Kea 3.3.3
gss_tsig_callouts.cc
Go to the documentation of this file.
1// Copyright (C) 2021-2026 Internet Systems Consortium, Inc. ("ISC")
2//
3// This Source Code Form is subject to the terms of the Mozilla Public
4// License, v. 2.0. If a copy of the MPL was not distributed with this
5// file, You can obtain one at http://mozilla.org/MPL/2.0/.
6
7#include <config.h>
8
14#include <process/daemon.h>
15
16#include <functional>
17#include <sstream>
18#include <string>
19
20using namespace isc;
21using namespace isc::asiolink;
22using namespace isc::gss_tsig;
23using namespace isc::d2;
24using namespace isc::data;
25using namespace isc::dns;
26using namespace isc::hooks;
27using namespace isc::log;
28using namespace isc::process;
29using namespace std;
30
31namespace isc {
32namespace gss_tsig {
33
36
37} // end of namespace isc::gss_tsig
38} // end of namespace isc
39
40extern "C" {
41
48int get(CalloutHandle& handle) {
49 impl->getHandler(handle);
50 return (0);
51}
52
57int get_all(CalloutHandle& handle) {
58 impl->getAllHandler(handle);
59 return (0);
60}
61
66int lists(CalloutHandle& handle) {
67 impl->listHandler(handle);
68 return (0);
69}
70
77int key_get(CalloutHandle& handle) {
78 impl->keyGetHandler(handle);
79 return (0);
80}
81
89 impl->keyExpireHandler(handle);
90 return (0);
91}
92
99int key_del(CalloutHandle& handle) {
100 impl->keyDelHandler(handle);
101 return (0);
102}
103
110int purge(CalloutHandle& handle) {
111 impl->purgeHandler(handle);
112 return (0);
113}
114
120 impl->purgeAllHandler(handle);
121 return (0);
122}
123
130int rekey(CalloutHandle& handle) {
131 impl->rekeyHandler(handle);
132 return (0);
133}
134
140 impl->rekeyAllHandler(handle);
141 return (0);
142}
143
147int load(LibraryHandle& handle) {
148 try {
149 // Create the implementation object.
150 impl.reset(new GssTsigImpl());
151
152 // Make the hook library loadable only by d2.
153 const std::string& proc_name = Daemon::getProcName();
154 if (proc_name != "kea-dhcp-ddns") {
155 isc_throw(Unexpected, "Bad process name: " << proc_name
156 << ", expected kea-dhcp-ddns");
157 }
158
159 // Load the configuration (syntax check).
161 impl->configure(config);
162
163 // Register commands.
164 handle.registerCommandCallout("gss-tsig-get", get);
165 handle.registerCommandCallout("gss-tsig-get-all", get_all);
166 handle.registerCommandCallout("gss-tsig-key-del", key_del);
167 handle.registerCommandCallout("gss-tsig-key-expire", key_expire);
168 handle.registerCommandCallout("gss-tsig-key-get", key_get);
169 handle.registerCommandCallout("gss-tsig-list", lists);
170 handle.registerCommandCallout("gss-tsig-purge", purge);
171 handle.registerCommandCallout("gss-tsig-purge-all", purge_all);
172 handle.registerCommandCallout("gss-tsig-rekey", rekey);
173 handle.registerCommandCallout("gss-tsig-rekey-all", rekey_all);
174 } catch (const std::exception& ex) {
176 .arg(ex.what());
177 return (1);
178 }
179
181 return (0);
182}
183
187int unload() {
188 if (impl) {
190 impl->stop();
191 impl.reset();
192 }
194 return (0);
195}
196
201 return (1);
202}
203
213 // First check the status.
215 return (0);
216 }
218 D2CfgContextPtr d2_config;
219 // Get the parameters.
220 handle.getArgument("server_config", d2_config);
221 if (!d2_config) {
222 const string error("Error: gss_tsig d2_srv_configured: server_config is null");
223 handle.setArgument("error", error);
225 return (1);
226 }
227 try {
228 impl->finishConfigure(d2_config);
229 impl->getIOService()->post([]() { impl->start(); });
230 } catch (const std::exception& ex) {
231 ostringstream os;
232 os << "gss_tsig config mismatch: " << ex.what();
233 string error(os.str());
234 handle.setArgument("error", error);
236 return (1);
237 }
238 return (0);
239}
240
254 // First check the status.
256 return (0);
257 }
258 // Get the parameters.
259 DnsServerInfoPtr server_info;
260 handle.getArgument("current_server", server_info);
261 D2TsigKeyPtr tsig_key;
262 handle.getArgument("tsig_key", tsig_key);
263 // Get the DNS server.
264 D2TsigKeyPtr key;
265 bool useGssTsig = false;
266 bool fallback = false;
267 if (server_info) {
268 key = impl->findKey(server_info, useGssTsig, fallback);
269 }
270 if (useGssTsig) {
271 if (key) {
272 handle.setArgument("tsig_key", key);
273 } else if (!fallback) {
275 }
276 }
277 return (0);
278}
279
287 try {
288 impl->commandProcessed(handle);
289 } catch (const std::exception& ex) {
291 .arg(ex.what());
292 return (1);
293 }
294
295 return (0);
296}
297
298} // end extern "C"
@ NEXT_STEP_CONTINUE
continue normally
@ NEXT_STEP_DROP
drop the packet
@ NEXT_STEP_SKIP
skip the next processing step
A generic exception that is thrown when an unexpected error condition occurs.
GSS-TSIG hook implementation.
Per-packet callout handle.
@ NEXT_STEP_DROP
drop the packet
CalloutNextStep getStatus() const
Returns the next processing step.
void setStatus(const CalloutNextStep next)
Sets the next processing step.
void getArgument(const std::string &name, T &value) const
Get argument.
void setArgument(const std::string &name, T value)
Set argument.
void registerCommandCallout(const std::string &command_name, CalloutPtr callout)
Register control command handler.
isc::data::ConstElementPtr getParameters()
Get configuration parameter common code.
static std::string getProcName()
returns the process name This value is used as when forming the default PID file name
Definition daemon.cc:156
#define isc_throw(type, stream)
A shortcut macro to insert known values into exception arguments.
int key_expire(CalloutHandle &handle)
The gss-tsig-key-expire command.
int purge(CalloutHandle &handle)
The gss-tsig-purge command.
int select_key(CalloutHandle &handle)
This function is called when the server selects a DNS server and optionally a TSIG key.
int command_processed(CalloutHandle &handle)
This function is called when a command was processed.
int rekey_all(CalloutHandle &handle)
The gss-tsig-rekey-all command.
int get(CalloutHandle &handle)
The gss-tsig-get command.
int key_get(CalloutHandle &handle)
The gss-tsig-key-get command.
int multi_threading_compatible()
This function is called to retrieve the multi-threading compatibility.
int d2_srv_configured(CalloutHandle &handle)
This function is called when the server finishes (re)configuration.
int unload()
This function is called when the library is unloaded.
int get_all(CalloutHandle &handle)
The gss-tsig-get-all command.
int purge_all(CalloutHandle &handle)
The gss-tsig-purge-all command.
int rekey(CalloutHandle &handle)
The gss-tsig-rekey command.
int lists(CalloutHandle &handle)
The gss-tsig-list command.
int load(LibraryHandle &handle)
This function is called when the library is loaded.
int key_del(CalloutHandle &handle)
The gss-tsig-key-del command.
Implements a TSIGContext derived class which can be used as the value of TSIGContext pointers so with...
#define LOG_ERROR(LOGGER, MESSAGE)
Macro to conveniently test error output and log it.
Definition macros.h:32
#define LOG_INFO(LOGGER, MESSAGE)
Macro to conveniently test info output and log it.
Definition macros.h:20
boost::shared_ptr< DnsServerInfo > DnsServerInfoPtr
Defines a pointer for DnsServerInfo instances.
Definition d2_config.h:554
boost::shared_ptr< D2CfgContext > D2CfgContextPtr
Pointer to a configuration context.
Definition d2_cfg_mgr.h:26
boost::shared_ptr< D2TsigKey > D2TsigKeyPtr
Type of pointer to a D2 TSIG key.
Definition d2_tsig_key.h:71
boost::shared_ptr< const Element > ConstElementPtr
Definition data.h:30
std::unique_ptr< GssTsigImpl > GssTsigImplPtr
Type of pointer to a GSS-TSIG hook configuration.
const isc::log::MessageID GSS_TSIG_LOAD_FAILED
const isc::log::MessageID GSS_TSIG_LOAD_OK
const isc::log::MessageID GSS_TSIG_COMMAND_PROCESSED_FAILED
isc::log::Logger gss_tsig_logger("gss-tsig-hooks")
GssTsigImplPtr impl
The GSS-TSIG hook implementation object.
const isc::log::MessageID GSS_TSIG_UNLOAD_OK
Defines the logger used by the top-level component of kea-lfc.