Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 1 | /* |
| 2 | * Copyright 2018-present Open Networking Foundation |
| 3 | * |
| 4 | * Licensed under the Apache License, Version 2.0 (the "License"); |
| 5 | * you may not use this file except in compliance with the License. |
| 6 | * You may obtain a copy of the License at |
| 7 | * |
| 8 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 9 | * |
| 10 | * Unless required by applicable law or agreed to in writing, software |
| 11 | * distributed under the License is distributed on an "AS IS" BASIS, |
| 12 | * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 13 | * See the License for the specific language governing permissions and |
| 14 | * limitations under the License. |
| 15 | */ |
| 16 | |
| 17 | package org.opencord.kafka.integrations; |
Shubham Sharma | 9188dde | 2019-06-20 07:16:08 +0000 | [diff] [blame] | 18 | import java.time.Instant; |
| 19 | |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 20 | import org.apache.felix.scr.annotations.Activate; |
| 21 | import org.apache.felix.scr.annotations.Component; |
| 22 | import org.apache.felix.scr.annotations.Deactivate; |
| 23 | import org.apache.felix.scr.annotations.Reference; |
| 24 | import org.apache.felix.scr.annotations.ReferenceCardinality; |
Matteo Scandolo | d50a4d3 | 2019-04-24 12:10:21 -0700 | [diff] [blame] | 25 | import org.apache.felix.scr.annotations.ReferencePolicy; |
Matteo Scandolo | 580fb7f | 2019-04-17 15:33:15 -0700 | [diff] [blame] | 26 | import org.onosproject.net.AnnotationKeys; |
| 27 | import org.onosproject.net.device.DeviceService; |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 28 | import org.opencord.aaa.AuthenticationEvent; |
| 29 | import org.opencord.aaa.AuthenticationEventListener; |
| 30 | import org.opencord.aaa.AuthenticationService; |
kartikey dubey | 6e90309 | 2019-05-22 13:35:28 +0000 | [diff] [blame] | 31 | import org.opencord.aaa.AuthenticationStatisticsEvent; |
| 32 | import org.opencord.aaa.AuthenticationStatisticsEventListener; |
| 33 | import org.opencord.aaa.AuthenticationStatisticsService; |
Shubham Sharma | 9188dde | 2019-06-20 07:16:08 +0000 | [diff] [blame] | 34 | import org.opencord.kafka.EventBusService; |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 35 | import org.slf4j.Logger; |
| 36 | import org.slf4j.LoggerFactory; |
| 37 | |
Shubham Sharma | 9188dde | 2019-06-20 07:16:08 +0000 | [diff] [blame] | 38 | import com.fasterxml.jackson.databind.JsonNode; |
| 39 | import com.fasterxml.jackson.databind.ObjectMapper; |
| 40 | import com.fasterxml.jackson.databind.node.ObjectNode; |
Jonathan Hart | 2aad779 | 2018-07-31 15:09:17 -0400 | [diff] [blame] | 41 | |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 42 | /** |
| 43 | * Listens for AAA events and pushes them on a Kafka bus. |
| 44 | */ |
| 45 | @Component(immediate = true) |
| 46 | public class AaaKafkaIntegration { |
| 47 | |
| 48 | public Logger log = LoggerFactory.getLogger(getClass()); |
| 49 | |
| 50 | @Reference(cardinality = ReferenceCardinality.MANDATORY_UNARY) |
| 51 | protected EventBusService eventBusService; |
| 52 | |
Matteo Scandolo | 580fb7f | 2019-04-17 15:33:15 -0700 | [diff] [blame] | 53 | @Reference(cardinality = ReferenceCardinality.MANDATORY_UNARY) |
| 54 | protected DeviceService deviceService; |
| 55 | |
Matteo Scandolo | 03f13c1 | 2019-03-20 14:38:12 -0700 | [diff] [blame] | 56 | @Reference(cardinality = ReferenceCardinality.OPTIONAL_UNARY, |
Matteo Scandolo | d50a4d3 | 2019-04-24 12:10:21 -0700 | [diff] [blame] | 57 | policy = ReferencePolicy.DYNAMIC, |
Matteo Scandolo | 03f13c1 | 2019-03-20 14:38:12 -0700 | [diff] [blame] | 58 | bind = "bindAuthenticationService", |
| 59 | unbind = "unbindAuthenticationService") |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 60 | protected AuthenticationService authenticationService; |
kartikey dubey | 6e90309 | 2019-05-22 13:35:28 +0000 | [diff] [blame] | 61 | @Reference(cardinality = ReferenceCardinality.OPTIONAL_UNARY, |
| 62 | policy = ReferencePolicy.DYNAMIC, |
| 63 | bind = "bindAuthenticationStatService", |
| 64 | unbind = "unbindAuthenticationStatService") |
| 65 | protected AuthenticationStatisticsService authenticationStatisticsService; |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 66 | |
| 67 | private final AuthenticationEventListener listener = new InternalAuthenticationListener(); |
kartikey dubey | 6e90309 | 2019-05-22 13:35:28 +0000 | [diff] [blame] | 68 | private final AuthenticationStatisticsEventListener authenticationStatisticsEventListener = |
Shubham Sharma | 9188dde | 2019-06-20 07:16:08 +0000 | [diff] [blame] | 69 | new InternalAuthenticationStatisticsListner(); |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 70 | |
kartikey dubey | 6e90309 | 2019-05-22 13:35:28 +0000 | [diff] [blame] | 71 | // topics |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 72 | private static final String TOPIC = "authentication.events"; |
kartikey dubey | 6e90309 | 2019-05-22 13:35:28 +0000 | [diff] [blame] | 73 | private static final String AUTHENTICATION_STATISTICS_TOPIC = "onos.aaa.stats.kpis"; |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 74 | |
kartikey dubey | 6e90309 | 2019-05-22 13:35:28 +0000 | [diff] [blame] | 75 | // auth event params |
Jonathan Hart | 2aad779 | 2018-07-31 15:09:17 -0400 | [diff] [blame] | 76 | private static final String TIMESTAMP = "timestamp"; |
Jonathan Hart | f54e5ba | 2018-07-31 14:57:22 -0400 | [diff] [blame] | 77 | private static final String DEVICE_ID = "deviceId"; |
| 78 | private static final String PORT_NUMBER = "portNumber"; |
Matteo Scandolo | 580fb7f | 2019-04-17 15:33:15 -0700 | [diff] [blame] | 79 | private static final String SERIAL_NUMBER = "serialNumber"; |
Jonathan Hart | f54e5ba | 2018-07-31 14:57:22 -0400 | [diff] [blame] | 80 | private static final String AUTHENTICATION_STATE = "authenticationState"; |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 81 | |
kartikey dubey | 6e90309 | 2019-05-22 13:35:28 +0000 | [diff] [blame] | 82 | // auth stats event params |
| 83 | private static final String ACCEPT_RESPONSES_RX = "acceptResponsesRx"; |
| 84 | private static final String REJECT_RESPONSES_RX = "rejectResponsesRx"; |
| 85 | private static final String CHALLENGE_RESPONSES_RX = "challengeResponsesRx"; |
| 86 | private static final String ACCESS_REQUESTS_TX = "accessRequestsTx"; |
| 87 | private static final String INVALID_VALIDATORS_RX = "invalidValidatorsRx"; |
| 88 | private static final String UNKNOWN_TYPE_RX = "unknownTypeRx"; |
| 89 | private static final String PENDING_REQUESTS = "pendingRequests"; |
| 90 | private static final String DROPPED_RESPONSES_RX = "droppedResponsesRx"; |
| 91 | private static final String MALFORMED_RESPONSES_RX = "malformedResponsesRx"; |
| 92 | private static final String UNKNOWN_SERVER_RX = "unknownServerRx"; |
| 93 | private static final String REQUEST_RTT_MILLIS = "requestRttMillis"; |
| 94 | private static final String REQUEST_RE_TX = "requestReTx"; |
Shubham Sharma | 9188dde | 2019-06-20 07:16:08 +0000 | [diff] [blame] | 95 | private static final String TIMED_OUT_PACKETS = "timedOutPackets"; |
Shubham Sharma | 0357efb | 2019-08-09 06:54:22 +0000 | [diff] [blame] | 96 | private static final String EAPOL_LOGOFF_RX = "eapolLogoffRx"; |
| 97 | private static final String EAPOL_RES_IDENTITY_MSG_TRANS = "eapolResIdentityMsgTrans"; |
| 98 | private static final String EAPOL_AUTH_SUCCESS_TRANS = "eapolAuthSuccessTrans"; |
| 99 | private static final String EAPOL_AUTH_FAILURE_TRANS = "eapolAuthFailureTrans"; |
| 100 | private static final String EAPOL_START_REQ_TRANS = "eapolStartReqTrans"; |
| 101 | private static final String EAP_PKT_TX_AUTH_CHOOSE_EAP = "eapPktTxauthChooseEap"; |
| 102 | private static final String EAPOL_TRANS_RESP_NOT_NAK = "eapolTransRespNotNak"; |
Shubham Sharma | abe0a26 | 2019-09-16 10:07:02 +0000 | [diff] [blame^] | 103 | private static final String EAPOL_FRAMES_TX = "eapolFramesTx"; |
| 104 | private static final String AUTH_STATE_IDLE = "authStateIdle"; |
| 105 | private static final String REQUEST_ID_FRAMES_TX = "requestIdFramesTx"; |
| 106 | private static final String REQUEST_EAP_FRAMES_TX = "requestEapFramesTx"; |
| 107 | private static final String INVALID_PKT_TYPE = "invalidPktType"; |
| 108 | private static final String INVALID_BODY_LENGTH = "invalidBodyLength"; |
| 109 | private static final String VALID_EAPOL_FRAMES_RX = "validEapolFramesRx"; |
| 110 | private static final String PENDING_RES_SUPPLICANT = "pendingResSupplicant"; |
| 111 | private static final String RES_ID_EAP_FRAMES_RX = "resIdEapFramesRx"; |
kartikey dubey | 6e90309 | 2019-05-22 13:35:28 +0000 | [diff] [blame] | 112 | |
Matteo Scandolo | 03f13c1 | 2019-03-20 14:38:12 -0700 | [diff] [blame] | 113 | protected void bindAuthenticationService(AuthenticationService authenticationService) { |
Matteo Scandolo | d50a4d3 | 2019-04-24 12:10:21 -0700 | [diff] [blame] | 114 | log.info("bindAuthenticationService"); |
Matteo Scandolo | 03f13c1 | 2019-03-20 14:38:12 -0700 | [diff] [blame] | 115 | if (this.authenticationService == null) { |
| 116 | log.info("Binding AuthenticationService"); |
| 117 | this.authenticationService = authenticationService; |
| 118 | log.info("Adding listener on AuthenticationService"); |
| 119 | authenticationService.addListener(listener); |
| 120 | } else { |
| 121 | log.warn("Trying to bind AuthenticationService but it is already bound"); |
| 122 | } |
| 123 | } |
| 124 | |
| 125 | protected void unbindAuthenticationService(AuthenticationService authenticationService) { |
Matteo Scandolo | d50a4d3 | 2019-04-24 12:10:21 -0700 | [diff] [blame] | 126 | log.info("unbindAuthenticationService"); |
Matteo Scandolo | 03f13c1 | 2019-03-20 14:38:12 -0700 | [diff] [blame] | 127 | if (this.authenticationService == authenticationService) { |
| 128 | log.info("Unbinding AuthenticationService"); |
| 129 | this.authenticationService = null; |
| 130 | log.info("Removing listener on AuthenticationService"); |
| 131 | authenticationService.removeListener(listener); |
| 132 | } else { |
| 133 | log.warn("Trying to unbind AuthenticationService but it is already unbound"); |
| 134 | } |
| 135 | } |
| 136 | |
kartikey dubey | 6e90309 | 2019-05-22 13:35:28 +0000 | [diff] [blame] | 137 | protected void bindAuthenticationStatService(AuthenticationStatisticsService authenticationStatisticsService) { |
| 138 | log.info("bindAuthenticationStatService"); |
| 139 | if (this.authenticationStatisticsService == null) { |
| 140 | log.info("Binding AuthenticationStastService"); |
| 141 | this.authenticationStatisticsService = authenticationStatisticsService; |
| 142 | log.info("Adding listener on AuthenticationStatService"); |
| 143 | authenticationStatisticsService.addListener(authenticationStatisticsEventListener); |
| 144 | } else { |
| 145 | log.warn("Trying to bind AuthenticationStatService but it is already bound"); |
| 146 | } |
| 147 | } |
| 148 | |
| 149 | protected void unbindAuthenticationStatService(AuthenticationStatisticsService authenticationStatisticsService) { |
| 150 | log.info("unbindAuthenticationStatService"); |
| 151 | if (this.authenticationStatisticsService == authenticationStatisticsService) { |
| 152 | log.info("Unbinding AuthenticationStatService"); |
| 153 | this.authenticationStatisticsService = null; |
| 154 | log.info("Removing listener on AuthenticationStatService"); |
| 155 | authenticationStatisticsService.removeListener(authenticationStatisticsEventListener); |
| 156 | } else { |
| 157 | log.warn("Trying to unbind AuthenticationStatService but it is already unbound"); |
| 158 | } |
| 159 | } |
| 160 | |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 161 | @Activate |
| 162 | public void activate() { |
Matteo Scandolo | d50a4d3 | 2019-04-24 12:10:21 -0700 | [diff] [blame] | 163 | log.info("Started AaaKafkaIntegration"); |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 164 | } |
| 165 | |
| 166 | @Deactivate |
| 167 | public void deactivate() { |
Matteo Scandolo | d50a4d3 | 2019-04-24 12:10:21 -0700 | [diff] [blame] | 168 | log.info("Stopped AaaKafkaIntegration"); |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 169 | } |
| 170 | |
| 171 | private void handle(AuthenticationEvent event) { |
| 172 | eventBusService.send(TOPIC, serialize(event)); |
| 173 | } |
| 174 | |
kartikey dubey | 6e90309 | 2019-05-22 13:35:28 +0000 | [diff] [blame] | 175 | private void handleStat(AuthenticationStatisticsEvent event) { |
| 176 | eventBusService.send(AUTHENTICATION_STATISTICS_TOPIC, serializeStat(event)); |
Matteo Scandolo | eba419b | 2019-11-25 10:42:04 -0700 | [diff] [blame] | 177 | log.trace("AuthenticationStatisticsEvent sent successfully"); |
kartikey dubey | 6e90309 | 2019-05-22 13:35:28 +0000 | [diff] [blame] | 178 | } |
Matteo Scandolo | 580fb7f | 2019-04-17 15:33:15 -0700 | [diff] [blame] | 179 | |
kartikey dubey | 6e90309 | 2019-05-22 13:35:28 +0000 | [diff] [blame] | 180 | private JsonNode serialize(AuthenticationEvent event) { |
Matteo Scandolo | 580fb7f | 2019-04-17 15:33:15 -0700 | [diff] [blame] | 181 | String sn = deviceService.getPort(event.subject()).annotations().value(AnnotationKeys.PORT_NAME); |
| 182 | |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 183 | ObjectMapper mapper = new ObjectMapper(); |
| 184 | ObjectNode authEvent = mapper.createObjectNode(); |
Jonathan Hart | 2aad779 | 2018-07-31 15:09:17 -0400 | [diff] [blame] | 185 | authEvent.put(TIMESTAMP, Instant.now().toString()); |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 186 | authEvent.put(DEVICE_ID, event.subject().deviceId().toString()); |
| 187 | authEvent.put(PORT_NUMBER, event.subject().port().toString()); |
Matteo Scandolo | 580fb7f | 2019-04-17 15:33:15 -0700 | [diff] [blame] | 188 | authEvent.put(SERIAL_NUMBER, sn); |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 189 | authEvent.put(AUTHENTICATION_STATE, event.type().toString()); |
| 190 | return authEvent; |
| 191 | } |
| 192 | |
kartikey dubey | 6e90309 | 2019-05-22 13:35:28 +0000 | [diff] [blame] | 193 | private JsonNode serializeStat(AuthenticationStatisticsEvent event) { |
Matteo Scandolo | eba419b | 2019-11-25 10:42:04 -0700 | [diff] [blame] | 194 | log.trace("Serializing AuthenticationStatisticsEvent"); |
kartikey dubey | 6e90309 | 2019-05-22 13:35:28 +0000 | [diff] [blame] | 195 | ObjectMapper mapper = new ObjectMapper(); |
| 196 | ObjectNode authMetricsEvent = mapper.createObjectNode(); |
| 197 | authMetricsEvent.put(TIMESTAMP, Instant.now().toString()); |
| 198 | authMetricsEvent.put(ACCEPT_RESPONSES_RX, event.subject().getAcceptResponsesRx()); |
| 199 | authMetricsEvent.put(REJECT_RESPONSES_RX, event.subject().getRejectResponsesRx()); |
| 200 | authMetricsEvent.put(CHALLENGE_RESPONSES_RX, event.subject().getChallengeResponsesRx()); |
| 201 | authMetricsEvent.put(ACCESS_REQUESTS_TX, event.subject().getAccessRequestsTx()); |
| 202 | authMetricsEvent.put(INVALID_VALIDATORS_RX, event.subject().getInvalidValidatorsRx()); |
| 203 | authMetricsEvent.put(UNKNOWN_TYPE_RX, event.subject().getUnknownTypeRx()); |
| 204 | authMetricsEvent.put(PENDING_REQUESTS, event.subject().getPendingRequests()); |
| 205 | authMetricsEvent.put(DROPPED_RESPONSES_RX, event.subject().getDroppedResponsesRx()); |
| 206 | authMetricsEvent.put(MALFORMED_RESPONSES_RX, event.subject().getMalformedResponsesRx()); |
| 207 | authMetricsEvent.put(UNKNOWN_SERVER_RX, event.subject().getUnknownServerRx()); |
| 208 | authMetricsEvent.put(REQUEST_RTT_MILLIS, event.subject().getRequestRttMilis()); |
| 209 | authMetricsEvent.put(REQUEST_RE_TX, event.subject().getRequestReTx()); |
Shubham Sharma | 9188dde | 2019-06-20 07:16:08 +0000 | [diff] [blame] | 210 | authMetricsEvent.put(TIMED_OUT_PACKETS, event.subject().getTimedOutPackets()); |
Shubham Sharma | 0357efb | 2019-08-09 06:54:22 +0000 | [diff] [blame] | 211 | authMetricsEvent.put(EAPOL_LOGOFF_RX, event.subject().getEapolLogoffRx()); |
| 212 | authMetricsEvent.put(EAPOL_RES_IDENTITY_MSG_TRANS, event.subject().getEapolResIdentityMsgTrans()); |
| 213 | authMetricsEvent.put(EAPOL_AUTH_SUCCESS_TRANS, event.subject().getEapolAuthSuccessTrans()); |
| 214 | authMetricsEvent.put(EAPOL_AUTH_FAILURE_TRANS, event.subject().getEapolAuthFailureTrans()); |
| 215 | authMetricsEvent.put(EAPOL_START_REQ_TRANS, event.subject().getEapolStartReqTrans()); |
| 216 | authMetricsEvent.put(EAP_PKT_TX_AUTH_CHOOSE_EAP, event.subject().getEapPktTxauthChooseEap()); |
| 217 | authMetricsEvent.put(EAPOL_TRANS_RESP_NOT_NAK, event.subject().getEapolTransRespNotNak()); |
Shubham Sharma | abe0a26 | 2019-09-16 10:07:02 +0000 | [diff] [blame^] | 218 | authMetricsEvent.put(EAPOL_FRAMES_TX, event.subject().getEapolFramesTx()); |
| 219 | authMetricsEvent.put(AUTH_STATE_IDLE, event.subject().getAuthStateIdle()); |
| 220 | authMetricsEvent.put(REQUEST_ID_FRAMES_TX, event.subject().getRequestIdFramesTx()); |
| 221 | authMetricsEvent.put(REQUEST_EAP_FRAMES_TX, event.subject().getReqEapFramesTx()); |
| 222 | authMetricsEvent.put(INVALID_PKT_TYPE, event.subject().getInvalidPktType()); |
| 223 | authMetricsEvent.put(INVALID_BODY_LENGTH, event.subject().getInvalidBodyLength()); |
| 224 | authMetricsEvent.put(VALID_EAPOL_FRAMES_RX, event.subject().getValidEapolFramesRx()); |
| 225 | authMetricsEvent.put(PENDING_RES_SUPPLICANT, event.subject().getPendingResSupp()); |
| 226 | authMetricsEvent.put(RES_ID_EAP_FRAMES_RX, event.subject().getEapolattrIdentity()); |
kartikey dubey | 6e90309 | 2019-05-22 13:35:28 +0000 | [diff] [blame] | 227 | return authMetricsEvent; |
| 228 | } |
| 229 | |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 230 | private class InternalAuthenticationListener implements |
Shubham Sharma | 9188dde | 2019-06-20 07:16:08 +0000 | [diff] [blame] | 231 | AuthenticationEventListener { |
Jonathan Hart | 501f788 | 2018-07-24 14:39:57 -0700 | [diff] [blame] | 232 | @Override |
| 233 | public void event(AuthenticationEvent authenticationEvent) { |
| 234 | handle(authenticationEvent); |
| 235 | } |
| 236 | } |
kartikey dubey | 6e90309 | 2019-05-22 13:35:28 +0000 | [diff] [blame] | 237 | |
| 238 | private class InternalAuthenticationStatisticsListner implements |
| 239 | AuthenticationStatisticsEventListener { |
| 240 | @Override |
| 241 | public void event(AuthenticationStatisticsEvent authenticationStatisticsEvent) { |
| 242 | handleStat(authenticationStatisticsEvent); |
| 243 | } |
| 244 | } |
Shubham Sharma | abe0a26 | 2019-09-16 10:07:02 +0000 | [diff] [blame^] | 245 | } |