From c8b6ff88de72d4106dde0778f862ba2874b7a511 Mon Sep 17 00:00:00 2001 From: Jouni Malinen Date: Sun, 8 Oct 2017 13:49:45 +0300 Subject: [PATCH] OWE: Include RSNE in (Re)Association Response frame This is not normally done in RSN, but RFC 8110 seems to imply that AP has to include OWE AKM in the RSNE within these frames. So, add the RSNE to (Re)Association Response frames when OWE is being negotiated. Signed-off-by: Jouni Malinen --- .../esp_supplicant/src/esp_hostap.c | 33 +++++++++++++------ components/wpa_supplicant/src/ap/wpa_auth.h | 2 ++ .../wpa_supplicant/src/ap/wpa_auth_ie.c | 14 ++++++++ 3 files changed, 39 insertions(+), 10 deletions(-) diff --git a/components/wpa_supplicant/esp_supplicant/src/esp_hostap.c b/components/wpa_supplicant/esp_supplicant/src/esp_hostap.c index 3ce012b32a3..1f3ebd9e617 100644 --- a/components/wpa_supplicant/esp_supplicant/src/esp_hostap.c +++ b/components/wpa_supplicant/esp_supplicant/src/esp_hostap.c @@ -385,7 +385,8 @@ u16 esp_send_assoc_resp(struct hostapd_data *hapd, const u8 *addr, send_len = esp_wifi_build_rsnxe(hapd, buf, ASSOC_RESP_LENGTH); } #ifdef CONFIG_OWE_SOFTAP -#define OWE_DH_GROUP 19 +#define OWE_DH_GROUP 19 +#define OWE_DHIE_LEN 37 if ((hapd->conf->wpa_key_mgmt & WPA_KEY_MGMT_OWE)) { struct wpabuf *pub; struct sta_info *sta = ap_get_sta(hapd, addr); @@ -393,22 +394,35 @@ u16 esp_send_assoc_resp(struct hostapd_data *hapd, const u8 *addr, return WLAN_STATUS_UNSPECIFIED_FAILURE; } + struct wpabuf *owe_buf = wpabuf_alloc(hapd->wpa_auth->wpa_ie_len); + if (!owe_buf) { + wpa_printf(MSG_ERROR, "Memory allocation failed for OWE IE"); + return WLAN_STATUS_UNSPECIFIED_FAILURE; + } + + u8 *pos, buf[128]; + int res; + int owe_ie_len = 0; + + pos = buf; + + pos = wpa_auth_write_assoc_resp_owe(sta->wpa_sm, pos, + buf + sizeof(buf) - pos); + + wpabuf_resize(&owe_buf, pos - buf); + wpabuf_put_data(owe_buf, buf, pos - buf); + owe_ie_len = pos - buf; + pub = crypto_ecdh_get_pubkey(sta->owe_ecdh, 0); if (!pub) { res = WLAN_STATUS_UNSPECIFIED_FAILURE; return res; } - struct wpabuf *owe_buf = wpabuf_alloc(37); - if (!owe_buf) { - wpa_printf(MSG_ERROR, "Memory allocation failed for OWE IE"); - return WLAN_STATUS_UNSPECIFIED_FAILURE; - } - wpa_hexdump_buf(MSG_DEBUG, "Own public key", pub); - // wpabuf_resize(&owe_buf, OWE_DHIE_LEN); + wpabuf_resize(&owe_buf, OWE_DHIE_LEN); wpabuf_put_u8(owe_buf, WLAN_EID_EXTENSION); wpabuf_put_u8(owe_buf, 1 + 2 + wpabuf_len(pub)); wpabuf_put_u8(owe_buf, WLAN_EID_EXT_OWE_DH_PARAM); @@ -417,7 +431,7 @@ u16 esp_send_assoc_resp(struct hostapd_data *hapd, const u8 *addr, wpabuf_free(pub); wpa_hexdump_buf(MSG_DEBUG, "OWE: Buffer", owe_buf); - int owe_ie_len = wpabuf_len(owe_buf); + owe_ie_len = wpabuf_len(owe_buf); esp_wifi_set_appie_internal(WIFI_APPIE_ASSOC_RESP, (uint8_t *)wpabuf_head(owe_buf), owe_ie_len, 0); } @@ -528,7 +542,6 @@ bool hostap_new_assoc_sta(struct sta_info *sta, uint8_t *bssid, u8 *wpa_ie, } #endif /* CONFIG_OWE_SOFTAP */ - send_resp: if (!rsnxe) { omit_rsnxe = true; diff --git a/components/wpa_supplicant/src/ap/wpa_auth.h b/components/wpa_supplicant/src/ap/wpa_auth.h index 34ae7bc54df..1f8abe71300 100644 --- a/components/wpa_supplicant/src/ap/wpa_auth.h +++ b/components/wpa_supplicant/src/ap/wpa_auth.h @@ -327,5 +327,7 @@ static inline bool wpa_auth_pmf_enabled(struct wpa_auth_config *conf) return conf->ieee80211w != NO_MGMT_FRAME_PROTECTION; #endif } +u8 * wpa_auth_write_assoc_resp_owe(struct wpa_state_machine *sm, + u8 *pos, size_t max_len); #endif /* WPA_AUTH_H */ diff --git a/components/wpa_supplicant/src/ap/wpa_auth_ie.c b/components/wpa_supplicant/src/ap/wpa_auth_ie.c index 79a836443f5..0727191b41a 100644 --- a/components/wpa_supplicant/src/ap/wpa_auth_ie.c +++ b/components/wpa_supplicant/src/ap/wpa_auth_ie.c @@ -868,3 +868,17 @@ int wpa_auth_uses_mfp(struct wpa_state_machine *sm) { return sm ? sm->mgmt_frame_prot : 0; } + + +#ifdef CONFIG_OWE_SOFTAP +u8 * wpa_auth_write_assoc_resp_owe(struct wpa_state_machine *sm, + u8 *pos, size_t max_len) +{ + int res; + + res = wpa_write_rsn_ie(&sm->wpa_auth->conf, pos, max_len, NULL); + if (res < 0) + return pos; + return pos + res; +} +#endif /* CONFIG_OWE_SOFTAP */