test_tnc.py 3.0 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283
  1. # -*- coding: utf-8 -*-
  2. # TNC tests
  3. # Copyright (c) 2014, Jouni Malinen <j@w1.fi>
  4. #
  5. # This software may be distributed under the terms of the BSD license.
  6. # See README for more details.
  7. import os.path
  8. import hostapd
  9. from test_ap_eap import int_eap_server_params
  10. def test_tnc_peap_soh(dev, apdev):
  11. """TNC PEAP-SoH"""
  12. params = int_eap_server_params()
  13. params["tnc"] = "1"
  14. hostapd.add_ap(apdev[0]['ifname'], params)
  15. dev[0].connect("test-wpa2-eap", key_mgmt="WPA-EAP",
  16. eap="PEAP", identity="user", password="password",
  17. ca_cert="auth_serv/ca.pem",
  18. phase1="peapver=0 tnc=soh cryptobinding=0",
  19. phase2="auth=MSCHAPV2",
  20. wait_connect=False)
  21. dev[0].wait_connected(timeout=10)
  22. dev[1].connect("test-wpa2-eap", key_mgmt="WPA-EAP",
  23. eap="PEAP", identity="user", password="password",
  24. ca_cert="auth_serv/ca.pem",
  25. phase1="peapver=0 tnc=soh1 cryptobinding=1",
  26. phase2="auth=MSCHAPV2",
  27. wait_connect=False)
  28. dev[1].wait_connected(timeout=10)
  29. dev[2].connect("test-wpa2-eap", key_mgmt="WPA-EAP",
  30. eap="PEAP", identity="user", password="password",
  31. ca_cert="auth_serv/ca.pem",
  32. phase1="peapver=0 tnc=soh2 cryptobinding=2",
  33. phase2="auth=MSCHAPV2",
  34. wait_connect=False)
  35. dev[2].wait_connected(timeout=10)
  36. def test_tnc_ttls(dev, apdev):
  37. """TNC TTLS"""
  38. params = int_eap_server_params()
  39. params["tnc"] = "1"
  40. hostapd.add_ap(apdev[0]['ifname'], params)
  41. if not os.path.exists("tnc/libhostap_imc.so"):
  42. logger.info("No IMC installed - skip")
  43. return "skip"
  44. dev[0].connect("test-wpa2-eap", key_mgmt="WPA-EAP",
  45. eap="TTLS", identity="DOMAIN\mschapv2 user",
  46. anonymous_identity="ttls", password="password",
  47. phase2="auth=MSCHAPV2",
  48. ca_cert="auth_serv/ca.pem",
  49. wait_connect=False)
  50. dev[0].wait_connected(timeout=10)
  51. def test_tnc_fast(dev, apdev):
  52. """TNC FAST"""
  53. params = int_eap_server_params()
  54. params["tnc"] = "1"
  55. params["pac_opaque_encr_key"] ="000102030405060708090a0b0c0d0e00"
  56. params["eap_fast_a_id"] = "101112131415161718191a1b1c1d1e00"
  57. params["eap_fast_a_id_info"] = "test server2"
  58. hostapd.add_ap(apdev[0]['ifname'], params)
  59. if not os.path.exists("tnc/libhostap_imc.so"):
  60. logger.info("No IMC installed - skip")
  61. return "skip"
  62. dev[0].connect("test-wpa2-eap", key_mgmt="WPA-EAP",
  63. eap="FAST", identity="user",
  64. anonymous_identity="FAST", password="password",
  65. phase2="auth=GTC",
  66. phase1="fast_provisioning=2",
  67. pac_file="blob://fast_pac_auth_tnc",
  68. ca_cert="auth_serv/ca.pem",
  69. wait_connect=False)
  70. dev[0].wait_connected(timeout=10)