aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--configure.in4
-rw-r--r--src/libcharon/Makefile.am7
-rw-r--r--src/libcharon/plugins/certexpire/Makefile.am16
-rw-r--r--src/libcharon/plugins/certexpire/certexpire_plugin.c63
-rw-r--r--src/libcharon/plugins/certexpire/certexpire_plugin.h42
5 files changed, 132 insertions, 0 deletions
diff --git a/configure.in b/configure.in
index 2de37bb8e..d38b0fabb 100644
--- a/configure.in
+++ b/configure.in
@@ -183,6 +183,7 @@ ARG_ENABL_SET([maemo], [enable Maemo specific plugin.])
ARG_ENABL_SET([nm], [enable NetworkManager plugin.])
ARG_ENABL_SET([ha], [enable high availability cluster plugin.])
ARG_ENABL_SET([whitelist], [enable peer identity whitelisting plugin.])
+ARG_ENABL_SET([certexpire], [enable CSV export of expiration dates of used certificates.])
ARG_ENABL_SET([led], [enable plugin to control LEDs on IKEv2 activity using the Linux kernel LED subsystem.])
ARG_ENABL_SET([duplicheck], [advanced duplicate checking plugin using liveness checks.])
ARG_ENABL_SET([coupling], [enable IKEv2 plugin to couple peer certificates permanently to authentication.])
@@ -817,6 +818,7 @@ ADD_PLUGIN([dhcp], [c libcharon])
ADD_PLUGIN([android], [c libcharon])
ADD_PLUGIN([ha], [c libcharon])
ADD_PLUGIN([whitelist], [c libcharon])
+ADD_PLUGIN([certexpire], [c libcharon])
ADD_PLUGIN([led], [c libcharon])
ADD_PLUGIN([duplicheck], [c libcharon])
ADD_PLUGIN([coupling], [c libcharon])
@@ -899,6 +901,7 @@ AM_CONDITIONAL(USE_UNIT_TESTS, test x$unit_tester = xtrue)
AM_CONDITIONAL(USE_LOAD_TESTER, test x$load_tester = xtrue)
AM_CONDITIONAL(USE_HA, test x$ha = xtrue)
AM_CONDITIONAL(USE_WHITELIST, test x$whitelist = xtrue)
+AM_CONDITIONAL(USE_CERTEXPIRE, test x$certexpire = xtrue)
AM_CONDITIONAL(USE_LED, test x$led = xtrue)
AM_CONDITIONAL(USE_DUPLICHECK, test x$duplicheck = xtrue)
AM_CONDITIONAL(USE_COUPLING, test x$coupling = xtrue)
@@ -1103,6 +1106,7 @@ AC_OUTPUT(
src/libcharon/plugins/uci/Makefile
src/libcharon/plugins/ha/Makefile
src/libcharon/plugins/whitelist/Makefile
+ src/libcharon/plugins/certexpire/Makefile
src/libcharon/plugins/led/Makefile
src/libcharon/plugins/duplicheck/Makefile
src/libcharon/plugins/coupling/Makefile
diff --git a/src/libcharon/Makefile.am b/src/libcharon/Makefile.am
index 42c02db6e..7b461866d 100644
--- a/src/libcharon/Makefile.am
+++ b/src/libcharon/Makefile.am
@@ -431,6 +431,13 @@ if MONOLITHIC
endif
endif
+if USE_CERTEXPIRE
+ SUBDIRS += plugins/certexpire
+if MONOLITHIC
+ libcharon_la_LIBADD += plugins/certexpire/libstrongswan-certexpire.la
+endif
+endif
+
if USE_LED
SUBDIRS += plugins/led
if MONOLITHIC
diff --git a/src/libcharon/plugins/certexpire/Makefile.am b/src/libcharon/plugins/certexpire/Makefile.am
new file mode 100644
index 000000000..806cb94c8
--- /dev/null
+++ b/src/libcharon/plugins/certexpire/Makefile.am
@@ -0,0 +1,16 @@
+
+INCLUDES = -I$(top_srcdir)/src/libstrongswan -I$(top_srcdir)/src/libhydra \
+ -I$(top_srcdir)/src/libcharon
+
+AM_CFLAGS = -rdynamic \
+ -DIPSEC_PIDDIR=\"${piddir}\"
+
+if MONOLITHIC
+noinst_LTLIBRARIES = libstrongswan-certexpire.la
+else
+plugin_LTLIBRARIES = libstrongswan-certexpire.la
+endif
+
+libstrongswan_certexpire_la_SOURCES = certexpire_plugin.h certexpire_plugin.c
+
+libstrongswan_certexpire_la_LDFLAGS = -module -avoid-version
diff --git a/src/libcharon/plugins/certexpire/certexpire_plugin.c b/src/libcharon/plugins/certexpire/certexpire_plugin.c
new file mode 100644
index 000000000..8f92b5894
--- /dev/null
+++ b/src/libcharon/plugins/certexpire/certexpire_plugin.c
@@ -0,0 +1,63 @@
+/*
+ * Copyright (C) 2011 Martin Willi
+ * Copyright (C) 2011 revosec AG
+ *
+ * This program is free software; you can redistribute it and/or modify it
+ * under the terms of the GNU General Public License as published by the
+ * Free Software Foundation; either version 2 of the License, or (at your
+ * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
+ *
+ * This program is distributed in the hope that it will be useful, but
+ * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
+ * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
+ * for more details.
+ */
+
+#include "certexpire_plugin.h"
+
+#include <daemon.h>
+
+typedef struct private_certexpire_plugin_t private_certexpire_plugin_t;
+
+/**
+ * Private data of certexpire plugin
+ */
+struct private_certexpire_plugin_t {
+
+ /**
+ * Implements plugin interface
+ */
+ certexpire_plugin_t public;
+};
+
+METHOD(plugin_t, get_name, char*,
+ private_certexpire_plugin_t *this)
+{
+ return "certexpire";
+}
+
+METHOD(plugin_t, destroy, void,
+ private_certexpire_plugin_t *this)
+{
+ free(this);
+}
+
+/**
+ * Plugin constructor
+ */
+plugin_t *certexpire_plugin_create()
+{
+ private_certexpire_plugin_t *this;
+
+ INIT(this,
+ .public = {
+ .plugin = {
+ .get_name = _get_name,
+ .reload = (void*)return_false,
+ .destroy = _destroy,
+ },
+ },
+ );
+
+ return &this->public.plugin;
+}
diff --git a/src/libcharon/plugins/certexpire/certexpire_plugin.h b/src/libcharon/plugins/certexpire/certexpire_plugin.h
new file mode 100644
index 000000000..bcb5606f5
--- /dev/null
+++ b/src/libcharon/plugins/certexpire/certexpire_plugin.h
@@ -0,0 +1,42 @@
+/*
+ * Copyright (C) 2011 Martin Willi
+ * Copyright (C) 2011 revosec AG
+ *
+ * This program is free software; you can redistribute it and/or modify it
+ * under the terms of the GNU General Public License as published by the
+ * Free Software Foundation; either version 2 of the License, or (at your
+ * option) any later version. See <http://www.fsf.org/copyleft/gpl.txt>.
+ *
+ * This program is distributed in the hope that it will be useful, but
+ * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY
+ * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
+ * for more details.
+ */
+
+/**
+ * @defgroup certexpire certexpire
+ * @ingroup cplugins
+ *
+ * @defgroup certexpire_plugin certexpire_plugin
+ * @{ @ingroup certexpire
+ */
+
+#ifndef CERTEXPIRE_PLUGIN_H_
+#define CERTEXPIRE_PLUGIN_H_
+
+#include <plugins/plugin.h>
+
+typedef struct certexpire_plugin_t certexpire_plugin_t;
+
+/**
+ * Plugin exporting expiration dates of used certificates to CSV files.
+ */
+struct certexpire_plugin_t {
+
+ /**
+ * Implements plugin interface.
+ */
+ plugin_t plugin;
+};
+
+#endif /** CERTEXPIRE_PLUGIN_H_ @}*/