18d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/*
28d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * IKEv2 responder (RFC 4306) for EAP-IKEV2
38d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Copyright (c) 2007, Jouni Malinen <j@w1.fi>
48d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *
5c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * This software may be distributed under the terms of the BSD license.
6c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * See README for more details.
78d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */
88d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
98d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#ifndef IKEV2_H
108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define IKEV2_H
118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "eap_common/ikev2_common.h"
138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct ikev2_proposal_data {
158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	u8 proposal_num;
168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	int integ;
178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	int prf;
188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	int encr;
198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	int dh;
208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt};
218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct ikev2_responder_data {
248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	enum { SA_INIT, SA_AUTH, CHILD_SA, NOTIFY, IKEV2_DONE, IKEV2_FAILED }
258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt		state;
268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	u8 i_spi[IKEV2_SPI_LEN];
278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	u8 r_spi[IKEV2_SPI_LEN];
288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	u8 i_nonce[IKEV2_NONCE_MAX_LEN];
298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	size_t i_nonce_len;
308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	u8 r_nonce[IKEV2_NONCE_MAX_LEN];
318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	size_t r_nonce_len;
328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct wpabuf *i_dh_public;
338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct wpabuf *r_dh_private;
348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct ikev2_proposal_data proposal;
358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	const struct dh_group *dh;
368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct ikev2_keys keys;
378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	u8 *IDi;
388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	size_t IDi_len;
398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	u8 IDi_type;
408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	u8 *IDr;
418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	size_t IDr_len;
428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct wpabuf *r_sign_msg;
438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	struct wpabuf *i_sign_msg;
448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	u8 *shared_secret;
458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	size_t shared_secret_len;
468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	enum { PEER_AUTH_CERT, PEER_AUTH_SECRET } peer_auth;
478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	u8 *key_pad;
488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	size_t key_pad_len;
498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	u16 error_type;
508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt	enum { LAST_MSG_SA_INIT, LAST_MSG_SA_AUTH } last_msg;
518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt};
528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtvoid ikev2_responder_deinit(struct ikev2_responder_data *data);
558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtint ikev2_responder_process(struct ikev2_responder_data *data,
568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt			    const struct wpabuf *buf);
578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct wpabuf * ikev2_responder_build(struct ikev2_responder_data *data);
588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt
598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#endif /* IKEV2_H */
60