OpenVPN
key_state Struct Reference

Security parameter state of one TLS and data channel key session. More...

#include <ssl_common.h>

Collaboration diagram for key_state:

Data Fields

int state
unsigned int auth_token_state_flags
 The state of the auth-token sent from the client.
int key_id
 Key id for this key_state, inherited from struct tls_session.
uint32_t peer_id
 Key id for this key_state, inherited from struct tls_session.
struct key_state_ssl ks_ssl
time_t initial
time_t established
time_t must_negotiate
time_t must_die
time_t peer_last_packet
int initial_opcode
struct session_id session_id_remote
struct link_socket_actual remote_addr
struct crypto_options crypto_options
struct key_source2 * key_src
struct buffer plaintext_read_buf
struct buffer plaintext_write_buf
struct buffer ack_write_buf
struct reliable * send_reliable
struct reliable * rec_reliable
struct reliable_ack * rec_ack
struct reliable_ack * lru_acks
struct buffer_list * paybuf
 Holds outgoing message for the control channel until ks->state reaches S_ACTIVE.
counter_type n_bytes
counter_type n_packets
enum ks_auth_state authenticated
time_t auth_deferred_expire
unsigned int mda_key_id
enum auth_deferred_result mda_status
time_t acf_last_mod
struct auth_deferred_status plugin_auth
struct auth_deferred_status script_auth
enum dco_key_status dco_status

Detailed Description

Security parameter state of one TLS and data channel key session.

This structure represents one security parameter session between OpenVPN peers. It includes the control channel TLS state and the data channel crypto state. It also contains the reliability layer structures used for control channel messages.

A new key_state structure is initialized for each hard or soft reset.

See also

Definition at line 207 of file ssl_common.h.

Field Documentation

◆ acf_last_mod

time_t key_state::acf_last_mod

Definition at line 266 of file ssl_common.h.

◆ ack_write_buf

struct buffer key_state::ack_write_buf

◆ auth_deferred_expire

time_t key_state::auth_deferred_expire

◆ auth_token_state_flags

unsigned int key_state::auth_token_state_flags

The state of the auth-token sent from the client.

Definition at line 211 of file ssl_common.h.

Referenced by auth_token_test_env(), generate_auth_token(), and verify_user_pass().

◆ authenticated

◆ crypto_options

◆ dco_status

enum dco_key_status key_state::dco_status

Definition at line 271 of file ssl_common.h.

◆ established

time_t key_state::established

◆ initial

time_t key_state::initial

Definition at line 227 of file ssl_common.h.

Referenced by send_auth_pending_messages(), and session_move_pre_start().

◆ initial_opcode

int key_state::initial_opcode

Definition at line 233 of file ssl_common.h.

Referenced by key_state_init(), and session_move_pre_start().

◆ key_id

◆ key_src

◆ ks_ssl

◆ lru_acks

struct reliable_ack* key_state::lru_acks

◆ mda_key_id

unsigned int key_state::mda_key_id

◆ mda_status

enum auth_deferred_result key_state::mda_status

Definition at line 264 of file ssl_common.h.

Referenced by man_def_auth_test(), tls_authenticate_key(), and verify_user_pass().

◆ must_die

time_t key_state::must_die

Definition at line 230 of file ssl_common.h.

Referenced by key_state_soft_reset(), and lame_duck_must_die().

◆ must_negotiate

time_t key_state::must_negotiate

◆ n_bytes

◆ n_packets

counter_type key_state::n_packets

◆ paybuf

struct buffer_list* key_state::paybuf

Holds outgoing message for the control channel until ks->state reaches S_ACTIVE.

Definition at line 252 of file ssl_common.h.

Referenced by flush_payload_buffer(), key_state_free(), and tls_send_payload().

◆ peer_id

uint32_t key_state::peer_id

Key id for this key_state, inherited from struct tls_session.

See also
tls_multi::peer_id.

Definition at line 223 of file ssl_common.h.

◆ peer_last_packet

time_t key_state::peer_last_packet

Definition at line 231 of file ssl_common.h.

Referenced by send_push_request(), and tls_pre_decrypt().

◆ plaintext_read_buf

struct buffer key_state::plaintext_read_buf

◆ plaintext_write_buf

struct buffer key_state::plaintext_write_buf

Definition at line 242 of file ssl_common.h.

Referenced by key_state_free(), key_state_init(), and tls_process_state().

◆ plugin_auth

◆ rec_ack

◆ rec_reliable

◆ remote_addr

◆ script_auth

◆ send_reliable

◆ session_id_remote

◆ state


The documentation for this struct was generated from the following file: