mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 03:00:34 +03:00
feat(roaming): ignore WPA2-only APs on transition disable
This commit introduces a new feature to the roaming logic. If the currently connected AP has the 'transition disable' bit set in its RSN IE, the roaming logic will now ignore any scanned APs that only support WPA2-PSK. This prevents a security downgrade when roaming in a mixed WPA2/WPA3 environment. A new Kconfig option, CONFIG_ESP_WIFI_IGNORE_WPA2_ONLY_ON_TRANSITION_DISABLE, has been added to control this feature. It is disabled by default.
This commit is contained in:
@@ -219,4 +219,13 @@ menu "Blacklist Configuration"
|
||||
default 5
|
||||
help
|
||||
Maximum number of roaming candidates to consider. This also defines the size of the blacklist.
|
||||
|
||||
config ESP_WIFI_ROAMING_PREVENT_DOWNGRADE
|
||||
bool "Prevent security downgrade when roaming"
|
||||
default n
|
||||
help
|
||||
If the currently connected AP sends a "transition disable" bit,
|
||||
this option will make the roaming logic ignore less secure APs.
|
||||
This helps prevent security downgrades when roaming in a mixed
|
||||
security environment (e.g., WPA2/WPA3).
|
||||
endmenu # "Blacklist Configuration"
|
||||
|
||||
@@ -605,8 +605,40 @@ static bool candidate_security_match(wifi_ap_record_t candidate)
|
||||
return false;
|
||||
}
|
||||
|
||||
#include "esp_wpas_glue.h"
|
||||
|
||||
static bool candidate_profile_match(wifi_ap_record_t candidate)
|
||||
{
|
||||
u8 transition_disable = wpa_supplicant_get_transition_disable();
|
||||
|
||||
#if CONFIG_ESP_WIFI_ROAMING_PREVENT_DOWNGRADE
|
||||
if (transition_disable & TRANSITION_DISABLE_WPA3_PERSONAL) {
|
||||
if (candidate.authmode == WIFI_AUTH_WPA2_PSK) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
if (transition_disable & TRANSITION_DISABLE_ENHANCED_OPEN) {
|
||||
if (candidate.authmode == WIFI_AUTH_OPEN) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
if (transition_disable & TRANSITION_DISABLE_WPA3_ENTERPRISE) {
|
||||
if (candidate.authmode == WIFI_AUTH_WPA2_ENTERPRISE) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
#if TODO // application doesn't have a way to know SAE-PK enabled AP atm
|
||||
if (transition_disable & TRANSITION_DISABLE_SAE_PK) {
|
||||
/* This is a simplification. A more accurate check would involve
|
||||
* parsing the candidate's RSN IE to see if it supports SAE-PK.
|
||||
* For now, we reject all SAE APs if SAE-PK is enforced. */
|
||||
if (candidate.authmode == WIFI_AUTH_WPA3_PSK) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
#endif
|
||||
#endif
|
||||
|
||||
return candidate_security_match(candidate);
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user