1999-05-11 17:53:45 +08:00
|
|
|
/*
|
|
|
|
* Rest in pieces - RIP protocol
|
|
|
|
*
|
|
|
|
* Copyright (c) 1999 Pavel Machek <pavel@ucw.cz>
|
|
|
|
*
|
|
|
|
* Can be freely distributed and used under the terms of the GNU GPL.
|
|
|
|
*/
|
|
|
|
|
|
|
|
#define LOCAL_DEBUG
|
|
|
|
|
|
|
|
#include <string.h>
|
|
|
|
#include <stdlib.h>
|
|
|
|
|
|
|
|
#include "nest/bird.h"
|
|
|
|
#include "nest/iface.h"
|
|
|
|
#include "nest/protocol.h"
|
|
|
|
#include "nest/route.h"
|
|
|
|
#include "lib/socket.h"
|
|
|
|
#include "lib/resource.h"
|
|
|
|
#include "lib/lists.h"
|
|
|
|
#include "lib/timer.h"
|
1999-06-01 03:16:22 +08:00
|
|
|
#include "lib/md5.h"
|
1999-05-11 17:53:45 +08:00
|
|
|
|
|
|
|
#include "rip.h"
|
|
|
|
|
|
|
|
#define P ((struct rip_proto *) p)
|
|
|
|
#define P_CF ((struct rip_proto_config *)p->cf)
|
|
|
|
|
1999-08-20 17:59:39 +08:00
|
|
|
#define PACKETLEN(num) (num * sizeof(struct rip_block) + sizeof(struct rip_packet_heading))
|
|
|
|
|
1999-06-01 01:12:38 +08:00
|
|
|
/* 1 == failed, 0 == ok */
|
1999-05-11 17:53:45 +08:00
|
|
|
int
|
1999-06-01 01:12:38 +08:00
|
|
|
rip_incoming_authentication( struct proto *p, struct rip_block_auth *block, struct rip_packet *packet, int num )
|
1999-05-11 17:53:45 +08:00
|
|
|
{
|
|
|
|
DBG( "Incoming authentication: " );
|
1999-06-01 01:12:38 +08:00
|
|
|
switch (block->authtype) { /* Authentication type */
|
1999-05-11 17:53:45 +08:00
|
|
|
case AT_PLAINTEXT:
|
|
|
|
DBG( "Plaintext passwd" );
|
1999-06-01 01:12:38 +08:00
|
|
|
if (!P_CF->passwords) {
|
|
|
|
log( L_AUTH "no passwords set and password authentication came\n" );
|
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
if (strncmp( (char *) (&block->packetlen), P_CF->passwords->password, 16)) {
|
1999-08-20 17:59:39 +08:00
|
|
|
log( L_AUTH "Passwd authentication failed!\n" );
|
1999-05-11 17:53:45 +08:00
|
|
|
return 1;
|
|
|
|
}
|
|
|
|
return 0;
|
1999-06-01 01:12:38 +08:00
|
|
|
case AT_MD5:
|
|
|
|
DBG( "md5 password" );
|
|
|
|
{
|
|
|
|
struct password_item *head;
|
1999-06-01 03:16:22 +08:00
|
|
|
struct rip_md5_tail *tail;
|
|
|
|
|
1999-08-20 17:59:39 +08:00
|
|
|
if (block->packetlen != PACKETLEN(num)) {
|
|
|
|
log( L_ERR "packetlen in md5 does not match computed value\n" );
|
|
|
|
return 1;
|
|
|
|
}
|
1999-08-18 21:19:33 +08:00
|
|
|
|
1999-06-01 03:22:40 +08:00
|
|
|
tail = (struct rip_md5_tail *) ((char *) packet + (block->packetlen - sizeof(struct rip_block_auth)));
|
1999-06-01 03:16:22 +08:00
|
|
|
|
1999-06-01 01:12:38 +08:00
|
|
|
head = P_CF->passwords;
|
1999-08-20 17:59:39 +08:00
|
|
|
while (head) {
|
1999-08-18 21:19:33 +08:00
|
|
|
/* FIXME: should check serial numbers, somehow */
|
1999-08-20 17:59:39 +08:00
|
|
|
if ((head->from > now) || (head->to < now))
|
|
|
|
continue;
|
1999-06-01 03:16:22 +08:00
|
|
|
if (head->id == block->keyid) {
|
|
|
|
struct MD5Context ctxt;
|
|
|
|
char md5sum_packet[16];
|
|
|
|
char md5sum_computed[16];
|
|
|
|
|
1999-06-01 03:22:40 +08:00
|
|
|
memcpy(md5sum_packet, tail->md5, 16);
|
1999-06-01 03:16:22 +08:00
|
|
|
password_strncpy(tail->md5, head->password, 16);
|
|
|
|
|
|
|
|
MD5Init(&ctxt);
|
1999-06-01 03:22:40 +08:00
|
|
|
MD5Update(&ctxt, (char *) packet, block->packetlen );
|
1999-06-01 03:16:22 +08:00
|
|
|
MD5Final(md5sum_computed, &ctxt);
|
|
|
|
|
|
|
|
if (memcmp(md5sum_packet, md5sum_computed, 16))
|
|
|
|
return 1;
|
|
|
|
}
|
1999-06-01 01:12:38 +08:00
|
|
|
head = head->next;
|
|
|
|
}
|
|
|
|
return 1;
|
|
|
|
}
|
1999-05-11 17:53:45 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
void
|
1999-06-01 01:12:38 +08:00
|
|
|
rip_outgoing_authentication( struct proto *p, struct rip_block_auth *block, struct rip_packet *packet, int num )
|
1999-05-11 17:53:45 +08:00
|
|
|
{
|
1999-08-18 21:19:33 +08:00
|
|
|
struct password_item *passwd = get_best_password( P_CF->passwords, 0 );
|
1999-05-11 17:53:45 +08:00
|
|
|
DBG( "Outgoing authentication: " );
|
|
|
|
|
1999-08-18 21:19:33 +08:00
|
|
|
if (!passwd) {
|
|
|
|
log( L_ERR "no suitable password found for authentication\n" );
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
1999-06-01 01:12:38 +08:00
|
|
|
block->authtype = P_CF->authtype;
|
1999-08-18 21:19:33 +08:00
|
|
|
block->mustbeFFFF = 0xffff;
|
1999-05-11 17:53:45 +08:00
|
|
|
switch (P_CF->authtype) {
|
|
|
|
case AT_PLAINTEXT:
|
1999-08-18 21:19:33 +08:00
|
|
|
password_strncpy( (char *) (&block->packetlen), passwd->password, 16);
|
|
|
|
return;
|
|
|
|
case AT_MD5:
|
|
|
|
{
|
|
|
|
struct rip_md5_tail *tail;
|
|
|
|
struct MD5Context ctxt;
|
|
|
|
static int sequence = 0;
|
|
|
|
|
|
|
|
if (num > PACKET_MD5_MAX)
|
|
|
|
bug( "we can not add MD5 authentication to this long packet\n" );
|
|
|
|
|
|
|
|
block->keyid = passwd->id;
|
|
|
|
block->authlen = 20;
|
|
|
|
block->seq = sequence++;
|
|
|
|
block->zero0 = 0;
|
|
|
|
block->zero1 = 1;
|
1999-08-20 17:59:39 +08:00
|
|
|
block->packetlen = PACKETLEN(num);
|
1999-08-18 21:19:33 +08:00
|
|
|
|
|
|
|
tail = (struct rip_md5_tail *) ((char *) packet + (block->packetlen - sizeof(struct rip_block_auth)));
|
|
|
|
tail->mustbeFFFF = 0xffff;
|
|
|
|
tail->mustbe0001 = 0x0001;
|
|
|
|
password_strncpy( (char *) (&tail->md5), passwd->password, 16 );
|
|
|
|
|
|
|
|
MD5Init(&ctxt);
|
|
|
|
MD5Update(&ctxt, (char *) packet, block->packetlen );
|
|
|
|
MD5Final((char *) (&tail->md5), &ctxt);
|
1999-06-01 01:12:38 +08:00
|
|
|
return;
|
|
|
|
}
|
1999-05-11 17:53:45 +08:00
|
|
|
}
|
|
|
|
}
|