Kea 3.3.3
radius_parsers.cc
Go to the documentation of this file.
1// Copyright (C) 2018-2026 Internet Systems Consortium, Inc. ("ISC")
2//
3// This Source Code Form is subject to the terms of the Mozilla Public
4// License, v. 2.0. If a copy of the MPL was not distributed with this
5// file, You can obtain one at http://mozilla.org/MPL/2.0/.
6
7#include <config.h>
8
9#include <cc/data.h>
11#include <dhcpsrv/cfgmgr.h>
12#include <eval/eval_context.h>
14#include <util/encode/encode.h>
15
16#include <cstdlib>
17#include <cstring>
18#include <limits>
19#include <sstream>
20#include <string>
21
22#include <radius_log.h>
23
24using namespace std;
25using namespace isc;
26using namespace isc::asiolink;
27using namespace isc::data;
28using namespace isc::dhcp;
29using namespace isc::util;
30
31namespace isc {
32namespace radius {
33
35const set<string>
37 "access", "accounting", "tls", // services
38 "bindaddr", "canonical-mac-address", "client-id-pop0",
39 "client-id-printable", "deadtime", "dictionary",
40 "extract-duid", "identifier-type4", "identifier-type6",
41 "nas-ports", "protocol",
42 "reselect-subnet-address", "reselect-subnet-pool",
43 "retries", "session-history", "thread-pool-size", "timeout",
44 "use-message-authenticator",
45 "comment" // not saved for toElement
46};
47
50 { "bindaddr", Element::string, "*" },
51 { "canonical-mac-address", Element::boolean, "false" },
52 { "client-id-pop0", Element::boolean, "false" },
53 { "client-id-printable", Element::boolean, "false" },
54 { "deadtime", Element::integer, "0" },
55 { "dictionary", Element::string, DICTIONARY },
56 { "extract-duid", Element::boolean, "true" },
57 { "identifier-type4", Element::string, "client-id" },
58 { "identifier-type6", Element::string, "duid" },
59 { "protocol", Element::string, "UDP" },
60 { "reselect-subnet-address", Element::boolean, "false" },
61 { "reselect-subnet-pool", Element::boolean, "false" },
62 { "retries", Element::integer, "3" },
63 { "session-history", Element::string, "" },
64 { "thread-pool-size", Element::integer, "0" },
65 { "timeout", Element::integer, "10" }
66};
67
70 { PW_USER_NAME, "User-Name", PW_TYPE_STRING },
71 { PW_USER_PASSWORD, "User-Password", PW_TYPE_STRING },
72 { PW_NAS_IP_ADDRESS, "NAS-IP-Address", PW_TYPE_IPADDR },
73 { PW_NAS_PORT, "NAS-Port", PW_TYPE_INTEGER },
74 { PW_SERVICE_TYPE, "Service-Type", PW_TYPE_INTEGER },
75 { PW_FRAMED_IP_ADDRESS, "Framed-IP-Address", PW_TYPE_IPADDR },
76 { PW_REPLY_MESSAGE, "Reply-Message", PW_TYPE_STRING },
77 { PW_CLASS, "Class", PW_TYPE_STRING },
78 { PW_VENDOR_SPECIFIC, "Vendor-Specific", PW_TYPE_VSA },
79 { PW_CALLING_STATION_ID, "Calling-Station-Id", PW_TYPE_STRING },
80 { PW_ACCT_STATUS_TYPE, "Acct-Status-Type", PW_TYPE_INTEGER },
81 { PW_ACCT_DELAY_TIME, "Acct-Delay-Time", PW_TYPE_INTEGER },
82 { PW_ACCT_SESSION_ID, "Acct-Session-Id", PW_TYPE_STRING },
83 { PW_MESSAGE_AUTHENTICATOR, "Message-Authenticator", PW_TYPE_STRING },
84 { PW_FRAMED_POOL, "Framed-Pool", PW_TYPE_STRING },
85 { PW_NAS_IPV6_ADDRESS, "NAS-IPv6-Address", PW_TYPE_IPV6ADDR },
86 { PW_DELEGATED_IPV6_PREFIX, "Delegated-IPv6-Prefix", PW_TYPE_IPV6PREFIX },
87 { PW_FRAMED_IPV6_ADDRESS, "Framed-IPv6-Address", PW_TYPE_IPV6ADDR }
88};
89
92 { "data", Element::string, "" },
93 { "expr", Element::string, "" },
94 { "raw", Element::string, "" },
95 { "vendor", Element::string, "" }
96};
97
98void
100 try {
102
103 // Set defaults.
105
106 // dictionary (do it first).
107 const ConstElementPtr& dictionary = config->get("dictionary");
108 riref.dictionary_ = dictionary->stringValue();
109
110 // Read the dictionary
111 if (!AttrDefs::instance().getByType(1)) {
112 uint32_t vendor = 0;
113 try {
115 } catch (const exception& ex) {
116 isc_throw(BadValue, "can't read radius dictionary: "
117 << ex.what());
118 }
119 if (vendor != 0) {
120 isc_throw(BadValue, "vendor definitions were not properly "
121 << "closed: vendor " << vendor << " is still open");
122 }
123 }
124
125 // Check it.
127
128 // Protocol.
129 const ConstElementPtr& protocol = config->get("protocol");
130 string proto = protocol->stringValue();
131 if (proto == "UDP") {
132 riref.proto_ = PW_PROTO_UDP;
133 } else if (proto == "TCP") {
134 riref.proto_ = PW_PROTO_TCP;
135 } else if (proto == "TLS") {
136 riref.proto_ = PW_PROTO_TLS;
137 } else {
138 isc_throw(BadValue, "unknown protocol " << proto);
139 }
140 if (riref.proto_ == PW_PROTO_TCP) {
141 isc_throw(NotImplemented, "protocol 'TCP' is not supported");
142 }
143
144 // bindaddr.
145 const ConstElementPtr& bindaddr = config->get("bindaddr");
146 riref.bindaddr_ = bindaddr->stringValue();
147
148 // canonical-mac-address.
149 const ConstElementPtr& canonical = config->get("canonical-mac-address");
150 riref.canonical_mac_address_ = canonical->boolValue();
151
152 // client-id-pop0.
153 const ConstElementPtr& pop0 = config->get("client-id-pop0");
154 riref.clientid_pop0_ = pop0->boolValue();
155
156 // client-id-printable.
157 const ConstElementPtr& try_printable = config->get("client-id-printable");
158 riref.clientid_printable_ = try_printable->boolValue();
159
160 // deadtime.
161 const ConstElementPtr& deadtime = config->get("deadtime");
162 int64_t deadtime64 = deadtime->intValue();
163 if ((deadtime64 < 0) ||
164 (deadtime64 > numeric_limits<unsigned>::max())) {
165 isc_throw(OutOfRange, "bad deadtime " << deadtime64
166 << " not in [0.."
167 << numeric_limits<unsigned>::max() << "]");
168 }
169 riref.deadtime_ = static_cast<unsigned>(deadtime64);
170
171 // extract-duid.
172 const ConstElementPtr& rfc4361 = config->get("extract-duid");
173 riref.extract_duid_ = rfc4361->boolValue();
174
175 // identifier-type4.
176 const ConstElementPtr& id_type4 = config->get("identifier-type4");
177 riref.id_type4_ = Host::getIdentifierType(id_type4->stringValue());
178
179 // identifier-type6.
180 const ConstElementPtr& id_type6 = config->get("identifier-type6");
181 riref.id_type6_ = Host::getIdentifierType(id_type6->stringValue());
182
183 // reselect-subnet-address.
184 const ConstElementPtr& resel_addr =
185 config->get("reselect-subnet-address");
186 riref.reselect_subnet_address_ = resel_addr->boolValue();
187
188 // reselect-subnet-pool.
189 const ConstElementPtr& resel_pool =
190 config->get("reselect-subnet-pool");
191 riref.reselect_subnet_pool_ = resel_pool->boolValue();
192
193 // retries.
194 const ConstElementPtr& retries = config->get("retries");
195 int64_t retries64 = retries->intValue();
196 if ((retries64 < 0) ||
197 (retries64 > numeric_limits<unsigned>::max())) {
198 isc_throw(OutOfRange, "bad retries " << retries64
199 << " not in [0.."
200 << numeric_limits<unsigned>::max() << "]");
201 }
202 riref.retries_ = static_cast<unsigned>(retries64);
203
204 // session-history.
205 const ConstElementPtr& session_history = config->get("session-history");
206 riref.session_history_filename_ = session_history->stringValue();
207
208 // thread-pool-size.
209 const ConstElementPtr& thread_pool_size = config->get("thread-pool-size");
210 riref.thread_pool_size_ = thread_pool_size->intValue();
211
212 // timeout.
213 const ConstElementPtr& timeout = config->get("timeout");
214 int64_t timeout64 = timeout->intValue();
215 if ((timeout64 < 0) ||
216 (timeout64 > numeric_limits<long>::max() / 1000)) {
217 isc_throw(OutOfRange, "bad timeout " << timeout64
218 << " not in [0.."
219 << (numeric_limits<long>::max() / 1000) << "]");
220 }
221 riref.timeout_ = static_cast<unsigned>(timeout64);
222
223 // use-message-authenticator.
224 const ConstElementPtr use_ma = config->get("use-message-authenticator");
225 if (!use_ma) {
226 if (riref.proto_ != PW_PROTO_TLS) {
227 riref.use_message_authenticator_ = true;
228 } else {
229 riref.use_message_authenticator_ = false;
230 }
231 } else {
232 riref.use_message_authenticator_ = use_ma->boolValue();
233 }
234
235 // TLS service.
236 const ConstElementPtr& tls = config->get("tls");
237 if (tls) {
238 if (riref.proto_ != PW_PROTO_TLS) {
239 isc_throw(BadValue, "'tls' service can't be configured "
240 << "when protocol is not 'TLS'");
241 }
242 RadiusServiceParser parser;
243 parser.parse(riref.tls_, tls);
244 parser.checkAttributes(riref.tls_);
245 }
246
247 // Access service.
248 const ConstElementPtr& access = config->get("access");
249 if (access) {
250 RadiusServiceParser parser;
251 parser.parse(riref.auth_, access);
252 parser.checkAttributes(riref.auth_);
253 }
254
255 // Accounting service.
256 const ConstElementPtr& accounting = config->get("accounting");
257 if (accounting) {
258 RadiusServiceParser parser;
259 parser.parse(riref.acct_, accounting);
260 parser.checkAttributes(riref.acct_);
261 }
262
263 // nas-ports (last so we can return when it is not present.
264 const ConstElementPtr& nas_ports = config->get("nas-ports");
265 if (!nas_ports) {
266 return;
267 }
268 for (auto const& entry : nas_ports->listValue()) {
269 // port is mandatory.
270 const ConstElementPtr& port = entry->get("port");
271 if (!port) {
272 isc_throw(BadValue, "missing port in nas-ports entry: "
273 << entry->str());
274 }
275
276 // By subnet-id.
277 const ConstElementPtr& id = entry->get("subnet-id");
278 if (id) {
279 riref.remap_[id->intValue()] = port->intValue();
280 continue;
281 }
282
283 // By subnet-prefix (to be resolved into an ID).
284 const ConstElementPtr& prefix = entry->get("subnet-prefix");
285 if (prefix) {
286 if (CfgMgr::instance().getFamily() == AF_INET) {
287 auto subnet = CfgMgr::instance().getStagingCfg()->
288 getCfgSubnets4()->getByPrefix(prefix->stringValue());
289 if (!subnet) {
290 isc_throw(BadValue, "can't find subnet for "
291 << entry->str());
292 }
293 riref.remap_[subnet->getID()] = port->intValue();
294 continue;
295 } else {
296 auto subnet = CfgMgr::instance().getStagingCfg()->
297 getCfgSubnets6()->getByPrefix(prefix->stringValue());
298 if (!subnet) {
299 isc_throw(BadValue, "can't find subnet for "
300 << entry->str());
301 }
302 riref.remap_[subnet->getID()] = port->intValue();
303 continue;
304 }
305 }
306
307 // By shared-network-name (to be resolved, add all subnets).
308 const ConstElementPtr& name = entry->get("shared-network-name");
309 if (name) {
310 if (CfgMgr::instance().getFamily() == AF_INET) {
311 auto network = CfgMgr::instance().getStagingCfg()->
312 getCfgSharedNetworks4()->getByName(name->stringValue());
313 if (!network) {
314 isc_throw(BadValue, "can't find shared network for "
315 << entry->str());
316 }
317 for (auto const& subnet : *network->getAllSubnets()) {
318 riref.remap_[subnet->getID()] = port->intValue();
319 }
320 continue;
321 } else {
322 auto network = CfgMgr::instance().getStagingCfg()->
323 getCfgSharedNetworks6()->getByName(name->stringValue());
324 if (!network) {
325 isc_throw(BadValue, "can't find shared network for "
326 << entry->str());
327 }
328 for (auto const& subnet : *network->getAllSubnets()) {
329 riref.remap_[subnet->getID()] = port->intValue();
330 }
331 continue;
332 }
333 }
334
335 // Unknown selector.
336 if (entry->size() > 1) {
337 isc_throw(BadValue, "unknown selector in " << entry->str());
338 }
339
340 // Default is in subnet 0 (SUBNET_ID_DEFAULT).
341 riref.remap_[SUBNET_ID_DEFAULT] = port->intValue();
342 }
343
344 } catch (const ConfigError&) {
345 throw;
346 } catch (const std::exception& ex) {
347 isc_throw(ConfigError, ex.what());
348 }
349}
350
352const set<string>
354 "enabled", "servers", "attributes", "peer-updates", "max-pending-requests",
355 "idle-timer-interval"
356};
357
358void
360 const ConstElementPtr& srv_cfg) {
361 try {
363
364 // map type.
365 if (srv_cfg->getType() != Element::map) {
366 isc_throw(BadValue, "expected service to be map, but got "
367 << Element::typeToName(srv_cfg->getType())
368 << " instead");
369 }
370
371 // keywords.
372 const set<string> keywords = RadiusServiceParser::SERVICE_KEYWORDS;
373 for (auto const& entry : srv_cfg->mapValue()) {
374 if (keywords.count(entry.first) == 0) {
375 isc_throw(BadValue, "unknown service parameter: "
376 << entry.first);
377 }
378 }
379
380 // Enabled.
381 const ConstElementPtr& enabled = srv_cfg->get("enabled");
382 if (enabled) {
383 if (riref.proto_ != PW_PROTO_TLS) {
384 isc_throw(BadValue, "'enabled' makes sense only with TLS");
385 }
386 if (enabled->getType() != Element::boolean) {
387 isc_throw(BadValue, "expected enabled to be boolean, "
388 << "but got "
389 << Element::typeToName(enabled->getType())
390 << " instead");
391 }
392 if (service->name_ == "tls") {
393 isc_throw(BadValue, "can't set enabled in 'tls'");
394 }
395 service->enabled_ = enabled->boolValue();
396 } else {
397 if ((riref.proto_ == PW_PROTO_TLS) &&
398 (service->name_ != "tls")) {
399 service->enabled_ = true;
400 }
401 }
402
403 // servers.
404 const ConstElementPtr& servers = srv_cfg->get("servers");
405 if (servers) {
406 if ((riref.proto_ == PW_PROTO_TLS) &&
407 (service->name_ != "tls")) {
408 isc_throw(BadValue, "can't have servers entry in '"
409 << service->name_ << "' with TLS");
410 }
412 parser.parse(service, servers);
413 if (!service->servers_.empty()) {
414 service->enabled_ = true;
415 }
416 }
417
418 // attributes.
419 const ConstElementPtr& attributes = srv_cfg->get("attributes");
420 if (attributes) {
421 if (service->name_ == "tls") {
422 isc_throw(BadValue, "can't define attributes in 'tls'");
423 }
425 parser.parse(service, attributes);
426 }
427
428 // peer-updates.
429 const ConstElementPtr& peer_updates = srv_cfg->get("peer-updates");
430 if (peer_updates) {
431 if (service->name_ != "accounting") {
432 isc_throw(BadValue, "peer-updates configured for the "
433 << service->name_ << " service, but it is "
434 << "only supported for the accounting service");
435 }
436 if (peer_updates->getType() != Element::boolean) {
437 isc_throw(BadValue, "expected peer-updates to be boolean, "
438 << "but got "
439 << Element::typeToName(peer_updates->getType())
440 << " instead");
441 }
442 service->peer_updates_ = peer_updates->boolValue();
443 }
444
445 // max-pending-requests.
446 const ConstElementPtr& max_pending_requests =
447 srv_cfg->get("max-pending-requests");
448 if (max_pending_requests) {
449 if (service->name_ != "access") {
450 isc_throw(BadValue, "max-pending-requests configured for the "
451 << service->name_ << " service, but it is only "
452 << "supported for the access service");
453 }
454 if (max_pending_requests->getType() != Element::integer) {
455 isc_throw(BadValue, "expected max-pending-requests to be "
456 << "integer, but got "
457 << Element::typeToName(max_pending_requests->getType())
458 << " instead");
459 }
460 if (max_pending_requests->intValue() < 0) {
461 isc_throw(BadValue, "expected max-pending-requests to be "
462 << "positive, but got "
463 << max_pending_requests->intValue()
464 << " instead");
465 }
466 service->max_pending_requests_ = max_pending_requests->intValue();
467 }
468
469 // idle-timer-interval.
470 const ConstElementPtr& idle_timer_interval =
471 srv_cfg->get("idle-timer-interval");
472 if (idle_timer_interval) {
473 if ((riref.proto_ == PW_PROTO_TLS) &&
474 (service->name_ != "tls")) {
475 isc_throw(BadValue, "can't have idle-timer-interval entry in '"
476 << service->name_ << "' with TLS");
477 }
478 if (idle_timer_interval->getType() != Element::integer) {
479 isc_throw(BadValue, "expected idle-timer-interval to be "
480 << "integer, but got "
481 << Element::typeToName(idle_timer_interval->getType())
482 << " instead");
483 }
484 if (idle_timer_interval->intValue() < 0) {
485 isc_throw(BadValue, "expected idle-timer-interval to be "
486 << "positive, but got "
487 << idle_timer_interval->intValue()
488 << " instead");
489 }
490 service->idle_timer_interval_ = idle_timer_interval->intValue();
491 }
492 } catch (const std::exception& ex) {
493 isc_throw(ConfigError, ex.what() << " (parsing "
494 << service->name_ << ")");
495 }
496}
497
498void
500 if (!service->enabled_) {
501 return;
502 }
503
504 const CfgAttributes& cfg_attrs = service->attributes_;
505 const Attributes& attrs = cfg_attrs.getAll();
506 if (service->name_ == "access") {
507 // Nothing yet.
508 } else if (service->name_ == "accounting") {
509 // Expressions have no associated attributes.
510 if (cfg_attrs.size() > attrs.size()) {
512 "Expressions are not yet supported in accounting");
513 }
514 }
515}
516
517void
519 const ConstElementPtr& srv_list) {
520 for (auto const& srv : srv_list->listValue()) {
521 RadiusServerParser parser;
522 parser.parse(service, srv);
523 }
524}
525
526void
528 const ElementPtr& server) {
530
531 // Details will be logged.
532 ostringstream msg;
533
534 // Peer address (was name).
535 IOAddress peer_addr("::");
536 const string& name = getString(server, "name");
537 try {
538 peer_addr = IOAddress(name);
539 } catch (const Exception&) {
540 try {
541 peer_addr = Server::getAddress(name);
542 } catch (const Exception& ex) {
543 isc_throw(ConfigError, "can't resolve '" << name << "': "
544 << ex.what());
545 }
546 }
547 msg << "peer-addr=" << peer_addr.toText();
548
549 // port.
550 uint16_t port;
551 if (server->contains("port")) {
552 port = getUint16(server, "port");
553 } else if (service->name_ == "tls") {
554 port = PW_TLS_PORT;
555 } else if (service->name_ == "access") {
556 port = PW_AUTH_PORT;
557 } else {
558 port = PW_ACCT_PORT;
559 }
560 msg << " port=" << port;
561
562 // Local address.
563 IOAddress local_addr("::");
564 const string& local = riref.bindaddr_;
565 if (local != "*") {
566 try {
567 local_addr = IOAddress(local);
568 } catch (const Exception& ex) {
569 isc_throw(ConfigError, "bad local address '" << local << "': "
570 << ex.what());
571 }
572 } else {
573 try {
574 local_addr = Server::getSrcAddress(peer_addr);
575 } catch (const Exception& ex) {
576 isc_throw(ConfigError, "can't get local address: " << ex.what());
577 }
578 }
579 msg << " local_addr=" << local_addr;
580
581 // secret.
582 string secret;
583 if (!server->contains("secret") && (service->name_ == "tls")) {
584 secret = "radsec";
585 } else {
586 secret = getString(server, "secret");
587 try {
589 } catch (const DefaultCredential& ex) {
590 isc_throw(ConfigError, "illegal use of a default secret");
591 }
592 }
593 msg << " secret=*****";
594
595 // TLS parameters.
596 TlsContextPtr tls_context;
597 if (service->name_ == "tls") {
598 string trust_anchor = getString(server, "trust-anchor");
599 string cert_file = getString(server, "cert-file");
600 string key_file = getString(server, "key-file");
601 TlsContext::configure(tls_context, TlsRole::CLIENT,
602 trust_anchor, cert_file, key_file);
603 }
604
605 try {
606 ServerPtr srv(new Server(peer_addr, port, local_addr, tls_context,
607 secret, riref.timeout_, riref.deadtime_));
608 service->servers_.push_back(srv);
609 } catch (const Exception& ex) {
610 isc_throw(ConfigError, "can't create " << service->name_
611 << " server '" << msg.str() << "': " << ex.what());
612 }
613
614 // Done.
616 .arg(service->name_)
617 .arg(msg.str());
618}
619
620void
622 const ConstElementPtr& attr_list) {
623 for (auto const& attr : attr_list->listValue()) {
625 parser.parse(service, attr);
626 }
627}
628
629void
631 const ElementPtr& attr) {
632 AttrDefPtr def;
633
634 // Set defaults.
636
637 // vendor.
638 uint32_t vendor = 0;
639 const ConstElementPtr& vendor_elem = attr->get("vendor");
640 if (!vendor_elem) {
641 // Should not happen as it is added by setDefaults.
642 isc_throw(Unexpected, "no vendor parameter");
643 } else if (vendor_elem->getType() != Element::string) {
644 // Expected to be a common error.
645 isc_throw(TypeError, "vendor parameter must be a string");
646 }
647 const string& vendor_txt = vendor_elem->stringValue();
648 if (!vendor_txt.empty()) {
649 IntCstDefPtr vendor_cst =
651 if (vendor_cst) {
652 vendor = vendor_cst->value_;
653 } else {
654 try {
655 int64_t val = boost::lexical_cast<int64_t>(vendor_txt);
656 if ((val < numeric_limits<int32_t>::min()) ||
657 (val > numeric_limits<uint32_t>::max())) {
658 isc_throw(Unexpected, "not 32 bit " << vendor_txt);
659 }
660 vendor = static_cast<uint32_t>(val);
661 } catch (...) {
662 isc_throw(ConfigError, "can't parse vendor '"
663 << vendor_txt << "'");
664 }
665 }
666 }
667
668 // name.
669 const ConstElementPtr& name = attr->get("name");
670 if (name) {
671 if (name->stringValue().empty()) {
672 isc_throw(ConfigError, "attribute name is empty");
673 }
674 def = AttrDefs::instance().getByName(name->stringValue(), vendor);
675 if (!def) {
676 ostringstream msg;
677 msg << "attribute '" << name->stringValue() << "'";
678 if (vendor != 0) {
679 msg << " in vendor '" << vendor_txt << "'";
680 }
681 msg << " is unknown";
682 isc_throw(ConfigError, msg.str());
683 }
684 }
685
686 // type.
687 const ConstElementPtr& type = attr->get("type");
688 if (type) {
689 if ((type->intValue() < 0) || (type->intValue() > 255)) {
690 isc_throw(ConfigError, "out of range attribute type "
691 << type->intValue());
692 }
693 uint8_t attrib = static_cast<uint8_t>(type->intValue());
694 if (def && (def->type_ != attrib)) {
695 ostringstream msg;
696 msg << "'" << name->stringValue() << "' attribute";
697 if (vendor != 0) {
698 msg << " in vendor '" << vendor_txt << "'";
699 }
700 msg << " has type " << static_cast<unsigned>(def->type_)
701 << ", not " << static_cast<unsigned>(attrib);
702 isc_throw(ConfigError, msg.str());
703 }
704 if (!def) {
705 def = AttrDefs::instance().getByType(attrib, vendor);
706 }
707 if (!def) {
708 ostringstream msg;
709 msg << "attribute type " << static_cast<unsigned>(attrib);
710 if (vendor != 0) {
711 msg << " in vendor '" << vendor_txt << "'";
712 }
713 msg << " is unknown";
714 isc_throw(ConfigError, msg.str());
715 }
716 }
717
718 // name or type are required.
719 if (!def) {
720 isc_throw(ConfigError, "name or type are required");
721 }
722
723 // data.
724 const string& data_txt = getString(attr, "data");
725
726 // raw.
727 const string& raw_txt = getString(attr, "raw");
728
729 // expr.
730 const string& expr_txt = getString(attr, "expr");
731
733
734 ExpressionPtr expression;
735 if (!expr_txt.empty()) {
736 if (!data_txt.empty() || !raw_txt.empty()) {
737 isc_throw(ConfigError, "data, raw and expr are exclusive");
738 }
739 Option::Universe universe;
740 if (CfgMgr::instance().getFamily() == AF_INET) {
741 universe = Option::V4;
742 } else {
743 universe = Option::V6;
744 }
745 try {
746 EvalContext eval_ctx(universe);
747 eval_ctx.parseString(expr_txt, EvalContext::PARSER_STRING);
748 expression.reset(new Expression());
749 *expression = eval_ctx.expression_;
750 } catch (const std::exception& ex) {
751 isc_throw(ConfigError, "expression: [" << expr_txt
752 << "] error: " << ex.what() << " for "
753 << def->name_ << " attribute");
754 }
755
756 service->attributes_.add(def, AttributePtr(), expression, expr_txt);
757 } else if (!raw_txt.empty()) {
758 if (!data_txt.empty()) {
759 isc_throw(ConfigError, "data and raw are exclusive");
760 }
761 // The decodeHex function expects that the string contains an
762 // even number of digits. If we don't meet this requirement,
763 // we have to insert a leading 0.
764 string padded = raw_txt;
765 if ((padded.size() % 2) != 0) {
766 padded = padded.insert(0, "0");
767 }
768 vector<uint8_t> binary;
769 try {
770 encode::decodeHex(padded, binary);
771 } catch (...) {
772 isc_throw(ConfigError, "can't decode raw: [" << raw_txt
773 << "] for " << def->name_ << " attribute");
774 }
775 try {
776 AttributePtr attribute = Attribute::fromBytes(def, binary);
777 service->attributes_.add(def, attribute);
778 } catch (const Exception& ex) {
779 isc_throw(ConfigError, "can't create " << def->name_
780 << " attribute from raw: [" << raw_txt << "]: "
781 << ex.what());
782 }
783 } else {
784 try {
785 AttributePtr attribute = Attribute::fromText(def, data_txt);
786 service->attributes_.add(def, attribute);
787 } catch (const Exception& ex) {
788 isc_throw(ConfigError, "can't create " << def->name_
789 << " attribute from [" << data_txt << "]: "
790 << ex.what());
791 }
792 }
793}
794
795} // end of namespace isc::radius
796} // end of namespace isc
static std::string typeToName(Element::types type)
Returns the name of the given type as a string.
Definition data.cc:716
@ map
Definition data.h:160
@ integer
Definition data.h:153
@ boolean
Definition data.h:155
@ string
Definition data.h:157
A generic exception that is thrown if a parameter given to a method is considered invalid in that con...
An exception that is thrown if an error occurs while configuring any server.
This is a base class for exceptions thrown from the DNS library module.
virtual const char * what() const
Returns a C-style character string of the cause of the exception.
A generic exception that is thrown when a function is not implemented.
A generic exception that is thrown if a parameter given to a method would refer to or modify out-of-r...
A generic exception that is thrown when an unexpected error condition occurs.
Exception thrown on attempt to use a default credential.
static std::string getString(isc::data::ConstElementPtr scope, const std::string &name)
Returns a string parameter from a scope.
uint16_t getUint16(isc::data::ConstElementPtr scope, const std::string &name)
Returns a value converted to uint16_t.
static size_t setDefaults(isc::data::ElementPtr scope, const SimpleDefaults &default_values)
Sets the default values.
A standard Data module exception that is thrown if a function is called for an Element that has a wro...
Definition data.h:37
static CfgMgr & instance()
returns a single instance of Configuration Manager
Definition cfgmgr.cc:29
SrvConfigPtr getStagingCfg()
Returns a pointer to the staging configuration.
Definition cfgmgr.cc:121
IdentifierType getIdentifierType() const
Returns the identifier type.
Definition host.cc:280
Universe
defines option universe DHCPv4 or DHCPv6
Definition option.h:91
Evaluation context, an interface to the expression evaluation.
bool parseString(const std::string &str, ParserType type=PARSER_BOOL)
Run the parser on the string specified.
@ PARSER_STRING
expression is expected to evaluate to string
isc::dhcp::Expression expression_
Parsed expression (output tokens are stored here).
static AttrDefs & instance()
Returns a single instance.
void readDictionary(const std::string &path, uint32_t &vendor, unsigned int depth=0)
Read a dictionary from a file.
AttrDefPtr getByName(const std::string &name, const uint32_t vendor=0) const
Get attribute definition by name and vendor.
void checkStandardDefs(const AttrDefList &defs) const
Check if a list of standard attribute definitions are available and correct.
AttrDefPtr getByType(const uint8_t type, const uint32_t vendor=0) const
Get attribute definition by type and vendor.
static AttributePtr fromBytes(const std::vector< uint8_t > &bytes)
Generic factories.
static AttributePtr fromText(const AttrDefPtr &def, const std::string &value)
From definition generic factories.
Collection of attributes.
size_t size() const
Returns the number of elements.
Attribute data configuration.
Attributes getAll() const
Get all attributes in the configuration.
size_t size() const
Returns the number of elements.
Attribute list parser for Radius.
void parse(const RadiusServicePtr &service, const data::ConstElementPtr &attr_list)
Parses Radius list of attribute configurations.
Attribute configuration parser for Radius.
static const data::SimpleDefaults ATTRIBUTE_DEFAULTS
Defaults for Radius attribute configuration.
void parse(const RadiusServicePtr &service, const data::ElementPtr &attr)
Parses Radius attribute configuration.
static const std::set< std::string > RADIUS_KEYWORDS
Keywords (aka global configuration entry names).
void parse(data::ElementPtr &config)
Parses Radius configuration.
static const data::SimpleDefaults RADIUS_DEFAULTS
Defaults for Radius configuration.
static const AttrDefList USED_STANDARD_ATTR_DEFS
Needed standard attributes definitions.
Radius hooks library implementation.
Definition radius.h:151
unsigned thread_pool_size_
Thread pool size.
Definition radius.h:341
std::string dictionary_
Dictionary path.
Definition radius.h:281
boost::shared_ptr< RadiusTls > tls_
Pointer to tls (never null).
Definition radius.h:296
std::string bindaddr_
bindaddr.
Definition radius.h:311
bool clientid_pop0_
Client Id pop leading zero(s).
Definition radius.h:317
dhcp::Host::IdentifierType id_type4_
Identifier type for IPv4.
Definition radius.h:347
bool reselect_subnet_address_
Reselect subnet using address.
Definition radius.h:332
boost::shared_ptr< RadiusAccess > auth_
Pointer to access (never null).
Definition radius.h:299
bool extract_duid_
Extract Duid from Client Id.
Definition radius.h:326
unsigned timeout_
Timeout.
Definition radius.h:344
dhcp::Host::IdentifierType id_type6_
Identifier type for IPv6.
Definition radius.h:350
bool canonical_mac_address_
Canonical MAC address.
Definition radius.h:314
unsigned deadtime_
Deadtime.
Definition radius.h:323
boost::shared_ptr< RadiusAccounting > acct_
Pointer to accounting (never null).
Definition radius.h:302
unsigned retries_
Retries.
Definition radius.h:335
std::map< uint32_t, uint32_t > remap_
Subnet ID to NAS port map.
Definition radius.h:293
std::string session_history_filename_
Session history filename.
Definition radius.h:338
bool reselect_subnet_pool_
Reselect subnet using pool.
Definition radius.h:329
bool clientid_printable_
Client Id try printable.
Definition radius.h:320
RadiusProtocol proto_
Transport protocol.
Definition radius.h:284
static RadiusImpl & instance()
RadiusImpl is a singleton class.
Definition radius.cc:194
bool use_message_authenticator_
Use Message-Authenticator attribute.
Definition radius.h:353
Server list parser for Radius.
void parse(const RadiusServicePtr &service, const data::ConstElementPtr &srv_list)
Parses Radius server list.
Server parser for Radius.
void parse(const RadiusServicePtr &service, const data::ElementPtr &server)
Parses Radius server.
Service parser for Radius.
static const std::set< std::string > SERVICE_KEYWORDS
Keywords (aka service configuration entry names).
void checkAttributes(const RadiusServicePtr &service)
Check Radius attributes.
void parse(const RadiusServicePtr &service, const data::ConstElementPtr &srv_cfg)
Parses Radius service.
RADIUS server class.
static asiolink::IOAddress getSrcAddress(const asiolink::IOAddress &dest)
Get the source address from a destination address.
static asiolink::IOAddress getAddress(const std::string &name)
Get an address from a name.
#define isc_throw(type, stream)
A shortcut macro to insert known values into exception arguments.
#define LOG_INFO(LOGGER, MESSAGE)
Macro to conveniently test info output and log it.
Definition macros.h:20
boost::shared_ptr< const Element > ConstElementPtr
Definition data.h:30
std::vector< SimpleDefault > SimpleDefaults
This specifies all default values in a given scope (e.g. a subnet).
boost::shared_ptr< Element > ElementPtr
Definition data.h:29
boost::shared_ptr< Expression > ExpressionPtr
Definition token.h:33
std::vector< TokenPtr > Expression
This is a structure that holds an expression converted to RPN.
Definition token.h:31
boost::shared_ptr< IntCstDef > IntCstDefPtr
Shared pointers to Integer constant definition.
const isc::log::MessageID RADIUS_SERVER_CONFIGURED
@ PW_DELEGATED_IPV6_PREFIX
ipv6prefix.
@ PW_MESSAGE_AUTHENTICATOR
string.
@ PW_FRAMED_IPV6_ADDRESS
ipv6addr.
std::list< AttrDef > AttrDefList
List of Attribute definitions.
boost::shared_ptr< AttrDef > AttrDefPtr
Shared pointers to Attribute definition.
boost::shared_ptr< Server > ServerPtr
Type of shared pointers to a RADIUS server object.
boost::shared_ptr< RadiusService > RadiusServicePtr
Type of pointers to Radius service.
boost::shared_ptr< Attribute > AttributePtr
isc::log::Logger radius_logger("radius-hooks")
Radius Logger.
Definition radius_log.h:35
vector< uint8_t > pop0(const ClientIdPtr &client_id)
Pop leading zero in a DHCPv4 client-id.
void decodeHex(const string &encoded_str, vector< uint8_t > &output)
Decode a base16 encoded string into binary data.
Definition encode.cc:367
Defines the logger used by the top-level component of kea-lfc.
static void check(const std::string &value)
Check if the value is a default credential.