duplicheck plugin » History » Version 1

Martin Willi, 28.02.2011 16:22

1 1 Martin Willi
h1. duplicheck plugin
2 1 Martin Willi
3 1 Martin Willi
The _duplicheck_ plugin provides an advanced but very specialized peer identity duplicate checking. It works independent from the [[IpsecConf|ipsec.conf]] uniqueids feature.
4 1 Martin Willi
5 1 Martin Willi
h2. Behavior
6 1 Martin Willi
7 1 Martin Willi
The behavior of the _duplicheck_ plugin is as follows:
8 1 Martin Willi
* While establishing a new IKE_SA, check if already one exists with the same peer identity
9 1 Martin Willi
* If yes:
10 1 Martin Willi
** Initiate an IKE_SA delete exchange on the old IKE_SA to liveness check and simultaneously delete it
11 1 Martin Willi
** If no response is received after several retransmits to the delete, destroy the old IKE_SA
12 1 Martin Willi
** If a response is received:
13 1 Martin Willi
*** Also delete the newly established IKE_SA
14 1 Martin Willi
*** Send a notification over a UNIX socket to listening applications (if any)
15 1 Martin Willi
16 1 Martin Willi
h2. Notifications
17 1 Martin Willi
18 1 Martin Willi
If two IKE_SAs exists with the same peer identity, and the old IKE_SA confirmed the triggered delete message, a notification is sent to a listening application over a UNIX socket. An example application of a listener is provided with the _duplicheck_ tool. It listens on the socket and receives the affected peer identity.
19 1 Martin Willi
20 1 Martin Willi
To integrate notification listening to your application, see source:src/libcharon/plugins/duplicheck/duplicheck.c. You'll have to start a dedicated thread to read from the socket or integrated the file descriptor to your applications main loop.