 
198  //Nonces used in IKEv2 must be at least half the key size of the
199  //negotiated pseudorandom function (refer to RFC 7296, section 2.10)
200  error = ikeCheckNonceLength(sa, sa->responderNonceLen);
201  //Unacceptable nonce length?
202  if(error)
203  break;
204 
205  //The Key Exchange payload is used to exchange Diffie-Hellman public
206  //numbers as part of a Diffie-Hellman key exchange
207  error = ikeParseKePayload(&sa->keContext, payloads.ke);
208  //Any error to report?
209  if(error)
210  break;
211 
212  //The Certificate Request payload is optional
213  if(payloads.certReq != NULL)
214  {
215  //The Certificate Request payload provides a means to request preferred
216  //certificates via IKE (refer to RFC 7296, section 3.7)
217  error = ikeParseCertReqPayload(sa, payloads.certReq);
218  //Any error to report?
219  if(error)
220  break;
221  }
222 
223 #if (IKE_NAT_TRAVERSAL_SUPPORT == ENABLED)
224  //NAT_DETECTION_SOURCE_IP notification received?
225  if(payloads.natDetectSrcIpNotify != NULL)
226  {
227  //There MAY be multiple NAT_DETECTION_SOURCE_IP payloads in a message
228  //if the sender does not know which of several network attachments
229  //will be used to send the packet (refer to RFC 7296, section 2.23)
231 
232  //Malformed notification?
233  if(error)
234  {
235  sa->notifyMsgType = IKE_NOTIFY_MSG_TYPE_INVALID_SYNTAX;
236  break;
237  }
238  }
239 
240  //NAT_DETECTION_DESTINATION_IP notification received?
241  if(payloads.natDetectDestIpNotify != NULL)
242  {
243  //The NAT_DETECTION_DESTINATION_IP payloads can be used to detect if
244  //there is NAT between the hosts
246  payloads.natDetectDestIpNotify);
247 
248  //Malformed notification?
249  if(error)
250  {
251  sa->notifyMsgType = IKE_NOTIFY_MSG_TYPE_INVALID_SYNTAX;
252  break;
253  }
254  }
255 #endif
256 
257 #if (IKE_SIGN_HASH_ALGOS_SUPPORT == ENABLED)
258  //SIGNATURE_HASH_ALGORITHMS notification received?
259  if(payloads.signHashAlgosNotify != NULL)
260  {
261  //This notification indicates the list of hash functions supported by
262  //the sending peer (refer to RFC 7427, section 4)
264  payloads.signHashAlgosNotify);
265  //Any error to report?
266  if(error)
267  break;
268  }
269  else
270  {
271  //The notification is not present in the IKE_SA_INIT message
272  sa->signHashAlgos = 0;
273  }
274 #endif
275 
276  //End of exception handling block
277  } while(0);
278 
279  //Check status code
280  if(error == NO_ERROR)
281  {
282  //The second pair of messages (IKE_AUTH) authenticate the previous
283  //messages, exchange identities and certificates, and establish the
284  //first Child SA
285  error = ikeSendIkeAuthRequest(sa);
286  }
287  else if(error == ERROR_RETRY)
288  {
289  //The initiator must then retry the IKE_SA_INIT request
290  error = ikeSendIkeSaInitRequest(sa);
291  }
292  else
293  {
294  //The IKE_SA_INIT response is not valid
295  }
296 
297  //Check whether the IKE_SA_INIT exchange has failed
298  if(error)
299  {
300  ikeDeleteSaEntry(sa);
301  }
302 
303  //Return status code
304  return error;
305 }
306 
307 
308 /**
309  * @brief Parse incoming IKE_AUTH response
310  * @param[in] sa Pointer to the IKE SA
311  * @param[in] message Pointer to the received IKE message
312  * @param[in] length Length of the IKE message, in bytes
313  * @return Error code
314  **/
315 
317  size_t length)
318 {
319  error_t error;
320  uint16_t notifyMsgType;
321  IkeMessagePayloads payloads;
322  IpsecPadEntry *padEntry;
323 
324  //Start of exception handling block
325  do
326  {
327  //Check the state of the IKE SA
328  if(sa->state != IKE_SA_STATE_AUTH_RESP)
329  {
330  error = ERROR_UNEXPECTED_MESSAGE;
331  break;
332  }
333 
334  //Payloads sent in IKE response messages must not have the critical flag
335  //set (refer to RFC 7296, section 2.5)
336  error = ikeCheckCriticalPayloads(message, length, NULL);
337  //Any error to report?
338  if(error)
339  break;
340 
341  //Parse IKE message payloads
343 
344  //Error notification received?
345  if(payloads.errorNotify != NULL)
346  {
347  //Types in the range 0-16383 are intended for reporting errors
348  notifyMsgType = ntohs(payloads.errorNotify->notifyMsgType);
349 
350  //If creating the Child SA during the IKE_AUTH exchange fails for some
351  //reason, the IKE SA is still created as usual (refer to RFC 7296,
352  //section 1.2)
358  {
359  error = ERROR_UNEXPECTED_STATUS;
360  break;
361  }
362  }
363 
364  //Mandatory payloads must be included in the received message
365  if(payloads.idr == NULL || payloads.auth == NULL)
366  {
368  break;
369  }
370 
371  //Parse Identification payload
372  error = ikeParseIdPayload(sa, payloads.idr);
373  //Malformed Identification payload?
374  if(error)
375  {
377  break;
378  }
379 
380 #if (IKE_NAT_TRAVERSAL_SUPPORT == ENABLED)
381  //Check if the remote endpoint is behind a NAT
382  if(sa->remoteNat)
383  {
384  //Perform ID substitution
385  ikeSubstituteId(sa);
386  }
387 #endif
388 
389  //Perform lookup in the PAD database based on the ID
390  padEntry = ipsecFindPadEntry(sa->context->netContext->ipsecContext,
391  sa->peerIdType, sa->peerId, sa->peerIdLen);
392  //Invalid ID?
393  if(padEntry == NULL)
394  {
396  break;
397  }
398 
399 #if (IKE_CERT_AUTH_SUPPORT == ENABLED)
400  //Check whether a Certificate payload is included
401  if(payloads.cert != NULL)
402  {
403  //Parse the certificate chain
404  error = ikeParseCertificateChain(sa, padEntry, message, length);
405  //Failed to validate certificate chain?
406  if(error)
407  {
409  break;
410  }
411  }
412 #endif
413 
414  //The peers are authenticated by having each sign (or MAC using a padded
415  //shared secret as the key, as described later in this section) a block
416  //of data (refer to RFC 7296, section 2.15)
417  error = ikeVerifyAuth(sa, padEntry, payloads.idr, payloads.cert,
418  payloads.auth);
419  //Authentication failure?
420  if(error)
421  {
423  break;
424  }
425 
426  //Child SAs can be created either by being piggybacked on the IKE_AUTH
427  //exchange, or using a separate CREATE_CHILD_SA exchange
428  if(sa->childSa1 != NULL)
429  {
430  //The responder completes negotiation of a Child SA with additional
431  //fields
432  error = ikeProcessInitialChildSaCreateResponse(sa, &payloads);
433  //Any error to report?
434  if(error)
435  break;
436  }
437 
438 #if (IKE_INITIAL_CONTACT_SUPPORT == ENABLED)
439  //The INITIAL_CONTACT notification asserts that this IKE SA is the only
440  //IKE SA currently active between the authenticated identities
441  if(payloads.initialContactNotify)
442  {
443  //It may be sent when an IKE SA is established after a crash, and the
444  //recipient may use this information to delete any other IKE SAs it
445  //has to the same authenticated identity without waiting for a timeout
447  }
448 #endif
449 
450  //End of exception handling block
451  } while(0);
452 
453  //Check status code
454  if(error == NO_ERROR)
455  {
456  //The initiator has received the IKE_AUTH response
458 
459  //Successful Child SA creation?
460  if(sa->childSa1 != NULL)
461  {
462  //Update the state of the Child SA
464 
465  //ESP and AH SAs exist in pairs (one in each direction), so two SAs
466  //are created in a single Child SA negotiation for them
467  ikeCreateIpsecSaPair(sa->childSa1);
468  }
469 
470 #if (IKE_REAUTH_SUPPORT == ENABLED)
471  //Check whether reauthentication is on-going
472  if(sa->oldSa != NULL)
473  {
474  //IKEv2 does not have any special support for reauthentication.
475  //Reauthentication is done by creating a new IKE SA from scratch,
476  //creating new Child SAs within the new IKE SA, and finally deleting
477  //the old IKE SA
478  ikeProcessSaDeleteEvent(sa->oldSa);
479 
480  //Detach the old IKE SA
481  sa->oldSa = NULL;
482  }
483 #endif
484  }
485  else if(error == ERROR_AUTHENTICATION_FAILED)
486  {
487  //All errors causing the authentication to fail for whatever reason
488  //(invalid shared secret, invalid ID, untrusted certificate issuer,
489  //revoked or expired certificate, etc.) should result in an
490  //AUTHENTICATION_FAILED notification
492 
493  //If the error occurs on the initiator, the notification may be returned
494  //in a separate INFORMATIONAL exchange, usually with no other payloads.
495  //This is an exception for the general rule of not starting new exchanges
496  //based on errors in responses (refer to RFC 7296, section 2.21.2)
497  ikeSendInfoRequest(sa);
498  }
499  else
500  {
501  //The IKE_AUTH exchange has failed
502  ikeDeleteSaEntry(sa);
503  }
504 
505  //Return status code
506  return error;
507 }
508 
509 
510 /**
511  * @brief Parse incoming CREATE_CHILD_SA response
512  * @param[in] sa Pointer to the IKE SA
513  * @param[in] message Pointer to the received IKE message
514  * @param[in] length Length of the IKE message, in bytes
515  * @return Error code
516  **/
517 
519  size_t length)
520 {
521 #if (IKE_CREATE_CHILD_SA_SUPPORT == ENABLED)
522  error_t error;
523  IkeMessagePayloads payloads;
524 
525  //Payloads sent in IKE response messages must not have the critical flag
526  //set (refer to RFC 7296, section 2.5)
527  error = ikeCheckCriticalPayloads(message, length, NULL);
528 
529  //Check status code
530  if(!error)
531  {
532  //Parse IKE message payloads
534 
535  //The CREATE_CHILD_SA exchange is used to create new Child SAs and to
536  //rekey both IKE SAs and Child SAs (refer to RFC 7296, section 1.3)
537  if(sa->state == IKE_SA_STATE_REKEY_RESP)
538  {
539  //IKE SA rekeying
540  error = ikeProcessIkeSaRekeyResponse(sa, &payloads);
541  }
542  else if(sa->state == IKE_SA_STATE_CREATE_CHILD_RESP)
543  {
544  //Child SA creation
545  error = ikeProcessChildSaCreateResponse(sa, &payloads);
546  }
547  else if(sa->state == IKE_SA_STATE_REKEY_CHILD_RESP)
548  {
549  //Child SA rekeying
550  error = ikeProcessChildSaRekeyResponse(sa, &payloads);
551  }
552  else
553  {
554  //Unexpected message received
555  error = ERROR_UNEXPECTED_MESSAGE;
556  }
557  }
558 
559  //Check status code
560  if(error)
561  {
562  //IKE SA rekeying?
563  if(sa->state == IKE_SA_STATE_REKEY_RESP)
564  {
565  //Delete the new IKE SA
566  ikeDeleteSaEntry(sa->newSa1);
567  }
568 
569  //Delete the IKE SA
570  ikeDeleteSaEntry(sa);
571  }
572 
573  //Return status code
574  return error;
575 #else
576  //Minimal implementations are not required to support the CREATE_CHILD_SA
577  //exchange (refer to RFC 7296, section 4)
579 #endif
580 }
581 
582 
583 /**
584  * @brief Parse incoming INFORMATIONAL response
585  * @param[in] sa Pointer to the IKE SA
586  * @param[in] message Pointer to the received IKE message
587  * @param[in] length Length of the IKE message, in bytes
588  * @return Error code
589  **/
590 
592  size_t length)
593 {
594  error_t error;
595  uint_t i;
596  IkeMessagePayloads payloads;
597  const IkeDeletePayload *deletePayload;
598 
599  //Start of exception handling block
600  do
601  {
602  //Check the state of the IKE SA
603  if(sa->state != IKE_SA_STATE_DPD_RESP &&
604  sa->state != IKE_SA_STATE_DELETE_RESP &&
605  sa->state != IKE_SA_STATE_DELETE_CHILD_RESP &&
606  sa->state != IKE_SA_STATE_AUTH_FAILURE_RESP)
607  {
608  error = ERROR_UNEXPECTED_MESSAGE;
609  break;
610  }
611 
612  //Payloads sent in IKE response messages must not have the critical flag
613  //set (refer to RFC 7296, section 2.5)
614  error = ikeCheckCriticalPayloads(message, length, NULL);
615  //Any error to report?
616  if(error)
617  break;
618 
619  //Parse IKE message payloads
621 
622  //Error notification received?
623  if(payloads.errorNotify != NULL)
624  {
625  //An implementation receiving an error type that it does not recognize
626  //in a response must assume that the corresponding request has failed
627  //entirely (refer to RFC 7296, section 3.10.1)
628  error = ERROR_UNEXPECTED_STATUS;
629  break;
630  }
631 
632  //The response in the INFORMATIONAL exchange will contain Delete payloads
633  //for the paired SAs going in the other direction
634  for(i = 0; ; i++)
635  {
636  //Extract next Delete payload
637  deletePayload = (IkeDeletePayload *) ikeGetPayload(message, length,
638  IKE_PAYLOAD_TYPE_D, i);
639  //Delete payload not found?
640  if(deletePayload == NULL)
641  break;
642 
643  //The Delete payload list the SPIs to be deleted
644  error = ikeParseDeletePayload(sa, deletePayload, TRUE);
645  //Malformed payload?
646  if(error)
647  break;
648  }
649 
650  //End of exception handling block
651  } while(0);
652 
653  //Check status code
654  if(error == NO_ERROR)
655  {
656  //Check the state of the IKE SA
657  if(sa->state == IKE_SA_STATE_DPD_RESP)
658  {
659  //Receipt of a fresh cryptographically protected message on an IKE SA
660  //ensures liveness of the IKE SA and all of its Child SAs
662  }
663  else if(sa->state == IKE_SA_STATE_DELETE_RESP ||
664  sa->state == IKE_SA_STATE_AUTH_FAILURE_RESP)
665  {
666  //Deleting an IKE SA implicitly closes any remaining Child SAs
667  //negotiated under it (refer to RFC 7296, section 1.4.1)
668  ikeDeleteSaEntry(sa);
669  }
670  else if(sa->state == IKE_SA_STATE_DELETE_CHILD_RESP)
671  {
672  //Update the state of the IKE SA
674  sa->childSa1 = NULL;
675  }
676  else
677  {
678  //Just for sanity
679  }
680  }
681  else
682  {
683  //Delete the IKE SA
684  ikeDeleteSaEntry(sa);
685  }
686 
687  //Return status code
688  return error;
689 }
690 
691 
692 /**
693  * @brief Process initial Child SA creation response
694  * @param[in] sa Pointer to the IKE SA
695  * @param[in] payloads Pointer to the IKE message payloads
696  * @return Error code
697  **/
698 
700  IkeMessagePayloads *payloads)
701 {
702  error_t error;
703  IkeChildSaEntry *childSa;
704 
705  //Point to the Child SA
706  childSa = sa->childSa1;
707 
708  //Error notification received?
709  if(payloads->errorNotify != NULL)
710  {
711  //Delete the Child SA
712  ikeDeleteChildSaEntry(sa->childSa1);
713  sa->childSa1 = NULL;
714 
715 #if (IKE_CREATE_CHILD_SA_SUPPORT == DISABLED)
716  //Request closure of the IKE SA
717  sa->deleteRequest = TRUE;
718 #endif
719 
720  //If creating the Child SA during the IKE_AUTH exchange fails for some
721  //reason, the IKE SA is still created as usual (refer to RFC 7296,
722  //section 1.2)
723  return NO_ERROR;
724  }
725 
726  //Mandatory payloads must be included in the received message
727  if(payloads->sa == NULL || payloads->tsi == NULL ||
728  payloads->tsr == NULL)
729  {
730  return ERROR_INVALID_MESSAGE;
731  }
732 
733  //Check the syntax of the SAr payload
734  error = ikeParseSaPayload(payloads->sa);
735  //Malformed SAr payload?
736  if(error)
737  return error;
738 
739  //The initiator of an exchange must check that the accepted offer
740  //is consistent with one of its proposals, and if not must terminate
741  //the exchange (refer to RFC 7296, section 3.3.6)
742  error = ikeCheckChildSaProposal(childSa, payloads->sa);
743  //Invalid cryptographic suite?
744  if(error)
745  return error;
746 
747  //The initiator can request that the Child SA use transport mode
748  //rather than tunnel mode for the SA created
749  if(childSa->mode == IPSEC_MODE_TRANSPORT)
750  {
751  //If the request is accepted, the response must also include a
752  //notification of type USE_TRANSPORT_MODE
753  if(payloads->useTransportModeNotify == NULL)
754  {
755  //Use tunnel mode
756  childSa->mode = IPSEC_MODE_TUNNEL;
757  }
758  }
759 
760  //When the responder chooses a subset of the traffic proposed by
761  //the initiator, it narrows the Traffic Selectors to some subset
762  //of the initiator's proposal (refer to RFC 7296, section 2.9)
763  error = ikeCheckTs(childSa, payloads->tsi, payloads->tsr, FALSE);
764  //Invalid traffic selector?
765  if(error)
766  return error;
767 
768  //For the first Child SA created, Ni and Nr are the nonces from the
769  //IKE_SA_INIT exchange (refer to RFC 7296, section 2.17)
770  osMemcpy(childSa->initiatorNonce, sa->initiatorNonce,
771  sa->initiatorNonceLen);
772 
773  osMemcpy(childSa->responderNonce, sa->responderNonce,
774  sa->responderNonceLen);
775 
776  //Save the length of Ni and Nr nonces
777  childSa->initiatorNonceLen = sa->initiatorNonceLen;
778  childSa->responderNonceLen = sa->responderNonceLen;
779 
780  //A single Child SA is created by the IKE_AUTH exchange. Keying
781  //material for the Child SA must be taken from the expanded KEYMAT
782  //(refer to RFC 7296, section 2.17)
783  return ikeGenerateChildSaKeyMaterial(childSa);
784 }
785 
786 
787 /**
788  * @brief Process Child SA creation response
789  * @param[in] sa Pointer to the IKE SA
790  * @param[in] payloads Pointer to the IKE message payloads
791  * @return Error code
792  **/
793 
795  IkeMessagePayloads *payloads)
796 {
797 #if (IKE_CREATE_CHILD_SA_SUPPORT == ENABLED)
798  error_t error;
799  uint16_t notifyMsgType;
800  IkeChildSaEntry *childSa;
801 
802  //Point to the Child SA
803  childSa = sa->childSa1;
804 
805  //Error notification received?
806  if(payloads->errorNotify != NULL)
807  {
808  //Types in the range 0-16383 are intended for reporting errors
809  notifyMsgType = ntohs(payloads->errorNotify->notifyMsgType);
810 
811  //Check the type of the notification message
813  {
814  //The INVALID_SYNTAX error notification is considered fatal in both
815  //peers, meaning that the IKE SA is deleted without needing an explicit
816  //Delete payload (refer to RFC 7296, section 2.21.3)
817  return ERROR_INVALID_SYNTAX;
818  }
819 #if (IKE_CHILD_SA_PFS_SUPPORT == ENABLED)
821  {
822  IkeContext *context;
823 
824  //Point to the IKE context
825  context = sa->context;
826 
827  //If the responder indicates its preferred Diffie-Hellman group in the
828  //INVALID_KE_PAYLOAD Notify payload (refer to RFC 7296, section 1.3)
829  error = ikeParseInvalidKePayloadNotification(&childSa->keContext,
830  payloads->errorNotify);
831  //Malformed notification?
832  if(error)
833  return error;
834 
835  //Reinitialize Diffie-Hellman context
836  ikeFreeKeContext(&childSa->keContext);
837  ikeInitKeContext(&childSa->keContext);
838 
839  //Generate a new ephemeral key pair
840  error = ikeGenerateKeyPair(&childSa->keContext, context->prngAlgo,
841  context->prngContext);
842  //Any error to report?
843  if(error)
844  return error;
845 
846  //Update the state of the IKE SA
848 
849  //The initiator retries the exchange with a Diffie-Hellman proposal and
850  //KEi in the group that the responder gave in the INVALID_KE_PAYLOAD
851  //Notify payload
852  return ikeSendCreateChildSaRequest(sa);
853  }
854 #endif
856  {
857  //The responder sends a NO_ADDITIONAL_SAS notification to indicate
858  //that a CREATE_CHILD_SA request is unacceptable because the responder
859  //is unwilling to accept any more Child SAs on this IKE SA (refer to
860  //RFC 7296, section 1.3)
861  sa->noAdditionalSas = TRUE;
862 
863  //Delete the Child SA
864  ikeDeleteChildSaEntry(childSa);
865  sa->childSa1 = NULL;
866 
867  //Update the state of the IKE SA
869 
870  //A failed attempt to create a Child SA should not tear down the IKE
871  //SA. There is no reason to lose the work done to set up the IKE SA
872  //(refer to RFC 7296, section 1.3.1)
873  return NO_ERROR;
874  }
876  {
877  //When a peer receives a TEMPORARY_FAILURE notification, it must not
878  //immediately retry the operation; it must wait so that the sender may
879  //complete whatever operation caused the temporary condition (refer to
880  //RFC 7296, section 2.25)
881  return NO_ERROR;
882  }
883  else
884  {
885  //An implementation receiving an error type that it does not recognize
886  //in a response must assume that the corresponding request has failed
887  //entirely (refer to RFC 7296, section 3.10.1)
888  ikeDeleteChildSaEntry(childSa);
889  sa->childSa1 = NULL;
890 
891  //Update the state of the IKE SA
893 
894  //A failed attempt to create a Child SA should not tear down the IKE
895  //SA. There is no reason to lose the work done to set up the IKE SA
896  //(refer to RFC 7296, section 1.3.1)
897  return NO_ERROR;
898  }
899  }
900 
901  //Mandatory payloads must be included in the received message
902  if(payloads->sa == NULL || payloads->nonce == NULL ||
903  payloads->tsi == NULL || payloads->tsr == NULL)
904  {
905  return ERROR_INVALID_MESSAGE;
906  }
907 
908  //Save responder's nonce
909  error = ikeParseNoncePayload(payloads->nonce, childSa->responderNonce,
910  &childSa->responderNonceLen);
911  //Malformed nonce?
912  if(error)
913  return error;
914 
915  //Check the syntax of the SAr payload
916  error = ikeParseSaPayload(payloads->sa);
917  //Malformed SAr payload?
918  if(error)
919  return error;
920 
921  //The initiator of an exchange must check that the accepted offer is
922  //consistent with one of its proposals, and if not must terminate the
923  //exchange (refer to RFC 7296, section 3.3.6)
924  error = ikeCheckChildSaProposal(childSa, payloads->sa);
925  //Invalid cryptographic suite?
926  if(error)
927  return error;
928 
929  //The initiator can request that the Child SA use transport mode rather than
930  //tunnel mode for the SA created
931  if(childSa->mode == IPSEC_MODE_TRANSPORT)
932  {
933  //If the request is accepted, the response must also include a
934  //notification of type USE_TRANSPORT_MODE
935  if(payloads->useTransportModeNotify == NULL)
936  {
937  //Use tunnel mode
938  childSa->mode = IPSEC_MODE_TUNNEL;
939  }
940  }
941 
942  //When the responder chooses a subset of the traffic proposed by the
943  //initiator, it narrows the Traffic Selectors to some subset of the
944  //initiator's proposal (refer to RFC 7296, section 2.9)
945  error = ikeCheckTs(childSa, payloads->tsi, payloads->tsr, FALSE);
946  //Invalid traffic selector?
947  if(error)
948  return error;
949 
950 #if (IKE_CHILD_SA_PFS_SUPPORT == ENABLED)
951  //Perfect forward secrecy?
952  if(childSa->pfs)
953  {
954  //The responder replies with a Diffie-Hellman value in the KEr payload if
955  //KEi was included in the request and the selected cryptographic suite
956  //includes that group (refer to RFC 7296, section 1.3.1)
957  error = ikeParseKePayload(&childSa->keContext, payloads->ke);
958  //Any error to report?
959  if(error)
960  return error;
961 
962  //Let g^ir be the Diffie-Hellman shared secret
963  error = ikeComputeSharedSecret(&childSa->keContext, childSa->sharedSecret,
964  &childSa->sharedSecretLen);
965  //Any error to report?
966  if(error)
967  return error;
968 
969  //The ephemeral private key must be destroyed as soon as possible (refer
970  //to RFC 9206, section 10)
971  ikeFreeKeContext(&childSa->keContext);
972  ikeInitKeContext(&childSa->keContext);
973  }
974 #endif
975 
976  //Keying material for Child SAs must be taken from the expanded KEYMAT (refer
977  //to RFC 7296, section 2.17)
978  error = ikeGenerateChildSaKeyMaterial(childSa);
979  //Any error to report?
980  if(error)
981  return error;
982 
983  //The new Child SA has been successfully created
985 
986  //ESP and AH SAs exist in pairs (one in each direction), so two SAs are
987  //created in a single Child SA negotiation for them
988  ikeCreateIpsecSaPair(childSa);
989 
990  //Update the state of the IKE SA
992  sa->childSa1 = NULL;
993 
994  //Successful processing
995  return NO_ERROR;
996 #else
997  //Minimal implementations are not required to support the CREATE_CHILD_SA
998  //exchange (refer to RFC 7296, section 4)
999  return ERROR_NOT_IMPLEMENTED;
1000 #endif
1001 }
1002 
1003 
1004 /**
1005  * @brief Process Child SA rekeying response
1006  * @param[in] sa Pointer to the IKE SA
1007  * @param[in] payloads Pointer to the IKE message payloads
1008  * @return Error code
1009  **/
1010 
1012  IkeMessagePayloads *payloads)
1013 {
1014 #if (IKE_CREATE_CHILD_SA_SUPPORT == ENABLED)
1015  error_t error;
1016  uint16_t notifyMsgType;
1017  IkeChildSaEntry *childSa;
1018  IkeChildSaEntry *oldChildSa;
1019 
1020  //Point to the Child SA
1021  childSa = sa->childSa1;
1022  //Point to the old Child SA
1023  oldChildSa = childSa->oldChildSa;
1024 
1025  //Error notification received?
1026  if(payloads->errorNotify != NULL)
1027  {
1028  //Types in the range 0-16383 are intended for reporting errors
1029  notifyMsgType = ntohs(payloads->errorNotify->notifyMsgType);
1030 
1031  //Check the type of the notification message
1033  {
1034  //The INVALID_SYNTAX error notification is considered fatal in both
1035  //peers, meaning that the IKE SA is deleted without needing an explicit
1036  //Delete payload (refer to RFC 7296, section 2.21.3)
1037  return ERROR_INVALID_SYNTAX;
1038  }
1039 #if (IKE_CHILD_SA_PFS_SUPPORT == ENABLED)
1041  {
1042  IkeContext *context;
1043 
1044  //Point to the IKE context
1045  context = sa->context;
1046 
1047  //If the responder indicates its preferred Diffie-Hellman group in the
1048  //INVALID_KE_PAYLOAD Notify payload (refer to RFC 7296, section 1.3)
1049  error = ikeParseInvalidKePayloadNotification(&childSa->keContext,
1050  payloads->errorNotify);
1051  //Malformed notification?
1052  if(error)
1053  return error;
1054 
1055  //Reinitialize Diffie-Hellman context
1056  ikeFreeKeContext(&childSa->keContext);
1057  ikeInitKeContext(&childSa->keContext);
1058 
1059  //Generate a new ephemeral key pair
1060  error = ikeGenerateKeyPair(&childSa->keContext, context->prngAlgo,
1061  context->prngContext);
1062  //Any error to report?
1063  if(error)
1064  return error;
1065 
1066  //Update the state of the IKE SA
1068 
1069  //The initiator retries the exchange with a Diffie-Hellman proposal and
1070  //KEi in the group that the responder gave in the INVALID_KE_PAYLOAD
1071  //Notify payload
1072  return ikeSendCreateChildSaRequest(sa);
1073  }
1074 #endif
1076  {
1077  //The responder sends a NO_ADDITIONAL_SAS notification to indicate
1078  //that a CREATE_CHILD_SA request is unacceptable because the responder
1079  //is unwilling to accept any more Child SAs on this IKE SA (refer to
1080  //RFC 7296, section 1.3)
1081  ikeDeleteChildSaEntry(childSa);
1082  sa->childSa1 = NULL;
1083 
1084  //Close the IKE SA
1085  return ikeProcessSaDeleteEvent(sa);
1086  }
1088  {
1089  //When a peer receives a TEMPORARY_FAILURE notification, it must not
1090  //immediately retry the operation; it must wait so that the sender may
1091  //complete whatever operation caused the temporary condition (refer to
1092  //RFC 7296, section 2.25)
1093  return NO_ERROR;
1094  }
1095  else
1096  {
1097  //An implementation receiving an error type that it does not recognize
1098  //in a response must assume that the corresponding request has failed
1099  //entirely (refer to RFC 7296, section 3.10.1)
1100  ikeDeleteChildSaEntry(childSa);
1101  sa->childSa1 = NULL;
1102 
1103  //Close the old Child SA
1104  return ikeProcessChildSaDeleteEvent(oldChildSa);
1105  }
1106  }
1107 
1108  //Mandatory payloads must be included in the received message
1109  if(payloads->sa == NULL || payloads->nonce == NULL ||
1110  payloads->tsi == NULL || payloads->tsr == NULL)
1111  {
1112  return ERROR_INVALID_MESSAGE;
1113  }
1114 
1115  //Save responder's nonce
1116  error = ikeParseNoncePayload(payloads->nonce, childSa->responderNonce,
1117  &childSa->responderNonceLen);
1118  //Malformed nonce?
1119  if(error)
1120  return error;
1121 
1122  //Check the syntax of the SAr payload
1123  error = ikeParseSaPayload(payloads->sa);
1124  //Malformed SAr payload?
1125  if(error)
1126  return error;
1127 
1128  //The initiator of an exchange must check that the accepted offer is
1129  //consistent with one of its proposals, and if not must terminate the
1130  //exchange (refer to RFC 7296, section 3.3.6)
1131  error = ikeCheckChildSaProposal(childSa, payloads->sa);
1132  //Invalid cryptographic suite?
1133  if(error)
1134  return error;
1135 
1136  //The initiator can request that the Child SA use transport mode rather than
1137  //tunnel mode for the SA created
1138  if(childSa->mode == IPSEC_MODE_TRANSPORT)
1139  {
1140  //If the request is accepted, the response must also include a
1141  //notification of type USE_TRANSPORT_MODE
1142  if(payloads->useTransportModeNotify == NULL)
1143  {
1144  //Use tunnel mode
1145  childSa->mode = IPSEC_MODE_TUNNEL;
1146  }
1147  }
1148 
1149  //The responder must not narrow down the Traffic Selectors narrower than the
1150  //scope currently in use (refer to RFC 7296, section 2.9.2)
1151  error = ikeCheckTs(childSa, payloads->tsi, payloads->tsr, TRUE);
1152  //Invalid traffic selector?
1153  if(error)
1154  return error;
1155 
1156 #if (IKE_CHILD_SA_PFS_SUPPORT == ENABLED)
1157  //Perfect forward secrecy?
1158  if(childSa->pfs)
1159  {
1160  //The responder replies with a Diffie-Hellman value in the KEr payload if
1161  //KEi was included in the request and the selected cryptographic suite
1162  //includes that group (refer to RFC 7296, section 1.3.1)
1163  error = ikeParseKePayload(&childSa->keContext, payloads->ke);
1164  //Any error to report?
1165  if(error)
1166  return error;
1167 
1168  //Let g^ir be the Diffie-Hellman shared secret
1169  error = ikeComputeSharedSecret(&childSa->keContext, childSa->sharedSecret,
1170  &childSa->sharedSecretLen);
1171  //Any error to report?
1172  if(error)
1173  return error;
1174 
1175  //The ephemeral private key must be destroyed as soon as possible (refer
1176  //to RFC 9206, section 10)
1177  ikeFreeKeContext(&childSa->keContext);
1178  ikeInitKeContext(&childSa->keContext);
1179  }
1180 #endif
1181 
1182  //Keying material for Child SAs must be taken from the expanded KEYMAT (refer
1183  //to RFC 7296, section 2.17)
1184  error = ikeGenerateChildSaKeyMaterial(childSa);
1185  //Any error to report?
1186  if(error)
1187  return error;
1188 
1189  //Simultaneous rekeying?
1190  if(sa->childSa2 != NULL)
1191  {
1192  //Simultaneous Child SA rekeying may temporarily result in multiple
1193  //similar SAs between the same pairs of nodes (refer to RFC 7296,
1194  //section 2.8.1)
1195  if(ikeCompareChildSaNonces(sa->childSa2, childSa) > 0)
1196  {
1197  //Update the state of the surviving new Child SA
1199 
1200  //ESP and AH SAs always exist in pairs, with one SA in each direction
1201  ikeCreateIpsecSaPair(sa->childSa2);
1202 
1203  //Detach the newly created Child SA
1204  sa->childSa2 = NULL;
1205 
1206  //The SA created with the lowest of the four nonces used in the two
1207  //exchanges should be closed by the endpoint that created it
1208  error = ikeProcessChildSaDeleteEvent(childSa);
1209  }
1210  else
1211  {
1212  //The SA created with the lowest of the four nonces used in the two
1213  //exchanges should be closed by the endpoint that created it
1215 
1216  //Detach the newly created Child SA
1217  sa->childSa2 = NULL;
1218 
1219  //Update the state of the surviving new Child SA
1221 
1222  //ESP and AH SAs always exist in pairs, with one SA in each direction
1223  ikeCreateIpsecSaPair(childSa);
1224 
1225  //The node that initiated the surviving rekeyed SA should delete the
1226  //replaced SA after the new one is established
1227  error = ikeProcessChildSaDeleteEvent(oldChildSa);
1228  }
1229  }
1230  else
1231  {
1232  //The new Child SA has been successfully created
1234 
1235  //ESP and AH SAs always exist in pairs, with one SA in each direction
1236  ikeCreateIpsecSaPair(childSa);
1237 
1238  //To rekey a Child SA within an existing IKE SA, create a new, equivalent
1239  //SA, and when the new one is established, delete the old one (refer to
1240  //RFC 7296, section 2.8)
1241  error = ikeProcessChildSaDeleteEvent(oldChildSa);
1242  }
1243 
1244  //Return status code
1245  return error;
1246 #else
1247  //Minimal implementations are not required to support the CREATE_CHILD_SA
1248  //exchange (refer to RFC 7296, section 4)
1249  return ERROR_NOT_IMPLEMENTED;
1250 #endif
1251 }
1252 
1253 
1254 /**
1255  * @brief Process IKE SA rekeying response
1256  * @param[in] sa Pointer to the IKE SA
1257  * @param[in] payloads Pointer to the IKE message payloads
1258  * @return Error code
1259  **/
1260 
1262  IkeMessagePayloads *payloads)
1263 {
1264 #if (IKE_CREATE_CHILD_SA_SUPPORT == ENABLED)
1265  error_t error;
1266  uint16_t notifyMsgType;
1267  IkeSaEntry *newSa;
1268 
1269  //Point to the new IKE SA
1270  newSa = sa->newSa1;
1271 
1272  //Error notification received?
1273  if(payloads->errorNotify != NULL)
1274  {
1275  //Types in the range 0-16383 are intended for reporting errors
1276  notifyMsgType = ntohs(payloads->errorNotify->notifyMsgType);
1277 
1278  //Check the type of the notification message
1280  {
1281  //The INVALID_SYNTAX error notification is considered fatal in both
1282  //peers, meaning that the IKE SA is deleted without needing an explicit
1283  //Delete payload (refer to RFC 7296, section 2.21.3)
1284  return ERROR_INVALID_SYNTAX;
1285  }
1287  {
1288  IkeContext *context;
1289 
1290  //Point to the IKE context
1291  context = sa->context;
1292 
1293  //If the initiator guesses wrong, the responder will respond with a
1294  //Notify payload of type INVALID_KE_PAYLOAD indicating the selected
1295  //group (refer to RFC 7296, section 1.2)
1296  error = ikeParseInvalidKePayloadNotification(&newSa->keContext,
1297  payloads->errorNotify);
1298  //Malformed notification?
1299  if(error)
1300  return error;
1301 
1302  //Reinitialize Diffie-Hellman context
1303  ikeFreeKeContext(&newSa->keContext);
1304  ikeInitKeContext(&newSa->keContext);
1305 
1306  //Generate a new ephemeral key pair
1307  error = ikeGenerateKeyPair(&newSa->keContext, context->prngAlgo,
1308  context->prngContext);
1309  //Any error to report?
1310  if(error)
1311  return error;
1312 
1313  //Update the state of the IKE SA
1315 
1316  //The initiator must retry the CREATE_CHILD_SA with the corrected
1317  //Diffie-Hellman group
1318  return ikeSendCreateChildSaRequest(sa);
1319  }
1321  {
1322  //If the responder rejects the CREATE_CHILD_SA request with a
1323  //NO_ADDITIONAL_SAS notification, the implementation must be capable
1324  //of instead deleting the old SA and creating a new one (refer to
1325  //RFC 7296, section 4)
1326  ikeDeleteSaEntry(newSa);
1327  sa->newSa1 = NULL;
1328 
1329  //Close the IKE SA
1330  return ikeProcessSaDeleteEvent(sa);
1331  }
1333  {
1334  //When a peer receives a TEMPORARY_FAILURE notification, it must not
1335  //immediately retry the operation; it must wait so that the sender may
1336  //complete whatever operation caused the temporary condition (refer to
1337  //RFC 7296, section 2.25)
1338  return NO_ERROR;
1339  }
1340  else
1341  {
1342  //An implementation receiving an error type that it does not recognize
1343  //in a response must assume that the corresponding request has failed
1344  //entirely (refer to RFC 7296, section 3.10.1)
1345  ikeDeleteSaEntry(newSa);
1346  sa->newSa1 = NULL;
1347 
1348  //Close the IKE SA
1349  return ikeProcessSaDeleteEvent(sa);
1350  }
1351  }
1352 
1353  //Mandatory payloads must be included in the received message
1354  if(payloads->sa == NULL || payloads->nonce == NULL || payloads->ke == NULL)
1355  return ERROR_INVALID_MESSAGE;
1356 
1357  //Save responder's nonce
1358  error = ikeParseNoncePayload(payloads->nonce, newSa->responderNonce,
1359  &newSa->responderNonceLen);
1360  //Malformed nonce?
1361  if(error)
1362  return error;
1363 
1364  //Check the syntax of the SAr payload
1365  error = ikeParseSaPayload(payloads->sa);
1366  //Malformed SAr payload?
1367  if(error)
1368  return error;
1369 
1370  //The initiator of an exchange must check that the accepted offer is
1371  //consistent with one of its proposals, and if not must terminate the
1372  //exchange (refer to RFC 7296, section 3.3.6)
1373  error = ikeCheckSaProposal(newSa, payloads->sa);
1374  //Invalid cryptographic suite?
1375  if(error)
1376  return error;
1377 
1378  //Nonces used in IKEv2 must be at least half the key size of the negotiated
1379  //pseudorandom function (refer to RFC 7296, section 2.10)
1380  error = ikeCheckNonceLength(newSa, newSa->responderNonceLen);
1381  //Unacceptable nonce length?
1382  if(error)
1383  return error;
1384 
1385  //The Key Exchange payload is used to exchange Diffie-Hellman public numbers
1386  //as part of a Diffie-Hellman key exchange
1387  error = ikeParseKePayload(&newSa->keContext, payloads->ke);
1388  //Any error to report?
1389  if(error)
1390  return error;
1391 
1392  //Let g^ir be the Diffie-Hellman shared secret
1393  error = ikeComputeSharedSecret(&newSa->keContext, newSa->sharedSecret,
1394  &newSa->sharedSecretLen);
1395  //Any error to report?
1396  if(error)
1397  return error;
1398 
1399  //The ephemeral private key must be destroyed as soon as possible (refer to
1400  //RFC 9206, section 10)
1401  ikeFreeKeContext(&newSa->keContext);
1402  ikeInitKeContext(&newSa->keContext);
1403 
1404  //At this point in the negotiation, each party can generate a quantity
1405  //called SKEYSEED, from which all keys are derived for that IKE SA (refer
1406  //to RFC 7296, section 1.2)
1407  error = ikeGenerateSaKeyMaterial(newSa, sa);
1408  //Any error to report?
1409  if(error)
1410  return error;
1411 
1412  //Simultaneous rekeying?
1413  if(sa->newSa2 != NULL)
1414  {
1415  //When both peers try to rekey the IKE SA at the same time, it is
1416  //important to ensure that the Child SAs are inherited by the correct
1417  //IKE SA (refer to RFC 7296, section 2.8.2)
1418  if(ikeCompareSaNonces(sa->newSa2, newSa) > 0)
1419  {
1420  //Update the state of the surviving new IKE SA
1421  ikeChangeSaState(sa->newSa2, IKE_SA_STATE_OPEN);
1422 
1423  //The surviving new IKE SA must inherit all the Child SAs
1424  ikeInheritChildSas(sa->newSa2, sa);
1425 
1426  //Detach the newly created IKE SA
1427  sa->newSa2 = NULL;
1428 
1429  //The new IKE SA containing the lowest nonce should be deleted by the
1430  //node that created it
1431  error = ikeProcessSaDeleteEvent(newSa);
1432  }
1433  else
1434  {
1435  //The new IKE SA containing the lowest nonce should be deleted by the
1436  //node that created it
1437  ikeChangeSaState(sa->newSa2, IKE_SA_STATE_OPEN);
1438 
1439  //Detach the newly created IKE SA
1440  sa->newSa2 = NULL;
1441 
1442  //Update the state of the surviving new IKE SA
1444 
1445  //The surviving new IKE SA must inherit all the Child SAs
1446  ikeInheritChildSas(newSa, sa);
1447 
1448  //The node that initiated the surviving rekeyed SA should delete the
1449  //replaced SA after the new one is established
1450  error = ikeProcessSaDeleteEvent(sa);
1451  }
1452  }
1453  else
1454  {
1455  //The new IKE SA has been successfully created
1457 
1458  //The new IKE SA inherits all of the original IKE SA's Child SAs, and is
1459  //used for all control messages needed to maintain those Child SAs
1460  ikeInheritChildSas(newSa, sa);
1461 
1462  //After the new equivalent IKE SA is created, the initiator deletes the
1463  //old IKE SA, and the Delete payload to delete itself must be the last
1464  //request sent over the old IKE SA (refer to RFC 7296, section 2.8)
1465  error = ikeProcessSaDeleteEvent(sa);
1466  }
1467 
1468  //Return status code
1469  return error;
1470 #else
1471  //Minimal implementations are not required to support the CREATE_CHILD_SA
1472  //exchange (refer to RFC 7296, section 4)
1473  return ERROR_NOT_IMPLEMENTED;
1474 #endif
1475 }
1476 
1477 #endif
int_t ikeCompareChildSaNonces(IkeChildSaEntry *childSa1, IkeChildSaEntry *childSa2)
Compare Child SA nonces.
Definition: ike_misc.c:1422
error_t ikeSendIkeSaInitRequest(IkeSaEntry *sa)
Send IKE_SA_INIT request.
void ikeFreeKeContext(IkeKeContext *keContext)
Release key exchange context.
error_t ikeParseIdPayload(IkeSaEntry *sa, const IkeIdPayload *idPayload)
Parse Identification payload.
Diffie-Hellman key exchange.
void ikeInitKeContext(IkeKeContext *keContext)
Initialize key exchange context.
Authentication of the IKE SA.
Helper functions for IKEv2.
error_t ikeComputeSharedSecret(IkeKeContext *keContext, uint8_t *output, size_t *outputLen)
Compute shared secret.
const IkeNotifyPayload * initialContactNotify
int_t ikeCompareSaNonces(IkeSaEntry *sa1, IkeSaEntry *sa2)
Compare IKE SA nonces.
Definition: ike_misc.c:1376
error_t ikeParseCookieNotification(IkeSaEntry *sa, const IkeNotifyPayload *notifyPayload)
Parse COOKIE notification.
IpsecPadEntry * ipsecFindPadEntry(IpsecContext *context, uint8_t idType, const uint8_t *id, size_t idLen)
Find PAD entry that matches the specified identification data.
Definition: ipsec_misc.c:254
const IkeNotifyPayload * natDetectSrcIpNotify
error_t ikeCheckTs(IkeChildSaEntry *childSa, const IkeTsPayload *tsiPayload, const IkeTsPayload *tsrPayload, bool_t rekey)
Check whether the selected traffic selectors are acceptable.
Definition: ike_misc.c:1046
@ ERROR_NOT_IMPLEMENTED
Definition: error.h:66
@ IKE_NOTIFY_MSG_TYPE_NO_PROPOSAL_CHOSEN
Definition: ike.h:1189
@ ERROR_UNEXPECTED_MESSAGE
Definition: error.h:195
const IkeNotifyPayload * errorNotify
error_t ikeCheckCriticalPayloads(const uint8_t *message, size_t length, uint8_t *unsupportedCriticalPayload)
Check whether the message contains an unsupported critical payload.
uint8_t message[]
Definition: chap.h:154
const IkeNotifyPayload * cookieNotify
IKE message payloads.
const IkePayloadHeader * ikeGetPayload(const uint8_t *message, size_t length, uint8_t type, uint_t index)
Search an IKE message for a given payload type.
#define TRUE
Definition: os_port.h:50
error_t ikeCheckSaProposal(IkeSaEntry *sa, const IkeSaPayload *payload)
Check whether the selected proposal is acceptable (IKE protocol)
const IkeNoncePayload * nonce
error_t ikeParseNoncePayload(const IkeNoncePayload *noncePayload, uint8_t *nonce, size_t *nonceLen)
Parse Nonce payload.
const IkeTsPayload * tsr
#define osMemcmp(p1, p2, length)
Definition: os_port.h:159
const IkeCertPayload * cert
@ ERROR_INVALID_MESSAGE
Definition: error.h:105
IKEv2 finite state machine.
IKE response parsing.
const IkeCertReqPayload * certReq
@ IPSEC_MODE_TUNNEL
Definition: ipsec.h:211
error_t ikeParseSignHashAlgosNotification(IkeSaEntry *sa, const IkeNotifyPayload *notifyPayload)
Parse SIGNATURE_HASH_ALGORITHMS notification.
error_t ikeProcessSaDeleteEvent(IkeSaEntry *sa)
Handle IKE SA deletion event.
Definition: ike_fsm.c:802
@ IKE_SA_STATE_REKEY_REQ
Definition: ike.h:1363
error_t ikeParseCreateChildSaResponse(IkeSaEntry *sa, const uint8_t *message, size_t length)
Parse incoming CREATE_CHILD_SA response.
error_t ikeParseKePayload(IkeKeContext *keContext, const IkeKePayload *kePayload)
Parse Key Exchange payload.
@ IKE_NOTIFY_MSG_TYPE_TS_UNACCEPTABLE
Definition: ike.h:1196
void ikeChangeSaState(IkeSaEntry *sa, IkeSaState newState)
Update IKE SA state.
Definition: ike_fsm.c:53
const uint8_t IKE_INVALID_SPI[8]
Definition: ike_misc.c:47
Peer Authorization Database (PAD) entry.
Definition: ipsec.h:412
#define IkeContext
Definition: ike.h:832
@ IKE_NOTIFY_MSG_TYPE_FAILED_CP_REQUIRED
Definition: ike.h:1195
@ IKE_SA_STATE_DELETE_CHILD_RESP
Definition: ike.h:1372
#define FALSE
Definition: os_port.h:46
error_t ikeParseNatDetectDestIpNotification(IkeSaEntry *sa, const IkeNotifyPayload *notifyPayload)
Parse NAT_DETECTION_DESTINATION_IP notification.
uint16_t notifyMsgType
Definition: ike.h:1630
@ ERROR_UNEXPECTED_STATUS
Definition: error.h:284
#define osMemcpy(dest, src, length)
Definition: os_port.h:147
@ IPSEC_MODE_TRANSPORT
Definition: ipsec.h:212
const IkeKePayload * ke
@ IKE_SA_STATE_OPEN
Definition: ike.h:1360
error_t
Error codes.
Definition: error.h:43
@ IKE_SA_STATE_AUTH_FAILURE_RESP
Definition: ike.h:1374
@ IKE_SA_STATE_REKEY_CHILD_REQ
Definition: ike.h:1369
Key material generation.
error_t ikeSendInfoRequest(IkeSaEntry *sa)
Send INFORMATIONAL request.
#define IKE_SPI_SIZE
Definition: ike.h:826
Helper routines for IPsec.
error_t ikeParseCertificateChain(IkeSaEntry *sa, IpsecPadEntry *padEntry, const uint8_t *message, size_t length)
Parse certificate chain.
@ ERROR_RETRY
Definition: error.h:299
const IkeNotifyPayload * natDetectDestIpNotify
error_t ikeProcessChildSaCreateResponse(IkeSaEntry *sa, IkeMessagePayloads *payloads)
Process Child SA creation response.
error_t ikeParseInfoResponse(IkeSaEntry *sa, const uint8_t *message, size_t length)
Parse incoming INFORMATIONAL response.
void ikeDeleteSaEntry(IkeSaEntry *sa)
Delete an IKE Security Association.
Definition: ike_misc.c:347
const IkeSaPayload * sa
error_t ikeSendIkeAuthRequest(IkeSaEntry *sa)
Send IKE_AUTH request.
error_t ikeVerifyAuth(IkeSaEntry *sa, IpsecPadEntry *padEntry, const IkeIdPayload *idPayload, const IkeCertPayload *certPayload, const IkeAuthPayload *authPayload)
Verify signature or MAC.
Definition: ike_auth.c:138
error_t ikeParseNatDetectSrcIpNotification(IkeSaEntry *sa, const uint8_t *message, size_t length)
Parse NAT_DETECTION_SOURCE_IP notification.
const IkeAuthPayload * auth
void ikeDeleteDuplicateSaEntries(IkeSaEntry *sa)
Delete an duplicate IKE Security Associations.
Definition: ike_misc.c:408
void ikeDeleteChildSaEntry(IkeChildSaEntry *childSa)
Delete a Child Security Association.
Definition: ike_misc.c:560
error_t ikeCheckNonceLength(IkeSaEntry *sa, size_t nonceLen)
Check the length of the nonce.
Definition: ike_misc.c:1238
error_t ikeParseInvalidKePayloadNotification(IkeKeContext *keContext, const IkeNotifyPayload *notifyPayload)
Parse INVALID_KE_PAYLOAD notification.
uint8_t length
Definition: tcp.h:375
void ikeInheritChildSas(IkeSaEntry *newSa, IkeSaEntry *oldSa)
Move inherited Child SAs.
Definition: ike_misc.c:597
IkeHeader
Definition: ike.h:1459
error_t ikeProcessInitialChildSaCreateResponse(IkeSaEntry *sa, IkeMessagePayloads *payloads)
Process initial Child SA creation response.
void ikeChangeChildSaState(IkeChildSaEntry *childSa, IkeChildSaState newState)
Update Child SA state.
Definition: ike_fsm.c:110
error_t ikeProcessChildSaRekeyResponse(IkeSaEntry *sa, IkeMessagePayloads *payloads)
Process Child SA rekeying response.
error_t ikeParseSaPayload(const IkeSaPayload *saPayload)
Parse Security Association payload.
error_t ikeSendCreateChildSaRequest(IkeSaEntry *sa)
Send CREATE_CHILD_SA request.
IkeDeletePayload
Definition: ike.h:1646
IKEv2 (Internet Key Exchange Protocol)
error_t ikeCreateIpsecSaPair(IkeChildSaEntry *childSa)
Create AH or ESP SA pair.
Definition: ike_misc.c:1467
const IkeTsPayload * tsi
#define ntohs(value)
Definition: cpu_endian.h:421
@ IKE_SA_STATE_CREATE_CHILD_REQ
Definition: ike.h:1367
@ IKE_NOTIFY_MSG_TYPE_INVALID_KE_PAYLOAD
Definition: ike.h:1190
IKE payload parsing.
void ikeParseIkeMessagePayloads(const uint8_t *message, size_t length, IkeMessagePayloads *payloads)
Parse IKE message payloads.
error_t ikeGenerateKeyPair(IkeKeContext *keContext, const PrngAlgo *prngAlgo, void *prngContext)
Key pair generation.
#define IkeSaEntry
Definition: ike.h:836
@ IKE_NOTIFY_MSG_TYPE_NO_ADDITIONAL_SAS
Definition: ike.h:1193
error_t ikeGenerateChildSaKeyMaterial(IkeChildSaEntry *childSa)
Generate keying material for the Child SA.
error_t ikeParseIkeSaInitResponse(IkeSaEntry *sa, const uint8_t *message, size_t length)
Parse incoming IKE_SA_INIT response.
@ IKE_SA_STATE_REKEY_CHILD_RESP
Definition: ike.h:1370
error_t ikeGenerateSaKeyMaterial(IkeSaEntry *sa, IkeSaEntry *oldSa)
Generate keying material for the IKE SA.
@ ERROR_AUTHENTICATION_FAILED
Definition: error.h:69
const IkeNotifyPayload * signHashAlgosNotify
error_t ikeParseIkeAuthResponse(IkeSaEntry *sa, const uint8_t *message, size_t length)
Parse incoming IKE_AUTH response.
error_t ikeParseCertReqPayload(IkeSaEntry *sa, const IkeCertReqPayload *certReqPayload)
Parse Certificate Request payload.
@ IKE_SA_STATE_DELETE_RESP
Definition: ike.h:1366
X.509 certificate handling.
@ IKE_NOTIFY_MSG_TYPE_TEMPORARY_FAILURE
Definition: ike.h:1201
@ IKE_SA_STATE_AUTH_RESP
Definition: ike.h:1359
@ IKE_SA_STATE_INIT_RESP
Definition: ike.h:1357
@ IKE_NOTIFY_MSG_TYPE_INTERNAL_ADDRESS_FAILURE
Definition: ike.h:1194
@ ERROR_INVALID_SYNTAX
Definition: error.h:68
@ IKE_SA_STATE_AUTH_FAILURE_REQ
Definition: ike.h:1373
const IkeNotifyPayload * useTransportModeNotify
@ IKE_SA_STATE_REKEY_RESP
Definition: ike.h:1364
@ IKE_NOTIFY_MSG_TYPE_SINGLE_PAIR_REQUIRED
Definition: ike.h:1192
@ IKE_SA_STATE_CREATE_CHILD_RESP
Definition: ike.h:1368
@ IKE_SA_STATE_DPD_RESP
Definition: ike.h:1362
error_t ikeParseDeletePayload(IkeSaEntry *sa, const IkeDeletePayload *deletePayload, bool_t response)
Parse Delete payload.
unsigned int uint_t
Definition: compiler_port.h:57
@ IKE_PAYLOAD_TYPE_D
Delete.
Definition: ike.h:896
error_t ikeProcessChildSaDeleteEvent(IkeChildSaEntry *childSa)
Handle Child SA deletion event.
Definition: ike_fsm.c:1090
error_t ikeCheckChildSaProposal(IkeChildSaEntry *childSa, const IkeSaPayload *payload)
Check whether the selected proposal is acceptable (AH or ESP protocol)
void ikeSubstituteId(IkeSaEntry *sa)
Perform ID substitution.
Definition: ike_misc.c:860
#define IkeChildSaEntry
Definition: ike.h:840
IKEv2 algorithm negotiation.
@ NO_ERROR
Success.
Definition: error.h:44
Debugging facilities.
error_t ikeProcessIkeSaRekeyResponse(IkeSaEntry *sa, IkeMessagePayloads *payloads)
Process IKE SA rekeying response.
IKE request formatting.
const IkeIdPayload * idr
@ IKE_NOTIFY_MSG_TYPE_INVALID_SYNTAX
Definition: ike.h:1186
@ IKE_CHILD_SA_STATE_OPEN
Definition: ike.h:1387