test_fils.py 61 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614
  1. # Test cases for FILS
  2. # Copyright (c) 2015-2017, Qualcomm Atheros, Inc.
  3. #
  4. # This software may be distributed under the terms of the BSD license.
  5. # See README for more details.
  6. import binascii
  7. import hashlib
  8. import logging
  9. logger = logging.getLogger()
  10. import os
  11. import socket
  12. import struct
  13. import time
  14. import hostapd
  15. from wpasupplicant import WpaSupplicant
  16. import hwsim_utils
  17. from utils import HwsimSkip, alloc_fail
  18. from test_erp import check_erp_capa, start_erp_as
  19. from test_ap_hs20 import ip_checksum
  20. def check_fils_capa(dev):
  21. capa = dev.get_capability("fils")
  22. if capa is None or "FILS" not in capa:
  23. raise HwsimSkip("FILS not supported")
  24. def check_fils_sk_pfs_capa(dev):
  25. capa = dev.get_capability("fils")
  26. if capa is None or "FILS-SK-PFS" not in capa:
  27. raise HwsimSkip("FILS-SK-PFS not supported")
  28. def test_fils_sk_full_auth(dev, apdev):
  29. """FILS SK full authentication"""
  30. check_fils_capa(dev[0])
  31. check_erp_capa(dev[0])
  32. start_erp_as(apdev[1])
  33. bssid = apdev[0]['bssid']
  34. params = hostapd.wpa2_eap_params(ssid="fils")
  35. params['wpa_key_mgmt'] = "FILS-SHA256"
  36. params['auth_server_port'] = "18128"
  37. params['erp_send_reauth_start'] = '1'
  38. params['erp_domain'] = 'example.com'
  39. params['fils_realm'] = 'example.com'
  40. params['wpa_group_rekey'] = '1'
  41. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  42. dev[0].scan_for_bss(bssid, freq=2412)
  43. bss = dev[0].get_bss(bssid)
  44. logger.debug("BSS: " + str(bss))
  45. if "[FILS]" not in bss['flags']:
  46. raise Exception("[FILS] flag not indicated")
  47. if "[WPA2-FILS-SHA256-CCMP]" not in bss['flags']:
  48. raise Exception("[WPA2-FILS-SHA256-CCMP] flag not indicated")
  49. res = dev[0].request("SCAN_RESULTS")
  50. logger.debug("SCAN_RESULTS: " + res)
  51. if "[FILS]" not in res:
  52. raise Exception("[FILS] flag not indicated")
  53. if "[WPA2-FILS-SHA256-CCMP]" not in res:
  54. raise Exception("[WPA2-FILS-SHA256-CCMP] flag not indicated")
  55. dev[0].request("ERP_FLUSH")
  56. dev[0].connect("fils", key_mgmt="FILS-SHA256",
  57. eap="PSK", identity="psk.user@example.com",
  58. password_hex="0123456789abcdef0123456789abcdef",
  59. erp="1", scan_freq="2412")
  60. hwsim_utils.test_connectivity(dev[0], hapd)
  61. ev = dev[0].wait_event(["WPA: Group rekeying completed"], timeout=2)
  62. if ev is None:
  63. raise Exception("GTK rekey timed out")
  64. hwsim_utils.test_connectivity(dev[0], hapd)
  65. conf = hapd.get_config()
  66. if conf['key_mgmt'] != 'FILS-SHA256':
  67. raise Exception("Unexpected config key_mgmt: " + conf['key_mgmt'])
  68. def test_fils_sk_sha384_full_auth(dev, apdev):
  69. """FILS SK full authentication (SHA384)"""
  70. check_fils_capa(dev[0])
  71. check_erp_capa(dev[0])
  72. start_erp_as(apdev[1])
  73. bssid = apdev[0]['bssid']
  74. params = hostapd.wpa2_eap_params(ssid="fils")
  75. params['wpa_key_mgmt'] = "FILS-SHA384"
  76. params['auth_server_port'] = "18128"
  77. params['erp_send_reauth_start'] = '1'
  78. params['erp_domain'] = 'example.com'
  79. params['fils_realm'] = 'example.com'
  80. params['wpa_group_rekey'] = '1'
  81. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  82. dev[0].scan_for_bss(bssid, freq=2412)
  83. bss = dev[0].get_bss(bssid)
  84. logger.debug("BSS: " + str(bss))
  85. if "[FILS]" not in bss['flags']:
  86. raise Exception("[FILS] flag not indicated")
  87. if "[WPA2-FILS-SHA384-CCMP]" not in bss['flags']:
  88. raise Exception("[WPA2-FILS-SHA384-CCMP] flag not indicated")
  89. res = dev[0].request("SCAN_RESULTS")
  90. logger.debug("SCAN_RESULTS: " + res)
  91. if "[FILS]" not in res:
  92. raise Exception("[FILS] flag not indicated")
  93. if "[WPA2-FILS-SHA384-CCMP]" not in res:
  94. raise Exception("[WPA2-FILS-SHA384-CCMP] flag not indicated")
  95. dev[0].request("ERP_FLUSH")
  96. dev[0].connect("fils", key_mgmt="FILS-SHA384",
  97. eap="PSK", identity="psk.user@example.com",
  98. password_hex="0123456789abcdef0123456789abcdef",
  99. erp="1", scan_freq="2412")
  100. hwsim_utils.test_connectivity(dev[0], hapd)
  101. ev = dev[0].wait_event(["WPA: Group rekeying completed"], timeout=2)
  102. if ev is None:
  103. raise Exception("GTK rekey timed out")
  104. hwsim_utils.test_connectivity(dev[0], hapd)
  105. conf = hapd.get_config()
  106. if conf['key_mgmt'] != 'FILS-SHA384':
  107. raise Exception("Unexpected config key_mgmt: " + conf['key_mgmt'])
  108. def test_fils_sk_pmksa_caching(dev, apdev):
  109. """FILS SK and PMKSA caching"""
  110. check_fils_capa(dev[0])
  111. check_erp_capa(dev[0])
  112. start_erp_as(apdev[1])
  113. bssid = apdev[0]['bssid']
  114. params = hostapd.wpa2_eap_params(ssid="fils")
  115. params['wpa_key_mgmt'] = "FILS-SHA256"
  116. params['auth_server_port'] = "18128"
  117. params['erp_domain'] = 'example.com'
  118. params['fils_realm'] = 'example.com'
  119. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  120. dev[0].scan_for_bss(bssid, freq=2412)
  121. dev[0].request("ERP_FLUSH")
  122. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  123. eap="PSK", identity="psk.user@example.com",
  124. password_hex="0123456789abcdef0123456789abcdef",
  125. erp="1", scan_freq="2412")
  126. pmksa = dev[0].get_pmksa(bssid)
  127. if pmksa is None:
  128. raise Exception("No PMKSA cache entry created")
  129. dev[0].request("DISCONNECT")
  130. dev[0].wait_disconnected()
  131. dev[0].dump_monitor()
  132. dev[0].select_network(id, freq=2412)
  133. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  134. "CTRL-EVENT-CONNECTED"], timeout=10)
  135. if ev is None:
  136. raise Exception("Connection using PMKSA caching timed out")
  137. if "CTRL-EVENT-EAP-STARTED" in ev:
  138. raise Exception("Unexpected EAP exchange")
  139. hwsim_utils.test_connectivity(dev[0], hapd)
  140. pmksa2 = dev[0].get_pmksa(bssid)
  141. if pmksa2 is None:
  142. raise Exception("No PMKSA cache entry found")
  143. if pmksa['pmkid'] != pmksa2['pmkid']:
  144. raise Exception("Unexpected PMKID change")
  145. # Verify EAPOL reauthentication after FILS authentication
  146. hapd.request("EAPOL_REAUTH " + dev[0].own_addr())
  147. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED"], timeout=5)
  148. if ev is None:
  149. raise Exception("EAP authentication did not start")
  150. ev = dev[0].wait_event(["CTRL-EVENT-EAP-SUCCESS"], timeout=5)
  151. if ev is None:
  152. raise Exception("EAP authentication did not succeed")
  153. time.sleep(0.1)
  154. hwsim_utils.test_connectivity(dev[0], hapd)
  155. def test_fils_sk_pmksa_caching_and_cache_id(dev, apdev):
  156. """FILS SK and PMKSA caching with Cache Identifier"""
  157. check_fils_capa(dev[0])
  158. check_erp_capa(dev[0])
  159. bssid = apdev[0]['bssid']
  160. params = hostapd.wpa2_eap_params(ssid="fils")
  161. params['wpa_key_mgmt'] = "FILS-SHA256"
  162. params['auth_server_port'] = "18128"
  163. params['erp_domain'] = 'example.com'
  164. params['fils_realm'] = 'example.com'
  165. params['fils_cache_id'] = "abcd"
  166. params["radius_server_clients"] = "auth_serv/radius_clients.conf"
  167. params["radius_server_auth_port"] = '18128'
  168. params["eap_server"] = "1"
  169. params["eap_user_file"] = "auth_serv/eap_user.conf"
  170. params["ca_cert"] = "auth_serv/ca.pem"
  171. params["server_cert"] = "auth_serv/server.pem"
  172. params["private_key"] = "auth_serv/server.key"
  173. params["eap_sim_db"] = "unix:/tmp/hlr_auc_gw.sock"
  174. params["dh_file"] = "auth_serv/dh.conf"
  175. params["pac_opaque_encr_key"] = "000102030405060708090a0b0c0d0e0f"
  176. params["eap_fast_a_id"] = "101112131415161718191a1b1c1d1e1f"
  177. params["eap_fast_a_id_info"] = "test server"
  178. params["eap_server_erp"] = "1"
  179. params["erp_domain"] = "example.com"
  180. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  181. dev[0].scan_for_bss(bssid, freq=2412)
  182. dev[0].request("ERP_FLUSH")
  183. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  184. eap="PSK", identity="psk.user@example.com",
  185. password_hex="0123456789abcdef0123456789abcdef",
  186. erp="1", scan_freq="2412")
  187. res = dev[0].request("PMKSA")
  188. if "FILS Cache Identifier" not in res:
  189. raise Exception("PMKSA list does not include FILS Cache Identifier")
  190. pmksa = dev[0].get_pmksa(bssid)
  191. if pmksa is None:
  192. raise Exception("No PMKSA cache entry created")
  193. if "cache_id" not in pmksa:
  194. raise Exception("No FILS Cache Identifier listed")
  195. if pmksa["cache_id"] != "abcd":
  196. raise Exception("The configured FILS Cache Identifier not seen in PMKSA")
  197. bssid2 = apdev[1]['bssid']
  198. params = hostapd.wpa2_eap_params(ssid="fils")
  199. params['wpa_key_mgmt'] = "FILS-SHA256"
  200. params['auth_server_port'] = "18128"
  201. params['erp_domain'] = 'example.com'
  202. params['fils_realm'] = 'example.com'
  203. params['fils_cache_id'] = "abcd"
  204. hapd2 = hostapd.add_ap(apdev[1]['ifname'], params)
  205. dev[0].scan_for_bss(bssid2, freq=2412)
  206. dev[0].dump_monitor()
  207. if "OK" not in dev[0].request("ROAM " + bssid2):
  208. raise Exception("ROAM failed")
  209. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  210. "CTRL-EVENT-CONNECTED"], timeout=10)
  211. if ev is None:
  212. raise Exception("Connection using PMKSA caching timed out")
  213. if "CTRL-EVENT-EAP-STARTED" in ev:
  214. raise Exception("Unexpected EAP exchange")
  215. if bssid2 not in ev:
  216. raise Exception("Failed to connect to the second AP")
  217. hwsim_utils.test_connectivity(dev[0], hapd2)
  218. pmksa2 = dev[0].get_pmksa(bssid2)
  219. if pmksa2:
  220. raise Exception("Unexpected extra PMKSA cache added")
  221. pmksa2 = dev[0].get_pmksa(bssid)
  222. if not pmksa2:
  223. raise Exception("Original PMKSA cache entry removed")
  224. if pmksa['pmkid'] != pmksa2['pmkid']:
  225. raise Exception("Unexpected PMKID change")
  226. def test_fils_sk_pmksa_caching_ctrl_ext(dev, apdev):
  227. """FILS SK and PMKSA caching with Cache Identifier and external management"""
  228. check_fils_capa(dev[0])
  229. check_erp_capa(dev[0])
  230. hapd_as = start_erp_as(apdev[1])
  231. bssid = apdev[0]['bssid']
  232. params = hostapd.wpa2_eap_params(ssid="fils")
  233. params['wpa_key_mgmt'] = "FILS-SHA384"
  234. params['auth_server_port'] = "18128"
  235. params['erp_send_reauth_start'] = '1'
  236. params['erp_domain'] = 'example.com'
  237. params['fils_realm'] = 'example.com'
  238. params['fils_cache_id'] = "ffee"
  239. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  240. dev[0].scan_for_bss(bssid, freq=2412)
  241. dev[0].request("ERP_FLUSH")
  242. id = dev[0].connect("fils", key_mgmt="FILS-SHA384",
  243. eap="PSK", identity="psk.user@example.com",
  244. password_hex="0123456789abcdef0123456789abcdef",
  245. erp="1", scan_freq="2412")
  246. res1 = dev[0].request("PMKSA_GET %d" % id)
  247. logger.info("PMKSA_GET: " + res1)
  248. if "UNKNOWN COMMAND" in res1:
  249. raise HwsimSkip("PMKSA_GET not supported in the build")
  250. if bssid not in res1:
  251. raise Exception("PMKSA cache entry missing")
  252. if "ffee" not in res1:
  253. raise Exception("FILS Cache Identifier not seen in PMKSA cache entry")
  254. dev[0].request("DISCONNECT")
  255. dev[0].wait_disconnected()
  256. hapd_as.disable()
  257. dev[0].scan_for_bss(bssid, freq=2412)
  258. dev[0].request("PMKSA_FLUSH")
  259. dev[0].request("ERP_FLUSH")
  260. for entry in res1.splitlines():
  261. if "OK" not in dev[0].request("PMKSA_ADD %d %s" % (id, entry)):
  262. raise Exception("Failed to add PMKSA entry")
  263. bssid2 = apdev[1]['bssid']
  264. params = hostapd.wpa2_eap_params(ssid="fils")
  265. params['wpa_key_mgmt'] = "FILS-SHA384"
  266. params['auth_server_port'] = "18128"
  267. params['erp_send_reauth_start'] = '1'
  268. params['erp_domain'] = 'example.com'
  269. params['fils_realm'] = 'example.com'
  270. params['fils_cache_id'] = "ffee"
  271. hapd2 = hostapd.add_ap(apdev[1]['ifname'], params)
  272. dev[0].scan_for_bss(bssid2, freq=2412)
  273. dev[0].set_network(id, "bssid", bssid2)
  274. dev[0].select_network(id, freq=2412)
  275. ev = dev[0].wait_connected()
  276. if bssid2 not in ev:
  277. raise Exception("Unexpected BSS selected")
  278. def test_fils_sk_erp(dev, apdev):
  279. """FILS SK using ERP"""
  280. run_fils_sk_erp(dev, apdev, "FILS-SHA256")
  281. def test_fils_sk_erp_sha384(dev, apdev):
  282. """FILS SK using ERP and SHA384"""
  283. run_fils_sk_erp(dev, apdev, "FILS-SHA384")
  284. def run_fils_sk_erp(dev, apdev, key_mgmt):
  285. check_fils_capa(dev[0])
  286. check_erp_capa(dev[0])
  287. start_erp_as(apdev[1])
  288. bssid = apdev[0]['bssid']
  289. params = hostapd.wpa2_eap_params(ssid="fils")
  290. params['wpa_key_mgmt'] = key_mgmt
  291. params['auth_server_port'] = "18128"
  292. params['erp_domain'] = 'example.com'
  293. params['fils_realm'] = 'example.com'
  294. params['disable_pmksa_caching'] = '1'
  295. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  296. dev[0].scan_for_bss(bssid, freq=2412)
  297. dev[0].request("ERP_FLUSH")
  298. id = dev[0].connect("fils", key_mgmt=key_mgmt,
  299. eap="PSK", identity="psk.user@example.com",
  300. password_hex="0123456789abcdef0123456789abcdef",
  301. erp="1", scan_freq="2412")
  302. dev[0].request("DISCONNECT")
  303. dev[0].wait_disconnected()
  304. dev[0].dump_monitor()
  305. dev[0].select_network(id, freq=2412)
  306. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  307. "EVENT-ASSOC-REJECT",
  308. "CTRL-EVENT-CONNECTED"], timeout=10)
  309. if ev is None:
  310. raise Exception("Connection using FILS/ERP timed out")
  311. if "CTRL-EVENT-EAP-STARTED" in ev:
  312. raise Exception("Unexpected EAP exchange")
  313. if "EVENT-ASSOC-REJECT" in ev:
  314. raise Exception("Association failed")
  315. hwsim_utils.test_connectivity(dev[0], hapd)
  316. def test_fils_sk_erp_followed_by_pmksa_caching(dev, apdev):
  317. check_fils_capa(dev[0])
  318. check_erp_capa(dev[0])
  319. start_erp_as(apdev[1])
  320. bssid = apdev[0]['bssid']
  321. params = hostapd.wpa2_eap_params(ssid="fils")
  322. params['wpa_key_mgmt'] = "FILS-SHA256"
  323. params['auth_server_port'] = "18128"
  324. params['erp_domain'] = 'example.com'
  325. params['fils_realm'] = 'example.com'
  326. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  327. dev[0].scan_for_bss(bssid, freq=2412)
  328. dev[0].request("ERP_FLUSH")
  329. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  330. eap="PSK", identity="psk.user@example.com",
  331. password_hex="0123456789abcdef0123456789abcdef",
  332. erp="1", scan_freq="2412")
  333. dev[0].request("DISCONNECT")
  334. dev[0].wait_disconnected()
  335. # Force the second connection to use ERP by deleting the PMKSA entry.
  336. dev[0].request("PMKSA_FLUSH")
  337. dev[0].dump_monitor()
  338. dev[0].select_network(id, freq=2412)
  339. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  340. "EVENT-ASSOC-REJECT",
  341. "CTRL-EVENT-CONNECTED"], timeout=10)
  342. if ev is None:
  343. raise Exception("Connection using FILS/ERP timed out")
  344. if "CTRL-EVENT-EAP-STARTED" in ev:
  345. raise Exception("Unexpected EAP exchange")
  346. if "EVENT-ASSOC-REJECT" in ev:
  347. raise Exception("Association failed")
  348. hwsim_utils.test_connectivity(dev[0], hapd)
  349. pmksa = dev[0].get_pmksa(bssid)
  350. if pmksa is None:
  351. raise Exception("No PMKSA cache entry created")
  352. dev[0].request("DISCONNECT")
  353. dev[0].wait_disconnected()
  354. # The third connection is expected to use PMKSA caching for FILS
  355. # authentication.
  356. dev[0].dump_monitor()
  357. dev[0].select_network(id, freq=2412)
  358. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  359. "EVENT-ASSOC-REJECT",
  360. "CTRL-EVENT-CONNECTED"], timeout=10)
  361. if ev is None:
  362. raise Exception("Connection using PMKSA caching timed out")
  363. if "CTRL-EVENT-EAP-STARTED" in ev:
  364. raise Exception("Unexpected EAP exchange")
  365. if "EVENT-ASSOC-REJECT" in ev:
  366. raise Exception("Association failed")
  367. hwsim_utils.test_connectivity(dev[0], hapd)
  368. pmksa2 = dev[0].get_pmksa(bssid)
  369. if pmksa2 is None:
  370. raise Exception("No PMKSA cache entry found")
  371. if pmksa['pmkid'] != pmksa2['pmkid']:
  372. raise Exception("Unexpected PMKID change")
  373. def test_fils_sk_erp_another_ssid(dev, apdev):
  374. """FILS SK using ERP and roam to another SSID"""
  375. check_fils_capa(dev[0])
  376. check_erp_capa(dev[0])
  377. start_erp_as(apdev[1])
  378. bssid = apdev[0]['bssid']
  379. params = hostapd.wpa2_eap_params(ssid="fils")
  380. params['wpa_key_mgmt'] = "FILS-SHA256"
  381. params['auth_server_port'] = "18128"
  382. params['erp_domain'] = 'example.com'
  383. params['fils_realm'] = 'example.com'
  384. params['disable_pmksa_caching'] = '1'
  385. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  386. dev[0].scan_for_bss(bssid, freq=2412)
  387. dev[0].request("ERP_FLUSH")
  388. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  389. eap="PSK", identity="psk.user@example.com",
  390. password_hex="0123456789abcdef0123456789abcdef",
  391. erp="1", scan_freq="2412")
  392. dev[0].request("DISCONNECT")
  393. dev[0].wait_disconnected()
  394. hapd.disable()
  395. dev[0].flush_scan_cache()
  396. if "FAIL" in dev[0].request("PMKSA_FLUSH"):
  397. raise Exception("PMKSA_FLUSH failed")
  398. params = hostapd.wpa2_eap_params(ssid="fils2")
  399. params['wpa_key_mgmt'] = "FILS-SHA256"
  400. params['auth_server_port'] = "18128"
  401. params['erp_domain'] = 'example.com'
  402. params['fils_realm'] = 'example.com'
  403. params['disable_pmksa_caching'] = '1'
  404. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  405. dev[0].scan_for_bss(bssid, freq=2412)
  406. dev[0].dump_monitor()
  407. id = dev[0].connect("fils2", key_mgmt="FILS-SHA256",
  408. eap="PSK", identity="psk.user@example.com",
  409. password_hex="0123456789abcdef0123456789abcdef",
  410. erp="1", scan_freq="2412", wait_connect=False)
  411. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  412. "EVENT-ASSOC-REJECT",
  413. "CTRL-EVENT-CONNECTED"], timeout=10)
  414. if ev is None:
  415. raise Exception("Connection using FILS/ERP timed out")
  416. if "CTRL-EVENT-EAP-STARTED" in ev:
  417. raise Exception("Unexpected EAP exchange")
  418. if "EVENT-ASSOC-REJECT" in ev:
  419. raise Exception("Association failed")
  420. hwsim_utils.test_connectivity(dev[0], hapd)
  421. def test_fils_sk_multiple_realms(dev, apdev):
  422. """FILS SK and multiple realms"""
  423. check_fils_capa(dev[0])
  424. check_erp_capa(dev[0])
  425. start_erp_as(apdev[1])
  426. bssid = apdev[0]['bssid']
  427. params = hostapd.wpa2_eap_params(ssid="fils")
  428. params['wpa_key_mgmt'] = "FILS-SHA256"
  429. params['auth_server_port'] = "18128"
  430. params['erp_domain'] = 'example.com'
  431. fils_realms = [ 'r1.example.org', 'r2.EXAMPLE.org', 'r3.example.org',
  432. 'r4.example.org', 'r5.example.org', 'r6.example.org',
  433. 'r7.example.org', 'r8.example.org',
  434. 'example.com',
  435. 'r9.example.org', 'r10.example.org', 'r11.example.org',
  436. 'r12.example.org', 'r13.example.org', 'r14.example.org',
  437. 'r15.example.org', 'r16.example.org' ]
  438. params['fils_realm'] = fils_realms
  439. params['fils_cache_id'] = "1234"
  440. params['hessid'] = bssid
  441. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  442. dev[0].scan_for_bss(bssid, freq=2412)
  443. if "OK" not in dev[0].request("ANQP_GET " + bssid + " 275"):
  444. raise Exception("ANQP_GET command failed")
  445. ev = dev[0].wait_event(["GAS-QUERY-DONE"], timeout=10)
  446. if ev is None:
  447. raise Exception("GAS query timed out")
  448. bss = dev[0].get_bss(bssid)
  449. if 'fils_info' not in bss:
  450. raise Exception("FILS Indication element information missing")
  451. if bss['fils_info'] != '02b8':
  452. raise Exception("Unexpected FILS Information: " + bss['fils_info'])
  453. if 'fils_cache_id' not in bss:
  454. raise Exception("FILS Cache Identifier missing")
  455. if bss['fils_cache_id'] != '1234':
  456. raise Exception("Unexpected FILS Cache Identifier: " + bss['fils_cache_id'])
  457. if 'fils_realms' not in bss:
  458. raise Exception("FILS Realm Identifiers missing")
  459. expected = ''
  460. count = 0
  461. for realm in fils_realms:
  462. hash = hashlib.sha256(realm.lower()).digest()
  463. expected += binascii.hexlify(hash[0:2])
  464. count += 1
  465. if count == 7:
  466. break
  467. if bss['fils_realms'] != expected:
  468. raise Exception("Unexpected FILS Realm Identifiers: " + bss['fils_realms'])
  469. if 'anqp_fils_realm_info' not in bss:
  470. raise Exception("FILS Realm Information ANQP-element not seen")
  471. info = bss['anqp_fils_realm_info'];
  472. expected = ''
  473. for realm in fils_realms:
  474. hash = hashlib.sha256(realm.lower()).digest()
  475. expected += binascii.hexlify(hash[0:2])
  476. if info != expected:
  477. raise Exception("Unexpected FILS Realm Info ANQP-element: " + info)
  478. dev[0].request("ERP_FLUSH")
  479. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  480. eap="PSK", identity="psk.user@example.com",
  481. password_hex="0123456789abcdef0123456789abcdef",
  482. erp="1", scan_freq="2412")
  483. dev[0].request("DISCONNECT")
  484. dev[0].wait_disconnected()
  485. dev[0].dump_monitor()
  486. dev[0].select_network(id, freq=2412)
  487. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  488. "EVENT-ASSOC-REJECT",
  489. "CTRL-EVENT-CONNECTED"], timeout=10)
  490. if ev is None:
  491. raise Exception("Connection using FILS/ERP timed out")
  492. if "CTRL-EVENT-EAP-STARTED" in ev:
  493. raise Exception("Unexpected EAP exchange")
  494. if "EVENT-ASSOC-REJECT" in ev:
  495. raise Exception("Association failed")
  496. hwsim_utils.test_connectivity(dev[0], hapd)
  497. # DHCP message op codes
  498. BOOTREQUEST=1
  499. BOOTREPLY=2
  500. OPT_PAD=0
  501. OPT_DHCP_MESSAGE_TYPE=53
  502. OPT_RAPID_COMMIT=80
  503. OPT_END=255
  504. DHCPDISCOVER=1
  505. DHCPOFFER=2
  506. DHCPREQUEST=3
  507. DHCPDECLINE=4
  508. DHCPACK=5
  509. DHCPNAK=6
  510. DHCPRELEASE=7
  511. DHCPINFORM=8
  512. def build_dhcp(req, dhcp_msg, chaddr, giaddr="0.0.0.0",
  513. ip_src="0.0.0.0", ip_dst="255.255.255.255",
  514. rapid_commit=True, override_op=None, magic_override=None,
  515. opt_end=True, extra_op=None):
  516. proto = '\x08\x00' # IPv4
  517. _ip_src = socket.inet_pton(socket.AF_INET, ip_src)
  518. _ip_dst = socket.inet_pton(socket.AF_INET, ip_dst)
  519. _ciaddr = '\x00\x00\x00\x00'
  520. _yiaddr = '\x00\x00\x00\x00'
  521. _siaddr = '\x00\x00\x00\x00'
  522. _giaddr = socket.inet_pton(socket.AF_INET, giaddr)
  523. _chaddr = binascii.unhexlify(chaddr.replace(':','')) + 10*'\x00'
  524. htype = 1 # Hardware address type; 1 = Ethernet
  525. hlen = 6 # Hardware address length
  526. hops = 0
  527. xid = 123456
  528. secs = 0
  529. flags = 0
  530. if req:
  531. op = BOOTREQUEST
  532. src_port = 68
  533. dst_port = 67
  534. else:
  535. op = BOOTREPLY
  536. src_port = 67
  537. dst_port = 68
  538. if override_op is not None:
  539. op = override_op
  540. payload = struct.pack('>BBBBLHH', op, htype, hlen, hops, xid, secs, flags)
  541. sname = 64*'\x00'
  542. file = 128*'\x00'
  543. payload += _ciaddr + _yiaddr + _siaddr + _giaddr + _chaddr + sname + file
  544. # magic - DHCP
  545. if magic_override is not None:
  546. payload += magic_override
  547. else:
  548. payload += '\x63\x82\x53\x63'
  549. # Option: DHCP Message Type
  550. if dhcp_msg is not None:
  551. payload += struct.pack('BBB', OPT_DHCP_MESSAGE_TYPE, 1, dhcp_msg)
  552. if rapid_commit:
  553. # Option: Rapid Commit
  554. payload += struct.pack('BB', OPT_RAPID_COMMIT, 0)
  555. if extra_op:
  556. payload += extra_op
  557. # End Option
  558. if opt_end:
  559. payload += struct.pack('B', OPT_END)
  560. udp = struct.pack('>HHHH', src_port, dst_port,
  561. 8 + len(payload), 0) + payload
  562. tot_len = 20 + len(udp)
  563. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  564. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  565. csum = ip_checksum(ipv4)
  566. ipv4 = start + csum + _ip_src + _ip_dst
  567. return proto + ipv4 + udp
  568. def fils_hlp_config(fils_hlp_wait_time=10000):
  569. params = hostapd.wpa2_eap_params(ssid="fils")
  570. params['wpa_key_mgmt'] = "FILS-SHA256"
  571. params['auth_server_port'] = "18128"
  572. params['erp_domain'] = 'example.com'
  573. params['fils_realm'] = 'example.com'
  574. params['disable_pmksa_caching'] = '1'
  575. params['own_ip_addr'] = '127.0.0.3'
  576. params['dhcp_server'] = '127.0.0.2'
  577. params['fils_hlp_wait_time'] = str(fils_hlp_wait_time)
  578. return params
  579. def test_fils_sk_hlp(dev, apdev):
  580. """FILS SK HLP (rapid commit server)"""
  581. run_fils_sk_hlp(dev, apdev, True)
  582. def test_fils_sk_hlp_no_rapid_commit(dev, apdev):
  583. """FILS SK HLP (no rapid commit server)"""
  584. run_fils_sk_hlp(dev, apdev, False)
  585. def run_fils_sk_hlp(dev, apdev, rapid_commit_server):
  586. check_fils_capa(dev[0])
  587. check_erp_capa(dev[0])
  588. start_erp_as(apdev[1])
  589. sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
  590. sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
  591. sock.settimeout(5)
  592. sock.bind(("127.0.0.2", 67))
  593. bssid = apdev[0]['bssid']
  594. params = fils_hlp_config()
  595. params['fils_hlp_wait_time'] = '10000'
  596. if not rapid_commit_server:
  597. params['dhcp_rapid_commit_proxy'] = '1'
  598. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  599. dev[0].scan_for_bss(bssid, freq=2412)
  600. dev[0].request("ERP_FLUSH")
  601. if "OK" not in dev[0].request("FILS_HLP_REQ_FLUSH"):
  602. raise Exception("Failed to flush pending FILS HLP requests")
  603. tests = [ "",
  604. "q",
  605. "ff:ff:ff:ff:ff:ff",
  606. "ff:ff:ff:ff:ff:ff q" ]
  607. for t in tests:
  608. if "FAIL" not in dev[0].request("FILS_HLP_REQ_ADD " + t):
  609. raise Exception("Invalid FILS_HLP_REQ_ADD accepted: " + t)
  610. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  611. chaddr=dev[0].own_addr())
  612. tests = [ "ff:ff:ff:ff:ff:ff aabb",
  613. "ff:ff:ff:ff:ff:ff " + 255*'cc',
  614. hapd.own_addr() + " ddee010203040506070809",
  615. "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc) ]
  616. for t in tests:
  617. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + t):
  618. raise Exception("FILS_HLP_REQ_ADD failed: " + t)
  619. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  620. eap="PSK", identity="psk.user@example.com",
  621. password_hex="0123456789abcdef0123456789abcdef",
  622. erp="1", scan_freq="2412")
  623. dev[0].request("DISCONNECT")
  624. dev[0].wait_disconnected()
  625. dev[0].dump_monitor()
  626. dev[0].select_network(id, freq=2412)
  627. (msg,addr) = sock.recvfrom(1000)
  628. logger.debug("Received DHCP message from %s" % str(addr))
  629. if rapid_commit_server:
  630. # TODO: Proper rapid commit response
  631. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPACK,
  632. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  633. sock.sendto(dhcpdisc[2+20+8:], addr)
  634. else:
  635. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  636. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  637. sock.sendto(dhcpdisc[2+20+8:], addr)
  638. (msg,addr) = sock.recvfrom(1000)
  639. logger.debug("Received DHCP message from %s" % str(addr))
  640. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPACK, rapid_commit=False,
  641. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  642. sock.sendto(dhcpdisc[2+20+8:], addr)
  643. ev = dev[0].wait_event(["FILS-HLP-RX"], timeout=10)
  644. if ev is None:
  645. raise Exception("FILS HLP response not reported")
  646. vals = ev.split(' ')
  647. frame = binascii.unhexlify(vals[3].split('=')[1])
  648. proto, = struct.unpack('>H', frame[0:2])
  649. if proto != 0x0800:
  650. raise Exception("Unexpected ethertype in HLP response: %d" % proto)
  651. frame = frame[2:]
  652. ip = frame[0:20]
  653. if ip_checksum(ip) != '\x00\x00':
  654. raise Exception("IP header checksum mismatch in HLP response")
  655. frame = frame[20:]
  656. udp = frame[0:8]
  657. frame = frame[8:]
  658. sport, dport, ulen, ucheck = struct.unpack('>HHHH', udp)
  659. if sport != 67 or dport != 68:
  660. raise Exception("Unexpected UDP port in HLP response")
  661. dhcp = frame[0:28]
  662. frame = frame[28:]
  663. op,htype,hlen,hops,xid,secs,flags,ciaddr,yiaddr,siaddr,giaddr = struct.unpack('>4BL2H4L', dhcp)
  664. chaddr = frame[0:16]
  665. frame = frame[16:]
  666. sname = frame[0:64]
  667. frame = frame[64:]
  668. file = frame[0:128]
  669. frame = frame[128:]
  670. options = frame
  671. if options[0:4] != '\x63\x82\x53\x63':
  672. raise Exception("No DHCP magic seen in HLP response")
  673. options = options[4:]
  674. # TODO: fully parse and validate DHCPACK options
  675. if struct.pack('BBB', OPT_DHCP_MESSAGE_TYPE, 1, DHCPACK) not in options:
  676. raise Exception("DHCPACK not in HLP response")
  677. dev[0].wait_connected()
  678. dev[0].request("FILS_HLP_REQ_FLUSH")
  679. def test_fils_sk_hlp_timeout(dev, apdev):
  680. """FILS SK HLP (rapid commit server timeout)"""
  681. check_fils_capa(dev[0])
  682. check_erp_capa(dev[0])
  683. start_erp_as(apdev[1])
  684. sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
  685. sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
  686. sock.settimeout(5)
  687. sock.bind(("127.0.0.2", 67))
  688. bssid = apdev[0]['bssid']
  689. params = fils_hlp_config(fils_hlp_wait_time=30)
  690. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  691. dev[0].scan_for_bss(bssid, freq=2412)
  692. dev[0].request("ERP_FLUSH")
  693. if "OK" not in dev[0].request("FILS_HLP_REQ_FLUSH"):
  694. raise Exception("Failed to flush pending FILS HLP requests")
  695. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  696. chaddr=dev[0].own_addr())
  697. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc)):
  698. raise Exception("FILS_HLP_REQ_ADD failed")
  699. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  700. eap="PSK", identity="psk.user@example.com",
  701. password_hex="0123456789abcdef0123456789abcdef",
  702. erp="1", scan_freq="2412")
  703. dev[0].request("DISCONNECT")
  704. dev[0].wait_disconnected()
  705. dev[0].dump_monitor()
  706. dev[0].select_network(id, freq=2412)
  707. (msg,addr) = sock.recvfrom(1000)
  708. logger.debug("Received DHCP message from %s" % str(addr))
  709. # Wait for HLP wait timeout to hit
  710. # FILS: HLP response timeout - continue with association response
  711. dev[0].wait_connected()
  712. dev[0].request("FILS_HLP_REQ_FLUSH")
  713. def test_fils_sk_hlp_oom(dev, apdev):
  714. """FILS SK HLP and hostapd OOM"""
  715. check_fils_capa(dev[0])
  716. check_erp_capa(dev[0])
  717. start_erp_as(apdev[1])
  718. sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
  719. sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
  720. sock.settimeout(5)
  721. sock.bind(("127.0.0.2", 67))
  722. bssid = apdev[0]['bssid']
  723. params = fils_hlp_config(fils_hlp_wait_time=500)
  724. params['dhcp_rapid_commit_proxy'] = '1'
  725. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  726. dev[0].scan_for_bss(bssid, freq=2412)
  727. dev[0].request("ERP_FLUSH")
  728. if "OK" not in dev[0].request("FILS_HLP_REQ_FLUSH"):
  729. raise Exception("Failed to flush pending FILS HLP requests")
  730. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  731. chaddr=dev[0].own_addr())
  732. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc)):
  733. raise Exception("FILS_HLP_REQ_ADD failed")
  734. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  735. eap="PSK", identity="psk.user@example.com",
  736. password_hex="0123456789abcdef0123456789abcdef",
  737. erp="1", scan_freq="2412")
  738. dev[0].request("DISCONNECT")
  739. dev[0].wait_disconnected()
  740. dev[0].dump_monitor()
  741. with alloc_fail(hapd, 1, "fils_process_hlp"):
  742. dev[0].select_network(id, freq=2412)
  743. dev[0].wait_connected()
  744. dev[0].request("DISCONNECT")
  745. dev[0].wait_disconnected()
  746. dev[0].dump_monitor()
  747. with alloc_fail(hapd, 1, "fils_process_hlp_dhcp"):
  748. dev[0].select_network(id, freq=2412)
  749. dev[0].wait_connected()
  750. dev[0].request("DISCONNECT")
  751. dev[0].wait_disconnected()
  752. dev[0].dump_monitor()
  753. with alloc_fail(hapd, 1, "wpabuf_alloc;fils_process_hlp_dhcp"):
  754. dev[0].select_network(id, freq=2412)
  755. dev[0].wait_connected()
  756. dev[0].request("DISCONNECT")
  757. dev[0].wait_disconnected()
  758. dev[0].dump_monitor()
  759. with alloc_fail(hapd, 1, "wpabuf_alloc;fils_dhcp_handler"):
  760. dev[0].select_network(id, freq=2412)
  761. (msg,addr) = sock.recvfrom(1000)
  762. logger.debug("Received DHCP message from %s" % str(addr))
  763. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPACK,
  764. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  765. sock.sendto(dhcpdisc[2+20+8:], addr)
  766. dev[0].wait_connected()
  767. dev[0].request("DISCONNECT")
  768. dev[0].wait_disconnected()
  769. dev[0].dump_monitor()
  770. with alloc_fail(hapd, 1, "wpabuf_resize;fils_dhcp_handler"):
  771. dev[0].select_network(id, freq=2412)
  772. (msg,addr) = sock.recvfrom(1000)
  773. logger.debug("Received DHCP message from %s" % str(addr))
  774. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPACK,
  775. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  776. sock.sendto(dhcpdisc[2+20+8:], addr)
  777. dev[0].wait_connected()
  778. dev[0].request("DISCONNECT")
  779. dev[0].wait_disconnected()
  780. dev[0].dump_monitor()
  781. dev[0].select_network(id, freq=2412)
  782. (msg,addr) = sock.recvfrom(1000)
  783. logger.debug("Received DHCP message from %s" % str(addr))
  784. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  785. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  786. with alloc_fail(hapd, 1, "wpabuf_resize;fils_dhcp_request"):
  787. sock.sendto(dhcpoffer[2+20+8:], addr)
  788. dev[0].wait_connected()
  789. dev[0].request("DISCONNECT")
  790. dev[0].wait_disconnected()
  791. dev[0].request("FILS_HLP_REQ_FLUSH")
  792. def test_fils_sk_hlp_req_parsing(dev, apdev):
  793. """FILS SK HLP request parsing"""
  794. check_fils_capa(dev[0])
  795. check_erp_capa(dev[0])
  796. start_erp_as(apdev[1])
  797. bssid = apdev[0]['bssid']
  798. params = fils_hlp_config(fils_hlp_wait_time=30)
  799. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  800. dev[0].scan_for_bss(bssid, freq=2412)
  801. dev[0].request("ERP_FLUSH")
  802. if "OK" not in dev[0].request("FILS_HLP_REQ_FLUSH"):
  803. raise Exception("Failed to flush pending FILS HLP requests")
  804. tot_len = 20 + 1
  805. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  806. _ip_src = '\x00\x00\x00\x00'
  807. _ip_dst = '\x00\x00\x00\x00'
  808. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  809. csum = ip_checksum(ipv4)
  810. ipv4_overflow = start + csum + _ip_src + _ip_dst
  811. tot_len = 20
  812. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 123)
  813. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  814. csum = ip_checksum(ipv4)
  815. ipv4_unknown_proto = start + csum + _ip_src + _ip_dst
  816. tot_len = 20
  817. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  818. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  819. csum = ip_checksum(ipv4)
  820. ipv4_missing_udp_hdr = start + csum + _ip_src + _ip_dst
  821. src_port = 68
  822. dst_port = 67
  823. udp = struct.pack('>HHHH', src_port, dst_port, 8 + 1, 0)
  824. tot_len = 20 + len(udp)
  825. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  826. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  827. csum = ip_checksum(ipv4)
  828. udp_overflow = start + csum + _ip_src + _ip_dst + udp
  829. udp = struct.pack('>HHHH', src_port, dst_port, 7, 0)
  830. tot_len = 20 + len(udp)
  831. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  832. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  833. csum = ip_checksum(ipv4)
  834. udp_underflow = start + csum + _ip_src + _ip_dst + udp
  835. src_port = 123
  836. dst_port = 456
  837. udp = struct.pack('>HHHH', src_port, dst_port, 8, 0)
  838. tot_len = 20 + len(udp)
  839. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  840. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  841. csum = ip_checksum(ipv4)
  842. udp_unknown_port = start + csum + _ip_src + _ip_dst + udp
  843. src_port = 68
  844. dst_port = 67
  845. udp = struct.pack('>HHHH', src_port, dst_port, 8, 0)
  846. tot_len = 20 + len(udp)
  847. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  848. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  849. csum = ip_checksum(ipv4)
  850. dhcp_missing_data = start + csum + _ip_src + _ip_dst + udp
  851. dhcp_not_req = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  852. chaddr=dev[0].own_addr(), override_op=BOOTREPLY)
  853. dhcp_no_magic = build_dhcp(req=True, dhcp_msg=None,
  854. chaddr=dev[0].own_addr(), magic_override='',
  855. rapid_commit=False, opt_end=False)
  856. dhcp_unknown_magic = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  857. chaddr=dev[0].own_addr(),
  858. magic_override='\x00\x00\x00\x00')
  859. dhcp_opts = build_dhcp(req=True, dhcp_msg=DHCPNAK,
  860. chaddr=dev[0].own_addr(),
  861. extra_op='\x00\x11', opt_end=False)
  862. dhcp_opts2 = build_dhcp(req=True, dhcp_msg=DHCPNAK,
  863. chaddr=dev[0].own_addr(),
  864. extra_op='\x11\x01', opt_end=False)
  865. dhcp_valid = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  866. chaddr=dev[0].own_addr())
  867. tests = [ "ff",
  868. "0800",
  869. "0800" + 20*"00",
  870. "0800" + binascii.hexlify(ipv4_overflow),
  871. "0800" + binascii.hexlify(ipv4_unknown_proto),
  872. "0800" + binascii.hexlify(ipv4_missing_udp_hdr),
  873. "0800" + binascii.hexlify(udp_overflow),
  874. "0800" + binascii.hexlify(udp_underflow),
  875. "0800" + binascii.hexlify(udp_unknown_port),
  876. "0800" + binascii.hexlify(dhcp_missing_data),
  877. binascii.hexlify(dhcp_not_req),
  878. binascii.hexlify(dhcp_no_magic),
  879. binascii.hexlify(dhcp_unknown_magic) ]
  880. for t in tests:
  881. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD ff:ff:ff:ff:ff:ff " + t):
  882. raise Exception("FILS_HLP_REQ_ADD failed: " + t)
  883. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  884. eap="PSK", identity="psk.user@example.com",
  885. password_hex="0123456789abcdef0123456789abcdef",
  886. erp="1", scan_freq="2412")
  887. dev[0].request("DISCONNECT")
  888. dev[0].wait_disconnected()
  889. dev[0].dump_monitor()
  890. dev[0].select_network(id, freq=2412)
  891. dev[0].wait_connected()
  892. dev[0].request("DISCONNECT")
  893. dev[0].wait_disconnected()
  894. dev[0].request("FILS_HLP_REQ_FLUSH")
  895. tests = [ binascii.hexlify(dhcp_opts),
  896. binascii.hexlify(dhcp_opts2) ]
  897. for t in tests:
  898. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD ff:ff:ff:ff:ff:ff " + t):
  899. raise Exception("FILS_HLP_REQ_ADD failed: " + t)
  900. dev[0].dump_monitor()
  901. dev[0].select_network(id, freq=2412)
  902. dev[0].wait_connected()
  903. dev[0].request("DISCONNECT")
  904. dev[0].wait_disconnected()
  905. dev[0].request("FILS_HLP_REQ_FLUSH")
  906. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcp_valid)):
  907. raise Exception("FILS_HLP_REQ_ADD failed")
  908. hapd.set("own_ip_addr", "0.0.0.0")
  909. dev[0].select_network(id, freq=2412)
  910. dev[0].wait_connected()
  911. dev[0].request("DISCONNECT")
  912. dev[0].wait_disconnected()
  913. hapd.set("dhcp_server", "0.0.0.0")
  914. dev[0].select_network(id, freq=2412)
  915. dev[0].wait_connected()
  916. dev[0].request("DISCONNECT")
  917. dev[0].wait_disconnected()
  918. # FILS: Failed to bind DHCP socket: Address already in use
  919. sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
  920. sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
  921. sock.settimeout(5)
  922. sock.bind(("127.0.0.2", 67))
  923. hapd.set("own_ip_addr", "127.0.0.2")
  924. hapd.set("dhcp_server", "127.0.0.2")
  925. dev[0].select_network(id, freq=2412)
  926. dev[0].wait_connected()
  927. dev[0].request("DISCONNECT")
  928. dev[0].wait_disconnected()
  929. # FILS: DHCP sendto failed: Invalid argument
  930. hapd.set("own_ip_addr", "127.0.0.3")
  931. hapd.set("dhcp_server", "127.0.0.2")
  932. hapd.set("dhcp_relay_port", "0")
  933. hapd.set("dhcp_server_port", "0")
  934. dev[0].select_network(id, freq=2412)
  935. dev[0].wait_connected()
  936. dev[0].request("DISCONNECT")
  937. dev[0].wait_disconnected()
  938. dev[0].request("FILS_HLP_REQ_FLUSH")
  939. def test_fils_sk_hlp_dhcp_parsing(dev, apdev):
  940. """FILS SK HLP and DHCP response parsing"""
  941. check_fils_capa(dev[0])
  942. check_erp_capa(dev[0])
  943. start_erp_as(apdev[1])
  944. sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
  945. sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
  946. sock.settimeout(5)
  947. sock.bind(("127.0.0.2", 67))
  948. bssid = apdev[0]['bssid']
  949. params = fils_hlp_config(fils_hlp_wait_time=30)
  950. params['dhcp_rapid_commit_proxy'] = '1'
  951. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  952. dev[0].scan_for_bss(bssid, freq=2412)
  953. dev[0].request("ERP_FLUSH")
  954. if "OK" not in dev[0].request("FILS_HLP_REQ_FLUSH"):
  955. raise Exception("Failed to flush pending FILS HLP requests")
  956. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  957. chaddr=dev[0].own_addr())
  958. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc)):
  959. raise Exception("FILS_HLP_REQ_ADD failed")
  960. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  961. eap="PSK", identity="psk.user@example.com",
  962. password_hex="0123456789abcdef0123456789abcdef",
  963. erp="1", scan_freq="2412")
  964. dev[0].request("DISCONNECT")
  965. dev[0].wait_disconnected()
  966. dev[0].dump_monitor()
  967. with alloc_fail(hapd, 1, "fils_process_hlp"):
  968. dev[0].select_network(id, freq=2412)
  969. dev[0].wait_connected()
  970. dev[0].request("DISCONNECT")
  971. dev[0].wait_disconnected()
  972. dev[0].dump_monitor()
  973. dev[0].select_network(id, freq=2412)
  974. (msg,addr) = sock.recvfrom(1000)
  975. logger.debug("Received DHCP message from %s" % str(addr))
  976. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPACK,
  977. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  978. #sock.sendto(dhcpdisc[2+20+8:], addr)
  979. chaddr = binascii.unhexlify(dev[0].own_addr().replace(':','')) + 10*'\x00'
  980. tests = [ "\x00",
  981. "\x02" + 500 * "\x00",
  982. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + 500 * "\x00",
  983. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + 16*"\x00" + 64*"\x00" + 128*"\x00" + "\x63\x82\x53\x63",
  984. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + 16*"\x00" + 64*"\x00" + 128*"\x00" + "\x63\x82\x53\x63" + "\x00\x11",
  985. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + 16*"\x00" + 64*"\x00" + 128*"\x00" + "\x63\x82\x53\x63" + "\x11\x01",
  986. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + chaddr + 64*"\x00" + 128*"\x00" + "\x63\x82\x53\x63" + "\x35\x00\xff",
  987. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + chaddr + 64*"\x00" + 128*"\x00" + "\x63\x82\x53\x63" + "\x35\x01\x00\xff",
  988. 1501 * "\x00" ]
  989. for t in tests:
  990. sock.sendto(t, addr)
  991. dev[0].wait_connected()
  992. dev[0].request("DISCONNECT")
  993. dev[0].wait_disconnected()
  994. # FILS: DHCP sendto failed: Invalid argument for second DHCP TX in proxy
  995. dev[0].dump_monitor()
  996. dev[0].select_network(id, freq=2412)
  997. (msg,addr) = sock.recvfrom(1000)
  998. logger.debug("Received DHCP message from %s" % str(addr))
  999. hapd.set("dhcp_server_port", "0")
  1000. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  1001. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  1002. sock.sendto(dhcpoffer[2+20+8:], addr)
  1003. dev[0].wait_connected()
  1004. dev[0].request("DISCONNECT")
  1005. dev[0].wait_disconnected()
  1006. hapd.set("dhcp_server_port", "67")
  1007. # Options in DHCPOFFER
  1008. dev[0].dump_monitor()
  1009. dev[0].select_network(id, freq=2412)
  1010. (msg,addr) = sock.recvfrom(1000)
  1011. logger.debug("Received DHCP message from %s" % str(addr))
  1012. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  1013. chaddr=dev[0].own_addr(), giaddr="127.0.0.3",
  1014. extra_op="\x00\x11", opt_end=False)
  1015. sock.sendto(dhcpoffer[2+20+8:], addr)
  1016. (msg,addr) = sock.recvfrom(1000)
  1017. logger.debug("Received DHCP message from %s" % str(addr))
  1018. dev[0].wait_connected()
  1019. dev[0].request("DISCONNECT")
  1020. dev[0].wait_disconnected()
  1021. # Options in DHCPOFFER (2)
  1022. dev[0].dump_monitor()
  1023. dev[0].select_network(id, freq=2412)
  1024. (msg,addr) = sock.recvfrom(1000)
  1025. logger.debug("Received DHCP message from %s" % str(addr))
  1026. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  1027. chaddr=dev[0].own_addr(), giaddr="127.0.0.3",
  1028. extra_op="\x11\x01", opt_end=False)
  1029. sock.sendto(dhcpoffer[2+20+8:], addr)
  1030. (msg,addr) = sock.recvfrom(1000)
  1031. logger.debug("Received DHCP message from %s" % str(addr))
  1032. dev[0].wait_connected()
  1033. dev[0].request("DISCONNECT")
  1034. dev[0].wait_disconnected()
  1035. # Server ID in DHCPOFFER
  1036. dev[0].dump_monitor()
  1037. dev[0].select_network(id, freq=2412)
  1038. (msg,addr) = sock.recvfrom(1000)
  1039. logger.debug("Received DHCP message from %s" % str(addr))
  1040. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  1041. chaddr=dev[0].own_addr(), giaddr="127.0.0.3",
  1042. extra_op="\x36\x01\x30")
  1043. sock.sendto(dhcpoffer[2+20+8:], addr)
  1044. (msg,addr) = sock.recvfrom(1000)
  1045. logger.debug("Received DHCP message from %s" % str(addr))
  1046. dev[0].wait_connected()
  1047. dev[0].request("DISCONNECT")
  1048. dev[0].wait_disconnected()
  1049. # FILS: Could not update DHCPDISCOVER
  1050. dev[0].request("FILS_HLP_REQ_FLUSH")
  1051. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  1052. chaddr=dev[0].own_addr(),
  1053. extra_op="\x00\x11", opt_end=False)
  1054. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc)):
  1055. raise Exception("FILS_HLP_REQ_ADD failed")
  1056. dev[0].dump_monitor()
  1057. dev[0].select_network(id, freq=2412)
  1058. (msg,addr) = sock.recvfrom(1000)
  1059. logger.debug("Received DHCP message from %s" % str(addr))
  1060. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  1061. chaddr=dev[0].own_addr(), giaddr="127.0.0.3",
  1062. extra_op="\x36\x01\x30")
  1063. sock.sendto(dhcpoffer[2+20+8:], addr)
  1064. dev[0].wait_connected()
  1065. dev[0].request("DISCONNECT")
  1066. dev[0].wait_disconnected()
  1067. # FILS: Could not update DHCPDISCOVER (2)
  1068. dev[0].request("FILS_HLP_REQ_FLUSH")
  1069. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  1070. chaddr=dev[0].own_addr(),
  1071. extra_op="\x11\x01", opt_end=False)
  1072. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc)):
  1073. raise Exception("FILS_HLP_REQ_ADD failed")
  1074. dev[0].dump_monitor()
  1075. dev[0].select_network(id, freq=2412)
  1076. (msg,addr) = sock.recvfrom(1000)
  1077. logger.debug("Received DHCP message from %s" % str(addr))
  1078. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  1079. chaddr=dev[0].own_addr(), giaddr="127.0.0.3",
  1080. extra_op="\x36\x01\x30")
  1081. sock.sendto(dhcpoffer[2+20+8:], addr)
  1082. dev[0].wait_connected()
  1083. dev[0].request("DISCONNECT")
  1084. dev[0].wait_disconnected()
  1085. dev[0].request("FILS_HLP_REQ_FLUSH")
  1086. def test_fils_sk_erp_and_reauth(dev, apdev):
  1087. """FILS SK using ERP and AP going away"""
  1088. check_fils_capa(dev[0])
  1089. check_erp_capa(dev[0])
  1090. start_erp_as(apdev[1])
  1091. bssid = apdev[0]['bssid']
  1092. params = hostapd.wpa2_eap_params(ssid="fils")
  1093. params['wpa_key_mgmt'] = "FILS-SHA256"
  1094. params['auth_server_port'] = "18128"
  1095. params['erp_domain'] = 'example.com'
  1096. params['fils_realm'] = 'example.com'
  1097. params['disable_pmksa_caching'] = '1'
  1098. params['broadcast_deauth'] = '0'
  1099. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1100. dev[0].scan_for_bss(bssid, freq=2412)
  1101. dev[0].request("ERP_FLUSH")
  1102. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1103. eap="PSK", identity="psk.user@example.com",
  1104. password_hex="0123456789abcdef0123456789abcdef",
  1105. erp="1", scan_freq="2412")
  1106. hapd.disable()
  1107. dev[0].wait_disconnected()
  1108. dev[0].dump_monitor()
  1109. hapd.enable()
  1110. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  1111. "EVENT-ASSOC-REJECT",
  1112. "CTRL-EVENT-CONNECTED"], timeout=10)
  1113. if ev is None:
  1114. raise Exception("Reconnection using FILS/ERP timed out")
  1115. if "CTRL-EVENT-EAP-STARTED" in ev:
  1116. raise Exception("Unexpected EAP exchange")
  1117. if "EVENT-ASSOC-REJECT" in ev:
  1118. raise Exception("Association failed")
  1119. def test_fils_sk_erp_sim(dev, apdev):
  1120. """FILS SK using ERP with SIM"""
  1121. check_fils_capa(dev[0])
  1122. check_erp_capa(dev[0])
  1123. realm='wlan.mnc001.mcc232.3gppnetwork.org'
  1124. start_erp_as(apdev[1], erp_domain=realm)
  1125. bssid = apdev[0]['bssid']
  1126. params = hostapd.wpa2_eap_params(ssid="fils")
  1127. params['wpa_key_mgmt'] = "FILS-SHA256"
  1128. params['auth_server_port'] = "18128"
  1129. params['fils_realm'] = realm
  1130. params['disable_pmksa_caching'] = '1'
  1131. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1132. dev[0].scan_for_bss(bssid, freq=2412)
  1133. dev[0].request("ERP_FLUSH")
  1134. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1135. eap="SIM", identity="1232010000000000@" + realm,
  1136. password="90dca4eda45b53cf0f12d7c9c3bc6a89:cb9cccc4b9258e6dca4760379fb82581",
  1137. erp="1", scan_freq="2412")
  1138. hapd.disable()
  1139. dev[0].wait_disconnected()
  1140. dev[0].dump_monitor()
  1141. hapd.enable()
  1142. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  1143. "EVENT-ASSOC-REJECT",
  1144. "CTRL-EVENT-CONNECTED"], timeout=10)
  1145. if ev is None:
  1146. raise Exception("Reconnection using FILS/ERP timed out")
  1147. if "CTRL-EVENT-EAP-STARTED" in ev:
  1148. raise Exception("Unexpected EAP exchange")
  1149. if "EVENT-ASSOC-REJECT" in ev:
  1150. raise Exception("Association failed")
  1151. def test_fils_sk_pfs_19(dev, apdev):
  1152. """FILS SK with PFS (DH group 19)"""
  1153. rul_fils_sk_pfs(dev, apdev, "19")
  1154. def test_fils_sk_pfs_20(dev, apdev):
  1155. """FILS SK with PFS (DH group 20)"""
  1156. rul_fils_sk_pfs(dev, apdev, "20")
  1157. def test_fils_sk_pfs_21(dev, apdev):
  1158. """FILS SK with PFS (DH group 21)"""
  1159. rul_fils_sk_pfs(dev, apdev, "21")
  1160. def test_fils_sk_pfs_25(dev, apdev):
  1161. """FILS SK with PFS (DH group 25)"""
  1162. rul_fils_sk_pfs(dev, apdev, "25")
  1163. def test_fils_sk_pfs_26(dev, apdev):
  1164. """FILS SK with PFS (DH group 26)"""
  1165. rul_fils_sk_pfs(dev, apdev, "26")
  1166. def test_fils_sk_pfs_27(dev, apdev):
  1167. """FILS SK with PFS (DH group 27)"""
  1168. rul_fils_sk_pfs(dev, apdev, "27")
  1169. def test_fils_sk_pfs_28(dev, apdev):
  1170. """FILS SK with PFS (DH group 28)"""
  1171. rul_fils_sk_pfs(dev, apdev, "28")
  1172. def test_fils_sk_pfs_29(dev, apdev):
  1173. """FILS SK with PFS (DH group 29)"""
  1174. rul_fils_sk_pfs(dev, apdev, "29")
  1175. def test_fils_sk_pfs_30(dev, apdev):
  1176. """FILS SK with PFS (DH group 30)"""
  1177. rul_fils_sk_pfs(dev, apdev, "30")
  1178. def rul_fils_sk_pfs(dev, apdev, group):
  1179. check_fils_sk_pfs_capa(dev[0])
  1180. check_erp_capa(dev[0])
  1181. tls = dev[0].request("GET tls_library")
  1182. if int(group) in [ 27, 28, 29, 30 ]:
  1183. if not (tls.startswith("OpenSSL") and ("build=OpenSSL 1.0.2" in tls or "build=OpenSSL 1.1" in tls) and ("run=OpenSSL 1.0.2" in tls or "run=OpenSSL 1.1" in tls)):
  1184. raise HwsimSkip("Brainpool EC group not supported")
  1185. start_erp_as(apdev[1])
  1186. bssid = apdev[0]['bssid']
  1187. params = hostapd.wpa2_eap_params(ssid="fils")
  1188. params['wpa_key_mgmt'] = "FILS-SHA256"
  1189. params['auth_server_port'] = "18128"
  1190. params['erp_domain'] = 'example.com'
  1191. params['fils_realm'] = 'example.com'
  1192. params['disable_pmksa_caching'] = '1'
  1193. params['fils_dh_group'] = group
  1194. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1195. dev[0].scan_for_bss(bssid, freq=2412)
  1196. dev[0].request("ERP_FLUSH")
  1197. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1198. eap="PSK", identity="psk.user@example.com",
  1199. password_hex="0123456789abcdef0123456789abcdef",
  1200. erp="1", fils_dh_group=group, scan_freq="2412")
  1201. dev[0].request("DISCONNECT")
  1202. dev[0].wait_disconnected()
  1203. dev[0].dump_monitor()
  1204. dev[0].select_network(id, freq=2412)
  1205. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  1206. "EVENT-ASSOC-REJECT",
  1207. "CTRL-EVENT-CONNECTED"], timeout=10)
  1208. if ev is None:
  1209. raise Exception("Connection using FILS/ERP timed out")
  1210. if "CTRL-EVENT-EAP-STARTED" in ev:
  1211. raise Exception("Unexpected EAP exchange")
  1212. if "EVENT-ASSOC-REJECT" in ev:
  1213. raise Exception("Association failed")
  1214. hwsim_utils.test_connectivity(dev[0], hapd)
  1215. def test_fils_sk_pfs_group_mismatch(dev, apdev):
  1216. """FILS SK PFS DH group mismatch"""
  1217. check_fils_sk_pfs_capa(dev[0])
  1218. check_erp_capa(dev[0])
  1219. start_erp_as(apdev[1])
  1220. bssid = apdev[0]['bssid']
  1221. params = hostapd.wpa2_eap_params(ssid="fils")
  1222. params['wpa_key_mgmt'] = "FILS-SHA256"
  1223. params['auth_server_port'] = "18128"
  1224. params['erp_domain'] = 'example.com'
  1225. params['fils_realm'] = 'example.com'
  1226. params['disable_pmksa_caching'] = '1'
  1227. params['fils_dh_group'] = "20"
  1228. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1229. dev[0].scan_for_bss(bssid, freq=2412)
  1230. dev[0].request("ERP_FLUSH")
  1231. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1232. eap="PSK", identity="psk.user@example.com",
  1233. password_hex="0123456789abcdef0123456789abcdef",
  1234. erp="1", fils_dh_group="19", scan_freq="2412")
  1235. dev[0].request("DISCONNECT")
  1236. dev[0].wait_disconnected()
  1237. dev[0].dump_monitor()
  1238. dev[0].select_network(id, freq=2412)
  1239. ev = dev[0].wait_event(["CTRL-EVENT-AUTH-REJECT"], timeout=10)
  1240. dev[0].request("DISCONNECT")
  1241. if ev is None:
  1242. raise Exception("Authentication rejection not seen")
  1243. if "auth_type=5 auth_transaction=2 status_code=77" not in ev:
  1244. raise Exception("Unexpected auth reject value: " + ev)
  1245. def test_fils_sk_auth_mismatch(dev, apdev):
  1246. """FILS SK authentication type mismatch (PFS not supported)"""
  1247. check_fils_sk_pfs_capa(dev[0])
  1248. check_erp_capa(dev[0])
  1249. start_erp_as(apdev[1])
  1250. bssid = apdev[0]['bssid']
  1251. params = hostapd.wpa2_eap_params(ssid="fils")
  1252. params['wpa_key_mgmt'] = "FILS-SHA256"
  1253. params['auth_server_port'] = "18128"
  1254. params['erp_domain'] = 'example.com'
  1255. params['fils_realm'] = 'example.com'
  1256. params['disable_pmksa_caching'] = '1'
  1257. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1258. dev[0].scan_for_bss(bssid, freq=2412)
  1259. dev[0].request("ERP_FLUSH")
  1260. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1261. eap="PSK", identity="psk.user@example.com",
  1262. password_hex="0123456789abcdef0123456789abcdef",
  1263. erp="1", fils_dh_group="19", scan_freq="2412")
  1264. dev[0].request("DISCONNECT")
  1265. dev[0].wait_disconnected()
  1266. dev[0].dump_monitor()
  1267. dev[0].select_network(id, freq=2412)
  1268. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  1269. "EVENT-ASSOC-REJECT",
  1270. "CTRL-EVENT-CONNECTED"], timeout=10)
  1271. if ev is None:
  1272. raise Exception("Connection using FILS/ERP timed out")
  1273. if "CTRL-EVENT-EAP-STARTED" not in ev:
  1274. raise Exception("No EAP exchange seen")
  1275. dev[0].wait_connected()
  1276. hwsim_utils.test_connectivity(dev[0], hapd)
  1277. def test_fils_auth_gtk_rekey(dev, apdev):
  1278. """GTK rekeying after FILS authentication"""
  1279. check_fils_capa(dev[0])
  1280. check_erp_capa(dev[0])
  1281. start_erp_as(apdev[1])
  1282. bssid = apdev[0]['bssid']
  1283. params = hostapd.wpa2_eap_params(ssid="fils")
  1284. params['wpa_key_mgmt'] = "FILS-SHA256"
  1285. params['auth_server_port'] = "18128"
  1286. params['erp_domain'] = 'example.com'
  1287. params['fils_realm'] = 'example.com'
  1288. params['wpa_group_rekey'] = '1'
  1289. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1290. dev[0].scan_for_bss(bssid, freq=2412)
  1291. dev[0].request("ERP_FLUSH")
  1292. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1293. eap="PSK", identity="psk.user@example.com",
  1294. password_hex="0123456789abcdef0123456789abcdef",
  1295. erp="1", scan_freq="2412")
  1296. dev[0].request("DISCONNECT")
  1297. dev[0].wait_disconnected()
  1298. dev[0].dump_monitor()
  1299. dev[0].select_network(id, freq=2412)
  1300. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  1301. "CTRL-EVENT-CONNECTED"], timeout=10)
  1302. if ev is None:
  1303. raise Exception("Connection using PMKSA caching timed out")
  1304. if "CTRL-EVENT-EAP-STARTED" in ev:
  1305. raise Exception("Unexpected EAP exchange")
  1306. dev[0].dump_monitor()
  1307. hwsim_utils.test_connectivity(dev[0], hapd)
  1308. ev = dev[0].wait_event(["WPA: Group rekeying completed"], timeout=2)
  1309. if ev is None:
  1310. raise Exception("GTK rekey timed out")
  1311. hwsim_utils.test_connectivity(dev[0], hapd)
  1312. ev = dev[0].wait_event(["CTRL-EVENT-DISCONNECTED"], timeout=5)
  1313. if ev is not None:
  1314. raise Exception("Rekeying failed - disconnected")
  1315. hwsim_utils.test_connectivity(dev[0], hapd)
  1316. def test_fils_and_ft(dev, apdev):
  1317. """FILS SK using ERP and FT initial mobility domain association"""
  1318. check_fils_capa(dev[0])
  1319. check_erp_capa(dev[0])
  1320. er = start_erp_as(apdev[1])
  1321. bssid = apdev[0]['bssid']
  1322. params = hostapd.wpa2_eap_params(ssid="fils")
  1323. params['wpa_key_mgmt'] = "FILS-SHA256"
  1324. params['auth_server_port'] = "18128"
  1325. params['erp_domain'] = 'example.com'
  1326. params['fils_realm'] = 'example.com'
  1327. params['disable_pmksa_caching'] = '1'
  1328. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1329. dev[0].scan_for_bss(bssid, freq=2412)
  1330. dev[0].request("ERP_FLUSH")
  1331. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1332. eap="PSK", identity="psk.user@example.com",
  1333. password_hex="0123456789abcdef0123456789abcdef",
  1334. erp="1", scan_freq="2412")
  1335. dev[0].request("DISCONNECT")
  1336. dev[0].wait_disconnected()
  1337. hapd.disable()
  1338. dev[0].flush_scan_cache()
  1339. if "FAIL" in dev[0].request("PMKSA_FLUSH"):
  1340. raise Exception("PMKSA_FLUSH failed")
  1341. params = hostapd.wpa2_eap_params(ssid="fils-ft")
  1342. params['wpa_key_mgmt'] = "FILS-SHA256 FT-FILS-SHA256 FT-EAP"
  1343. params['auth_server_port'] = "18128"
  1344. params['erp_domain'] = 'example.com'
  1345. params['fils_realm'] = 'example.com'
  1346. params['disable_pmksa_caching'] = '1'
  1347. params["mobility_domain"] = "a1b2"
  1348. params["r0_key_lifetime"] = "10000"
  1349. params["pmk_r1_push"] = "1"
  1350. params["reassociation_deadline"] = "1000"
  1351. params['nas_identifier'] = "nas1.w1.fi"
  1352. params['r1_key_holder'] = "000102030405"
  1353. params['r0kh'] = [ "02:00:00:00:04:00 nas2.w1.fi 300102030405060708090a0b0c0d0e0f" ]
  1354. params['r1kh'] = "02:00:00:00:04:00 00:01:02:03:04:06 200102030405060708090a0b0c0d0e0f"
  1355. params['ieee80211w'] = "1"
  1356. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1357. dev[0].scan_for_bss(bssid, freq=2412)
  1358. dev[0].dump_monitor()
  1359. id = dev[0].connect("fils-ft", key_mgmt="FILS-SHA256 FT-FILS-SHA256 FT-EAP",
  1360. ieee80211w="1",
  1361. eap="PSK", identity="psk.user@example.com",
  1362. password_hex="0123456789abcdef0123456789abcdef",
  1363. erp="1", scan_freq="2412", wait_connect=False)
  1364. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  1365. "CTRL-EVENT-AUTH-REJECT",
  1366. "EVENT-ASSOC-REJECT",
  1367. "CTRL-EVENT-CONNECTED"], timeout=10)
  1368. if ev is None:
  1369. raise Exception("Connection using FILS/ERP timed out")
  1370. if "CTRL-EVENT-EAP-STARTED" in ev:
  1371. raise Exception("Unexpected EAP exchange")
  1372. if "CTRL-EVENT-AUTH-REJECT" in ev:
  1373. raise Exception("Authentication failed")
  1374. if "EVENT-ASSOC-REJECT" in ev:
  1375. raise Exception("Association failed")
  1376. hwsim_utils.test_connectivity(dev[0], hapd)
  1377. er.disable()
  1378. # FIX: FT-FILS-SHA256 does not currently work for FT protocol due to not
  1379. # fully defined FT Reassociation Request/Response frame MIC use in FTE.
  1380. # FT-EAP can be used to work around that in this test case to confirm the
  1381. # FT key hierarchy was properly formed in the previous step.
  1382. #params['wpa_key_mgmt'] = "FILS-SHA256 FT-FILS-SHA256"
  1383. params['wpa_key_mgmt'] = "FT-EAP"
  1384. params['nas_identifier'] = "nas2.w1.fi"
  1385. params['r1_key_holder'] = "000102030406"
  1386. params['r0kh'] = [ "02:00:00:00:03:00 nas1.w1.fi 200102030405060708090a0b0c0d0e0f" ]
  1387. params['r1kh'] = "02:00:00:00:03:00 00:01:02:03:04:05 300102030405060708090a0b0c0d0e0f"
  1388. hapd2 = hostapd.add_ap(apdev[1]['ifname'], params)
  1389. dev[0].scan_for_bss(apdev[1]['bssid'], freq="2412", force_scan=True)
  1390. # FIX: Cannot use FT-over-DS without the FTE MIC issue addressed
  1391. #dev[0].roam_over_ds(apdev[1]['bssid'])
  1392. dev[0].roam(apdev[1]['bssid'])