-int req_key_h(connection_t *c)
-{
- char from_name[MAX_STRING_SIZE];
- char to_name[MAX_STRING_SIZE];
- node_t *from, *to;
-cp
- if(sscanf(c->buffer, "%*d "MAX_STRING" "MAX_STRING, from_name, to_name) != 2)
- {
- syslog(LOG_ERR, _("Got bad %s from %s (%s)"), "REQ_KEY",
- c->name, c->hostname);
- return -1;
- }
-
- from = lookup_node(from_name);
-
- if(!from)
- {
- syslog(LOG_ERR, _("Got %s from %s (%s) origin %s which does not exist in our connection list"), "REQ_KEY",
- c->name, c->hostname, from_name);
- return -1;
- }
-
- to = lookup_node(to_name);
-
- if(!to)
- {
- syslog(LOG_ERR, _("Got %s from %s (%s) destination %s which does not exist in our connection list"), "REQ_KEY",
- c->name, c->hostname, to_name);
- return -1;
- }
-
- /* Check if this key request is for us */
-
- if(to == myself) /* Yes, send our own key back */
- {
- mykeyused = 1;
- from->received_seqno = 0;
- send_ans_key(c, myself, from);
- }
- else
- {
-/* Proxy keys
- if(to->status.validkey)
- {
- send_ans_key(c, to, from);
- }
- else
-*/
- send_req_key(to->nexthop->connection, from, to);
- }
+bool send_req_key(node_t *to) {
+ if(to->status.sptps) {
+ if(!node_read_ecdsa_public_key(to)) {
+ logger(DEBUG_PROTOCOL, LOG_DEBUG, "No ECDSA key known for %s (%s)", to->name, to->hostname);
+ send_request(to->nexthop->connection, "%d %s %s %d", REQ_KEY, myself->name, to->name, REQ_PUBKEY);
+ return true;
+ }
+ char label[25 + strlen(myself->name) + strlen(to->name)];
+ snprintf(label, sizeof label, "tinc UDP key expansion %s %s", myself->name, to->name);
+ sptps_stop(&to->sptps);
+ to->status.validkey = false;
+ to->incompression = myself->incompression;
+ return sptps_start(&to->sptps, to, true, true, myself->connection->ecdsa, to->ecdsa, label, sizeof label, send_initial_sptps_data, receive_sptps_record);
+ }
+
+ return send_request(to->nexthop->connection, "%d %s %s", REQ_KEY, myself->name, to->name);
+}
+
+/* REQ_KEY is overloaded to allow arbitrary requests to be routed between two nodes. */
+
+static bool req_key_ext_h(connection_t *c, const char *request, node_t *from, int reqno) {
+ switch(reqno) {
+ case REQ_PUBKEY: {
+ char *pubkey = ecdsa_get_base64_public_key(&myself->connection->ecdsa);
+ send_request(from->nexthop->connection, "%d %s %s %d %s", REQ_KEY, myself->name, from->name, ANS_PUBKEY, pubkey);
+ free(pubkey);
+ return true;
+ }
+
+ case ANS_PUBKEY: {
+ if(node_read_ecdsa_public_key(from)) {
+ logger(DEBUG_PROTOCOL, LOG_WARNING, "Got ANS_PUBKEY from %s (%s) even though we already have his pubkey", from->name, from->hostname);
+ return true;
+ }
+
+ char pubkey[MAX_STRING_SIZE];
+ if(sscanf(request, "%*d %*s %*s %*d " MAX_STRING, pubkey) != 1 || !ecdsa_set_base64_public_key(&from->ecdsa, pubkey)) {
+ logger(DEBUG_ALWAYS, LOG_ERR, "Got bad %s from %s (%s): %s", "ANS_PUBKEY", from->name, from->hostname, "invalid pubkey");
+ return true;
+ }
+
+ logger(DEBUG_PROTOCOL, LOG_INFO, "Learned ECDSA public key from %s (%s)", from->name, from->hostname);
+ append_config_file(from->name, "ECDSAPublicKey", pubkey);
+ return true;
+ }
+
+ case REQ_KEY: {
+ if(!node_read_ecdsa_public_key(from)) {
+ logger(DEBUG_PROTOCOL, LOG_DEBUG, "No ECDSA key known for %s (%s)", from->name, from->hostname);
+ send_request(from->nexthop->connection, "%d %s %s %d", REQ_KEY, myself->name, from->name, REQ_PUBKEY);
+ return true;
+ }
+ }
+
+ case REQ_SPTPS: {
+ char buf[MAX_STRING_SIZE];
+ if(sscanf(request, "%*d %*s %*s %*d " MAX_STRING, buf) != 1) {
+ logger(DEBUG_ALWAYS, LOG_ERR, "Got bad %s from %s (%s): %s", "REQ_KEY", from->name, from->hostname, "invalid SPTPS data");
+ return true;
+ }
+ int len = b64decode(buf, buf, strlen(buf));
+
+
+ char label[25 + strlen(from->name) + strlen(myself->name)];
+ snprintf(label, sizeof label, "tinc UDP key expansion %s %s", from->name, myself->name);
+ sptps_stop(&from->sptps);
+ from->status.validkey = false;
+ sptps_start(&from->sptps, from, false, true, myself->connection->ecdsa, from->ecdsa, label, sizeof label, send_sptps_data, receive_sptps_record);
+ sptps_receive_data(&from->sptps, buf, len);
+ return true;
+ }
+
+ default:
+ logger(DEBUG_ALWAYS, LOG_ERR, "Unknown extended REQ_KEY request from %s (%s): %s", from->name, from->hostname, request);
+ return true;
+ }
+}
+
+bool req_key_h(connection_t *c, const char *request) {
+ char from_name[MAX_STRING_SIZE];
+ char to_name[MAX_STRING_SIZE];
+ node_t *from, *to;
+ int reqno = 0;
+
+ if(sscanf(request, "%*d " MAX_STRING " " MAX_STRING " %d", from_name, to_name, &reqno) < 2) {
+ logger(DEBUG_ALWAYS, LOG_ERR, "Got bad %s from %s (%s)", "REQ_KEY", c->name,
+ c->hostname);
+ return false;
+ }
+
+ if(!check_id(from_name) || !check_id(to_name)) {
+ logger(DEBUG_ALWAYS, LOG_ERR, "Got bad %s from %s (%s): %s", "REQ_KEY", c->name, c->hostname, "invalid name");
+ return false;
+ }
+
+ from = lookup_node(from_name);
+
+ if(!from) {
+ logger(DEBUG_ALWAYS, LOG_ERR, "Got %s from %s (%s) origin %s which does not exist in our connection list",
+ "REQ_KEY", c->name, c->hostname, from_name);
+ return true;
+ }
+
+ to = lookup_node(to_name);
+
+ if(!to) {
+ logger(DEBUG_ALWAYS, LOG_ERR, "Got %s from %s (%s) destination %s which does not exist in our connection list",
+ "REQ_KEY", c->name, c->hostname, to_name);
+ return true;
+ }
+
+ /* Check if this key request is for us */
+
+ if(to == myself) { /* Yes */
+ /* Is this an extended REQ_KEY message? */
+ if(experimental && reqno)
+ return req_key_ext_h(c, request, from, reqno);