ike_auth.h
Go to the documentation of this file.
1 /**
2  * @file ike_auth.h
3  * @brief Authentication of the IKE SA
4  *
5  * @section License
6  *
7  * SPDX-License-Identifier: GPL-2.0-or-later
8  *
9  * Copyright (C) 2022-2024 Oryx Embedded SARL. All rights reserved.
10  *
11  * This file is part of CycloneIPSEC Open.
12  *
13  * This program is free software; you can redistribute it and/or
14  * modify it under the terms of the GNU General Public License
15  * as published by the Free Software Foundation; either version 2
16  * of the License, or (at your option) any later version.
17  *
18  * This program is distributed in the hope that it will be useful,
19  * but WITHOUT ANY WARRANTY; without even the implied warranty of
20  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
21  * GNU General Public License for more details.
22  *
23  * You should have received a copy of the GNU General Public License
24  * along with this program; if not, write to the Free Software Foundation,
25  * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
26  *
27  * @author Oryx Embedded SARL (www.oryx-embedded.com)
28  * @version 2.4.0
29  **/
30 
31 #ifndef _IKE_AUTH_H
32 #define _IKE_AUTH_H
33 
34 //Dependencies
35 #include "ike/ike.h"
36 
37 //C++ guard
38 #ifdef __cplusplus
39 extern "C" {
40 #endif
41 
42 //IKEv2 related functions
43 error_t ikeGenerateAuth(IkeSaEntry *sa, const IkeIdPayload *idPayload,
44  uint8_t *authMethod, uint8_t *authData, size_t *authDataLen);
45 
47  const IkeIdPayload *idPayload, const IkeCertPayload *certPayload,
48  const IkeAuthPayload *authPayload);
49 
50 error_t ikeComputeMacAuth(IkeSaEntry *sa, const uint8_t *key, size_t keyLen,
51  const uint8_t *id, size_t idLen, uint8_t *mac, bool_t initiator);
52 
53 //C++ guard
54 #ifdef __cplusplus
55 }
56 #endif
57 
58 #endif
int bool_t
Definition: compiler_port.h:53
error_t
Error codes.
Definition: error.h:43
IKEv2 (Internet Key Exchange Protocol)
IkeIdPayload
Definition: ike.h:1366
IkeCertPayload
Definition: ike.h:1378
IkeAuthPayload
Definition: ike.h:1403
#define IkeSaEntry
Definition: ike.h:682
uint8_t authMethod
Definition: ike.h:1400
error_t ikeVerifyAuth(IkeSaEntry *sa, IpsecPadEntry *padEntry, const IkeIdPayload *idPayload, const IkeCertPayload *certPayload, const IkeAuthPayload *authPayload)
Verify signature or MAC.
Definition: ike_auth.c:137
error_t ikeComputeMacAuth(IkeSaEntry *sa, const uint8_t *key, size_t keyLen, const uint8_t *id, size_t idLen, uint8_t *mac, bool_t initiator)
Compute MAC authentication data.
Definition: ike_auth.c:310
error_t ikeGenerateAuth(IkeSaEntry *sa, const IkeIdPayload *idPayload, uint8_t *authMethod, uint8_t *authData, size_t *authDataLen)
Generate signature or MAC.
Definition: ike_auth.c:59
uint8_t authData[]
Definition: ipv6.h:344
Peer Authorization Database (PAD) entry.
Definition: ipsec.h:400