18d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/* 28d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * IKEv2 responder (RFC 4306) for EAP-IKEV2 38d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Copyright (c) 2007, Jouni Malinen <j@w1.fi> 48d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * 5c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * This software may be distributed under the terms of the BSD license. 6c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * See README for more details. 78d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */ 88d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 98d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#ifndef IKEV2_H 108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define IKEV2_H 118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "eap_common/ikev2_common.h" 138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct ikev2_proposal_data { 158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 proposal_num; 168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int integ; 178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int prf; 188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int encr; 198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int dh; 208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}; 218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct ikev2_responder_data { 248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt enum { SA_INIT, SA_AUTH, CHILD_SA, NOTIFY, IKEV2_DONE, IKEV2_FAILED } 258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt state; 268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 i_spi[IKEV2_SPI_LEN]; 278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 r_spi[IKEV2_SPI_LEN]; 288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 i_nonce[IKEV2_NONCE_MAX_LEN]; 298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t i_nonce_len; 308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 r_nonce[IKEV2_NONCE_MAX_LEN]; 318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t r_nonce_len; 328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct wpabuf *i_dh_public; 338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct wpabuf *r_dh_private; 348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct ikev2_proposal_data proposal; 358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt const struct dh_group *dh; 368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct ikev2_keys keys; 378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 *IDi; 388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t IDi_len; 398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 IDi_type; 408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 *IDr; 418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t IDr_len; 428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct wpabuf *r_sign_msg; 438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct wpabuf *i_sign_msg; 448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 *shared_secret; 458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t shared_secret_len; 468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt enum { PEER_AUTH_CERT, PEER_AUTH_SECRET } peer_auth; 478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 *key_pad; 488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t key_pad_len; 498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u16 error_type; 508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt enum { LAST_MSG_SA_INIT, LAST_MSG_SA_AUTH } last_msg; 518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}; 528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtvoid ikev2_responder_deinit(struct ikev2_responder_data *data); 558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtint ikev2_responder_process(struct ikev2_responder_data *data, 568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt const struct wpabuf *buf); 578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct wpabuf * ikev2_responder_build(struct ikev2_responder_data *data); 588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#endif /* IKEV2_H */ 60