test_fils.py 58 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546
  1. # Test cases for FILS
  2. # Copyright (c) 2015-2017, Qualcomm Atheros, Inc.
  3. #
  4. # This software may be distributed under the terms of the BSD license.
  5. # See README for more details.
  6. import binascii
  7. import hashlib
  8. import logging
  9. logger = logging.getLogger()
  10. import os
  11. import socket
  12. import struct
  13. import time
  14. import hostapd
  15. from wpasupplicant import WpaSupplicant
  16. import hwsim_utils
  17. from utils import HwsimSkip, alloc_fail
  18. from test_erp import check_erp_capa, start_erp_as
  19. from test_ap_hs20 import ip_checksum
  20. def check_fils_capa(dev):
  21. capa = dev.get_capability("fils")
  22. if capa is None or "FILS" not in capa:
  23. raise HwsimSkip("FILS not supported")
  24. def check_fils_sk_pfs_capa(dev):
  25. capa = dev.get_capability("fils")
  26. if capa is None or "FILS-SK-PFS" not in capa:
  27. raise HwsimSkip("FILS-SK-PFS not supported")
  28. def test_fils_sk_full_auth(dev, apdev):
  29. """FILS SK full authentication"""
  30. check_fils_capa(dev[0])
  31. check_erp_capa(dev[0])
  32. start_erp_as(apdev[1])
  33. bssid = apdev[0]['bssid']
  34. params = hostapd.wpa2_eap_params(ssid="fils")
  35. params['wpa_key_mgmt'] = "FILS-SHA256"
  36. params['auth_server_port'] = "18128"
  37. params['erp_send_reauth_start'] = '1'
  38. params['erp_domain'] = 'example.com'
  39. params['fils_realm'] = 'example.com'
  40. params['wpa_group_rekey'] = '1'
  41. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  42. dev[0].scan_for_bss(bssid, freq=2412)
  43. bss = dev[0].get_bss(bssid)
  44. logger.debug("BSS: " + str(bss))
  45. if "[FILS]" not in bss['flags']:
  46. raise Exception("[FILS] flag not indicated")
  47. if "[WPA2-FILS-SHA256-CCMP]" not in bss['flags']:
  48. raise Exception("[WPA2-FILS-SHA256-CCMP] flag not indicated")
  49. res = dev[0].request("SCAN_RESULTS")
  50. logger.debug("SCAN_RESULTS: " + res)
  51. if "[FILS]" not in res:
  52. raise Exception("[FILS] flag not indicated")
  53. if "[WPA2-FILS-SHA256-CCMP]" not in res:
  54. raise Exception("[WPA2-FILS-SHA256-CCMP] flag not indicated")
  55. dev[0].request("ERP_FLUSH")
  56. dev[0].connect("fils", key_mgmt="FILS-SHA256",
  57. eap="PSK", identity="psk.user@example.com",
  58. password_hex="0123456789abcdef0123456789abcdef",
  59. erp="1", scan_freq="2412")
  60. hwsim_utils.test_connectivity(dev[0], hapd)
  61. ev = dev[0].wait_event(["WPA: Group rekeying completed"], timeout=2)
  62. if ev is None:
  63. raise Exception("GTK rekey timed out")
  64. hwsim_utils.test_connectivity(dev[0], hapd)
  65. conf = hapd.get_config()
  66. if conf['key_mgmt'] != 'FILS-SHA256':
  67. raise Exception("Unexpected config key_mgmt: " + conf['key_mgmt'])
  68. def test_fils_sk_sha384_full_auth(dev, apdev):
  69. """FILS SK full authentication (SHA384)"""
  70. check_fils_capa(dev[0])
  71. check_erp_capa(dev[0])
  72. start_erp_as(apdev[1])
  73. bssid = apdev[0]['bssid']
  74. params = hostapd.wpa2_eap_params(ssid="fils")
  75. params['wpa_key_mgmt'] = "FILS-SHA384"
  76. params['auth_server_port'] = "18128"
  77. params['erp_send_reauth_start'] = '1'
  78. params['erp_domain'] = 'example.com'
  79. params['fils_realm'] = 'example.com'
  80. params['wpa_group_rekey'] = '1'
  81. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  82. dev[0].scan_for_bss(bssid, freq=2412)
  83. bss = dev[0].get_bss(bssid)
  84. logger.debug("BSS: " + str(bss))
  85. if "[FILS]" not in bss['flags']:
  86. raise Exception("[FILS] flag not indicated")
  87. if "[WPA2-FILS-SHA384-CCMP]" not in bss['flags']:
  88. raise Exception("[WPA2-FILS-SHA384-CCMP] flag not indicated")
  89. res = dev[0].request("SCAN_RESULTS")
  90. logger.debug("SCAN_RESULTS: " + res)
  91. if "[FILS]" not in res:
  92. raise Exception("[FILS] flag not indicated")
  93. if "[WPA2-FILS-SHA384-CCMP]" not in res:
  94. raise Exception("[WPA2-FILS-SHA384-CCMP] flag not indicated")
  95. dev[0].request("ERP_FLUSH")
  96. dev[0].connect("fils", key_mgmt="FILS-SHA384",
  97. eap="PSK", identity="psk.user@example.com",
  98. password_hex="0123456789abcdef0123456789abcdef",
  99. erp="1", scan_freq="2412")
  100. hwsim_utils.test_connectivity(dev[0], hapd)
  101. ev = dev[0].wait_event(["WPA: Group rekeying completed"], timeout=2)
  102. if ev is None:
  103. raise Exception("GTK rekey timed out")
  104. hwsim_utils.test_connectivity(dev[0], hapd)
  105. conf = hapd.get_config()
  106. if conf['key_mgmt'] != 'FILS-SHA384':
  107. raise Exception("Unexpected config key_mgmt: " + conf['key_mgmt'])
  108. def test_fils_sk_pmksa_caching(dev, apdev):
  109. """FILS SK and PMKSA caching"""
  110. check_fils_capa(dev[0])
  111. check_erp_capa(dev[0])
  112. start_erp_as(apdev[1])
  113. bssid = apdev[0]['bssid']
  114. params = hostapd.wpa2_eap_params(ssid="fils")
  115. params['wpa_key_mgmt'] = "FILS-SHA256"
  116. params['auth_server_port'] = "18128"
  117. params['erp_domain'] = 'example.com'
  118. params['fils_realm'] = 'example.com'
  119. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  120. dev[0].scan_for_bss(bssid, freq=2412)
  121. dev[0].request("ERP_FLUSH")
  122. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  123. eap="PSK", identity="psk.user@example.com",
  124. password_hex="0123456789abcdef0123456789abcdef",
  125. erp="1", scan_freq="2412")
  126. pmksa = dev[0].get_pmksa(bssid)
  127. if pmksa is None:
  128. raise Exception("No PMKSA cache entry created")
  129. dev[0].request("DISCONNECT")
  130. dev[0].wait_disconnected()
  131. dev[0].dump_monitor()
  132. dev[0].select_network(id, freq=2412)
  133. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  134. "CTRL-EVENT-CONNECTED"], timeout=10)
  135. if ev is None:
  136. raise Exception("Connection using PMKSA caching timed out")
  137. if "CTRL-EVENT-EAP-STARTED" in ev:
  138. raise Exception("Unexpected EAP exchange")
  139. hwsim_utils.test_connectivity(dev[0], hapd)
  140. pmksa2 = dev[0].get_pmksa(bssid)
  141. if pmksa2 is None:
  142. raise Exception("No PMKSA cache entry found")
  143. if pmksa['pmkid'] != pmksa2['pmkid']:
  144. raise Exception("Unexpected PMKID change")
  145. # Verify EAPOL reauthentication after FILS authentication
  146. hapd.request("EAPOL_REAUTH " + dev[0].own_addr())
  147. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED"], timeout=5)
  148. if ev is None:
  149. raise Exception("EAP authentication did not start")
  150. ev = dev[0].wait_event(["CTRL-EVENT-EAP-SUCCESS"], timeout=5)
  151. if ev is None:
  152. raise Exception("EAP authentication did not succeed")
  153. time.sleep(0.1)
  154. hwsim_utils.test_connectivity(dev[0], hapd)
  155. def test_fils_sk_pmksa_caching_and_cache_id(dev, apdev):
  156. """FILS SK and PMKSA caching with Cache Identifier"""
  157. check_fils_capa(dev[0])
  158. check_erp_capa(dev[0])
  159. bssid = apdev[0]['bssid']
  160. params = hostapd.wpa2_eap_params(ssid="fils")
  161. params['wpa_key_mgmt'] = "FILS-SHA256"
  162. params['auth_server_port'] = "18128"
  163. params['erp_domain'] = 'example.com'
  164. params['fils_realm'] = 'example.com'
  165. params['fils_cache_id'] = "abcd"
  166. params["radius_server_clients"] = "auth_serv/radius_clients.conf"
  167. params["radius_server_auth_port"] = '18128'
  168. params["eap_server"] = "1"
  169. params["eap_user_file"] = "auth_serv/eap_user.conf"
  170. params["ca_cert"] = "auth_serv/ca.pem"
  171. params["server_cert"] = "auth_serv/server.pem"
  172. params["private_key"] = "auth_serv/server.key"
  173. params["eap_sim_db"] = "unix:/tmp/hlr_auc_gw.sock"
  174. params["dh_file"] = "auth_serv/dh.conf"
  175. params["pac_opaque_encr_key"] = "000102030405060708090a0b0c0d0e0f"
  176. params["eap_fast_a_id"] = "101112131415161718191a1b1c1d1e1f"
  177. params["eap_fast_a_id_info"] = "test server"
  178. params["eap_server_erp"] = "1"
  179. params["erp_domain"] = "example.com"
  180. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  181. dev[0].scan_for_bss(bssid, freq=2412)
  182. dev[0].request("ERP_FLUSH")
  183. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  184. eap="PSK", identity="psk.user@example.com",
  185. password_hex="0123456789abcdef0123456789abcdef",
  186. erp="1", scan_freq="2412")
  187. res = dev[0].request("PMKSA")
  188. if "FILS Cache Identifier" not in res:
  189. raise Exception("PMKSA list does not include FILS Cache Identifier")
  190. pmksa = dev[0].get_pmksa(bssid)
  191. if pmksa is None:
  192. raise Exception("No PMKSA cache entry created")
  193. if "cache_id" not in pmksa:
  194. raise Exception("No FILS Cache Identifier listed")
  195. if pmksa["cache_id"] != "abcd":
  196. raise Exception("The configured FILS Cache Identifier not seen in PMKSA")
  197. bssid2 = apdev[1]['bssid']
  198. params = hostapd.wpa2_eap_params(ssid="fils")
  199. params['wpa_key_mgmt'] = "FILS-SHA256"
  200. params['auth_server_port'] = "18128"
  201. params['erp_domain'] = 'example.com'
  202. params['fils_realm'] = 'example.com'
  203. params['fils_cache_id'] = "abcd"
  204. hapd2 = hostapd.add_ap(apdev[1]['ifname'], params)
  205. dev[0].scan_for_bss(bssid2, freq=2412)
  206. dev[0].dump_monitor()
  207. if "OK" not in dev[0].request("ROAM " + bssid2):
  208. raise Exception("ROAM failed")
  209. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  210. "CTRL-EVENT-CONNECTED"], timeout=10)
  211. if ev is None:
  212. raise Exception("Connection using PMKSA caching timed out")
  213. if "CTRL-EVENT-EAP-STARTED" in ev:
  214. raise Exception("Unexpected EAP exchange")
  215. if bssid2 not in ev:
  216. raise Exception("Failed to connect to the second AP")
  217. hwsim_utils.test_connectivity(dev[0], hapd2)
  218. pmksa2 = dev[0].get_pmksa(bssid2)
  219. if pmksa2:
  220. raise Exception("Unexpected extra PMKSA cache added")
  221. pmksa2 = dev[0].get_pmksa(bssid)
  222. if not pmksa2:
  223. raise Exception("Original PMKSA cache entry removed")
  224. if pmksa['pmkid'] != pmksa2['pmkid']:
  225. raise Exception("Unexpected PMKID change")
  226. def test_fils_sk_pmksa_caching_ctrl_ext(dev, apdev):
  227. """FILS SK and PMKSA caching with Cache Identifier and external management"""
  228. check_fils_capa(dev[0])
  229. check_erp_capa(dev[0])
  230. hapd_as = start_erp_as(apdev[1])
  231. bssid = apdev[0]['bssid']
  232. params = hostapd.wpa2_eap_params(ssid="fils")
  233. params['wpa_key_mgmt'] = "FILS-SHA384"
  234. params['auth_server_port'] = "18128"
  235. params['erp_send_reauth_start'] = '1'
  236. params['erp_domain'] = 'example.com'
  237. params['fils_realm'] = 'example.com'
  238. params['fils_cache_id'] = "ffee"
  239. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  240. dev[0].scan_for_bss(bssid, freq=2412)
  241. dev[0].request("ERP_FLUSH")
  242. id = dev[0].connect("fils", key_mgmt="FILS-SHA384",
  243. eap="PSK", identity="psk.user@example.com",
  244. password_hex="0123456789abcdef0123456789abcdef",
  245. erp="1", scan_freq="2412")
  246. res1 = dev[0].request("PMKSA_GET %d" % id)
  247. logger.info("PMKSA_GET: " + res1)
  248. if "UNKNOWN COMMAND" in res1:
  249. raise HwsimSkip("PMKSA_GET not supported in the build")
  250. if bssid not in res1:
  251. raise Exception("PMKSA cache entry missing")
  252. if "ffee" not in res1:
  253. raise Exception("FILS Cache Identifier not seen in PMKSA cache entry")
  254. dev[0].request("DISCONNECT")
  255. dev[0].wait_disconnected()
  256. hapd_as.disable()
  257. dev[0].scan_for_bss(bssid, freq=2412)
  258. dev[0].request("PMKSA_FLUSH")
  259. dev[0].request("ERP_FLUSH")
  260. for entry in res1.splitlines():
  261. if "OK" not in dev[0].request("PMKSA_ADD %d %s" % (id, entry)):
  262. raise Exception("Failed to add PMKSA entry")
  263. bssid2 = apdev[1]['bssid']
  264. params = hostapd.wpa2_eap_params(ssid="fils")
  265. params['wpa_key_mgmt'] = "FILS-SHA384"
  266. params['auth_server_port'] = "18128"
  267. params['erp_send_reauth_start'] = '1'
  268. params['erp_domain'] = 'example.com'
  269. params['fils_realm'] = 'example.com'
  270. params['fils_cache_id'] = "ffee"
  271. hapd2 = hostapd.add_ap(apdev[1]['ifname'], params)
  272. dev[0].scan_for_bss(bssid2, freq=2412)
  273. dev[0].set_network(id, "bssid", bssid2)
  274. dev[0].select_network(id, freq=2412)
  275. ev = dev[0].wait_connected()
  276. if bssid2 not in ev:
  277. raise Exception("Unexpected BSS selected")
  278. def test_fils_sk_erp(dev, apdev):
  279. """FILS SK using ERP"""
  280. run_fils_sk_erp(dev, apdev, "FILS-SHA256")
  281. def test_fils_sk_erp_sha384(dev, apdev):
  282. """FILS SK using ERP and SHA384"""
  283. run_fils_sk_erp(dev, apdev, "FILS-SHA384")
  284. def run_fils_sk_erp(dev, apdev, key_mgmt):
  285. check_fils_capa(dev[0])
  286. check_erp_capa(dev[0])
  287. start_erp_as(apdev[1])
  288. bssid = apdev[0]['bssid']
  289. params = hostapd.wpa2_eap_params(ssid="fils")
  290. params['wpa_key_mgmt'] = key_mgmt
  291. params['auth_server_port'] = "18128"
  292. params['erp_domain'] = 'example.com'
  293. params['fils_realm'] = 'example.com'
  294. params['disable_pmksa_caching'] = '1'
  295. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  296. dev[0].scan_for_bss(bssid, freq=2412)
  297. dev[0].request("ERP_FLUSH")
  298. id = dev[0].connect("fils", key_mgmt=key_mgmt,
  299. eap="PSK", identity="psk.user@example.com",
  300. password_hex="0123456789abcdef0123456789abcdef",
  301. erp="1", scan_freq="2412")
  302. dev[0].request("DISCONNECT")
  303. dev[0].wait_disconnected()
  304. dev[0].dump_monitor()
  305. dev[0].select_network(id, freq=2412)
  306. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  307. "EVENT-ASSOC-REJECT",
  308. "CTRL-EVENT-CONNECTED"], timeout=10)
  309. if ev is None:
  310. raise Exception("Connection using FILS/ERP timed out")
  311. if "CTRL-EVENT-EAP-STARTED" in ev:
  312. raise Exception("Unexpected EAP exchange")
  313. if "EVENT-ASSOC-REJECT" in ev:
  314. raise Exception("Association failed")
  315. hwsim_utils.test_connectivity(dev[0], hapd)
  316. def test_fils_sk_erp_another_ssid(dev, apdev):
  317. """FILS SK using ERP and roam to another SSID"""
  318. check_fils_capa(dev[0])
  319. check_erp_capa(dev[0])
  320. start_erp_as(apdev[1])
  321. bssid = apdev[0]['bssid']
  322. params = hostapd.wpa2_eap_params(ssid="fils")
  323. params['wpa_key_mgmt'] = "FILS-SHA256"
  324. params['auth_server_port'] = "18128"
  325. params['erp_domain'] = 'example.com'
  326. params['fils_realm'] = 'example.com'
  327. params['disable_pmksa_caching'] = '1'
  328. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  329. dev[0].scan_for_bss(bssid, freq=2412)
  330. dev[0].request("ERP_FLUSH")
  331. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  332. eap="PSK", identity="psk.user@example.com",
  333. password_hex="0123456789abcdef0123456789abcdef",
  334. erp="1", scan_freq="2412")
  335. dev[0].request("DISCONNECT")
  336. dev[0].wait_disconnected()
  337. hapd.disable()
  338. dev[0].flush_scan_cache()
  339. if "FAIL" in dev[0].request("PMKSA_FLUSH"):
  340. raise Exception("PMKSA_FLUSH failed")
  341. params = hostapd.wpa2_eap_params(ssid="fils2")
  342. params['wpa_key_mgmt'] = "FILS-SHA256"
  343. params['auth_server_port'] = "18128"
  344. params['erp_domain'] = 'example.com'
  345. params['fils_realm'] = 'example.com'
  346. params['disable_pmksa_caching'] = '1'
  347. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  348. dev[0].scan_for_bss(bssid, freq=2412)
  349. dev[0].dump_monitor()
  350. id = dev[0].connect("fils2", key_mgmt="FILS-SHA256",
  351. eap="PSK", identity="psk.user@example.com",
  352. password_hex="0123456789abcdef0123456789abcdef",
  353. erp="1", scan_freq="2412", wait_connect=False)
  354. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  355. "EVENT-ASSOC-REJECT",
  356. "CTRL-EVENT-CONNECTED"], timeout=10)
  357. if ev is None:
  358. raise Exception("Connection using FILS/ERP timed out")
  359. if "CTRL-EVENT-EAP-STARTED" in ev:
  360. raise Exception("Unexpected EAP exchange")
  361. if "EVENT-ASSOC-REJECT" in ev:
  362. raise Exception("Association failed")
  363. hwsim_utils.test_connectivity(dev[0], hapd)
  364. def test_fils_sk_multiple_realms(dev, apdev):
  365. """FILS SK and multiple realms"""
  366. check_fils_capa(dev[0])
  367. check_erp_capa(dev[0])
  368. start_erp_as(apdev[1])
  369. bssid = apdev[0]['bssid']
  370. params = hostapd.wpa2_eap_params(ssid="fils")
  371. params['wpa_key_mgmt'] = "FILS-SHA256"
  372. params['auth_server_port'] = "18128"
  373. params['erp_domain'] = 'example.com'
  374. fils_realms = [ 'r1.example.org', 'r2.EXAMPLE.org', 'r3.example.org',
  375. 'r4.example.org', 'r5.example.org', 'r6.example.org',
  376. 'r7.example.org', 'r8.example.org',
  377. 'example.com',
  378. 'r9.example.org', 'r10.example.org', 'r11.example.org',
  379. 'r12.example.org', 'r13.example.org', 'r14.example.org',
  380. 'r15.example.org', 'r16.example.org' ]
  381. params['fils_realm'] = fils_realms
  382. params['fils_cache_id'] = "1234"
  383. params['hessid'] = bssid
  384. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  385. dev[0].scan_for_bss(bssid, freq=2412)
  386. if "OK" not in dev[0].request("ANQP_GET " + bssid + " 275"):
  387. raise Exception("ANQP_GET command failed")
  388. ev = dev[0].wait_event(["GAS-QUERY-DONE"], timeout=10)
  389. if ev is None:
  390. raise Exception("GAS query timed out")
  391. bss = dev[0].get_bss(bssid)
  392. if 'fils_info' not in bss:
  393. raise Exception("FILS Indication element information missing")
  394. if bss['fils_info'] != '02b8':
  395. raise Exception("Unexpected FILS Information: " + bss['fils_info'])
  396. if 'fils_cache_id' not in bss:
  397. raise Exception("FILS Cache Identifier missing")
  398. if bss['fils_cache_id'] != '1234':
  399. raise Exception("Unexpected FILS Cache Identifier: " + bss['fils_cache_id'])
  400. if 'fils_realms' not in bss:
  401. raise Exception("FILS Realm Identifiers missing")
  402. expected = ''
  403. count = 0
  404. for realm in fils_realms:
  405. hash = hashlib.sha256(realm.lower()).digest()
  406. expected += binascii.hexlify(hash[0:2])
  407. count += 1
  408. if count == 7:
  409. break
  410. if bss['fils_realms'] != expected:
  411. raise Exception("Unexpected FILS Realm Identifiers: " + bss['fils_realms'])
  412. if 'anqp_fils_realm_info' not in bss:
  413. raise Exception("FILS Realm Information ANQP-element not seen")
  414. info = bss['anqp_fils_realm_info'];
  415. expected = ''
  416. for realm in fils_realms:
  417. hash = hashlib.sha256(realm.lower()).digest()
  418. expected += binascii.hexlify(hash[0:2])
  419. if info != expected:
  420. raise Exception("Unexpected FILS Realm Info ANQP-element: " + info)
  421. dev[0].request("ERP_FLUSH")
  422. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  423. eap="PSK", identity="psk.user@example.com",
  424. password_hex="0123456789abcdef0123456789abcdef",
  425. erp="1", scan_freq="2412")
  426. dev[0].request("DISCONNECT")
  427. dev[0].wait_disconnected()
  428. dev[0].dump_monitor()
  429. dev[0].select_network(id, freq=2412)
  430. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  431. "EVENT-ASSOC-REJECT",
  432. "CTRL-EVENT-CONNECTED"], timeout=10)
  433. if ev is None:
  434. raise Exception("Connection using FILS/ERP timed out")
  435. if "CTRL-EVENT-EAP-STARTED" in ev:
  436. raise Exception("Unexpected EAP exchange")
  437. if "EVENT-ASSOC-REJECT" in ev:
  438. raise Exception("Association failed")
  439. hwsim_utils.test_connectivity(dev[0], hapd)
  440. # DHCP message op codes
  441. BOOTREQUEST=1
  442. BOOTREPLY=2
  443. OPT_PAD=0
  444. OPT_DHCP_MESSAGE_TYPE=53
  445. OPT_RAPID_COMMIT=80
  446. OPT_END=255
  447. DHCPDISCOVER=1
  448. DHCPOFFER=2
  449. DHCPREQUEST=3
  450. DHCPDECLINE=4
  451. DHCPACK=5
  452. DHCPNAK=6
  453. DHCPRELEASE=7
  454. DHCPINFORM=8
  455. def build_dhcp(req, dhcp_msg, chaddr, giaddr="0.0.0.0",
  456. ip_src="0.0.0.0", ip_dst="255.255.255.255",
  457. rapid_commit=True, override_op=None, magic_override=None,
  458. opt_end=True, extra_op=None):
  459. proto = '\x08\x00' # IPv4
  460. _ip_src = socket.inet_pton(socket.AF_INET, ip_src)
  461. _ip_dst = socket.inet_pton(socket.AF_INET, ip_dst)
  462. _ciaddr = '\x00\x00\x00\x00'
  463. _yiaddr = '\x00\x00\x00\x00'
  464. _siaddr = '\x00\x00\x00\x00'
  465. _giaddr = socket.inet_pton(socket.AF_INET, giaddr)
  466. _chaddr = binascii.unhexlify(chaddr.replace(':','')) + 10*'\x00'
  467. htype = 1 # Hardware address type; 1 = Ethernet
  468. hlen = 6 # Hardware address length
  469. hops = 0
  470. xid = 123456
  471. secs = 0
  472. flags = 0
  473. if req:
  474. op = BOOTREQUEST
  475. src_port = 68
  476. dst_port = 67
  477. else:
  478. op = BOOTREPLY
  479. src_port = 67
  480. dst_port = 68
  481. if override_op is not None:
  482. op = override_op
  483. payload = struct.pack('>BBBBLHH', op, htype, hlen, hops, xid, secs, flags)
  484. sname = 64*'\x00'
  485. file = 128*'\x00'
  486. payload += _ciaddr + _yiaddr + _siaddr + _giaddr + _chaddr + sname + file
  487. # magic - DHCP
  488. if magic_override is not None:
  489. payload += magic_override
  490. else:
  491. payload += '\x63\x82\x53\x63'
  492. # Option: DHCP Message Type
  493. if dhcp_msg is not None:
  494. payload += struct.pack('BBB', OPT_DHCP_MESSAGE_TYPE, 1, dhcp_msg)
  495. if rapid_commit:
  496. # Option: Rapid Commit
  497. payload += struct.pack('BB', OPT_RAPID_COMMIT, 0)
  498. if extra_op:
  499. payload += extra_op
  500. # End Option
  501. if opt_end:
  502. payload += struct.pack('B', OPT_END)
  503. udp = struct.pack('>HHHH', src_port, dst_port,
  504. 8 + len(payload), 0) + payload
  505. tot_len = 20 + len(udp)
  506. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  507. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  508. csum = ip_checksum(ipv4)
  509. ipv4 = start + csum + _ip_src + _ip_dst
  510. return proto + ipv4 + udp
  511. def fils_hlp_config(fils_hlp_wait_time=10000):
  512. params = hostapd.wpa2_eap_params(ssid="fils")
  513. params['wpa_key_mgmt'] = "FILS-SHA256"
  514. params['auth_server_port'] = "18128"
  515. params['erp_domain'] = 'example.com'
  516. params['fils_realm'] = 'example.com'
  517. params['disable_pmksa_caching'] = '1'
  518. params['own_ip_addr'] = '127.0.0.3'
  519. params['dhcp_server'] = '127.0.0.2'
  520. params['fils_hlp_wait_time'] = str(fils_hlp_wait_time)
  521. return params
  522. def test_fils_sk_hlp(dev, apdev):
  523. """FILS SK HLP (rapid commit server)"""
  524. run_fils_sk_hlp(dev, apdev, True)
  525. def test_fils_sk_hlp_no_rapid_commit(dev, apdev):
  526. """FILS SK HLP (no rapid commit server)"""
  527. run_fils_sk_hlp(dev, apdev, False)
  528. def run_fils_sk_hlp(dev, apdev, rapid_commit_server):
  529. check_fils_capa(dev[0])
  530. check_erp_capa(dev[0])
  531. start_erp_as(apdev[1])
  532. sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
  533. sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
  534. sock.settimeout(5)
  535. sock.bind(("127.0.0.2", 67))
  536. bssid = apdev[0]['bssid']
  537. params = fils_hlp_config()
  538. params['fils_hlp_wait_time'] = '10000'
  539. if not rapid_commit_server:
  540. params['dhcp_rapid_commit_proxy'] = '1'
  541. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  542. dev[0].scan_for_bss(bssid, freq=2412)
  543. dev[0].request("ERP_FLUSH")
  544. if "OK" not in dev[0].request("FILS_HLP_REQ_FLUSH"):
  545. raise Exception("Failed to flush pending FILS HLP requests")
  546. tests = [ "",
  547. "q",
  548. "ff:ff:ff:ff:ff:ff",
  549. "ff:ff:ff:ff:ff:ff q" ]
  550. for t in tests:
  551. if "FAIL" not in dev[0].request("FILS_HLP_REQ_ADD " + t):
  552. raise Exception("Invalid FILS_HLP_REQ_ADD accepted: " + t)
  553. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  554. chaddr=dev[0].own_addr())
  555. tests = [ "ff:ff:ff:ff:ff:ff aabb",
  556. "ff:ff:ff:ff:ff:ff " + 255*'cc',
  557. hapd.own_addr() + " ddee010203040506070809",
  558. "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc) ]
  559. for t in tests:
  560. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + t):
  561. raise Exception("FILS_HLP_REQ_ADD failed: " + t)
  562. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  563. eap="PSK", identity="psk.user@example.com",
  564. password_hex="0123456789abcdef0123456789abcdef",
  565. erp="1", scan_freq="2412")
  566. dev[0].request("DISCONNECT")
  567. dev[0].wait_disconnected()
  568. dev[0].dump_monitor()
  569. dev[0].select_network(id, freq=2412)
  570. (msg,addr) = sock.recvfrom(1000)
  571. logger.debug("Received DHCP message from %s" % str(addr))
  572. if rapid_commit_server:
  573. # TODO: Proper rapid commit response
  574. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPACK,
  575. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  576. sock.sendto(dhcpdisc[2+20+8:], addr)
  577. else:
  578. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  579. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  580. sock.sendto(dhcpdisc[2+20+8:], addr)
  581. (msg,addr) = sock.recvfrom(1000)
  582. logger.debug("Received DHCP message from %s" % str(addr))
  583. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPACK, rapid_commit=False,
  584. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  585. sock.sendto(dhcpdisc[2+20+8:], addr)
  586. ev = dev[0].wait_event(["FILS-HLP-RX"], timeout=10)
  587. if ev is None:
  588. raise Exception("FILS HLP response not reported")
  589. vals = ev.split(' ')
  590. frame = binascii.unhexlify(vals[3].split('=')[1])
  591. proto, = struct.unpack('>H', frame[0:2])
  592. if proto != 0x0800:
  593. raise Exception("Unexpected ethertype in HLP response: %d" % proto)
  594. frame = frame[2:]
  595. ip = frame[0:20]
  596. if ip_checksum(ip) != '\x00\x00':
  597. raise Exception("IP header checksum mismatch in HLP response")
  598. frame = frame[20:]
  599. udp = frame[0:8]
  600. frame = frame[8:]
  601. sport, dport, ulen, ucheck = struct.unpack('>HHHH', udp)
  602. if sport != 67 or dport != 68:
  603. raise Exception("Unexpected UDP port in HLP response")
  604. dhcp = frame[0:28]
  605. frame = frame[28:]
  606. op,htype,hlen,hops,xid,secs,flags,ciaddr,yiaddr,siaddr,giaddr = struct.unpack('>4BL2H4L', dhcp)
  607. chaddr = frame[0:16]
  608. frame = frame[16:]
  609. sname = frame[0:64]
  610. frame = frame[64:]
  611. file = frame[0:128]
  612. frame = frame[128:]
  613. options = frame
  614. if options[0:4] != '\x63\x82\x53\x63':
  615. raise Exception("No DHCP magic seen in HLP response")
  616. options = options[4:]
  617. # TODO: fully parse and validate DHCPACK options
  618. if struct.pack('BBB', OPT_DHCP_MESSAGE_TYPE, 1, DHCPACK) not in options:
  619. raise Exception("DHCPACK not in HLP response")
  620. dev[0].wait_connected()
  621. dev[0].request("FILS_HLP_REQ_FLUSH")
  622. def test_fils_sk_hlp_timeout(dev, apdev):
  623. """FILS SK HLP (rapid commit server timeout)"""
  624. check_fils_capa(dev[0])
  625. check_erp_capa(dev[0])
  626. start_erp_as(apdev[1])
  627. sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
  628. sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
  629. sock.settimeout(5)
  630. sock.bind(("127.0.0.2", 67))
  631. bssid = apdev[0]['bssid']
  632. params = fils_hlp_config(fils_hlp_wait_time=30)
  633. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  634. dev[0].scan_for_bss(bssid, freq=2412)
  635. dev[0].request("ERP_FLUSH")
  636. if "OK" not in dev[0].request("FILS_HLP_REQ_FLUSH"):
  637. raise Exception("Failed to flush pending FILS HLP requests")
  638. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  639. chaddr=dev[0].own_addr())
  640. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc)):
  641. raise Exception("FILS_HLP_REQ_ADD failed")
  642. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  643. eap="PSK", identity="psk.user@example.com",
  644. password_hex="0123456789abcdef0123456789abcdef",
  645. erp="1", scan_freq="2412")
  646. dev[0].request("DISCONNECT")
  647. dev[0].wait_disconnected()
  648. dev[0].dump_monitor()
  649. dev[0].select_network(id, freq=2412)
  650. (msg,addr) = sock.recvfrom(1000)
  651. logger.debug("Received DHCP message from %s" % str(addr))
  652. # Wait for HLP wait timeout to hit
  653. # FILS: HLP response timeout - continue with association response
  654. dev[0].wait_connected()
  655. dev[0].request("FILS_HLP_REQ_FLUSH")
  656. def test_fils_sk_hlp_oom(dev, apdev):
  657. """FILS SK HLP and hostapd OOM"""
  658. check_fils_capa(dev[0])
  659. check_erp_capa(dev[0])
  660. start_erp_as(apdev[1])
  661. sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
  662. sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
  663. sock.settimeout(5)
  664. sock.bind(("127.0.0.2", 67))
  665. bssid = apdev[0]['bssid']
  666. params = fils_hlp_config(fils_hlp_wait_time=500)
  667. params['dhcp_rapid_commit_proxy'] = '1'
  668. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  669. dev[0].scan_for_bss(bssid, freq=2412)
  670. dev[0].request("ERP_FLUSH")
  671. if "OK" not in dev[0].request("FILS_HLP_REQ_FLUSH"):
  672. raise Exception("Failed to flush pending FILS HLP requests")
  673. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  674. chaddr=dev[0].own_addr())
  675. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc)):
  676. raise Exception("FILS_HLP_REQ_ADD failed")
  677. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  678. eap="PSK", identity="psk.user@example.com",
  679. password_hex="0123456789abcdef0123456789abcdef",
  680. erp="1", scan_freq="2412")
  681. dev[0].request("DISCONNECT")
  682. dev[0].wait_disconnected()
  683. dev[0].dump_monitor()
  684. with alloc_fail(hapd, 1, "fils_process_hlp"):
  685. dev[0].select_network(id, freq=2412)
  686. dev[0].wait_connected()
  687. dev[0].request("DISCONNECT")
  688. dev[0].wait_disconnected()
  689. dev[0].dump_monitor()
  690. with alloc_fail(hapd, 1, "fils_process_hlp_dhcp"):
  691. dev[0].select_network(id, freq=2412)
  692. dev[0].wait_connected()
  693. dev[0].request("DISCONNECT")
  694. dev[0].wait_disconnected()
  695. dev[0].dump_monitor()
  696. with alloc_fail(hapd, 1, "wpabuf_alloc;fils_process_hlp_dhcp"):
  697. dev[0].select_network(id, freq=2412)
  698. dev[0].wait_connected()
  699. dev[0].request("DISCONNECT")
  700. dev[0].wait_disconnected()
  701. dev[0].dump_monitor()
  702. with alloc_fail(hapd, 1, "wpabuf_alloc;fils_dhcp_handler"):
  703. dev[0].select_network(id, freq=2412)
  704. (msg,addr) = sock.recvfrom(1000)
  705. logger.debug("Received DHCP message from %s" % str(addr))
  706. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPACK,
  707. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  708. sock.sendto(dhcpdisc[2+20+8:], addr)
  709. dev[0].wait_connected()
  710. dev[0].request("DISCONNECT")
  711. dev[0].wait_disconnected()
  712. dev[0].dump_monitor()
  713. with alloc_fail(hapd, 1, "wpabuf_resize;fils_dhcp_handler"):
  714. dev[0].select_network(id, freq=2412)
  715. (msg,addr) = sock.recvfrom(1000)
  716. logger.debug("Received DHCP message from %s" % str(addr))
  717. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPACK,
  718. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  719. sock.sendto(dhcpdisc[2+20+8:], addr)
  720. dev[0].wait_connected()
  721. dev[0].request("DISCONNECT")
  722. dev[0].wait_disconnected()
  723. dev[0].dump_monitor()
  724. dev[0].select_network(id, freq=2412)
  725. (msg,addr) = sock.recvfrom(1000)
  726. logger.debug("Received DHCP message from %s" % str(addr))
  727. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  728. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  729. with alloc_fail(hapd, 1, "wpabuf_resize;fils_dhcp_request"):
  730. sock.sendto(dhcpoffer[2+20+8:], addr)
  731. dev[0].wait_connected()
  732. dev[0].request("DISCONNECT")
  733. dev[0].wait_disconnected()
  734. dev[0].request("FILS_HLP_REQ_FLUSH")
  735. def test_fils_sk_hlp_req_parsing(dev, apdev):
  736. """FILS SK HLP request parsing"""
  737. check_fils_capa(dev[0])
  738. check_erp_capa(dev[0])
  739. start_erp_as(apdev[1])
  740. bssid = apdev[0]['bssid']
  741. params = fils_hlp_config(fils_hlp_wait_time=30)
  742. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  743. dev[0].scan_for_bss(bssid, freq=2412)
  744. dev[0].request("ERP_FLUSH")
  745. if "OK" not in dev[0].request("FILS_HLP_REQ_FLUSH"):
  746. raise Exception("Failed to flush pending FILS HLP requests")
  747. tot_len = 20 + 1
  748. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  749. _ip_src = '\x00\x00\x00\x00'
  750. _ip_dst = '\x00\x00\x00\x00'
  751. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  752. csum = ip_checksum(ipv4)
  753. ipv4_overflow = start + csum + _ip_src + _ip_dst
  754. tot_len = 20
  755. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 123)
  756. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  757. csum = ip_checksum(ipv4)
  758. ipv4_unknown_proto = start + csum + _ip_src + _ip_dst
  759. tot_len = 20
  760. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  761. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  762. csum = ip_checksum(ipv4)
  763. ipv4_missing_udp_hdr = start + csum + _ip_src + _ip_dst
  764. src_port = 68
  765. dst_port = 67
  766. udp = struct.pack('>HHHH', src_port, dst_port, 8 + 1, 0)
  767. tot_len = 20 + len(udp)
  768. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  769. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  770. csum = ip_checksum(ipv4)
  771. udp_overflow = start + csum + _ip_src + _ip_dst + udp
  772. udp = struct.pack('>HHHH', src_port, dst_port, 7, 0)
  773. tot_len = 20 + len(udp)
  774. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  775. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  776. csum = ip_checksum(ipv4)
  777. udp_underflow = start + csum + _ip_src + _ip_dst + udp
  778. src_port = 123
  779. dst_port = 456
  780. udp = struct.pack('>HHHH', src_port, dst_port, 8, 0)
  781. tot_len = 20 + len(udp)
  782. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  783. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  784. csum = ip_checksum(ipv4)
  785. udp_unknown_port = start + csum + _ip_src + _ip_dst + udp
  786. src_port = 68
  787. dst_port = 67
  788. udp = struct.pack('>HHHH', src_port, dst_port, 8, 0)
  789. tot_len = 20 + len(udp)
  790. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  791. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  792. csum = ip_checksum(ipv4)
  793. dhcp_missing_data = start + csum + _ip_src + _ip_dst + udp
  794. dhcp_not_req = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  795. chaddr=dev[0].own_addr(), override_op=BOOTREPLY)
  796. dhcp_no_magic = build_dhcp(req=True, dhcp_msg=None,
  797. chaddr=dev[0].own_addr(), magic_override='',
  798. rapid_commit=False, opt_end=False)
  799. dhcp_unknown_magic = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  800. chaddr=dev[0].own_addr(),
  801. magic_override='\x00\x00\x00\x00')
  802. dhcp_opts = build_dhcp(req=True, dhcp_msg=DHCPNAK,
  803. chaddr=dev[0].own_addr(),
  804. extra_op='\x00\x11', opt_end=False)
  805. dhcp_opts2 = build_dhcp(req=True, dhcp_msg=DHCPNAK,
  806. chaddr=dev[0].own_addr(),
  807. extra_op='\x11\x01', opt_end=False)
  808. dhcp_valid = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  809. chaddr=dev[0].own_addr())
  810. tests = [ "ff",
  811. "0800",
  812. "0800" + 20*"00",
  813. "0800" + binascii.hexlify(ipv4_overflow),
  814. "0800" + binascii.hexlify(ipv4_unknown_proto),
  815. "0800" + binascii.hexlify(ipv4_missing_udp_hdr),
  816. "0800" + binascii.hexlify(udp_overflow),
  817. "0800" + binascii.hexlify(udp_underflow),
  818. "0800" + binascii.hexlify(udp_unknown_port),
  819. "0800" + binascii.hexlify(dhcp_missing_data),
  820. binascii.hexlify(dhcp_not_req),
  821. binascii.hexlify(dhcp_no_magic),
  822. binascii.hexlify(dhcp_unknown_magic) ]
  823. for t in tests:
  824. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD ff:ff:ff:ff:ff:ff " + t):
  825. raise Exception("FILS_HLP_REQ_ADD failed: " + t)
  826. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  827. eap="PSK", identity="psk.user@example.com",
  828. password_hex="0123456789abcdef0123456789abcdef",
  829. erp="1", scan_freq="2412")
  830. dev[0].request("DISCONNECT")
  831. dev[0].wait_disconnected()
  832. dev[0].dump_monitor()
  833. dev[0].select_network(id, freq=2412)
  834. dev[0].wait_connected()
  835. dev[0].request("DISCONNECT")
  836. dev[0].wait_disconnected()
  837. dev[0].request("FILS_HLP_REQ_FLUSH")
  838. tests = [ binascii.hexlify(dhcp_opts),
  839. binascii.hexlify(dhcp_opts2) ]
  840. for t in tests:
  841. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD ff:ff:ff:ff:ff:ff " + t):
  842. raise Exception("FILS_HLP_REQ_ADD failed: " + t)
  843. dev[0].dump_monitor()
  844. dev[0].select_network(id, freq=2412)
  845. dev[0].wait_connected()
  846. dev[0].request("DISCONNECT")
  847. dev[0].wait_disconnected()
  848. dev[0].request("FILS_HLP_REQ_FLUSH")
  849. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcp_valid)):
  850. raise Exception("FILS_HLP_REQ_ADD failed")
  851. hapd.set("own_ip_addr", "0.0.0.0")
  852. dev[0].select_network(id, freq=2412)
  853. dev[0].wait_connected()
  854. dev[0].request("DISCONNECT")
  855. dev[0].wait_disconnected()
  856. hapd.set("dhcp_server", "0.0.0.0")
  857. dev[0].select_network(id, freq=2412)
  858. dev[0].wait_connected()
  859. dev[0].request("DISCONNECT")
  860. dev[0].wait_disconnected()
  861. # FILS: Failed to bind DHCP socket: Address already in use
  862. sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
  863. sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
  864. sock.settimeout(5)
  865. sock.bind(("127.0.0.2", 67))
  866. hapd.set("own_ip_addr", "127.0.0.2")
  867. hapd.set("dhcp_server", "127.0.0.2")
  868. dev[0].select_network(id, freq=2412)
  869. dev[0].wait_connected()
  870. dev[0].request("DISCONNECT")
  871. dev[0].wait_disconnected()
  872. # FILS: DHCP sendto failed: Invalid argument
  873. hapd.set("own_ip_addr", "127.0.0.3")
  874. hapd.set("dhcp_server", "127.0.0.2")
  875. hapd.set("dhcp_relay_port", "0")
  876. hapd.set("dhcp_server_port", "0")
  877. dev[0].select_network(id, freq=2412)
  878. dev[0].wait_connected()
  879. dev[0].request("DISCONNECT")
  880. dev[0].wait_disconnected()
  881. dev[0].request("FILS_HLP_REQ_FLUSH")
  882. def test_fils_sk_hlp_dhcp_parsing(dev, apdev):
  883. """FILS SK HLP and DHCP response parsing"""
  884. check_fils_capa(dev[0])
  885. check_erp_capa(dev[0])
  886. start_erp_as(apdev[1])
  887. sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
  888. sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
  889. sock.settimeout(5)
  890. sock.bind(("127.0.0.2", 67))
  891. bssid = apdev[0]['bssid']
  892. params = fils_hlp_config(fils_hlp_wait_time=30)
  893. params['dhcp_rapid_commit_proxy'] = '1'
  894. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  895. dev[0].scan_for_bss(bssid, freq=2412)
  896. dev[0].request("ERP_FLUSH")
  897. if "OK" not in dev[0].request("FILS_HLP_REQ_FLUSH"):
  898. raise Exception("Failed to flush pending FILS HLP requests")
  899. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  900. chaddr=dev[0].own_addr())
  901. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc)):
  902. raise Exception("FILS_HLP_REQ_ADD failed")
  903. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  904. eap="PSK", identity="psk.user@example.com",
  905. password_hex="0123456789abcdef0123456789abcdef",
  906. erp="1", scan_freq="2412")
  907. dev[0].request("DISCONNECT")
  908. dev[0].wait_disconnected()
  909. dev[0].dump_monitor()
  910. with alloc_fail(hapd, 1, "fils_process_hlp"):
  911. dev[0].select_network(id, freq=2412)
  912. dev[0].wait_connected()
  913. dev[0].request("DISCONNECT")
  914. dev[0].wait_disconnected()
  915. dev[0].dump_monitor()
  916. dev[0].select_network(id, freq=2412)
  917. (msg,addr) = sock.recvfrom(1000)
  918. logger.debug("Received DHCP message from %s" % str(addr))
  919. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPACK,
  920. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  921. #sock.sendto(dhcpdisc[2+20+8:], addr)
  922. chaddr = binascii.unhexlify(dev[0].own_addr().replace(':','')) + 10*'\x00'
  923. tests = [ "\x00",
  924. "\x02" + 500 * "\x00",
  925. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + 500 * "\x00",
  926. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + 16*"\x00" + 64*"\x00" + 128*"\x00" + "\x63\x82\x53\x63",
  927. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + 16*"\x00" + 64*"\x00" + 128*"\x00" + "\x63\x82\x53\x63" + "\x00\x11",
  928. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + 16*"\x00" + 64*"\x00" + 128*"\x00" + "\x63\x82\x53\x63" + "\x11\x01",
  929. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + chaddr + 64*"\x00" + 128*"\x00" + "\x63\x82\x53\x63" + "\x35\x00\xff",
  930. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + chaddr + 64*"\x00" + 128*"\x00" + "\x63\x82\x53\x63" + "\x35\x01\x00\xff",
  931. 1501 * "\x00" ]
  932. for t in tests:
  933. sock.sendto(t, addr)
  934. dev[0].wait_connected()
  935. dev[0].request("DISCONNECT")
  936. dev[0].wait_disconnected()
  937. # FILS: DHCP sendto failed: Invalid argument for second DHCP TX in proxy
  938. dev[0].dump_monitor()
  939. dev[0].select_network(id, freq=2412)
  940. (msg,addr) = sock.recvfrom(1000)
  941. logger.debug("Received DHCP message from %s" % str(addr))
  942. hapd.set("dhcp_server_port", "0")
  943. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  944. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  945. sock.sendto(dhcpoffer[2+20+8:], addr)
  946. dev[0].wait_connected()
  947. dev[0].request("DISCONNECT")
  948. dev[0].wait_disconnected()
  949. hapd.set("dhcp_server_port", "67")
  950. # Options in DHCPOFFER
  951. dev[0].dump_monitor()
  952. dev[0].select_network(id, freq=2412)
  953. (msg,addr) = sock.recvfrom(1000)
  954. logger.debug("Received DHCP message from %s" % str(addr))
  955. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  956. chaddr=dev[0].own_addr(), giaddr="127.0.0.3",
  957. extra_op="\x00\x11", opt_end=False)
  958. sock.sendto(dhcpoffer[2+20+8:], addr)
  959. (msg,addr) = sock.recvfrom(1000)
  960. logger.debug("Received DHCP message from %s" % str(addr))
  961. dev[0].wait_connected()
  962. dev[0].request("DISCONNECT")
  963. dev[0].wait_disconnected()
  964. # Options in DHCPOFFER (2)
  965. dev[0].dump_monitor()
  966. dev[0].select_network(id, freq=2412)
  967. (msg,addr) = sock.recvfrom(1000)
  968. logger.debug("Received DHCP message from %s" % str(addr))
  969. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  970. chaddr=dev[0].own_addr(), giaddr="127.0.0.3",
  971. extra_op="\x11\x01", opt_end=False)
  972. sock.sendto(dhcpoffer[2+20+8:], addr)
  973. (msg,addr) = sock.recvfrom(1000)
  974. logger.debug("Received DHCP message from %s" % str(addr))
  975. dev[0].wait_connected()
  976. dev[0].request("DISCONNECT")
  977. dev[0].wait_disconnected()
  978. # Server ID in DHCPOFFER
  979. dev[0].dump_monitor()
  980. dev[0].select_network(id, freq=2412)
  981. (msg,addr) = sock.recvfrom(1000)
  982. logger.debug("Received DHCP message from %s" % str(addr))
  983. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  984. chaddr=dev[0].own_addr(), giaddr="127.0.0.3",
  985. extra_op="\x36\x01\x30")
  986. sock.sendto(dhcpoffer[2+20+8:], addr)
  987. (msg,addr) = sock.recvfrom(1000)
  988. logger.debug("Received DHCP message from %s" % str(addr))
  989. dev[0].wait_connected()
  990. dev[0].request("DISCONNECT")
  991. dev[0].wait_disconnected()
  992. # FILS: Could not update DHCPDISCOVER
  993. dev[0].request("FILS_HLP_REQ_FLUSH")
  994. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  995. chaddr=dev[0].own_addr(),
  996. extra_op="\x00\x11", opt_end=False)
  997. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc)):
  998. raise Exception("FILS_HLP_REQ_ADD failed")
  999. dev[0].dump_monitor()
  1000. dev[0].select_network(id, freq=2412)
  1001. (msg,addr) = sock.recvfrom(1000)
  1002. logger.debug("Received DHCP message from %s" % str(addr))
  1003. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  1004. chaddr=dev[0].own_addr(), giaddr="127.0.0.3",
  1005. extra_op="\x36\x01\x30")
  1006. sock.sendto(dhcpoffer[2+20+8:], addr)
  1007. dev[0].wait_connected()
  1008. dev[0].request("DISCONNECT")
  1009. dev[0].wait_disconnected()
  1010. # FILS: Could not update DHCPDISCOVER (2)
  1011. dev[0].request("FILS_HLP_REQ_FLUSH")
  1012. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  1013. chaddr=dev[0].own_addr(),
  1014. extra_op="\x11\x01", opt_end=False)
  1015. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc)):
  1016. raise Exception("FILS_HLP_REQ_ADD failed")
  1017. dev[0].dump_monitor()
  1018. dev[0].select_network(id, freq=2412)
  1019. (msg,addr) = sock.recvfrom(1000)
  1020. logger.debug("Received DHCP message from %s" % str(addr))
  1021. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  1022. chaddr=dev[0].own_addr(), giaddr="127.0.0.3",
  1023. extra_op="\x36\x01\x30")
  1024. sock.sendto(dhcpoffer[2+20+8:], addr)
  1025. dev[0].wait_connected()
  1026. dev[0].request("DISCONNECT")
  1027. dev[0].wait_disconnected()
  1028. dev[0].request("FILS_HLP_REQ_FLUSH")
  1029. def test_fils_sk_erp_and_reauth(dev, apdev):
  1030. """FILS SK using ERP and AP going away"""
  1031. check_fils_capa(dev[0])
  1032. check_erp_capa(dev[0])
  1033. start_erp_as(apdev[1])
  1034. bssid = apdev[0]['bssid']
  1035. params = hostapd.wpa2_eap_params(ssid="fils")
  1036. params['wpa_key_mgmt'] = "FILS-SHA256"
  1037. params['auth_server_port'] = "18128"
  1038. params['erp_domain'] = 'example.com'
  1039. params['fils_realm'] = 'example.com'
  1040. params['disable_pmksa_caching'] = '1'
  1041. params['broadcast_deauth'] = '0'
  1042. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1043. dev[0].scan_for_bss(bssid, freq=2412)
  1044. dev[0].request("ERP_FLUSH")
  1045. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1046. eap="PSK", identity="psk.user@example.com",
  1047. password_hex="0123456789abcdef0123456789abcdef",
  1048. erp="1", scan_freq="2412")
  1049. hapd.disable()
  1050. dev[0].wait_disconnected()
  1051. dev[0].dump_monitor()
  1052. hapd.enable()
  1053. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  1054. "EVENT-ASSOC-REJECT",
  1055. "CTRL-EVENT-CONNECTED"], timeout=10)
  1056. if ev is None:
  1057. raise Exception("Reconnection using FILS/ERP timed out")
  1058. if "CTRL-EVENT-EAP-STARTED" in ev:
  1059. raise Exception("Unexpected EAP exchange")
  1060. if "EVENT-ASSOC-REJECT" in ev:
  1061. raise Exception("Association failed")
  1062. def test_fils_sk_erp_sim(dev, apdev):
  1063. """FILS SK using ERP with SIM"""
  1064. check_fils_capa(dev[0])
  1065. check_erp_capa(dev[0])
  1066. realm='wlan.mnc001.mcc232.3gppnetwork.org'
  1067. start_erp_as(apdev[1], erp_domain=realm)
  1068. bssid = apdev[0]['bssid']
  1069. params = hostapd.wpa2_eap_params(ssid="fils")
  1070. params['wpa_key_mgmt'] = "FILS-SHA256"
  1071. params['auth_server_port'] = "18128"
  1072. params['fils_realm'] = realm
  1073. params['disable_pmksa_caching'] = '1'
  1074. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1075. dev[0].scan_for_bss(bssid, freq=2412)
  1076. dev[0].request("ERP_FLUSH")
  1077. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1078. eap="SIM", identity="1232010000000000@" + realm,
  1079. password="90dca4eda45b53cf0f12d7c9c3bc6a89:cb9cccc4b9258e6dca4760379fb82581",
  1080. erp="1", scan_freq="2412")
  1081. hapd.disable()
  1082. dev[0].wait_disconnected()
  1083. dev[0].dump_monitor()
  1084. hapd.enable()
  1085. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  1086. "EVENT-ASSOC-REJECT",
  1087. "CTRL-EVENT-CONNECTED"], timeout=10)
  1088. if ev is None:
  1089. raise Exception("Reconnection using FILS/ERP timed out")
  1090. if "CTRL-EVENT-EAP-STARTED" in ev:
  1091. raise Exception("Unexpected EAP exchange")
  1092. if "EVENT-ASSOC-REJECT" in ev:
  1093. raise Exception("Association failed")
  1094. def test_fils_sk_pfs_19(dev, apdev):
  1095. """FILS SK with PFS (DH group 19)"""
  1096. rul_fils_sk_pfs(dev, apdev, "19")
  1097. def test_fils_sk_pfs_20(dev, apdev):
  1098. """FILS SK with PFS (DH group 20)"""
  1099. rul_fils_sk_pfs(dev, apdev, "20")
  1100. def test_fils_sk_pfs_21(dev, apdev):
  1101. """FILS SK with PFS (DH group 21)"""
  1102. rul_fils_sk_pfs(dev, apdev, "21")
  1103. def test_fils_sk_pfs_25(dev, apdev):
  1104. """FILS SK with PFS (DH group 25)"""
  1105. rul_fils_sk_pfs(dev, apdev, "25")
  1106. def test_fils_sk_pfs_26(dev, apdev):
  1107. """FILS SK with PFS (DH group 26)"""
  1108. rul_fils_sk_pfs(dev, apdev, "26")
  1109. def test_fils_sk_pfs_27(dev, apdev):
  1110. """FILS SK with PFS (DH group 27)"""
  1111. rul_fils_sk_pfs(dev, apdev, "27")
  1112. def test_fils_sk_pfs_28(dev, apdev):
  1113. """FILS SK with PFS (DH group 28)"""
  1114. rul_fils_sk_pfs(dev, apdev, "28")
  1115. def test_fils_sk_pfs_29(dev, apdev):
  1116. """FILS SK with PFS (DH group 29)"""
  1117. rul_fils_sk_pfs(dev, apdev, "29")
  1118. def test_fils_sk_pfs_30(dev, apdev):
  1119. """FILS SK with PFS (DH group 30)"""
  1120. rul_fils_sk_pfs(dev, apdev, "30")
  1121. def rul_fils_sk_pfs(dev, apdev, group):
  1122. check_fils_sk_pfs_capa(dev[0])
  1123. check_erp_capa(dev[0])
  1124. tls = dev[0].request("GET tls_library")
  1125. if int(group) in [ 27, 28, 29, 30 ]:
  1126. if not (tls.startswith("OpenSSL") and ("build=OpenSSL 1.0.2" in tls or "build=OpenSSL 1.1" in tls) and ("run=OpenSSL 1.0.2" in tls or "run=OpenSSL 1.1" in tls)):
  1127. raise HwsimSkip("Brainpool EC group not supported")
  1128. start_erp_as(apdev[1])
  1129. bssid = apdev[0]['bssid']
  1130. params = hostapd.wpa2_eap_params(ssid="fils")
  1131. params['wpa_key_mgmt'] = "FILS-SHA256"
  1132. params['auth_server_port'] = "18128"
  1133. params['erp_domain'] = 'example.com'
  1134. params['fils_realm'] = 'example.com'
  1135. params['disable_pmksa_caching'] = '1'
  1136. params['fils_dh_group'] = group
  1137. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1138. dev[0].scan_for_bss(bssid, freq=2412)
  1139. dev[0].request("ERP_FLUSH")
  1140. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1141. eap="PSK", identity="psk.user@example.com",
  1142. password_hex="0123456789abcdef0123456789abcdef",
  1143. erp="1", fils_dh_group=group, scan_freq="2412")
  1144. dev[0].request("DISCONNECT")
  1145. dev[0].wait_disconnected()
  1146. dev[0].dump_monitor()
  1147. dev[0].select_network(id, freq=2412)
  1148. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  1149. "EVENT-ASSOC-REJECT",
  1150. "CTRL-EVENT-CONNECTED"], timeout=10)
  1151. if ev is None:
  1152. raise Exception("Connection using FILS/ERP timed out")
  1153. if "CTRL-EVENT-EAP-STARTED" in ev:
  1154. raise Exception("Unexpected EAP exchange")
  1155. if "EVENT-ASSOC-REJECT" in ev:
  1156. raise Exception("Association failed")
  1157. hwsim_utils.test_connectivity(dev[0], hapd)
  1158. def test_fils_sk_pfs_group_mismatch(dev, apdev):
  1159. """FILS SK PFS DH group mismatch"""
  1160. check_fils_sk_pfs_capa(dev[0])
  1161. check_erp_capa(dev[0])
  1162. start_erp_as(apdev[1])
  1163. bssid = apdev[0]['bssid']
  1164. params = hostapd.wpa2_eap_params(ssid="fils")
  1165. params['wpa_key_mgmt'] = "FILS-SHA256"
  1166. params['auth_server_port'] = "18128"
  1167. params['erp_domain'] = 'example.com'
  1168. params['fils_realm'] = 'example.com'
  1169. params['disable_pmksa_caching'] = '1'
  1170. params['fils_dh_group'] = "20"
  1171. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1172. dev[0].scan_for_bss(bssid, freq=2412)
  1173. dev[0].request("ERP_FLUSH")
  1174. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1175. eap="PSK", identity="psk.user@example.com",
  1176. password_hex="0123456789abcdef0123456789abcdef",
  1177. erp="1", fils_dh_group="19", scan_freq="2412")
  1178. dev[0].request("DISCONNECT")
  1179. dev[0].wait_disconnected()
  1180. dev[0].dump_monitor()
  1181. dev[0].select_network(id, freq=2412)
  1182. ev = dev[0].wait_event(["CTRL-EVENT-AUTH-REJECT"], timeout=10)
  1183. dev[0].request("DISCONNECT")
  1184. if ev is None:
  1185. raise Exception("Authentication rejection not seen")
  1186. if "auth_type=5 auth_transaction=2 status_code=77" not in ev:
  1187. raise Exception("Unexpected auth reject value: " + ev)
  1188. def test_fils_sk_auth_mismatch(dev, apdev):
  1189. """FILS SK authentication type mismatch (PFS not supported)"""
  1190. check_fils_sk_pfs_capa(dev[0])
  1191. check_erp_capa(dev[0])
  1192. start_erp_as(apdev[1])
  1193. bssid = apdev[0]['bssid']
  1194. params = hostapd.wpa2_eap_params(ssid="fils")
  1195. params['wpa_key_mgmt'] = "FILS-SHA256"
  1196. params['auth_server_port'] = "18128"
  1197. params['erp_domain'] = 'example.com'
  1198. params['fils_realm'] = 'example.com'
  1199. params['disable_pmksa_caching'] = '1'
  1200. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1201. dev[0].scan_for_bss(bssid, freq=2412)
  1202. dev[0].request("ERP_FLUSH")
  1203. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1204. eap="PSK", identity="psk.user@example.com",
  1205. password_hex="0123456789abcdef0123456789abcdef",
  1206. erp="1", fils_dh_group="19", scan_freq="2412")
  1207. dev[0].request("DISCONNECT")
  1208. dev[0].wait_disconnected()
  1209. dev[0].dump_monitor()
  1210. dev[0].select_network(id, freq=2412)
  1211. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  1212. "EVENT-ASSOC-REJECT",
  1213. "CTRL-EVENT-CONNECTED"], timeout=10)
  1214. if ev is None:
  1215. raise Exception("Connection using FILS/ERP timed out")
  1216. if "CTRL-EVENT-EAP-STARTED" not in ev:
  1217. raise Exception("No EAP exchange seen")
  1218. dev[0].wait_connected()
  1219. hwsim_utils.test_connectivity(dev[0], hapd)
  1220. def test_fils_auth_gtk_rekey(dev, apdev):
  1221. """GTK rekeying after FILS authentication"""
  1222. check_fils_capa(dev[0])
  1223. check_erp_capa(dev[0])
  1224. start_erp_as(apdev[1])
  1225. bssid = apdev[0]['bssid']
  1226. params = hostapd.wpa2_eap_params(ssid="fils")
  1227. params['wpa_key_mgmt'] = "FILS-SHA256"
  1228. params['auth_server_port'] = "18128"
  1229. params['erp_domain'] = 'example.com'
  1230. params['fils_realm'] = 'example.com'
  1231. params['wpa_group_rekey'] = '1'
  1232. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1233. dev[0].scan_for_bss(bssid, freq=2412)
  1234. dev[0].request("ERP_FLUSH")
  1235. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1236. eap="PSK", identity="psk.user@example.com",
  1237. password_hex="0123456789abcdef0123456789abcdef",
  1238. erp="1", scan_freq="2412")
  1239. dev[0].request("DISCONNECT")
  1240. dev[0].wait_disconnected()
  1241. dev[0].dump_monitor()
  1242. dev[0].select_network(id, freq=2412)
  1243. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  1244. "CTRL-EVENT-CONNECTED"], timeout=10)
  1245. if ev is None:
  1246. raise Exception("Connection using PMKSA caching timed out")
  1247. if "CTRL-EVENT-EAP-STARTED" in ev:
  1248. raise Exception("Unexpected EAP exchange")
  1249. dev[0].dump_monitor()
  1250. hwsim_utils.test_connectivity(dev[0], hapd)
  1251. ev = dev[0].wait_event(["WPA: Group rekeying completed"], timeout=2)
  1252. if ev is None:
  1253. raise Exception("GTK rekey timed out")
  1254. hwsim_utils.test_connectivity(dev[0], hapd)
  1255. ev = dev[0].wait_event(["CTRL-EVENT-DISCONNECTED"], timeout=5)
  1256. if ev is not None:
  1257. raise Exception("Rekeying failed - disconnected")
  1258. hwsim_utils.test_connectivity(dev[0], hapd)
  1259. def test_fils_and_ft(dev, apdev):
  1260. """FILS SK using ERP and FT initial mobility domain association"""
  1261. check_fils_capa(dev[0])
  1262. check_erp_capa(dev[0])
  1263. er = start_erp_as(apdev[1])
  1264. bssid = apdev[0]['bssid']
  1265. params = hostapd.wpa2_eap_params(ssid="fils")
  1266. params['wpa_key_mgmt'] = "FILS-SHA256"
  1267. params['auth_server_port'] = "18128"
  1268. params['erp_domain'] = 'example.com'
  1269. params['fils_realm'] = 'example.com'
  1270. params['disable_pmksa_caching'] = '1'
  1271. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1272. dev[0].scan_for_bss(bssid, freq=2412)
  1273. dev[0].request("ERP_FLUSH")
  1274. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1275. eap="PSK", identity="psk.user@example.com",
  1276. password_hex="0123456789abcdef0123456789abcdef",
  1277. erp="1", scan_freq="2412")
  1278. dev[0].request("DISCONNECT")
  1279. dev[0].wait_disconnected()
  1280. hapd.disable()
  1281. dev[0].flush_scan_cache()
  1282. if "FAIL" in dev[0].request("PMKSA_FLUSH"):
  1283. raise Exception("PMKSA_FLUSH failed")
  1284. params = hostapd.wpa2_eap_params(ssid="fils-ft")
  1285. params['wpa_key_mgmt'] = "FILS-SHA256 FT-FILS-SHA256 FT-EAP"
  1286. params['auth_server_port'] = "18128"
  1287. params['erp_domain'] = 'example.com'
  1288. params['fils_realm'] = 'example.com'
  1289. params['disable_pmksa_caching'] = '1'
  1290. params["mobility_domain"] = "a1b2"
  1291. params["r0_key_lifetime"] = "10000"
  1292. params["pmk_r1_push"] = "1"
  1293. params["reassociation_deadline"] = "1000"
  1294. params['nas_identifier'] = "nas1.w1.fi"
  1295. params['r1_key_holder'] = "000102030405"
  1296. params['r0kh'] = [ "02:00:00:00:04:00 nas2.w1.fi 300102030405060708090a0b0c0d0e0f" ]
  1297. params['r1kh'] = "02:00:00:00:04:00 00:01:02:03:04:06 200102030405060708090a0b0c0d0e0f"
  1298. params['ieee80211w'] = "1"
  1299. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1300. dev[0].scan_for_bss(bssid, freq=2412)
  1301. dev[0].dump_monitor()
  1302. id = dev[0].connect("fils-ft", key_mgmt="FILS-SHA256 FT-FILS-SHA256 FT-EAP",
  1303. ieee80211w="1",
  1304. eap="PSK", identity="psk.user@example.com",
  1305. password_hex="0123456789abcdef0123456789abcdef",
  1306. erp="1", scan_freq="2412", wait_connect=False)
  1307. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  1308. "CTRL-EVENT-AUTH-REJECT",
  1309. "EVENT-ASSOC-REJECT",
  1310. "CTRL-EVENT-CONNECTED"], timeout=10)
  1311. if ev is None:
  1312. raise Exception("Connection using FILS/ERP timed out")
  1313. if "CTRL-EVENT-EAP-STARTED" in ev:
  1314. raise Exception("Unexpected EAP exchange")
  1315. if "CTRL-EVENT-AUTH-REJECT" in ev:
  1316. raise Exception("Authentication failed")
  1317. if "EVENT-ASSOC-REJECT" in ev:
  1318. raise Exception("Association failed")
  1319. hwsim_utils.test_connectivity(dev[0], hapd)
  1320. er.disable()
  1321. # FIX: FT-FILS-SHA256 does not currently work for FT protocol due to not
  1322. # fully defined FT Reassociation Request/Response frame MIC use in FTE.
  1323. # FT-EAP can be used to work around that in this test case to confirm the
  1324. # FT key hierarchy was properly formed in the previous step.
  1325. #params['wpa_key_mgmt'] = "FILS-SHA256 FT-FILS-SHA256"
  1326. params['wpa_key_mgmt'] = "FT-EAP"
  1327. params['nas_identifier'] = "nas2.w1.fi"
  1328. params['r1_key_holder'] = "000102030406"
  1329. params['r0kh'] = [ "02:00:00:00:03:00 nas1.w1.fi 200102030405060708090a0b0c0d0e0f" ]
  1330. params['r1kh'] = "02:00:00:00:03:00 00:01:02:03:04:05 300102030405060708090a0b0c0d0e0f"
  1331. hapd2 = hostapd.add_ap(apdev[1]['ifname'], params)
  1332. dev[0].scan_for_bss(apdev[1]['bssid'], freq="2412", force_scan=True)
  1333. # FIX: Cannot use FT-over-DS without the FTE MIC issue addressed
  1334. #dev[0].roam_over_ds(apdev[1]['bssid'])
  1335. dev[0].roam(apdev[1]['bssid'])