wpas_kay.c 8.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380
  1. /*
  2. * IEEE 802.1X-2010 KaY Interface
  3. * Copyright (c) 2013-2014, Qualcomm Atheros, Inc.
  4. *
  5. * This software may be distributed under the terms of the BSD license.
  6. * See README for more details.
  7. */
  8. #include <openssl/ssl.h>
  9. #include "utils/includes.h"
  10. #include "utils/common.h"
  11. #include "eap_peer/eap.h"
  12. #include "eap_peer/eap_i.h"
  13. #include "eapol_supp/eapol_supp_sm.h"
  14. #include "pae/ieee802_1x_key.h"
  15. #include "pae/ieee802_1x_kay.h"
  16. #include "wpa_supplicant_i.h"
  17. #include "config.h"
  18. #include "config_ssid.h"
  19. #include "driver_i.h"
  20. #include "wpas_kay.h"
  21. #define DEFAULT_KEY_LEN 16
  22. /* secure Connectivity Association Key Name (CKN) */
  23. #define DEFAULT_CKN_LEN 16
  24. static int wpas_macsec_init(void *priv, struct macsec_init_params *params)
  25. {
  26. return wpa_drv_macsec_init(priv, params);
  27. }
  28. static int wpas_macsec_deinit(void *priv)
  29. {
  30. return wpa_drv_macsec_deinit(priv);
  31. }
  32. static int wpas_enable_protect_frames(void *wpa_s, Boolean enabled)
  33. {
  34. return wpa_drv_enable_protect_frames(wpa_s, enabled);
  35. }
  36. static int wpas_set_replay_protect(void *wpa_s, Boolean enabled, u32 window)
  37. {
  38. return wpa_drv_set_replay_protect(wpa_s, enabled, window);
  39. }
  40. static int wpas_set_current_cipher_suite(void *wpa_s, const u8 *cs,
  41. size_t cs_len)
  42. {
  43. return wpa_drv_set_current_cipher_suite(wpa_s, cs, cs_len);
  44. }
  45. static int wpas_enable_controlled_port(void *wpa_s, Boolean enabled)
  46. {
  47. return wpa_drv_enable_controlled_port(wpa_s, enabled);
  48. }
  49. static int wpas_get_receive_lowest_pn(void *wpa_s, u32 channel,
  50. u8 an, u32 *lowest_pn)
  51. {
  52. return wpa_drv_get_receive_lowest_pn(wpa_s, channel, an, lowest_pn);
  53. }
  54. static int wpas_get_transmit_next_pn(void *wpa_s, u32 channel,
  55. u8 an, u32 *next_pn)
  56. {
  57. return wpa_drv_get_transmit_next_pn(wpa_s, channel, an, next_pn);
  58. }
  59. static int wpas_set_transmit_next_pn(void *wpa_s, u32 channel,
  60. u8 an, u32 next_pn)
  61. {
  62. return wpa_drv_set_transmit_next_pn(wpa_s, channel, an, next_pn);
  63. }
  64. static int wpas_get_available_receive_sc(void *wpa_s, u32 *channel)
  65. {
  66. return wpa_drv_get_available_receive_sc(wpa_s, channel);
  67. }
  68. static unsigned int conf_offset_val(enum confidentiality_offset co)
  69. {
  70. switch (co) {
  71. case CONFIDENTIALITY_OFFSET_30:
  72. return 30;
  73. break;
  74. case CONFIDENTIALITY_OFFSET_50:
  75. return 50;
  76. default:
  77. return 0;
  78. }
  79. }
  80. static int wpas_create_receive_sc(void *wpa_s, u32 channel,
  81. struct ieee802_1x_mka_sci *sci,
  82. enum validate_frames vf,
  83. enum confidentiality_offset co)
  84. {
  85. return wpa_drv_create_receive_sc(wpa_s, channel, sci->addr,
  86. be_to_host16(sci->port),
  87. conf_offset_val(co), vf);
  88. }
  89. static int wpas_delete_receive_sc(void *wpa_s, u32 channel)
  90. {
  91. return wpa_drv_delete_receive_sc(wpa_s, channel);
  92. }
  93. static int wpas_create_receive_sa(void *wpa_s, u32 channel, u8 an,
  94. u32 lowest_pn, const u8 *sak)
  95. {
  96. return wpa_drv_create_receive_sa(wpa_s, channel, an, lowest_pn, sak);
  97. }
  98. static int wpas_enable_receive_sa(void *wpa_s, u32 channel, u8 an)
  99. {
  100. return wpa_drv_enable_receive_sa(wpa_s, channel, an);
  101. }
  102. static int wpas_disable_receive_sa(void *wpa_s, u32 channel, u8 an)
  103. {
  104. return wpa_drv_disable_receive_sa(wpa_s, channel, an);
  105. }
  106. static int wpas_get_available_transmit_sc(void *wpa_s, u32 *channel)
  107. {
  108. return wpa_drv_get_available_transmit_sc(wpa_s, channel);
  109. }
  110. static int
  111. wpas_create_transmit_sc(void *wpa_s, u32 channel,
  112. const struct ieee802_1x_mka_sci *sci,
  113. enum confidentiality_offset co)
  114. {
  115. return wpa_drv_create_transmit_sc(wpa_s, channel, sci->addr,
  116. be_to_host16(sci->port),
  117. conf_offset_val(co));
  118. }
  119. static int wpas_delete_transmit_sc(void *wpa_s, u32 channel)
  120. {
  121. return wpa_drv_delete_transmit_sc(wpa_s, channel);
  122. }
  123. static int wpas_create_transmit_sa(void *wpa_s, u32 channel, u8 an,
  124. u32 next_pn, Boolean confidentiality,
  125. const u8 *sak)
  126. {
  127. return wpa_drv_create_transmit_sa(wpa_s, channel, an, next_pn,
  128. confidentiality, sak);
  129. }
  130. static int wpas_enable_transmit_sa(void *wpa_s, u32 channel, u8 an)
  131. {
  132. return wpa_drv_enable_transmit_sa(wpa_s, channel, an);
  133. }
  134. static int wpas_disable_transmit_sa(void *wpa_s, u32 channel, u8 an)
  135. {
  136. return wpa_drv_disable_transmit_sa(wpa_s, channel, an);
  137. }
  138. int ieee802_1x_alloc_kay_sm(struct wpa_supplicant *wpa_s, struct wpa_ssid *ssid)
  139. {
  140. struct ieee802_1x_kay_ctx *kay_ctx;
  141. struct ieee802_1x_kay *res = NULL;
  142. enum macsec_policy policy;
  143. ieee802_1x_dealloc_kay_sm(wpa_s);
  144. if (!ssid || ssid->macsec_policy == 0)
  145. return 0;
  146. policy = ssid->macsec_policy == 1 ? SHOULD_SECURE : DO_NOT_SECURE;
  147. kay_ctx = os_zalloc(sizeof(*kay_ctx));
  148. if (!kay_ctx)
  149. return -1;
  150. kay_ctx->ctx = wpa_s;
  151. kay_ctx->macsec_init = wpas_macsec_init;
  152. kay_ctx->macsec_deinit = wpas_macsec_deinit;
  153. kay_ctx->enable_protect_frames = wpas_enable_protect_frames;
  154. kay_ctx->set_replay_protect = wpas_set_replay_protect;
  155. kay_ctx->set_current_cipher_suite = wpas_set_current_cipher_suite;
  156. kay_ctx->enable_controlled_port = wpas_enable_controlled_port;
  157. kay_ctx->get_receive_lowest_pn = wpas_get_receive_lowest_pn;
  158. kay_ctx->get_transmit_next_pn = wpas_get_transmit_next_pn;
  159. kay_ctx->set_transmit_next_pn = wpas_set_transmit_next_pn;
  160. kay_ctx->get_available_receive_sc = wpas_get_available_receive_sc;
  161. kay_ctx->create_receive_sc = wpas_create_receive_sc;
  162. kay_ctx->delete_receive_sc = wpas_delete_receive_sc;
  163. kay_ctx->create_receive_sa = wpas_create_receive_sa;
  164. kay_ctx->enable_receive_sa = wpas_enable_receive_sa;
  165. kay_ctx->disable_receive_sa = wpas_disable_receive_sa;
  166. kay_ctx->get_available_transmit_sc = wpas_get_available_transmit_sc;
  167. kay_ctx->create_transmit_sc = wpas_create_transmit_sc;
  168. kay_ctx->delete_transmit_sc = wpas_delete_transmit_sc;
  169. kay_ctx->create_transmit_sa = wpas_create_transmit_sa;
  170. kay_ctx->enable_transmit_sa = wpas_enable_transmit_sa;
  171. kay_ctx->disable_transmit_sa = wpas_disable_transmit_sa;
  172. res = ieee802_1x_kay_init(kay_ctx, policy, wpa_s->ifname,
  173. wpa_s->own_addr);
  174. if (res == NULL) {
  175. os_free(kay_ctx);
  176. return -1;
  177. }
  178. wpa_s->kay = res;
  179. return 0;
  180. }
  181. void ieee802_1x_dealloc_kay_sm(struct wpa_supplicant *wpa_s)
  182. {
  183. if (!wpa_s->kay)
  184. return;
  185. ieee802_1x_kay_deinit(wpa_s->kay);
  186. wpa_s->kay = NULL;
  187. }
  188. static int ieee802_1x_auth_get_session_id(struct wpa_supplicant *wpa_s,
  189. const u8 *addr, u8 *sid, size_t *len)
  190. {
  191. const u8 *session_id;
  192. size_t id_len, need_len;
  193. session_id = eapol_sm_get_session_id(wpa_s->eapol, &id_len);
  194. if (session_id == NULL) {
  195. wpa_printf(MSG_DEBUG,
  196. "Failed to get SessionID from EAPOL state machines");
  197. return -1;
  198. }
  199. need_len = 1 + 2 * SSL3_RANDOM_SIZE;
  200. if (need_len > id_len) {
  201. wpa_printf(MSG_DEBUG, "EAP Session-Id not long enough");
  202. return -1;
  203. }
  204. os_memcpy(sid, session_id, need_len);
  205. *len = need_len;
  206. return 0;
  207. }
  208. static int ieee802_1x_auth_get_msk(struct wpa_supplicant *wpa_s, const u8 *addr,
  209. u8 *msk, size_t *len)
  210. {
  211. u8 key[EAP_MSK_LEN];
  212. size_t keylen;
  213. struct eapol_sm *sm;
  214. int res;
  215. sm = wpa_s->eapol;
  216. if (sm == NULL)
  217. return -1;
  218. keylen = EAP_MSK_LEN;
  219. res = eapol_sm_get_key(sm, key, keylen);
  220. if (res) {
  221. wpa_printf(MSG_DEBUG,
  222. "Failed to get MSK from EAPOL state machines");
  223. return -1;
  224. }
  225. if (keylen > *len)
  226. keylen = *len;
  227. os_memcpy(msk, key, keylen);
  228. *len = keylen;
  229. return 0;
  230. }
  231. void * ieee802_1x_notify_create_actor(struct wpa_supplicant *wpa_s,
  232. const u8 *peer_addr)
  233. {
  234. u8 *sid;
  235. size_t sid_len = 128;
  236. struct mka_key_name *ckn;
  237. struct mka_key *cak;
  238. struct mka_key *msk;
  239. void *res = NULL;
  240. if (!wpa_s->kay || wpa_s->kay->policy == DO_NOT_SECURE)
  241. return NULL;
  242. wpa_printf(MSG_DEBUG,
  243. "IEEE 802.1X: External notification - Create MKA for "
  244. MACSTR, MAC2STR(peer_addr));
  245. msk = os_zalloc(sizeof(*msk));
  246. sid = os_zalloc(sid_len);
  247. ckn = os_zalloc(sizeof(*ckn));
  248. cak = os_zalloc(sizeof(*cak));
  249. if (!msk || !sid || !ckn || !cak)
  250. goto fail;
  251. msk->len = DEFAULT_KEY_LEN;
  252. if (ieee802_1x_auth_get_msk(wpa_s, wpa_s->bssid, msk->key, &msk->len)) {
  253. wpa_printf(MSG_ERROR, "IEEE 802.1X: Could not get MSK");
  254. goto fail;
  255. }
  256. if (ieee802_1x_auth_get_session_id(wpa_s, wpa_s->bssid, sid, &sid_len))
  257. {
  258. wpa_printf(MSG_ERROR,
  259. "IEEE 802.1X: Could not get EAP Session Id");
  260. goto fail;
  261. }
  262. /* Derive CAK from MSK */
  263. cak->len = DEFAULT_KEY_LEN;
  264. if (ieee802_1x_cak_128bits_aes_cmac(msk->key, wpa_s->own_addr,
  265. peer_addr, cak->key)) {
  266. wpa_printf(MSG_ERROR,
  267. "IEEE 802.1X: Deriving CAK failed");
  268. goto fail;
  269. }
  270. wpa_hexdump_key(MSG_DEBUG, "Derived CAK", cak->key, cak->len);
  271. /* Derive CKN from MSK */
  272. ckn->len = DEFAULT_CKN_LEN;
  273. if (ieee802_1x_ckn_128bits_aes_cmac(msk->key, wpa_s->own_addr,
  274. peer_addr, sid, sid_len,
  275. ckn->name)) {
  276. wpa_printf(MSG_ERROR,
  277. "IEEE 802.1X: Deriving CKN failed");
  278. goto fail;
  279. }
  280. wpa_hexdump(MSG_DEBUG, "Derived CKN", ckn->name, ckn->len);
  281. res = ieee802_1x_kay_create_mka(wpa_s->kay, ckn, cak, 0,
  282. EAP_EXCHANGE, FALSE);
  283. fail:
  284. if (msk) {
  285. os_memset(msk, 0, sizeof(*msk));
  286. os_free(msk);
  287. }
  288. os_free(sid);
  289. os_free(ckn);
  290. if (cak) {
  291. os_memset(cak, 0, sizeof(*cak));
  292. os_free(cak);
  293. }
  294. return res;
  295. }