OWE: Define and parse OWE AKM selector

This adds a new RSN AKM "OWE".

Signed-off-by: Jouni Malinen <j@w1.fi>
This commit is contained in:
Jouni Malinen
2026-05-05 21:40:29 +05:30
committed by tarun.kumar
parent 92288a2d84
commit e83d0debf1
2 changed files with 30 additions and 1 deletions
@@ -48,7 +48,8 @@ static bool authmode_has_rsn(uint8_t authmode)
return (authmode == WIFI_AUTH_WPA2_PSK ||
authmode == WIFI_AUTH_WPA_WPA2_PSK ||
authmode == WIFI_AUTH_WPA3_PSK ||
authmode == WIFI_AUTH_WPA2_WPA3_PSK);
authmode == WIFI_AUTH_WPA2_WPA3_PSK ||
authmode == WIFI_AUTH_OWE);
}
void *hostap_init(void)
@@ -192,6 +193,13 @@ void *hostap_init(void)
#endif /* CONFIG_IEEE80211W */
esp_wifi_ap_set_group_mgmt_cipher_internal(cipher_type_map_supp_to_public(auth_conf->group_mgmt_cipher));
#ifdef CONFIG_OWE_SOFTAP
if (authmode == WIFI_AUTH_OWE) {
auth_conf->wpa_key_mgmt = WPA_KEY_MGMT_OWE;
}
#endif /* CONFIG_OWE_SOFTAP */
spp_attrubute = esp_wifi_get_spp_attrubute_internal(WIFI_IF_AP);
auth_conf->spp_sup.capable = ((spp_attrubute & WPA_CAPABILITY_SPP_CAPABLE) ? SPP_AMSDU_CAP_ENABLE : SPP_AMSDU_CAP_DISABLE);
auth_conf->spp_sup.require = ((spp_attrubute & WPA_CAPABILITY_SPP_REQUIRED) ? SPP_AMSDU_REQ_ENABLE : SPP_AMSDU_REQ_DISABLE);
@@ -234,6 +234,13 @@ static u8 * rsne_write_data(u8 *buf, size_t len, u8 *pos, int group,
num_suites++;
}
#endif /* CONFIG_SAE */
#ifdef CONFIG_OWE_SOFTAP
if (conf->wpa_key_mgmt & WPA_KEY_MGMT_OWE) {
RSN_SELECTOR_PUT(pos, RSN_AUTH_KEY_MGMT_OWE);
pos += RSN_SELECTOR_LEN;
num_suites++;
}
#endif /* CONFIG_OWE_SOFTAP */
#ifdef CONFIG_RSN_TESTING
if (rsn_testing) {
@@ -611,6 +618,10 @@ wpa_validate_wpa_ie(struct wpa_authenticator *wpa_auth,
selector = RSN_AUTH_KEY_MGMT_UNSPEC_802_1X;
else if (data.key_mgmt & WPA_KEY_MGMT_PSK)
selector = RSN_AUTH_KEY_MGMT_PSK_OVER_802_1X;
#ifdef CONFIG_OWE_SOFTAP
else if (data.key_mgmt & WPA_KEY_MGMT_OWE)
selector = RSN_AUTH_KEY_MGMT_OWE;
#endif /* CONFIG_OWE_SOFTAP */
selector = wpa_cipher_to_suite(WPA_PROTO_RSN,
data.pairwise_cipher);
@@ -692,6 +703,10 @@ wpa_validate_wpa_ie(struct wpa_authenticator *wpa_auth,
#endif /* CONFIG_SAE */
else if (key_mgmt & WPA_KEY_MGMT_IEEE8021X)
sm->wpa_key_mgmt = WPA_KEY_MGMT_IEEE8021X;
#ifdef CONFIG_OWE_SOFTAP
else if (key_mgmt & WPA_KEY_MGMT_OWE)
sm->wpa_key_mgmt = WPA_KEY_MGMT_OWE;
#endif /* CONFIG_OWE_SOFTAP */
else
sm->wpa_key_mgmt = WPA_KEY_MGMT_PSK;
@@ -810,6 +825,12 @@ wpa_validate_wpa_ie(struct wpa_authenticator *wpa_auth,
os_memcpy(wpa_auth->dot11RSNAPMKIDUsed, pmkid, PMKID_LEN);
}
#ifdef CONFIG_OWE_SOFTAP
if (sm->wpa_key_mgmt == WPA_KEY_MGMT_OWE && !sm->pmksa) {
wpa_printf(MSG_DEBUG, "No PMKSA cache entry found for OWE");
}
#endif /* CONFIG_OWE_SOFTAP */
#ifdef CONFIG_SAE
if ((sm->wpa_key_mgmt == WPA_KEY_MGMT_SAE || sm->wpa_key_mgmt == WPA_KEY_MGMT_SAE_EXT_KEY) && data.num_pmkid &&
!sm->pmksa) {