diff --git a/components/wpa_supplicant/src/ap/ieee802_11.c b/components/wpa_supplicant/src/ap/ieee802_11.c index 7aee02ac93a..37b8952f9fe 100644 --- a/components/wpa_supplicant/src/ap/ieee802_11.c +++ b/components/wpa_supplicant/src/ap/ieee802_11.c @@ -25,6 +25,13 @@ #include "ap/wpa_auth_i.h" #define OWE_DH_GRP19 19 #define OWE_DHIE_LEN 37 +/* +OWE_DHIE_LEN = 1 byte {WLAN_EID_EXTENSION} + + 1 byte {len of DHIE (1(pub_key len) + 2(dh group) + 32(len of pub_key)) = 35)} + + 1 byte {pub_key len} + + 2 bytes {DH group} + + 32 bytes {public key} +*/ #endif #ifdef CONFIG_SAE @@ -841,7 +848,6 @@ uint16_t owe_process_assoc_req(struct hostapd_data *hapd, struct sta_info *sta, "OWE: Try to reuse own previous DH key since the STA tried to go through OWE association again"); } else { - crypto_ecdh_deinit(sta->owe_ecdh); sta->owe_ecdh = crypto_ecdh_init(OWE_DH_GRP19); if (!sta->owe_ecdh) { wpa_printf(MSG_ERROR, "OWE: Error initializing ECDH for STA"); diff --git a/docs/en/api-guides/wifi-security.rst b/docs/en/api-guides/wifi-security.rst index 81101ed1923..b9d0fe11037 100644 --- a/docs/en/api-guides/wifi-security.rst +++ b/docs/en/api-guides/wifi-security.rst @@ -157,10 +157,17 @@ Enhanced Open™ is used for providing security and privacy to users connecting .. note:: - {IDF_TARGET_NAME} supports Wi-Fi Enhanced Open™ only in station mode. + {IDF_TARGET_NAME} supports Wi-Fi Enhanced Open™ (OWE Transition Mode + OWE Only) in station mode and (OWE Only) in softap mode. Setting up OWE with {IDF_TARGET_NAME} ++++++++++++++++++++++++++++++++++++++ +For station mode : + A configuration option :ref:`CONFIG_ESP_WIFI_ENABLE_WPA3_OWE_STA` and configuration parameter :cpp:type:`owe_enabled` in :cpp:type:`wifi_sta_config_t` is provided to enable OWE support for the station. To use OWE transition mode, along with the configuration provided above, `authmode` from :cpp:type:`wifi_scan_threshold_t` should be set to ``WIFI_AUTH_OPEN``. + + +For softap mode : + +A configuration option :ref:`CONFIG_ESP_WIFI_ENABLE_WPA3_OWE_SOFTAP` from menuconfig and configuration parameter :cpp:type:`owe_enabled` in :cpp:type:`wifi_ap_config_t` should be enabled and configuration parameter `authmode` from :cpp:type:`wifi_ap_config_t` should be set to ``WIFI_AUTH_OWE``. diff --git a/examples/wifi/getting_started/softAP/main/softap_example_main.c b/examples/wifi/getting_started/softAP/main/softap_example_main.c index c2bca87431a..dc455357427 100644 --- a/examples/wifi/getting_started/softAP/main/softap_example_main.c +++ b/examples/wifi/getting_started/softAP/main/softap_example_main.c @@ -90,7 +90,8 @@ void wifi_init_softap(void) .gtk_rekey_interval = EXAMPLE_GTK_REKEY_INTERVAL, }, }; - if (strlen(EXAMPLE_ESP_WIFI_PASS) == 0) { + if (strlen(EXAMPLE_ESP_WIFI_PASS) == 0 && + (wifi_config.ap.authmode != WIFI_AUTH_OWE || !wifi_config.ap.owe_enabled)) { wifi_config.ap.authmode = WIFI_AUTH_OPEN; }