【问题标题】:How to load a strongswan plugin at runtime如何在运行时加载 strongswan 插件
【发布时间】:2020-04-15 17:02:39
【问题描述】:

我们为 libcharon 编写了一个插件,可以调用我们的代码。这在我们的应用程序和 strongswan 之间造成了一些不必要的耦合,因为我们正在使用这个插件编译 strongswan。

我们称这个插件为 MyPlugin。 配置如下:

$ cat /etc/strongswan/strongswan.d/charon/myplugin.conf
myplugin {

    # Whether to load the plugin. Can also be an integer to increase the
    # priority of this plugin.
    load = yes

    proxy
    {
        # Should send to proxy
          send_to_proxy = yes
    }
    log
    {
                # Should save to file
                  log_path = /var/log/myplugin.log
                  log_ips = yes
    }
}

我们希望通过将这个插件编译为我们应用程序的一部分来实现 strongswan 接口,从而扭转这种依赖关系。

问题是,strongswan 支持这个吗? 插件可以部署在 strongswan 已经运行的机器上,并让 strongswan 加载并使用它吗?怎么样?

我们在 CentOS 6 上运行 strongswan 5.1.5。

【问题讨论】:

    标签: linux plugins centos6 strongswan


    【解决方案1】:

    是的,您可以这样做。但是,有一些警告:

    • strongSwan 不提供任何稳定的 API。因此,只有在针对最终加载插件的 strongSwan 版本的标头编译插件时,这才能安全地工作。
    • 您将需要来自您正在编译的构建(或相同平台的等效配置构建)中的config.h。编译插件时,通过-include 将路径传递给它。
    • 通过 config sn-p 加载插件需要一个适当的 strongswan.conf 文件(即启用 modular plugin loading 并将配置 sn-ps 包含在 strongswan.d 中,您可以在其中为插件放置一个 sn-p - the default 应该工作正常)。
    • 第三方插件可能存在许可问题,无论是否为树外插件(strongSwan 已根据 GPLv2 获得许可,但有商业许可可用)。

    您可以找到树外插件here 的示例。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2020-12-14
      • 1970-01-01
      • 2019-01-13
      • 1970-01-01
      • 1970-01-01
      • 2017-06-24
      相关资源
      最近更新 更多