forked from msgboxio/ike
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathidentity.go
67 lines (54 loc) · 1.35 KB
/
identity.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
package ike
import (
"crypto"
"crypto/x509"
"github.com/msgboxio/ike/protocol"
)
type Identity interface {
IdType() protocol.IdType
Id() []byte
AuthMethod() protocol.AuthMethod
AuthData(id []byte) []byte
}
type PskIdentities struct {
Ids map[string][]byte
Primary string
}
func (psk *PskIdentities) IdType() protocol.IdType {
return protocol.ID_RFC822_ADDR
}
func (psk *PskIdentities) Id() []byte {
return []byte(psk.Primary)
}
func (psk *PskIdentities) AuthMethod() protocol.AuthMethod {
return protocol.AUTH_SHARED_KEY_MESSAGE_INTEGRITY_CODE
}
func (psk *PskIdentities) AuthData(id []byte) []byte {
if d, ok := psk.Ids[string(id)]; ok {
return d
}
return nil
}
type CertIdentity struct {
Certificate *x509.Certificate
PrivateKey crypto.Signer
Roots *x509.CertPool
Name string
AuthenticationMethod protocol.AuthMethod
}
func (c *CertIdentity) IdType() protocol.IdType {
return protocol.ID_DER_ASN1_DN
}
func (c *CertIdentity) Id() []byte {
return c.Certificate.RawSubject
}
func (c *CertIdentity) AuthData(id []byte) []byte {
return nil
}
func (c *CertIdentity) AuthMethod() protocol.AuthMethod {
// if not explicitly configured, this defaults to AUTH_RSA_DIGITAL_SIGNATURE
if c.AuthenticationMethod == 0 {
return protocol.AUTH_RSA_DIGITAL_SIGNATURE
}
return c.AuthenticationMethod
}