test_ap_psk.py 38 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989
  1. # WPA2-Personal tests
  2. # Copyright (c) 2014, Qualcomm Atheros, Inc.
  3. #
  4. # This software may be distributed under the terms of the BSD license.
  5. # See README for more details.
  6. import binascii
  7. import hashlib
  8. import hmac
  9. import logging
  10. logger = logging.getLogger()
  11. import os
  12. import re
  13. import struct
  14. import subprocess
  15. import time
  16. import hostapd
  17. from utils import HwsimSkip
  18. import hwsim_utils
  19. def check_mib(dev, vals):
  20. mib = dev.get_mib()
  21. for v in vals:
  22. if mib[v[0]] != v[1]:
  23. raise Exception("Unexpected {} = {} (expected {})".format(v[0], mib[v[0]], v[1]))
  24. def test_ap_wpa2_psk(dev, apdev):
  25. """WPA2-PSK AP with PSK instead of passphrase"""
  26. ssid = "test-wpa2-psk"
  27. passphrase = 'qwertyuiop'
  28. psk = '602e323e077bc63bd80307ef4745b754b0ae0a925c2638ecd13a794b9527b9e6'
  29. params = hostapd.wpa2_params(ssid=ssid)
  30. params['wpa_psk'] = psk
  31. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  32. key_mgmt = hapd.get_config()['key_mgmt']
  33. if key_mgmt.split(' ')[0] != "WPA-PSK":
  34. raise Exception("Unexpected GET_CONFIG(key_mgmt): " + key_mgmt)
  35. dev[0].connect(ssid, raw_psk=psk, scan_freq="2412")
  36. dev[1].connect(ssid, psk=passphrase, scan_freq="2412")
  37. sig = dev[0].request("SIGNAL_POLL").splitlines()
  38. pkt = dev[0].request("PKTCNT_POLL").splitlines()
  39. if "FREQUENCY=2412" not in sig:
  40. raise Exception("Unexpected SIGNAL_POLL value: " + str(sig))
  41. if "TXBAD=0" not in pkt:
  42. raise Exception("Unexpected TXBAD value: " + str(pkt))
  43. def test_ap_wpa2_psk_file(dev, apdev):
  44. """WPA2-PSK AP with PSK from a file"""
  45. ssid = "test-wpa2-psk"
  46. passphrase = 'qwertyuiop'
  47. psk = '602e323e077bc63bd80307ef4745b754b0ae0a925c2638ecd13a794b9527b9e6'
  48. params = hostapd.wpa2_params(ssid=ssid, passphrase=passphrase)
  49. params['wpa_psk_file'] = 'hostapd.wpa_psk'
  50. hostapd.add_ap(apdev[0]['ifname'], params)
  51. dev[1].connect(ssid, psk="very secret", scan_freq="2412", wait_connect=False)
  52. dev[2].connect(ssid, raw_psk=psk, scan_freq="2412")
  53. dev[2].request("REMOVE_NETWORK all")
  54. dev[0].connect(ssid, psk="very secret", scan_freq="2412")
  55. dev[0].request("REMOVE_NETWORK all")
  56. dev[2].connect(ssid, psk="another passphrase for all STAs", scan_freq="2412")
  57. dev[0].connect(ssid, psk="another passphrase for all STAs", scan_freq="2412")
  58. ev = dev[1].wait_event(["WPA: 4-Way Handshake failed"], timeout=10)
  59. if ev is None:
  60. raise Exception("Timed out while waiting for failure report")
  61. dev[1].request("REMOVE_NETWORK all")
  62. def test_ap_wpa2_ptk_rekey(dev, apdev):
  63. """WPA2-PSK AP and PTK rekey enforced by station"""
  64. ssid = "test-wpa2-psk"
  65. passphrase = 'qwertyuiop'
  66. params = hostapd.wpa2_params(ssid=ssid, passphrase=passphrase)
  67. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  68. dev[0].connect(ssid, psk=passphrase, wpa_ptk_rekey="1", scan_freq="2412")
  69. ev = dev[0].wait_event(["WPA: Key negotiation completed"])
  70. if ev is None:
  71. raise Exception("PTK rekey timed out")
  72. hwsim_utils.test_connectivity(dev[0], hapd)
  73. def test_ap_wpa2_ptk_rekey_ap(dev, apdev):
  74. """WPA2-PSK AP and PTK rekey enforced by AP"""
  75. ssid = "test-wpa2-psk"
  76. passphrase = 'qwertyuiop'
  77. params = hostapd.wpa2_params(ssid=ssid, passphrase=passphrase)
  78. params['wpa_ptk_rekey'] = '2'
  79. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  80. dev[0].connect(ssid, psk=passphrase, scan_freq="2412")
  81. ev = dev[0].wait_event(["WPA: Key negotiation completed"])
  82. if ev is None:
  83. raise Exception("PTK rekey timed out")
  84. hwsim_utils.test_connectivity(dev[0], hapd)
  85. def test_ap_wpa2_sha256_ptk_rekey(dev, apdev):
  86. """WPA2-PSK/SHA256 AKM AP and PTK rekey enforced by station"""
  87. ssid = "test-wpa2-psk"
  88. passphrase = 'qwertyuiop'
  89. params = hostapd.wpa2_params(ssid=ssid, passphrase=passphrase)
  90. params["wpa_key_mgmt"] = "WPA-PSK-SHA256"
  91. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  92. dev[0].connect(ssid, psk=passphrase, key_mgmt="WPA-PSK-SHA256",
  93. wpa_ptk_rekey="1", scan_freq="2412")
  94. ev = dev[0].wait_event(["WPA: Key negotiation completed"])
  95. if ev is None:
  96. raise Exception("PTK rekey timed out")
  97. hwsim_utils.test_connectivity(dev[0], hapd)
  98. check_mib(dev[0], [ ("dot11RSNAAuthenticationSuiteRequested", "00-0f-ac-6"),
  99. ("dot11RSNAAuthenticationSuiteSelected", "00-0f-ac-6") ])
  100. def test_ap_wpa2_sha256_ptk_rekey_ap(dev, apdev):
  101. """WPA2-PSK/SHA256 AKM AP and PTK rekey enforced by AP"""
  102. ssid = "test-wpa2-psk"
  103. passphrase = 'qwertyuiop'
  104. params = hostapd.wpa2_params(ssid=ssid, passphrase=passphrase)
  105. params["wpa_key_mgmt"] = "WPA-PSK-SHA256"
  106. params['wpa_ptk_rekey'] = '2'
  107. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  108. dev[0].connect(ssid, psk=passphrase, key_mgmt="WPA-PSK-SHA256",
  109. scan_freq="2412")
  110. ev = dev[0].wait_event(["WPA: Key negotiation completed"])
  111. if ev is None:
  112. raise Exception("PTK rekey timed out")
  113. hwsim_utils.test_connectivity(dev[0], hapd)
  114. check_mib(dev[0], [ ("dot11RSNAAuthenticationSuiteRequested", "00-0f-ac-6"),
  115. ("dot11RSNAAuthenticationSuiteSelected", "00-0f-ac-6") ])
  116. def test_ap_wpa_ptk_rekey(dev, apdev):
  117. """WPA-PSK/TKIP AP and PTK rekey enforced by station"""
  118. ssid = "test-wpa-psk"
  119. passphrase = 'qwertyuiop'
  120. params = hostapd.wpa_params(ssid=ssid, passphrase=passphrase)
  121. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  122. dev[0].connect(ssid, psk=passphrase, wpa_ptk_rekey="1", scan_freq="2412")
  123. if "[WPA-PSK-TKIP]" not in dev[0].request("SCAN_RESULTS"):
  124. raise Exception("Scan results missing WPA element info")
  125. ev = dev[0].wait_event(["WPA: Key negotiation completed"])
  126. if ev is None:
  127. raise Exception("PTK rekey timed out")
  128. hwsim_utils.test_connectivity(dev[0], hapd)
  129. def test_ap_wpa_ptk_rekey_ap(dev, apdev):
  130. """WPA-PSK/TKIP AP and PTK rekey enforced by AP"""
  131. ssid = "test-wpa-psk"
  132. passphrase = 'qwertyuiop'
  133. params = hostapd.wpa_params(ssid=ssid, passphrase=passphrase)
  134. params['wpa_ptk_rekey'] = '2'
  135. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  136. dev[0].connect(ssid, psk=passphrase, scan_freq="2412")
  137. ev = dev[0].wait_event(["WPA: Key negotiation completed"], timeout=10)
  138. if ev is None:
  139. raise Exception("PTK rekey timed out")
  140. hwsim_utils.test_connectivity(dev[0], hapd)
  141. def test_ap_wpa_ccmp(dev, apdev):
  142. """WPA-PSK/CCMP"""
  143. ssid = "test-wpa-psk"
  144. passphrase = 'qwertyuiop'
  145. params = hostapd.wpa_params(ssid=ssid, passphrase=passphrase)
  146. params['wpa_pairwise'] = "CCMP"
  147. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  148. dev[0].connect(ssid, psk=passphrase, scan_freq="2412")
  149. hwsim_utils.test_connectivity(dev[0], hapd)
  150. check_mib(dev[0], [ ("dot11RSNAConfigGroupCipherSize", "128"),
  151. ("dot11RSNAGroupCipherRequested", "00-50-f2-4"),
  152. ("dot11RSNAPairwiseCipherRequested", "00-50-f2-4"),
  153. ("dot11RSNAAuthenticationSuiteRequested", "00-50-f2-2"),
  154. ("dot11RSNAGroupCipherSelected", "00-50-f2-4"),
  155. ("dot11RSNAPairwiseCipherSelected", "00-50-f2-4"),
  156. ("dot11RSNAAuthenticationSuiteSelected", "00-50-f2-2"),
  157. ("dot1xSuppSuppControlledPortStatus", "Authorized") ])
  158. def test_ap_wpa2_psk_file(dev, apdev):
  159. """WPA2-PSK AP with various PSK file error and success cases"""
  160. addr0 = dev[0].p2p_dev_addr()
  161. addr1 = dev[1].p2p_dev_addr()
  162. addr2 = dev[2].p2p_dev_addr()
  163. ssid = "psk"
  164. pskfile = "/tmp/ap_wpa2_psk_file_errors.psk_file"
  165. try:
  166. os.remove(pskfile)
  167. except:
  168. pass
  169. params = { "ssid": ssid, "wpa": "2", "wpa_key_mgmt": "WPA-PSK",
  170. "rsn_pairwise": "CCMP", "wpa_psk_file": pskfile }
  171. try:
  172. # missing PSK file
  173. hapd = hostapd.add_ap(apdev[0]['ifname'], params, no_enable=True)
  174. if "FAIL" not in hapd.request("ENABLE"):
  175. raise Exception("Unexpected ENABLE success")
  176. hapd.request("DISABLE")
  177. # invalid MAC address
  178. with open(pskfile, "w") as f:
  179. f.write("\n")
  180. f.write("foo\n")
  181. if "FAIL" not in hapd.request("ENABLE"):
  182. raise Exception("Unexpected ENABLE success")
  183. hapd.request("DISABLE")
  184. # no PSK on line
  185. with open(pskfile, "w") as f:
  186. f.write("00:11:22:33:44:55\n")
  187. if "FAIL" not in hapd.request("ENABLE"):
  188. raise Exception("Unexpected ENABLE success")
  189. hapd.request("DISABLE")
  190. # invalid PSK
  191. with open(pskfile, "w") as f:
  192. f.write("00:11:22:33:44:55 1234567\n")
  193. if "FAIL" not in hapd.request("ENABLE"):
  194. raise Exception("Unexpected ENABLE success")
  195. hapd.request("DISABLE")
  196. # valid PSK file
  197. with open(pskfile, "w") as f:
  198. f.write("00:11:22:33:44:55 12345678\n")
  199. f.write(addr0 + " 123456789\n")
  200. f.write(addr1 + " 123456789a\n")
  201. f.write(addr2 + " 0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef\n")
  202. if "FAIL" in hapd.request("ENABLE"):
  203. raise Exception("Unexpected ENABLE failure")
  204. dev[0].connect(ssid, psk="123456789", scan_freq="2412")
  205. dev[1].connect(ssid, psk="123456789a", scan_freq="2412")
  206. dev[2].connect(ssid, raw_psk="0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef", scan_freq="2412")
  207. finally:
  208. try:
  209. os.remove(pskfile)
  210. except:
  211. pass
  212. def test_ap_wpa2_psk_wildcard_ssid(dev, apdev):
  213. """WPA2-PSK AP and wildcard SSID configuration"""
  214. ssid = "test-wpa2-psk"
  215. passphrase = 'qwertyuiop'
  216. psk = '602e323e077bc63bd80307ef4745b754b0ae0a925c2638ecd13a794b9527b9e6'
  217. params = hostapd.wpa2_params(ssid=ssid, passphrase=passphrase)
  218. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  219. dev[0].connect("", bssid=apdev[0]['bssid'], psk=passphrase,
  220. scan_freq="2412")
  221. dev[1].connect("", bssid=apdev[0]['bssid'], raw_psk=psk, scan_freq="2412")
  222. def test_ap_wpa2_gtk_rekey(dev, apdev):
  223. """WPA2-PSK AP and GTK rekey enforced by AP"""
  224. ssid = "test-wpa2-psk"
  225. passphrase = 'qwertyuiop'
  226. params = hostapd.wpa2_params(ssid=ssid, passphrase=passphrase)
  227. params['wpa_group_rekey'] = '1'
  228. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  229. dev[0].connect(ssid, psk=passphrase, scan_freq="2412")
  230. ev = dev[0].wait_event(["WPA: Group rekeying completed"], timeout=2)
  231. if ev is None:
  232. raise Exception("GTK rekey timed out")
  233. hwsim_utils.test_connectivity(dev[0], hapd)
  234. def test_ap_wpa_gtk_rekey(dev, apdev):
  235. """WPA-PSK/TKIP AP and GTK rekey enforced by AP"""
  236. ssid = "test-wpa-psk"
  237. passphrase = 'qwertyuiop'
  238. params = hostapd.wpa_params(ssid=ssid, passphrase=passphrase)
  239. params['wpa_group_rekey'] = '1'
  240. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  241. dev[0].connect(ssid, psk=passphrase, scan_freq="2412")
  242. ev = dev[0].wait_event(["WPA: Group rekeying completed"], timeout=2)
  243. if ev is None:
  244. raise Exception("GTK rekey timed out")
  245. hwsim_utils.test_connectivity(dev[0], hapd)
  246. def test_ap_wpa2_gmk_rekey(dev, apdev):
  247. """WPA2-PSK AP and GMK and GTK rekey enforced by AP"""
  248. ssid = "test-wpa2-psk"
  249. passphrase = 'qwertyuiop'
  250. params = hostapd.wpa2_params(ssid=ssid, passphrase=passphrase)
  251. params['wpa_group_rekey'] = '1'
  252. params['wpa_gmk_rekey'] = '2'
  253. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  254. dev[0].connect(ssid, psk=passphrase, scan_freq="2412")
  255. for i in range(0, 3):
  256. ev = dev[0].wait_event(["WPA: Group rekeying completed"], timeout=2)
  257. if ev is None:
  258. raise Exception("GTK rekey timed out")
  259. hwsim_utils.test_connectivity(dev[0], hapd)
  260. def test_ap_wpa2_strict_rekey(dev, apdev):
  261. """WPA2-PSK AP and strict GTK rekey enforced by AP"""
  262. ssid = "test-wpa2-psk"
  263. passphrase = 'qwertyuiop'
  264. params = hostapd.wpa2_params(ssid=ssid, passphrase=passphrase)
  265. params['wpa_strict_rekey'] = '1'
  266. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  267. dev[0].connect(ssid, psk=passphrase, scan_freq="2412")
  268. dev[1].connect(ssid, psk=passphrase, scan_freq="2412")
  269. dev[1].request("DISCONNECT")
  270. ev = dev[0].wait_event(["WPA: Group rekeying completed"], timeout=2)
  271. if ev is None:
  272. raise Exception("GTK rekey timed out")
  273. hwsim_utils.test_connectivity(dev[0], hapd)
  274. def test_ap_wpa2_bridge_fdb(dev, apdev):
  275. """Bridge FDB entry removal"""
  276. try:
  277. ssid = "test-wpa2-psk"
  278. passphrase = "12345678"
  279. params = hostapd.wpa2_params(ssid=ssid, passphrase=passphrase)
  280. params['bridge'] = 'ap-br0'
  281. hostapd.add_ap(apdev[0]['ifname'], params)
  282. subprocess.call(['sudo', 'brctl', 'setfd', 'ap-br0', '0'])
  283. subprocess.call(['sudo', 'ip', 'link', 'set', 'dev', 'ap-br0', 'up'])
  284. dev[0].connect(ssid, psk=passphrase, scan_freq="2412",
  285. bssid=apdev[0]['bssid'])
  286. dev[1].connect(ssid, psk=passphrase, scan_freq="2412",
  287. bssid=apdev[0]['bssid'])
  288. addr0 = dev[0].p2p_interface_addr()
  289. hwsim_utils.test_connectivity_sta(dev[0], dev[1])
  290. cmd = subprocess.Popen(['brctl', 'showmacs', 'ap-br0'],
  291. stdout=subprocess.PIPE)
  292. macs1 = cmd.stdout.read()
  293. dev[0].request("DISCONNECT")
  294. dev[1].request("DISCONNECT")
  295. time.sleep(1)
  296. cmd = subprocess.Popen(['brctl', 'showmacs', 'ap-br0'],
  297. stdout=subprocess.PIPE)
  298. macs2 = cmd.stdout.read()
  299. addr1 = dev[1].p2p_interface_addr()
  300. if addr0 not in macs1 or addr1 not in macs1:
  301. raise Exception("Bridge FDB entry missing")
  302. if addr0 in macs2 or addr1 in macs2:
  303. raise Exception("Bridge FDB entry was not removed")
  304. finally:
  305. subprocess.call(['sudo', 'ip', 'link', 'set', 'dev', 'ap-br0', 'down'])
  306. subprocess.call(['sudo', 'brctl', 'delbr', 'ap-br0'])
  307. def test_ap_wpa2_already_in_bridge(dev, apdev):
  308. """hostapd behavior with interface already in bridge"""
  309. ifname = apdev[0]['ifname']
  310. br_ifname = 'ext-ap-br0'
  311. try:
  312. ssid = "test-wpa2-psk"
  313. passphrase = "12345678"
  314. subprocess.call(['brctl', 'addbr', br_ifname])
  315. subprocess.call(['brctl', 'setfd', br_ifname, '0'])
  316. subprocess.call(['ip', 'link', 'set', 'dev', br_ifname, 'up'])
  317. subprocess.call(['iw', ifname, 'set', 'type', '__ap'])
  318. subprocess.call(['brctl', 'addif', br_ifname, ifname])
  319. params = hostapd.wpa2_params(ssid=ssid, passphrase=passphrase)
  320. hapd = hostapd.add_ap(ifname, params)
  321. if hapd.get_driver_status_field('brname') != br_ifname:
  322. raise Exception("Bridge name not identified correctly")
  323. dev[0].connect(ssid, psk=passphrase, scan_freq="2412")
  324. finally:
  325. subprocess.call(['ip', 'link', 'set', 'dev', br_ifname, 'down'])
  326. subprocess.call(['brctl', 'delif', br_ifname, ifname])
  327. subprocess.call(['iw', ifname, 'set', 'type', 'station'])
  328. subprocess.call(['brctl', 'delbr', br_ifname])
  329. def test_ap_wpa2_in_different_bridge(dev, apdev):
  330. """hostapd behavior with interface in different bridge"""
  331. ifname = apdev[0]['ifname']
  332. br_ifname = 'ext-ap-br0'
  333. try:
  334. ssid = "test-wpa2-psk"
  335. passphrase = "12345678"
  336. subprocess.call(['brctl', 'addbr', br_ifname])
  337. subprocess.call(['brctl', 'setfd', br_ifname, '0'])
  338. subprocess.call(['ip', 'link', 'set', 'dev', br_ifname, 'up'])
  339. subprocess.call(['iw', ifname, 'set', 'type', '__ap'])
  340. subprocess.call(['brctl', 'addif', br_ifname, ifname])
  341. time.sleep(0.5)
  342. params = hostapd.wpa2_params(ssid=ssid, passphrase=passphrase)
  343. params['bridge'] = 'ap-br0'
  344. hapd = hostapd.add_ap(ifname, params)
  345. subprocess.call(['brctl', 'setfd', 'ap-br0', '0'])
  346. subprocess.call(['ip', 'link', 'set', 'dev', 'ap-br0', 'up'])
  347. brname = hapd.get_driver_status_field('brname')
  348. if brname != 'ap-br0':
  349. raise Exception("Incorrect bridge: " + brname)
  350. dev[0].connect(ssid, psk=passphrase, scan_freq="2412")
  351. hwsim_utils.test_connectivity_iface(dev[0], hapd, "ap-br0")
  352. if hapd.get_driver_status_field("added_bridge") != "1":
  353. raise Exception("Unexpected added_bridge value")
  354. if hapd.get_driver_status_field("added_if_into_bridge") != "1":
  355. raise Exception("Unexpected added_if_into_bridge value")
  356. dev[0].request("DISCONNECT")
  357. hapd.disable()
  358. finally:
  359. subprocess.call(['ip', 'link', 'set', 'dev', br_ifname, 'down'])
  360. subprocess.call(['brctl', 'delif', br_ifname, ifname],
  361. stderr=open('/dev/null', 'w'))
  362. subprocess.call(['brctl', 'delbr', br_ifname])
  363. def test_ap_wpa2_ext_add_to_bridge(dev, apdev):
  364. """hostapd behavior with interface added to bridge externally"""
  365. ifname = apdev[0]['ifname']
  366. br_ifname = 'ext-ap-br0'
  367. try:
  368. ssid = "test-wpa2-psk"
  369. passphrase = "12345678"
  370. params = hostapd.wpa2_params(ssid=ssid, passphrase=passphrase)
  371. hapd = hostapd.add_ap(ifname, params)
  372. subprocess.call(['brctl', 'addbr', br_ifname])
  373. subprocess.call(['brctl', 'setfd', br_ifname, '0'])
  374. subprocess.call(['ip', 'link', 'set', 'dev', br_ifname, 'up'])
  375. subprocess.call(['brctl', 'addif', br_ifname, ifname])
  376. dev[0].connect(ssid, psk=passphrase, scan_freq="2412")
  377. if hapd.get_driver_status_field('brname') != br_ifname:
  378. raise Exception("Bridge name not identified correctly")
  379. finally:
  380. subprocess.call(['ip', 'link', 'set', 'dev', br_ifname, 'down'])
  381. subprocess.call(['brctl', 'delif', br_ifname, ifname])
  382. subprocess.call(['brctl', 'delbr', br_ifname])
  383. def test_ap_wpa2_psk_ext(dev, apdev):
  384. """WPA2-PSK AP using external EAPOL I/O"""
  385. bssid = apdev[0]['bssid']
  386. ssid = "test-wpa2-psk"
  387. passphrase = 'qwertyuiop'
  388. psk = '602e323e077bc63bd80307ef4745b754b0ae0a925c2638ecd13a794b9527b9e6'
  389. params = hostapd.wpa2_params(ssid=ssid)
  390. params['wpa_psk'] = psk
  391. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  392. hapd.request("SET ext_eapol_frame_io 1")
  393. dev[0].request("SET ext_eapol_frame_io 1")
  394. dev[0].connect(ssid, psk=passphrase, scan_freq="2412", wait_connect=False)
  395. addr = dev[0].p2p_interface_addr()
  396. while True:
  397. ev = hapd.wait_event(["EAPOL-TX", "AP-STA-CONNECTED"], timeout=15)
  398. if ev is None:
  399. raise Exception("Timeout on EAPOL-TX from hostapd")
  400. if "AP-STA-CONNECTED" in ev:
  401. dev[0].wait_connected(timeout=15)
  402. break
  403. res = dev[0].request("EAPOL_RX " + bssid + " " + ev.split(' ')[2])
  404. if "OK" not in res:
  405. raise Exception("EAPOL_RX to wpa_supplicant failed")
  406. ev = dev[0].wait_event(["EAPOL-TX", "CTRL-EVENT-CONNECTED"], timeout=15)
  407. if ev is None:
  408. raise Exception("Timeout on EAPOL-TX from wpa_supplicant")
  409. if "CTRL-EVENT-CONNECTED" in ev:
  410. break
  411. res = hapd.request("EAPOL_RX " + addr + " " + ev.split(' ')[2])
  412. if "OK" not in res:
  413. raise Exception("EAPOL_RX to hostapd failed")
  414. def parse_eapol(data):
  415. (version, type, length) = struct.unpack('>BBH', data[0:4])
  416. payload = data[4:]
  417. if length > len(payload):
  418. raise Exception("Invalid EAPOL length")
  419. if length < len(payload):
  420. payload = payload[0:length]
  421. eapol = {}
  422. eapol['version'] = version
  423. eapol['type'] = type
  424. eapol['length'] = length
  425. eapol['payload'] = payload
  426. if type == 3:
  427. # EAPOL-Key
  428. (eapol['descr_type'],) = struct.unpack('B', payload[0:1])
  429. payload = payload[1:]
  430. if eapol['descr_type'] == 2 or eapol['descr_type'] == 254:
  431. # RSN EAPOL-Key
  432. (key_info, key_len) = struct.unpack('>HH', payload[0:4])
  433. eapol['rsn_key_info'] = key_info
  434. eapol['rsn_key_len'] = key_len
  435. eapol['rsn_replay_counter'] = payload[4:12]
  436. eapol['rsn_key_nonce'] = payload[12:44]
  437. eapol['rsn_key_iv'] = payload[44:60]
  438. eapol['rsn_key_rsc'] = payload[60:68]
  439. eapol['rsn_key_id'] = payload[68:76]
  440. eapol['rsn_key_mic'] = payload[76:92]
  441. payload = payload[92:]
  442. (eapol['rsn_key_data_len'],) = struct.unpack('>H', payload[0:2])
  443. payload = payload[2:]
  444. eapol['rsn_key_data'] = payload
  445. return eapol
  446. def build_eapol(msg):
  447. data = struct.pack(">BBH", msg['version'], msg['type'], msg['length'])
  448. if msg['type'] == 3:
  449. data += struct.pack('>BHH', msg['descr_type'], msg['rsn_key_info'],
  450. msg['rsn_key_len'])
  451. data += msg['rsn_replay_counter']
  452. data += msg['rsn_key_nonce']
  453. data += msg['rsn_key_iv']
  454. data += msg['rsn_key_rsc']
  455. data += msg['rsn_key_id']
  456. data += msg['rsn_key_mic']
  457. data += struct.pack('>H', msg['rsn_key_data_len'])
  458. data += msg['rsn_key_data']
  459. else:
  460. data += msg['payload']
  461. return data
  462. def sha1_prf(key, label, data, outlen):
  463. res = ''
  464. counter = 0
  465. while outlen > 0:
  466. m = hmac.new(key, label, hashlib.sha1)
  467. m.update(struct.pack('B', 0))
  468. m.update(data)
  469. m.update(struct.pack('B', counter))
  470. counter += 1
  471. hash = m.digest()
  472. if outlen > len(hash):
  473. res += hash
  474. outlen -= len(hash)
  475. else:
  476. res += hash[0:outlen]
  477. outlen = 0
  478. return res
  479. def pmk_to_ptk(pmk, addr1, addr2, nonce1, nonce2):
  480. if addr1 < addr2:
  481. data = binascii.unhexlify(addr1.replace(':','')) + binascii.unhexlify(addr2.replace(':',''))
  482. else:
  483. data = binascii.unhexlify(addr2.replace(':','')) + binascii.unhexlify(addr1.replace(':',''))
  484. if nonce1 < nonce2:
  485. data += nonce1 + nonce2
  486. else:
  487. data += nonce2 + nonce1
  488. label = "Pairwise key expansion"
  489. ptk = sha1_prf(pmk, label, data, 48)
  490. kck = ptk[0:16]
  491. kek = ptk[16:32]
  492. return (ptk, kck, kek)
  493. def eapol_key_mic(kck, msg):
  494. msg['rsn_key_mic'] = binascii.unhexlify('00000000000000000000000000000000')
  495. data = build_eapol(msg)
  496. m = hmac.new(kck, data, hashlib.sha1)
  497. msg['rsn_key_mic'] = m.digest()[0:16]
  498. def rsn_eapol_key_set(msg, key_info, key_len, nonce, data):
  499. msg['rsn_key_info'] = key_info
  500. msg['rsn_key_len'] = key_len
  501. if nonce:
  502. msg['rsn_key_nonce'] = nonce
  503. else:
  504. msg['rsn_key_nonce'] = binascii.unhexlify('0000000000000000000000000000000000000000000000000000000000000000')
  505. if data:
  506. msg['rsn_key_data_len'] = len(data)
  507. msg['rsn_key_data'] = data
  508. msg['length'] = 95 + len(data)
  509. else:
  510. msg['rsn_key_data_len'] = 0
  511. msg['rsn_key_data'] = ''
  512. msg['length'] = 95
  513. def recv_eapol(hapd):
  514. ev = hapd.wait_event(["EAPOL-TX"], timeout=15)
  515. if ev is None:
  516. raise Exception("Timeout on EAPOL-TX from hostapd")
  517. eapol = binascii.unhexlify(ev.split(' ')[2])
  518. return parse_eapol(eapol)
  519. def send_eapol(hapd, addr, data):
  520. res = hapd.request("EAPOL_RX " + addr + " " + binascii.hexlify(data))
  521. if "OK" not in res:
  522. raise Exception("EAPOL_RX to hostapd failed")
  523. def reply_eapol(info, hapd, addr, msg, key_info, nonce, data, kck):
  524. logger.info("Send EAPOL-Key msg " + info)
  525. rsn_eapol_key_set(msg, key_info, 0, nonce, data)
  526. eapol_key_mic(kck, msg)
  527. send_eapol(hapd, addr, build_eapol(msg))
  528. def hapd_connected(hapd):
  529. ev = hapd.wait_event(["AP-STA-CONNECTED"], timeout=15)
  530. if ev is None:
  531. raise Exception("Timeout on AP-STA-CONNECTED from hostapd")
  532. def eapol_test(apdev, dev, wpa2=True):
  533. bssid = apdev['bssid']
  534. if wpa2:
  535. ssid = "test-wpa2-psk"
  536. else:
  537. ssid = "test-wpa-psk"
  538. psk = '602e323e077bc63bd80307ef4745b754b0ae0a925c2638ecd13a794b9527b9e6'
  539. pmk = binascii.unhexlify(psk)
  540. if wpa2:
  541. params = hostapd.wpa2_params(ssid=ssid)
  542. else:
  543. params = hostapd.wpa_params(ssid=ssid)
  544. params['wpa_psk'] = psk
  545. hapd = hostapd.add_ap(apdev['ifname'], params)
  546. hapd.request("SET ext_eapol_frame_io 1")
  547. dev.request("SET ext_eapol_frame_io 1")
  548. dev.connect(ssid, psk="not used", scan_freq="2412", wait_connect=False)
  549. addr = dev.p2p_interface_addr()
  550. if wpa2:
  551. rsne = binascii.unhexlify('30140100000fac040100000fac040100000fac020000')
  552. else:
  553. rsne = binascii.unhexlify('dd160050f20101000050f20201000050f20201000050f202')
  554. snonce = binascii.unhexlify('1111111111111111111111111111111111111111111111111111111111111111')
  555. return (bssid,ssid,hapd,snonce,pmk,addr,rsne)
  556. def test_ap_wpa2_psk_ext_eapol(dev, apdev):
  557. """WPA2-PSK AP using external EAPOL supplicant"""
  558. (bssid,ssid,hapd,snonce,pmk,addr,rsne) = eapol_test(apdev[0], dev[0])
  559. msg = recv_eapol(hapd)
  560. anonce = msg['rsn_key_nonce']
  561. logger.info("Replay same data back")
  562. send_eapol(hapd, addr, build_eapol(msg))
  563. (ptk, kck, kek) = pmk_to_ptk(pmk, addr, bssid, snonce, anonce)
  564. logger.info("Truncated Key Data in EAPOL-Key msg 2/4")
  565. rsn_eapol_key_set(msg, 0x0101, 0, snonce, rsne)
  566. msg['length'] = 95 + 22 - 1
  567. send_eapol(hapd, addr, build_eapol(msg))
  568. reply_eapol("2/4", hapd, addr, msg, 0x010a, snonce, rsne, kck)
  569. msg = recv_eapol(hapd)
  570. if anonce != msg['rsn_key_nonce']:
  571. raise Exception("ANonce changed")
  572. logger.info("Replay same data back")
  573. send_eapol(hapd, addr, build_eapol(msg))
  574. reply_eapol("4/4", hapd, addr, msg, 0x030a, None, None, kck)
  575. hapd_connected(hapd)
  576. def test_ap_wpa2_psk_ext_eapol_retry1(dev, apdev):
  577. """WPA2 4-way handshake with EAPOL-Key 1/4 retransmitted"""
  578. (bssid,ssid,hapd,snonce,pmk,addr,rsne) = eapol_test(apdev[0], dev[0])
  579. msg1 = recv_eapol(hapd)
  580. anonce = msg1['rsn_key_nonce']
  581. msg2 = recv_eapol(hapd)
  582. if anonce != msg2['rsn_key_nonce']:
  583. raise Exception("ANonce changed")
  584. (ptk, kck, kek) = pmk_to_ptk(pmk, addr, bssid, snonce, anonce)
  585. logger.info("Send EAPOL-Key msg 2/4")
  586. msg = msg2
  587. rsn_eapol_key_set(msg, 0x010a, 0, snonce, rsne)
  588. eapol_key_mic(kck, msg)
  589. send_eapol(hapd, addr, build_eapol(msg))
  590. msg = recv_eapol(hapd)
  591. if anonce != msg['rsn_key_nonce']:
  592. raise Exception("ANonce changed")
  593. reply_eapol("4/4", hapd, addr, msg, 0x030a, None, None, kck)
  594. hapd_connected(hapd)
  595. def test_ap_wpa2_psk_ext_eapol_retry1b(dev, apdev):
  596. """WPA2 4-way handshake with EAPOL-Key 1/4 and 2/4 retransmitted"""
  597. (bssid,ssid,hapd,snonce,pmk,addr,rsne) = eapol_test(apdev[0], dev[0])
  598. msg1 = recv_eapol(hapd)
  599. anonce = msg1['rsn_key_nonce']
  600. msg2 = recv_eapol(hapd)
  601. if anonce != msg2['rsn_key_nonce']:
  602. raise Exception("ANonce changed")
  603. (ptk, kck, kek) = pmk_to_ptk(pmk, addr, bssid, snonce, anonce)
  604. reply_eapol("2/4 (a)", hapd, addr, msg1, 0x010a, snonce, rsne, kck)
  605. reply_eapol("2/4 (b)", hapd, addr, msg2, 0x010a, snonce, rsne, kck)
  606. msg = recv_eapol(hapd)
  607. if anonce != msg['rsn_key_nonce']:
  608. raise Exception("ANonce changed")
  609. reply_eapol("4/4", hapd, addr, msg, 0x030a, None, None, kck)
  610. hapd_connected(hapd)
  611. def test_ap_wpa2_psk_ext_eapol_retry1c(dev, apdev):
  612. """WPA2 4-way handshake with EAPOL-Key 1/4 and 2/4 retransmitted and SNonce changing"""
  613. (bssid,ssid,hapd,snonce,pmk,addr,rsne) = eapol_test(apdev[0], dev[0])
  614. msg1 = recv_eapol(hapd)
  615. anonce = msg1['rsn_key_nonce']
  616. msg2 = recv_eapol(hapd)
  617. if anonce != msg2['rsn_key_nonce']:
  618. raise Exception("ANonce changed")
  619. (ptk, kck, kek) = pmk_to_ptk(pmk, addr, bssid, snonce, anonce)
  620. reply_eapol("2/4 (a)", hapd, addr, msg1, 0x010a, snonce, rsne, kck)
  621. snonce2 = binascii.unhexlify('2222222222222222222222222222222222222222222222222222222222222222')
  622. (ptk, kck, kek) = pmk_to_ptk(pmk, addr, bssid, snonce2, anonce)
  623. reply_eapol("2/4 (b)", hapd, addr, msg2, 0x010a, snonce2, rsne, kck)
  624. msg = recv_eapol(hapd)
  625. if anonce != msg['rsn_key_nonce']:
  626. raise Exception("ANonce changed")
  627. reply_eapol("4/4", hapd, addr, msg, 0x030a, None, None, kck)
  628. hapd_connected(hapd)
  629. def test_ap_wpa2_psk_ext_eapol_retry1d(dev, apdev):
  630. """WPA2 4-way handshake with EAPOL-Key 1/4 and 2/4 retransmitted and SNonce changing and older used"""
  631. (bssid,ssid,hapd,snonce,pmk,addr,rsne) = eapol_test(apdev[0], dev[0])
  632. msg1 = recv_eapol(hapd)
  633. anonce = msg1['rsn_key_nonce']
  634. msg2 = recv_eapol(hapd)
  635. if anonce != msg2['rsn_key_nonce']:
  636. raise Exception("ANonce changed")
  637. (ptk, kck, kek) = pmk_to_ptk(pmk, addr, bssid, snonce, anonce)
  638. reply_eapol("2/4 (a)", hapd, addr, msg1, 0x010a, snonce, rsne, kck)
  639. snonce2 = binascii.unhexlify('2222222222222222222222222222222222222222222222222222222222222222')
  640. (ptk2, kck2, kek2) = pmk_to_ptk(pmk, addr, bssid, snonce2, anonce)
  641. reply_eapol("2/4 (b)", hapd, addr, msg2, 0x010a, snonce2, rsne, kck2)
  642. msg = recv_eapol(hapd)
  643. if anonce != msg['rsn_key_nonce']:
  644. raise Exception("ANonce changed")
  645. reply_eapol("4/4", hapd, addr, msg, 0x030a, None, None, kck)
  646. hapd_connected(hapd)
  647. def test_ap_wpa2_psk_ext_eapol_type_diff(dev, apdev):
  648. """WPA2 4-way handshake using external EAPOL supplicant"""
  649. (bssid,ssid,hapd,snonce,pmk,addr,rsne) = eapol_test(apdev[0], dev[0])
  650. msg = recv_eapol(hapd)
  651. anonce = msg['rsn_key_nonce']
  652. (ptk, kck, kek) = pmk_to_ptk(pmk, addr, bssid, snonce, anonce)
  653. # Incorrect descriptor type (frame dropped)
  654. msg['descr_type'] = 253
  655. rsn_eapol_key_set(msg, 0x010a, 0, snonce, rsne)
  656. eapol_key_mic(kck, msg)
  657. send_eapol(hapd, addr, build_eapol(msg))
  658. # Incorrect descriptor type, but with a workaround (frame processed)
  659. msg['descr_type'] = 254
  660. rsn_eapol_key_set(msg, 0x010a, 0, snonce, rsne)
  661. eapol_key_mic(kck, msg)
  662. send_eapol(hapd, addr, build_eapol(msg))
  663. msg = recv_eapol(hapd)
  664. if anonce != msg['rsn_key_nonce']:
  665. raise Exception("ANonce changed")
  666. logger.info("Replay same data back")
  667. send_eapol(hapd, addr, build_eapol(msg))
  668. reply_eapol("4/4", hapd, addr, msg, 0x030a, None, None, kck)
  669. hapd_connected(hapd)
  670. def test_ap_wpa_psk_ext_eapol(dev, apdev):
  671. """WPA2-PSK AP using external EAPOL supplicant"""
  672. (bssid,ssid,hapd,snonce,pmk,addr,wpae) = eapol_test(apdev[0], dev[0],
  673. wpa2=False)
  674. msg = recv_eapol(hapd)
  675. anonce = msg['rsn_key_nonce']
  676. logger.info("Replay same data back")
  677. send_eapol(hapd, addr, build_eapol(msg))
  678. logger.info("Too short data")
  679. send_eapol(hapd, addr, build_eapol(msg)[0:98])
  680. (ptk, kck, kek) = pmk_to_ptk(pmk, addr, bssid, snonce, anonce)
  681. msg['descr_type'] = 2
  682. reply_eapol("2/4(invalid type)", hapd, addr, msg, 0x010a, snonce, wpae, kck)
  683. msg['descr_type'] = 254
  684. reply_eapol("2/4", hapd, addr, msg, 0x010a, snonce, wpae, kck)
  685. msg = recv_eapol(hapd)
  686. if anonce != msg['rsn_key_nonce']:
  687. raise Exception("ANonce changed")
  688. logger.info("Replay same data back")
  689. send_eapol(hapd, addr, build_eapol(msg))
  690. reply_eapol("4/4", hapd, addr, msg, 0x030a, None, None, kck)
  691. hapd_connected(hapd)
  692. def test_ap_wpa2_psk_ext_eapol_key_info(dev, apdev):
  693. """WPA2-PSK 4-way handshake with strange key info values"""
  694. (bssid,ssid,hapd,snonce,pmk,addr,rsne) = eapol_test(apdev[0], dev[0])
  695. msg = recv_eapol(hapd)
  696. anonce = msg['rsn_key_nonce']
  697. (ptk, kck, kek) = pmk_to_ptk(pmk, addr, bssid, snonce, anonce)
  698. rsn_eapol_key_set(msg, 0x0000, 0, snonce, rsne)
  699. send_eapol(hapd, addr, build_eapol(msg))
  700. rsn_eapol_key_set(msg, 0xffff, 0, snonce, rsne)
  701. send_eapol(hapd, addr, build_eapol(msg))
  702. # SMK M1
  703. rsn_eapol_key_set(msg, 0x2802, 0, snonce, rsne)
  704. send_eapol(hapd, addr, build_eapol(msg))
  705. # SMK M3
  706. rsn_eapol_key_set(msg, 0x2002, 0, snonce, rsne)
  707. send_eapol(hapd, addr, build_eapol(msg))
  708. # Request
  709. rsn_eapol_key_set(msg, 0x0902, 0, snonce, rsne)
  710. send_eapol(hapd, addr, build_eapol(msg))
  711. # Request
  712. rsn_eapol_key_set(msg, 0x0902, 0, snonce, rsne)
  713. tmp_kck = binascii.unhexlify('00000000000000000000000000000000')
  714. eapol_key_mic(tmp_kck, msg)
  715. send_eapol(hapd, addr, build_eapol(msg))
  716. reply_eapol("2/4", hapd, addr, msg, 0x010a, snonce, rsne, kck)
  717. msg = recv_eapol(hapd)
  718. if anonce != msg['rsn_key_nonce']:
  719. raise Exception("ANonce changed")
  720. # Request (valic MIC)
  721. rsn_eapol_key_set(msg, 0x0902, 0, snonce, rsne)
  722. eapol_key_mic(kck, msg)
  723. send_eapol(hapd, addr, build_eapol(msg))
  724. # Request (valid MIC, replayed counter)
  725. rsn_eapol_key_set(msg, 0x0902, 0, snonce, rsne)
  726. eapol_key_mic(kck, msg)
  727. send_eapol(hapd, addr, build_eapol(msg))
  728. reply_eapol("4/4", hapd, addr, msg, 0x030a, None, None, kck)
  729. hapd_connected(hapd)
  730. def find_wpas_process(dev):
  731. ifname = dev.ifname
  732. cmd = subprocess.Popen(['ps', 'ax'], stdout=subprocess.PIPE)
  733. (data,err) = cmd.communicate()
  734. for l in data.splitlines():
  735. if "wpa_supplicant" not in l:
  736. continue
  737. if "-i" + ifname not in l:
  738. continue
  739. return int(l.strip().split(' ')[0])
  740. raise Exception("Could not find wpa_supplicant process")
  741. def read_process_memory(pid, key=None):
  742. buf = bytes()
  743. with open('/proc/%d/maps' % pid, 'r') as maps, \
  744. open('/proc/%d/mem' % pid, 'r') as mem:
  745. for l in maps.readlines():
  746. m = re.match(r'([0-9a-f]+)-([0-9a-f]+) ([-r][-w][-x][-p])', l)
  747. if not m:
  748. continue
  749. start = int(m.group(1), 16)
  750. end = int(m.group(2), 16)
  751. perm = m.group(3)
  752. if start > 0xffffffffffff:
  753. continue
  754. if end < start:
  755. continue
  756. if not perm.startswith('rw'):
  757. continue
  758. mem.seek(start)
  759. data = mem.read(end - start)
  760. buf += data
  761. if key and key in data:
  762. logger.info("Key found in " + l)
  763. return buf
  764. def verify_not_present(buf, key, fname, keyname):
  765. pos = buf.find(key)
  766. if pos < 0:
  767. return
  768. prefix = 2048 if pos > 2048 else pos
  769. with open(fname + keyname, 'w') as f:
  770. f.write(buf[pos - prefix:pos + 2048])
  771. raise Exception(keyname + " found after disassociation")
  772. def get_key_locations(buf, key, keyname):
  773. count = 0
  774. pos = 0
  775. while True:
  776. pos = buf.find(key, pos)
  777. if pos < 0:
  778. break
  779. logger.info("Found %s at %d" % (keyname, pos))
  780. count += 1
  781. pos += len(key)
  782. return count
  783. def test_wpa2_psk_key_lifetime_in_memory(dev, apdev, params):
  784. """WPA2-PSK and PSK/PTK lifetime in memory"""
  785. ssid = "test-wpa2-psk"
  786. passphrase = 'qwertyuiop'
  787. psk = '602e323e077bc63bd80307ef4745b754b0ae0a925c2638ecd13a794b9527b9e6'
  788. pmk = binascii.unhexlify(psk)
  789. p = hostapd.wpa2_params(ssid=ssid)
  790. p['wpa_psk'] = psk
  791. hapd = hostapd.add_ap(apdev[0]['ifname'], p)
  792. pid = find_wpas_process(dev[0])
  793. id = dev[0].connect(ssid, raw_psk=psk, scan_freq="2412",
  794. only_add_network=True)
  795. logger.info("Checking keys in memory after network profile configuration")
  796. buf = read_process_memory(pid, pmk)
  797. get_key_locations(buf, pmk, "PMK")
  798. dev[0].request("REMOVE_NETWORK all")
  799. logger.info("Checking keys in memory after network profile removal")
  800. buf = read_process_memory(pid, pmk)
  801. get_key_locations(buf, pmk, "PMK")
  802. id = dev[0].connect(ssid, psk=passphrase, scan_freq="2412",
  803. only_add_network=True)
  804. logger.info("Checking keys in memory before connection")
  805. buf = read_process_memory(pid, pmk)
  806. get_key_locations(buf, pmk, "PMK")
  807. dev[0].connect_network(id, timeout=20)
  808. time.sleep(0.1)
  809. buf = read_process_memory(pid, pmk)
  810. dev[0].request("DISCONNECT")
  811. dev[0].wait_disconnected()
  812. dev[0].relog()
  813. ptk = None
  814. gtk = None
  815. with open(os.path.join(params['logdir'], 'log0'), 'r') as f:
  816. for l in f.readlines():
  817. if "WPA: PTK - hexdump" in l:
  818. val = l.strip().split(':')[3].replace(' ', '')
  819. ptk = binascii.unhexlify(val)
  820. if "WPA: Group Key - hexdump" in l:
  821. val = l.strip().split(':')[3].replace(' ', '')
  822. gtk = binascii.unhexlify(val)
  823. if not pmk or not ptk or not gtk:
  824. raise Exception("Could not find keys from debug log")
  825. if len(gtk) != 16:
  826. raise Exception("Unexpected GTK length")
  827. kck = ptk[0:16]
  828. kek = ptk[16:32]
  829. tk = ptk[32:48]
  830. logger.info("Checking keys in memory while associated")
  831. get_key_locations(buf, pmk, "PMK")
  832. if pmk not in buf:
  833. raise HwsimSkip("PMK not found while associated")
  834. if kck not in buf:
  835. raise Exception("KCK not found while associated")
  836. if kek not in buf:
  837. raise Exception("KEK not found while associated")
  838. if tk in buf:
  839. raise Exception("TK found from memory")
  840. if gtk in buf:
  841. raise Exception("GTK found from memory")
  842. logger.info("Checking keys in memory after disassociation")
  843. buf = read_process_memory(pid, pmk)
  844. get_key_locations(buf, pmk, "PMK")
  845. # Note: PMK/PSK is still present in network configuration
  846. fname = os.path.join(params['logdir'],
  847. 'wpa2_psk_key_lifetime_in_memory.memctx-')
  848. verify_not_present(buf, kck, fname, "KCK")
  849. verify_not_present(buf, kek, fname, "KEK")
  850. verify_not_present(buf, tk, fname, "TK")
  851. verify_not_present(buf, gtk, fname, "GTK")
  852. dev[0].request("REMOVE_NETWORK all")
  853. logger.info("Checking keys in memory after network profile removal")
  854. buf = read_process_memory(pid, pmk)
  855. get_key_locations(buf, pmk, "PMK")
  856. verify_not_present(buf, pmk, fname, "PMK")
  857. verify_not_present(buf, kck, fname, "KCK")
  858. verify_not_present(buf, kek, fname, "KEK")
  859. verify_not_present(buf, tk, fname, "TK")
  860. verify_not_present(buf, gtk, fname, "GTK")
  861. def test_ap_wpa2_psk_wep(dev, apdev):
  862. """WPA2-PSK AP and WEP enabled"""
  863. ssid = "test-wpa2-psk"
  864. passphrase = 'qwertyuiop'
  865. params = hostapd.wpa2_params(ssid=ssid, passphrase=passphrase)
  866. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  867. try:
  868. hapd.set('wep_key0', '"hello"')
  869. raise Exception("WEP key accepted to WPA2 network")
  870. except Exception:
  871. pass