ViewVC Help
View File | Revision Log | Show Annotations | Download File
/cvs/gvpe/src/conf.C
(Generate patch)

Comparing gvpe/src/conf.C (file contents):
Revision 1.11 by pcg, Wed Apr 2 21:43:44 2003 UTC vs.
Revision 1.33 by pcg, Sun Mar 6 18:34:46 2005 UTC

1/* 1/*
2 conf.c -- configuration code 2 conf.c -- configuration code
3 Copyright (C) 1998 Robert van der Meulen 3 Copyright (C) 2003-2005 Marc Lehmann <gvpe@schmorp.de>
4 1998-2002 Ivo Timmermans <ivo@o2w.nl>
5 2000-2002 Guus Sliepen <guus@sliepen.eu.org>
6 2000 Cris van Pelt <tribbel@arise.dhs.org>
7 2003 Marc Lehmann <pcg@goof.com>
8 4
5 This file is part of GVPE.
6
9 This program is free software; you can redistribute it and/or modify 7 GVPE is free software; you can redistribute it and/or modify
10 it under the terms of the GNU General Public License as published by 8 it under the terms of the GNU General Public License as published by
11 the Free Software Foundation; either version 2 of the License, or 9 the Free Software Foundation; either version 2 of the License, or
12 (at your option) any later version. 10 (at your option) any later version.
13 11
14 This program is distributed in the hope that it will be useful, 12 This program is distributed in the hope that it will be useful,
15 but WITHOUT ANY WARRANTY; without even the implied warranty of 13 but WITHOUT ANY WARRANTY; without even the implied warranty of
16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the 14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 GNU General Public License for more details. 15 GNU General Public License for more details.
18 16
19 You should have received a copy of the GNU General Public License 17 You should have received a copy of the GNU General Public License
20 along with this program; if not, write to the Free Software 18 along with gvpe; if not, write to the Free Software
21 Foundation, Inc. 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA 19 Foundation, Inc. 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
22*/ 20*/
23 21
24#include "config.h" 22#include "config.h"
25 23
31#include <netdb.h> 29#include <netdb.h>
32#include <sys/stat.h> 30#include <sys/stat.h>
33#include <sys/types.h> 31#include <sys/types.h>
34#include <unistd.h> 32#include <unistd.h>
35 33
36#include <netinet/in.h> 34#include "netcompat.h"
37 35
38#include <openssl/err.h> 36#include <openssl/err.h>
39#include <openssl/pem.h> 37#include <openssl/pem.h>
40#include <openssl/rsa.h> 38#include <openssl/rsa.h>
41#include <openssl/rand.h> 39#include <openssl/rand.h>
40#include <openssl/bn.h>
42 41
43#include "gettext.h" 42#include "gettext.h"
44 43
45#include "conf.h" 44#include "conf.h"
46#include "slog.h" 45#include "slog.h"
47#include "util.h" 46#include "util.h"
48 47
49char *confbase; 48char *confbase;
50char *thisnode; 49char *thisnode;
51char *identname; 50char *identname;
52char *pidfilename;
53 51
54struct configuration conf; 52struct configuration conf;
55 53
56u8 best_protocol (u8 protset) 54u8 best_protocol (u8 protset)
57{ 55{
58 if (protset & PROT_IPv4 ) return PROT_IPv4; 56 if (protset & PROT_IPv4 ) return PROT_IPv4;
57 if (protset & PROT_ICMPv4) return PROT_ICMPv4;
59 if (protset & PROT_UDPv4) return PROT_UDPv4; 58 if (protset & PROT_UDPv4 ) return PROT_UDPv4;
60 if (protset & PROT_TCPv4) return PROT_TCPv4; 59 if (protset & PROT_TCPv4 ) return PROT_TCPv4;
60 if (protset & PROT_DNSv4 ) return PROT_DNSv4;
61 61
62 return 0; 62 return 0;
63} 63}
64 64
65const char *strprotocol (u8 protocol) 65const char *strprotocol (u8 protocol)
66{ 66{
67 if (protocol & PROT_IPv4 ) return "rawip"; 67 if (protocol & PROT_IPv4 ) return "rawip";
68 if (protocol & PROT_ICMPv4) return "icmp";
68 if (protocol & PROT_UDPv4) return "udp"; 69 if (protocol & PROT_UDPv4 ) return "udp";
69 if (protocol & PROT_TCPv4) return "tcp"; 70 if (protocol & PROT_TCPv4 ) return "tcp";
71 if (protocol & PROT_DNSv4 ) return "dns";
70 72
71 return "<unknown>"; 73 return "<unknown>";
72}
73
74configuration::configuration ()
75{
76 init ();
77}
78
79configuration::~configuration ()
80{
81 cleanup ();
82}
83
84void configuration::init ()
85{
86 memset (this, 0, sizeof (*this));
87
88 rekey = DEFAULT_REKEY;
89 keepalive = DEFAULT_KEEPALIVE;
90 llevel = L_INFO;
91 ip_proto = IPPROTO_GRE;
92
93 default_node.udp_port = DEFAULT_UDPPORT;
94 default_node.tcp_port = DEFAULT_UDPPORT;
95 default_node.connectmode = conf_node::C_ALWAYS;
96 default_node.compress = true;
97 default_node.protocols = PROT_UDPv4;
98}
99
100void configuration::cleanup()
101{
102 if (rsa_key)
103 RSA_free (rsa_key);
104
105 free (ifname);
106
107 rsa_key = 0;
108 ifname = 0;
109}
110
111void
112configuration::clear_config ()
113{
114 for (configuration::node_vector::iterator i = nodes.begin(); i != nodes.end(); ++i)
115 delete *i;
116
117 nodes.clear ();
118
119 cleanup ();
120 init ();
121}
122
123#define parse_bool(target,name,trueval,falseval) \
124 if (!strcmp (val, "yes")) target = trueval; \
125 else if (!strcmp (val, "no")) target = falseval; \
126 else if (!strcmp (val, "true")) target = trueval; \
127 else if (!strcmp (val, "false")) target = falseval; \
128 else if (!strcmp (val, "on")) target = trueval; \
129 else if (!strcmp (val, "off")) target = falseval; \
130 else \
131 slog (L_WARN, \
132 _("illegal value for '%s', only 'yes|true|on' or 'no|false|off' allowed, at '%s' line %d"), \
133 name, var, fname, lineno);
134
135void configuration::read_config (bool need_keys)
136{
137 char *fname;
138 FILE *f;
139
140 clear_config ();
141
142 asprintf (&fname, "%s/vped.conf", confbase);
143 f = fopen (fname, "r");
144
145 if (f)
146 {
147 char line[16384];
148 int lineno = 0;
149 char *var, *val;
150 conf_node *node = &default_node;
151
152 while (fgets (line, sizeof (line), f))
153 {
154 lineno++;
155
156 {
157 char *end = line + strlen (line);
158
159 while (*end < ' ' && end >= line)
160 end--;
161
162 *++end = 0;
163 }
164
165 char *tok = line;
166
167retry:
168 var = strtok (tok, "\t =");
169 tok = 0;
170
171 if (!var || !var[0])
172 continue; /* no tokens on this line */
173
174 if (var[0] == '#')
175 continue; /* comment: ignore */
176
177 val = strtok (NULL, "\t\n\r =");
178
179 if (!val || val[0] == '#')
180 {
181 slog (L_WARN,
182 _("no value for variable `%s', at '%s' line %d"),
183 var, fname, lineno);
184 break;
185 }
186
187 if (!strcmp (var, "on"))
188 {
189 if (!::thisnode
190 || (val[0] == '!' && strcmp (val + 1, ::thisnode))
191 || !strcmp (val, ::thisnode))
192 goto retry;
193
194 continue;
195 }
196
197 // truly global
198 if (!strcmp (var, "loglevel"))
199 {
200 loglevel l = string_to_loglevel (val);
201
202 if (l != L_NONE)
203 llevel = l;
204 else
205 slog (L_WARN, "'%s': %s, at '%s' line %d", val, UNKNOWN_LOGLEVEL, fname, line);
206 }
207 else if (!strcmp (var, "ip-proto"))
208 ip_proto = atoi (val);
209
210 // per config
211 else if (!strcmp (var, "node"))
212 {
213 default_node.id++;
214
215 node = new conf_node (default_node);
216
217 nodes.push_back (node);
218
219 node->nodename = strdup (val);
220
221 {
222 char *fname;
223 FILE *f;
224
225 asprintf (&fname, "%s/pubkey/%s", confbase, node->nodename);
226
227 f = fopen (fname, "r");
228 if (f)
229 {
230 node->rsa_key = RSA_new ();
231
232 if (!PEM_read_RSAPublicKey(f, &node->rsa_key, NULL, NULL))
233 {
234 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
235 slog (L_ERR, _("unable to open public rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
236 exit (1);
237 }
238
239 RSA_blinding_on (node->rsa_key, 0);
240
241 fclose (f);
242 }
243 else
244 {
245 slog (need_keys ? L_ERR : L_NOTICE, _("unable to read public rsa key file '%s': %s"), fname, strerror (errno));
246
247 if (need_keys)
248 exit (1);
249 }
250
251 free (fname);
252 }
253
254 if (!::thisnode || !strcmp (node->nodename, ::thisnode))
255 thisnode = node;
256 }
257 else if (!strcmp (var, "private-key"))
258 prikeyfile = strdup (val);
259 else if (!strcmp (var, "ifpersist"))
260 {
261 parse_bool (ifpersist, "ifpersist", true, false);
262 }
263 else if (!strcmp (var, "ifname"))
264 ifname = strdup (val);
265 else if (!strcmp (var, "rekey"))
266 rekey = atoi (val);
267 else if (!strcmp (var, "keepalive"))
268 keepalive = atoi (val);
269 else if (!strcmp (var, "mtu"))
270 mtu = atoi (val);
271 else if (!strcmp (var, "if-up"))
272 script_if_up = strdup (val);
273 else if (!strcmp (var, "node-up"))
274 script_node_up = strdup (val);
275 else if (!strcmp (var, "node-down"))
276 script_node_down = strdup (val);
277
278 /* node-specific, non-defaultable */
279 else if (node != &default_node && !strcmp (var, "hostname"))
280 {
281 free (node->hostname);
282 node->hostname = strdup (val);
283 }
284
285 /* node-specific, defaultable */
286 else if (!strcmp (var, "udp-port"))
287 node->udp_port = atoi (val);
288 else if (!strcmp (var, "tcp-port"))
289 node->tcp_port = atoi (val);
290 else if (!strcmp (var, "router-priority"))
291 node->routerprio = atoi (val);
292 else if (!strcmp (var, "connect"))
293 {
294 if (!strcmp (val, "ondemand"))
295 node->connectmode = conf_node::C_ONDEMAND;
296 else if (!strcmp (val, "never"))
297 node->connectmode = conf_node::C_NEVER;
298 else if (!strcmp (val, "always"))
299 node->connectmode = conf_node::C_ALWAYS;
300 else if (!strcmp (val, "disabled"))
301 node->connectmode = conf_node::C_DISABLED;
302 else
303 slog (L_WARN,
304 _("illegal value for 'connectmode', use one of 'ondemand', 'never', 'always' or 'disabled', at '%s' line %d"),
305 var, fname, lineno);
306 }
307 else if (!strcmp (var, "inherit-tos"))
308 {
309 parse_bool (node->inherit_tos, "inherit-tos", true, false);
310 }
311 else if (!strcmp (var, "compress"))
312 {
313 parse_bool (node->compress, "compress", true, false);
314 }
315 // all these bool options really really cost a lot of executable size!
316 else if (!strcmp (var, "enable-tcp"))
317 {
318#if ENABLE_TCP
319 u8 v; parse_bool (v, "enable-tcp" , PROT_TCPv4, 0); node->protocols = (node->protocols & ~PROT_TCPv4) | v;
320#endif
321 }
322 else if (!strcmp (var, "enable-udp"))
323 {
324 u8 v; parse_bool (v, "enable-udp" , PROT_UDPv4, 0); node->protocols = (node->protocols & ~PROT_UDPv4) | v;
325 }
326 else if (!strcmp (var, "enable-rawip"))
327 {
328 u8 v; parse_bool (v, "enable-rawip", PROT_IPv4, 0); node->protocols = (node->protocols & ~PROT_IPv4 ) | v;
329 }
330
331 // unknown or misplaced
332 else
333 {
334 slog (L_WARN,
335 _("unknown or misplaced variable `%s', at '%s' line %d"),
336 var, fname, lineno);
337 }
338 }
339
340 fclose (f);
341 }
342 else
343 {
344 slog (L_ERR, _("unable to read config file '%s': %s"), fname, strerror (errno));
345 exit (1);
346 }
347
348 free (fname);
349
350 fname = config_filename (prikeyfile, "hostkey");
351
352 f = fopen (fname, "r");
353 if (f)
354 {
355 rsa_key = RSA_new ();
356
357 if (!PEM_read_RSAPrivateKey (f, &rsa_key, NULL, NULL))
358 {
359 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
360 slog (L_ERR, _("unable to read private rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
361 exit (1);
362 }
363
364 RSA_blinding_on (rsa_key, 0);
365
366 fclose (f);
367 }
368 else
369 {
370 slog (need_keys ? L_ERR : L_NOTICE, _("unable to open private rsa key file '%s': %s"), fname, strerror (errno));
371
372 if (need_keys)
373 exit (1);
374 }
375
376 free (fname);
377}
378
379char *configuration::config_filename (const char *name, const char *dflt)
380{
381 char *fname;
382
383 asprintf (&fname, name ? name : dflt, ::thisnode);
384
385 if (!ABSOLUTE_PATH (fname))
386 {
387 char *rname = fname;
388 asprintf (&fname, "%s/%s", confbase, rname);
389 free (rname);
390 }
391
392 return fname;
393}
394
395void
396configuration::print ()
397{
398 printf (_("\nConfiguration\n\n"));
399 printf (_("# of nodes: %d\n"), nodes.size ());
400 printf (_("this node: %s\n"), thisnode ? thisnode->nodename : "<unset>");
401 printf (_("MTU: %d\n"), mtu);
402 printf (_("rekeying interval: %d\n"), rekey);
403 printf (_("keepalive interval: %d\n"), keepalive);
404 printf (_("interface: %s\n"), ifname);
405 printf (_("primary rsa key: %s\n"), prikeyfile ? prikeyfile : "<default>");
406 printf (_("rsa key size: %d\n"), rsa_key ? RSA_size (rsa_key) : -1);
407 printf ("\n");
408
409 printf ("%4s %-17s %s %-8.8s %-10.10s %s\n",
410 _("ID#"), _("MAC"), _("Com"), _("Conmode"), _("Node"), _("Host:Port"));
411
412 for (node_vector::iterator i = nodes.begin (); i != nodes.end (); ++i)
413 (*i)->print ();
414
415 printf ("\n");
416} 74}
417 75
418void 76void
419conf_node::print () 77conf_node::print ()
420{ 78{
430 hostname ? ":" : "", 88 hostname ? ":" : "",
431 hostname ? udp_port : 0 89 hostname ? udp_port : 0
432 ); 90 );
433} 91}
434 92
93conf_node::~conf_node ()
94{
95 if (rsa_key)
96 RSA_free (rsa_key);
97
98 free (nodename);
99 free (hostname);
100#if ENABLE_DNS
101 free (domain);
102 free (dns_hostname);
103#endif
104}
105
106void configuration::init ()
107{
108 memset (this, 0, sizeof (*this));
109
110 mtu = DEFAULT_MTU;
111 rekey = DEFAULT_REKEY;
112 keepalive = DEFAULT_KEEPALIVE;
113 llevel = L_INFO;
114 ip_proto = IPPROTO_GRE;
115#if ENABLE_ICMP
116 icmp_type = ICMP_ECHOREPLY;
117#endif
118
119 default_node.udp_port = DEFAULT_UDPPORT;
120 default_node.tcp_port = DEFAULT_UDPPORT; // ehrm
121 default_node.connectmode = conf_node::C_ALWAYS;
122 default_node.compress = true;
123 default_node.protocols = 0;
124 default_node.max_retry = DEFAULT_MAX_RETRY;
125
126#if ENABLE_DNS
127 default_node.dns_port = 0; // default is 0 == client
128 dns_forw_host = strdup ("127.0.0.1");
129 dns_forw_port = 53;
130#endif
131
132 conf.pidfilename = strdup (LOCALSTATEDIR "/run/gvpe.pid");
133}
134
135void configuration::cleanup()
136{
137 if (rsa_key)
138 RSA_free (rsa_key);
139
140 rsa_key = 0;
141
142 free (pidfilename); pidfilename = 0;
143 free (ifname); ifname = 0;
144#if ENABLE_HTTP_PROXY
145 free (proxy_host); proxy_host = 0;
146 free (proxy_auth); proxy_auth = 0;
147#endif
148#if ENABLE_DNS
149 free (dns_forw_host); dns_forw_host = 0;
150#endif
151}
152
153void
154configuration::clear_config ()
155{
156 for (configuration::node_vector::iterator i = nodes.begin(); i != nodes.end(); ++i)
157 delete *i;
158
159 nodes.clear ();
160
161 cleanup ();
162 init ();
163}
164
165#define parse_bool(target,name,trueval,falseval) \
166 if (!strcmp (val, "yes")) target = trueval; \
167 else if (!strcmp (val, "no")) target = falseval; \
168 else if (!strcmp (val, "true")) target = trueval; \
169 else if (!strcmp (val, "false")) target = falseval; \
170 else if (!strcmp (val, "on")) target = trueval; \
171 else if (!strcmp (val, "off")) target = falseval; \
172 else \
173 slog (L_WARN, \
174 _("illegal value for '%s', only 'yes|true|on' or 'no|false|off' allowed, at '%s' line %d"), \
175 name, var, fname, lineno);
176
177void configuration::read_config (bool need_keys)
178{
179 char *fname;
180 FILE *f;
181
182 clear_config ();
183
184 asprintf (&fname, "%s/gvpe.conf", confbase);
185 f = fopen (fname, "r");
186
187 if (f)
188 {
189 char line[16384];
190 int lineno = 0;
191 char *var, *val;
192 conf_node *node = &default_node;
193
194 while (fgets (line, sizeof (line), f))
195 {
196 lineno++;
197
198 {
199 char *end = line + strlen (line);
200
201 while (*end < ' ' && end >= line)
202 end--;
203
204 *++end = 0;
205 }
206
207 char *tok = line;
208
209retry:
210 var = strtok (tok, "\t =");
211 tok = 0;
212
213 if (!var || !var[0])
214 continue; /* no tokens on this line */
215
216 if (var[0] == '#')
217 continue; /* comment: ignore */
218
219 val = strtok (NULL, "\t\n\r =");
220
221 if (!val || val[0] == '#')
222 {
223 slog (L_WARN,
224 _("no value for variable `%s', at '%s' line %d"),
225 var, fname, lineno);
226 break;
227 }
228
229 if (!strcmp (var, "on"))
230 {
231 if (!::thisnode
232 || (val[0] == '!' && strcmp (val + 1, ::thisnode))
233 || !strcmp (val, ::thisnode))
234 goto retry;
235
236 continue;
237 }
238
239 // truly global
240 if (!strcmp (var, "loglevel"))
241 {
242 loglevel l = string_to_loglevel (val);
243
244 if (l != L_NONE)
245 llevel = l;
246 else
247 slog (L_WARN, "'%s': %s, at '%s' line %d", val, UNKNOWN_LOGLEVEL, fname, line);
248 }
249 else if (!strcmp (var, "ip-proto"))
250 ip_proto = atoi (val);
251 else if (!strcmp (var, "icmp-type"))
252 {
253#if ENABLE_ICMP
254 icmp_type = atoi (val);
255#endif
256 }
257
258 // per config
259 else if (!strcmp (var, "node"))
260 {
261 default_node.id++;
262
263 node = new conf_node (default_node);
264
265 nodes.push_back (node);
266
267 node->nodename = strdup (val);
268
269 {
270 char *fname;
271 FILE *f;
272
273 asprintf (&fname, "%s/pubkey/%s", confbase, node->nodename);
274
275 f = fopen (fname, "r");
276 if (f)
277 {
278 node->rsa_key = RSA_new ();
279
280 if (!PEM_read_RSAPublicKey(f, &node->rsa_key, NULL, NULL))
281 {
282 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
283 slog (L_ERR, _("unable to open public rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
284 exit (EXIT_FAILURE);
285 }
286
287 require (RSA_blinding_on (node->rsa_key, 0));
288
289 fclose (f);
290 }
291 else
292 {
293 slog (need_keys ? L_ERR : L_NOTICE, _("unable to read public rsa key file '%s': %s"), fname, strerror (errno));
294
295 if (need_keys)
296 exit (EXIT_FAILURE);
297 }
298
299 free (fname);
300 }
301
302 if (::thisnode && !strcmp (node->nodename, ::thisnode))
303 thisnode = node;
304 }
305 else if (!strcmp (var, "private-key"))
306 free (prikeyfile), prikeyfile = strdup (val);
307 else if (!strcmp (var, "ifpersist"))
308 {
309 parse_bool (ifpersist, "ifpersist", true, false);
310 }
311 else if (!strcmp (var, "ifname"))
312 free (ifname), ifname = strdup (val);
313 else if (!strcmp (var, "rekey"))
314 rekey = atoi (val);
315 else if (!strcmp (var, "keepalive"))
316 keepalive = atoi (val);
317 else if (!strcmp (var, "mtu"))
318 mtu = atoi (val);
319 else if (!strcmp (var, "if-up"))
320 free (script_if_up), script_if_up = strdup (val);
321 else if (!strcmp (var, "node-up"))
322 free (script_node_up), script_node_up = strdup (val);
323 else if (!strcmp (var, "node-down"))
324 free (script_node_down), script_node_down = strdup (val);
325 else if (!strcmp (var, "pid-file"))
326 free (pidfilename), pidfilename = strdup (val);
327#if ENABLE_DNS
328 else if (!strcmp (var, "dns-forw-host"))
329 free (dns_forw_host), dns_forw_host = strdup (val);
330 else if (!strcmp (var, "dns-forw-port"))
331 dns_forw_port = atoi (val);
332#endif
333 else if (!strcmp (var, "http-proxy-host"))
334 {
335#if ENABLE_HTTP_PROXY
336 free (proxy_host), proxy_host = strdup (val);
337#endif
338 }
339 else if (!strcmp (var, "http-proxy-port"))
340 {
341#if ENABLE_HTTP_PROXY
342 proxy_port = atoi (val);
343#endif
344 }
345 else if (!strcmp (var, "http-proxy-auth"))
346 {
347#if ENABLE_HTTP_PROXY
348 proxy_auth = (char *)base64_encode ((const u8 *)val, strlen (val));
349#endif
350 }
351
352 /* node-specific, non-defaultable */
353 else if (node != &default_node && !strcmp (var, "hostname"))
354 free (node->hostname), node->hostname = strdup (val);
355
356 /* node-specific, defaultable */
357 else if (!strcmp (var, "udp-port"))
358 node->udp_port = atoi (val);
359 else if (!strcmp (var, "tcp-port"))
360 node->tcp_port = atoi (val);
361#if ENABLE_DNS
362 else if (!strcmp (var, "dns-hostname"))
363 free (node->dns_hostname), node->dns_hostname = strdup (val);
364 else if (!strcmp (var, "dns-port"))
365 node->dns_port = atoi (val);
366 else if (!strcmp (var, "dns-domain"))
367 free (node->domain), node->domain = strdup (val);
368#endif
369 else if (!strcmp (var, "router-priority"))
370 node->routerprio = atoi (val);
371 else if (!strcmp (var, "max-retry"))
372 node->max_retry = atoi (val);
373 else if (!strcmp (var, "connect"))
374 {
375 if (!strcmp (val, "ondemand"))
376 node->connectmode = conf_node::C_ONDEMAND;
377 else if (!strcmp (val, "never"))
378 node->connectmode = conf_node::C_NEVER;
379 else if (!strcmp (val, "always"))
380 node->connectmode = conf_node::C_ALWAYS;
381 else if (!strcmp (val, "disabled"))
382 node->connectmode = conf_node::C_DISABLED;
383 else
384 slog (L_WARN,
385 _("illegal value for 'connectmode', use one of 'ondemand', 'never', 'always' or 'disabled', at '%s' line %d"),
386 var, fname, lineno);
387 }
388 else if (!strcmp (var, "inherit-tos"))
389 {
390 parse_bool (node->inherit_tos, "inherit-tos", true, false);
391 }
392 else if (!strcmp (var, "compress"))
393 {
394 parse_bool (node->compress, "compress", true, false);
395 }
396 // all these bool options really really cost a lot of executable size!
397 else if (!strcmp (var, "enable-tcp"))
398 {
399#if ENABLE_TCP
400 u8 v; parse_bool (v, "enable-tcp" , PROT_TCPv4, 0); node->protocols = (node->protocols & ~PROT_TCPv4) | v;
401#endif
402 }
403 else if (!strcmp (var, "enable-icmp"))
404 {
405#if ENABLE_ICMP
406 u8 v; parse_bool (v, "enable-icmp" , PROT_ICMPv4, 0); node->protocols = (node->protocols & ~PROT_ICMPv4) | v;
407#endif
408 }
409 else if (!strcmp (var, "enable-dns"))
410 {
411#if ENABLE_DNS
412 u8 v; parse_bool (v, "enable-dns" , PROT_DNSv4, 0); node->protocols = (node->protocols & ~PROT_DNSv4) | v;
413#endif
414 }
415 else if (!strcmp (var, "enable-udp"))
416 {
417 u8 v; parse_bool (v, "enable-udp" , PROT_UDPv4, 0); node->protocols = (node->protocols & ~PROT_UDPv4) | v;
418 }
419 else if (!strcmp (var, "enable-rawip"))
420 {
421 u8 v; parse_bool (v, "enable-rawip", PROT_IPv4, 0); node->protocols = (node->protocols & ~PROT_IPv4 ) | v;
422 }
423
424 // unknown or misplaced
425 else
426 slog (L_WARN,
427 _("unknown or misplaced variable `%s', at '%s' line %d"),
428 var, fname, lineno);
429 }
430
431 fclose (f);
432 }
433 else
434 {
435 slog (L_ERR, _("unable to read config file '%s': %s"), fname, strerror (errno));
436 exit (EXIT_FAILURE);
437 }
438
439 free (fname);
440
441 fname = config_filename (prikeyfile, "hostkey");
442
443 f = fopen (fname, "r");
444 if (f)
445 {
446 rsa_key = RSA_new ();
447
448 if (!PEM_read_RSAPrivateKey (f, &rsa_key, NULL, NULL))
449 {
450 ERR_load_RSA_strings (); ERR_load_PEM_strings ();
451 slog (L_ERR, _("unable to read private rsa key file '%s': %s"), fname, ERR_error_string (ERR_get_error (), 0));
452 exit (EXIT_FAILURE);
453 }
454
455 require (RSA_blinding_on (rsa_key, 0));
456
457 fclose (f);
458 }
459 else
460 {
461 slog (need_keys ? L_ERR : L_NOTICE, _("unable to open private rsa key file '%s': %s"), fname, strerror (errno));
462
463 if (need_keys)
464 exit (EXIT_FAILURE);
465 }
466
467 if (need_keys && ::thisnode
468 && rsa_key && thisnode && thisnode->rsa_key)
469 if (BN_cmp (rsa_key->n, thisnode->rsa_key->n) != 0
470 || BN_cmp (rsa_key->e, thisnode->rsa_key->e) != 0)
471 {
472 slog (L_NOTICE, _("private hostkey and public node key mismatch: is '%s' the correct node?"), ::thisnode);
473 exit (EXIT_FAILURE);
474 }
475
476 free (fname);
477}
478
479char *configuration::config_filename (const char *name, const char *dflt)
480{
481 char *fname;
482
483 asprintf (&fname, name ? name : dflt, ::thisnode);
484
485 if (!ABSOLUTE_PATH (fname))
486 {
487 char *rname = fname;
488 asprintf (&fname, "%s/%s", confbase, rname);
489 free (rname);
490 }
491
492 return fname;
493}
494
495void
496configuration::print ()
497{
498 printf (_("\nConfiguration\n\n"));
499 printf (_("# of nodes: %d\n"), nodes.size ());
500 printf (_("this node: %s\n"), thisnode ? thisnode->nodename : "<unset>");
501 printf (_("MTU: %d\n"), mtu);
502 printf (_("rekeying interval: %d\n"), rekey);
503 printf (_("keepalive interval: %d\n"), keepalive);
504 printf (_("interface: %s\n"), ifname);
505 printf (_("primary rsa key: %s\n"), prikeyfile ? prikeyfile : "<default>");
506 printf (_("rsa key size: %d\n"), rsa_key ? RSA_size (rsa_key) * 8 : -1);
507 printf ("\n");
508
509 printf ("%4s %-17s %s %-8.8s %-10.10s %s\n",
510 _("ID#"), _("MAC"), _("Com"), _("Conmode"), _("Node"), _("Host:Port"));
511
512 for (node_vector::iterator i = nodes.begin (); i != nodes.end (); ++i)
513 (*i)->print ();
514
515 printf ("\n");
516}
517
518configuration::configuration ()
519{
520 asprintf (&confbase, "%s/gvpe", CONFDIR);
521
522 init ();
523}
524
525configuration::~configuration ()
526{
527 cleanup ();
528}
529
530

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines