test_fils.py 53 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406
  1. # Test cases for FILS
  2. # Copyright (c) 2015-2017, Qualcomm Atheros, Inc.
  3. #
  4. # This software may be distributed under the terms of the BSD license.
  5. # See README for more details.
  6. import binascii
  7. import hashlib
  8. import logging
  9. logger = logging.getLogger()
  10. import os
  11. import socket
  12. import struct
  13. import time
  14. import hostapd
  15. from wpasupplicant import WpaSupplicant
  16. import hwsim_utils
  17. from utils import HwsimSkip, alloc_fail
  18. from test_erp import check_erp_capa, start_erp_as
  19. from test_ap_hs20 import ip_checksum
  20. def check_fils_capa(dev):
  21. capa = dev.get_capability("fils")
  22. if capa is None or "FILS" not in capa:
  23. raise HwsimSkip("FILS not supported")
  24. def test_fils_sk_full_auth(dev, apdev):
  25. """FILS SK full authentication"""
  26. check_fils_capa(dev[0])
  27. check_erp_capa(dev[0])
  28. start_erp_as(apdev[1])
  29. bssid = apdev[0]['bssid']
  30. params = hostapd.wpa2_eap_params(ssid="fils")
  31. params['wpa_key_mgmt'] = "FILS-SHA256"
  32. params['auth_server_port'] = "18128"
  33. params['erp_send_reauth_start'] = '1'
  34. params['erp_domain'] = 'example.com'
  35. params['fils_realm'] = 'example.com'
  36. params['wpa_group_rekey'] = '1'
  37. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  38. dev[0].scan_for_bss(bssid, freq=2412)
  39. bss = dev[0].get_bss(bssid)
  40. logger.debug("BSS: " + str(bss))
  41. if "[FILS]" not in bss['flags']:
  42. raise Exception("[FILS] flag not indicated")
  43. if "[WPA2-FILS-SHA256-CCMP]" not in bss['flags']:
  44. raise Exception("[WPA2-FILS-SHA256-CCMP] flag not indicated")
  45. res = dev[0].request("SCAN_RESULTS")
  46. logger.debug("SCAN_RESULTS: " + res)
  47. if "[FILS]" not in res:
  48. raise Exception("[FILS] flag not indicated")
  49. if "[WPA2-FILS-SHA256-CCMP]" not in res:
  50. raise Exception("[WPA2-FILS-SHA256-CCMP] flag not indicated")
  51. dev[0].request("ERP_FLUSH")
  52. dev[0].connect("fils", key_mgmt="FILS-SHA256",
  53. eap="PSK", identity="psk.user@example.com",
  54. password_hex="0123456789abcdef0123456789abcdef",
  55. erp="1", scan_freq="2412")
  56. hwsim_utils.test_connectivity(dev[0], hapd)
  57. ev = dev[0].wait_event(["WPA: Group rekeying completed"], timeout=2)
  58. if ev is None:
  59. raise Exception("GTK rekey timed out")
  60. hwsim_utils.test_connectivity(dev[0], hapd)
  61. conf = hapd.get_config()
  62. if conf['key_mgmt'] != 'FILS-SHA256':
  63. raise Exception("Unexpected config key_mgmt: " + conf['key_mgmt'])
  64. def test_fils_sk_sha384_full_auth(dev, apdev):
  65. """FILS SK full authentication (SHA384)"""
  66. check_fils_capa(dev[0])
  67. check_erp_capa(dev[0])
  68. start_erp_as(apdev[1])
  69. bssid = apdev[0]['bssid']
  70. params = hostapd.wpa2_eap_params(ssid="fils")
  71. params['wpa_key_mgmt'] = "FILS-SHA384"
  72. params['auth_server_port'] = "18128"
  73. params['erp_send_reauth_start'] = '1'
  74. params['erp_domain'] = 'example.com'
  75. params['fils_realm'] = 'example.com'
  76. params['wpa_group_rekey'] = '1'
  77. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  78. dev[0].scan_for_bss(bssid, freq=2412)
  79. bss = dev[0].get_bss(bssid)
  80. logger.debug("BSS: " + str(bss))
  81. if "[FILS]" not in bss['flags']:
  82. raise Exception("[FILS] flag not indicated")
  83. if "[WPA2-FILS-SHA384-CCMP]" not in bss['flags']:
  84. raise Exception("[WPA2-FILS-SHA384-CCMP] flag not indicated")
  85. res = dev[0].request("SCAN_RESULTS")
  86. logger.debug("SCAN_RESULTS: " + res)
  87. if "[FILS]" not in res:
  88. raise Exception("[FILS] flag not indicated")
  89. if "[WPA2-FILS-SHA384-CCMP]" not in res:
  90. raise Exception("[WPA2-FILS-SHA384-CCMP] flag not indicated")
  91. dev[0].request("ERP_FLUSH")
  92. dev[0].connect("fils", key_mgmt="FILS-SHA384",
  93. eap="PSK", identity="psk.user@example.com",
  94. password_hex="0123456789abcdef0123456789abcdef",
  95. erp="1", scan_freq="2412")
  96. hwsim_utils.test_connectivity(dev[0], hapd)
  97. ev = dev[0].wait_event(["WPA: Group rekeying completed"], timeout=2)
  98. if ev is None:
  99. raise Exception("GTK rekey timed out")
  100. hwsim_utils.test_connectivity(dev[0], hapd)
  101. conf = hapd.get_config()
  102. if conf['key_mgmt'] != 'FILS-SHA384':
  103. raise Exception("Unexpected config key_mgmt: " + conf['key_mgmt'])
  104. def test_fils_sk_pmksa_caching(dev, apdev):
  105. """FILS SK and PMKSA caching"""
  106. check_fils_capa(dev[0])
  107. check_erp_capa(dev[0])
  108. start_erp_as(apdev[1])
  109. bssid = apdev[0]['bssid']
  110. params = hostapd.wpa2_eap_params(ssid="fils")
  111. params['wpa_key_mgmt'] = "FILS-SHA256"
  112. params['auth_server_port'] = "18128"
  113. params['erp_domain'] = 'example.com'
  114. params['fils_realm'] = 'example.com'
  115. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  116. dev[0].scan_for_bss(bssid, freq=2412)
  117. dev[0].request("ERP_FLUSH")
  118. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  119. eap="PSK", identity="psk.user@example.com",
  120. password_hex="0123456789abcdef0123456789abcdef",
  121. erp="1", scan_freq="2412")
  122. pmksa = dev[0].get_pmksa(bssid)
  123. if pmksa is None:
  124. raise Exception("No PMKSA cache entry created")
  125. dev[0].request("DISCONNECT")
  126. dev[0].wait_disconnected()
  127. dev[0].dump_monitor()
  128. dev[0].select_network(id, freq=2412)
  129. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  130. "CTRL-EVENT-CONNECTED"], timeout=10)
  131. if ev is None:
  132. raise Exception("Connection using PMKSA caching timed out")
  133. if "CTRL-EVENT-EAP-STARTED" in ev:
  134. raise Exception("Unexpected EAP exchange")
  135. hwsim_utils.test_connectivity(dev[0], hapd)
  136. pmksa2 = dev[0].get_pmksa(bssid)
  137. if pmksa2 is None:
  138. raise Exception("No PMKSA cache entry found")
  139. if pmksa['pmkid'] != pmksa2['pmkid']:
  140. raise Exception("Unexpected PMKID change")
  141. # Verify EAPOL reauthentication after FILS authentication
  142. hapd.request("EAPOL_REAUTH " + dev[0].own_addr())
  143. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED"], timeout=5)
  144. if ev is None:
  145. raise Exception("EAP authentication did not start")
  146. ev = dev[0].wait_event(["CTRL-EVENT-EAP-SUCCESS"], timeout=5)
  147. if ev is None:
  148. raise Exception("EAP authentication did not succeed")
  149. time.sleep(0.1)
  150. hwsim_utils.test_connectivity(dev[0], hapd)
  151. def test_fils_sk_pmksa_caching_and_cache_id(dev, apdev):
  152. """FILS SK and PMKSA caching with Cache Identifier"""
  153. check_fils_capa(dev[0])
  154. check_erp_capa(dev[0])
  155. bssid = apdev[0]['bssid']
  156. params = hostapd.wpa2_eap_params(ssid="fils")
  157. params['wpa_key_mgmt'] = "FILS-SHA256"
  158. params['auth_server_port'] = "18128"
  159. params['erp_domain'] = 'example.com'
  160. params['fils_realm'] = 'example.com'
  161. params['fils_cache_id'] = "abcd"
  162. params["radius_server_clients"] = "auth_serv/radius_clients.conf"
  163. params["radius_server_auth_port"] = '18128'
  164. params["eap_server"] = "1"
  165. params["eap_user_file"] = "auth_serv/eap_user.conf"
  166. params["ca_cert"] = "auth_serv/ca.pem"
  167. params["server_cert"] = "auth_serv/server.pem"
  168. params["private_key"] = "auth_serv/server.key"
  169. params["eap_sim_db"] = "unix:/tmp/hlr_auc_gw.sock"
  170. params["dh_file"] = "auth_serv/dh.conf"
  171. params["pac_opaque_encr_key"] = "000102030405060708090a0b0c0d0e0f"
  172. params["eap_fast_a_id"] = "101112131415161718191a1b1c1d1e1f"
  173. params["eap_fast_a_id_info"] = "test server"
  174. params["eap_server_erp"] = "1"
  175. params["erp_domain"] = "example.com"
  176. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  177. dev[0].scan_for_bss(bssid, freq=2412)
  178. dev[0].request("ERP_FLUSH")
  179. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  180. eap="PSK", identity="psk.user@example.com",
  181. password_hex="0123456789abcdef0123456789abcdef",
  182. erp="1", scan_freq="2412")
  183. res = dev[0].request("PMKSA")
  184. if "FILS Cache Identifier" not in res:
  185. raise Exception("PMKSA list does not include FILS Cache Identifier")
  186. pmksa = dev[0].get_pmksa(bssid)
  187. if pmksa is None:
  188. raise Exception("No PMKSA cache entry created")
  189. if "cache_id" not in pmksa:
  190. raise Exception("No FILS Cache Identifier listed")
  191. if pmksa["cache_id"] != "abcd":
  192. raise Exception("The configured FILS Cache Identifier not seen in PMKSA")
  193. bssid2 = apdev[1]['bssid']
  194. params = hostapd.wpa2_eap_params(ssid="fils")
  195. params['wpa_key_mgmt'] = "FILS-SHA256"
  196. params['auth_server_port'] = "18128"
  197. params['erp_domain'] = 'example.com'
  198. params['fils_realm'] = 'example.com'
  199. params['fils_cache_id'] = "abcd"
  200. hapd2 = hostapd.add_ap(apdev[1]['ifname'], params)
  201. dev[0].scan_for_bss(bssid2, freq=2412)
  202. dev[0].dump_monitor()
  203. if "OK" not in dev[0].request("ROAM " + bssid2):
  204. raise Exception("ROAM failed")
  205. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  206. "CTRL-EVENT-CONNECTED"], timeout=10)
  207. if ev is None:
  208. raise Exception("Connection using PMKSA caching timed out")
  209. if "CTRL-EVENT-EAP-STARTED" in ev:
  210. raise Exception("Unexpected EAP exchange")
  211. if bssid2 not in ev:
  212. raise Exception("Failed to connect to the second AP")
  213. hwsim_utils.test_connectivity(dev[0], hapd2)
  214. pmksa2 = dev[0].get_pmksa(bssid2)
  215. if pmksa2:
  216. raise Exception("Unexpected extra PMKSA cache added")
  217. pmksa2 = dev[0].get_pmksa(bssid)
  218. if not pmksa2:
  219. raise Exception("Original PMKSA cache entry removed")
  220. if pmksa['pmkid'] != pmksa2['pmkid']:
  221. raise Exception("Unexpected PMKID change")
  222. def test_fils_sk_pmksa_caching_ctrl_ext(dev, apdev):
  223. """FILS SK and PMKSA caching with Cache Identifier and external management"""
  224. check_fils_capa(dev[0])
  225. check_erp_capa(dev[0])
  226. hapd_as = start_erp_as(apdev[1])
  227. bssid = apdev[0]['bssid']
  228. params = hostapd.wpa2_eap_params(ssid="fils")
  229. params['wpa_key_mgmt'] = "FILS-SHA384"
  230. params['auth_server_port'] = "18128"
  231. params['erp_send_reauth_start'] = '1'
  232. params['erp_domain'] = 'example.com'
  233. params['fils_realm'] = 'example.com'
  234. params['fils_cache_id'] = "ffee"
  235. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  236. dev[0].scan_for_bss(bssid, freq=2412)
  237. dev[0].request("ERP_FLUSH")
  238. id = dev[0].connect("fils", key_mgmt="FILS-SHA384",
  239. eap="PSK", identity="psk.user@example.com",
  240. password_hex="0123456789abcdef0123456789abcdef",
  241. erp="1", scan_freq="2412")
  242. res1 = dev[0].request("PMKSA_GET %d" % id)
  243. logger.info("PMKSA_GET: " + res1)
  244. if "UNKNOWN COMMAND" in res1:
  245. raise HwsimSkip("PMKSA_GET not supported in the build")
  246. if bssid not in res1:
  247. raise Exception("PMKSA cache entry missing")
  248. if "ffee" not in res1:
  249. raise Exception("FILS Cache Identifier not seen in PMKSA cache entry")
  250. dev[0].request("DISCONNECT")
  251. dev[0].wait_disconnected()
  252. hapd_as.disable()
  253. dev[0].scan_for_bss(bssid, freq=2412)
  254. dev[0].request("PMKSA_FLUSH")
  255. dev[0].request("ERP_FLUSH")
  256. for entry in res1.splitlines():
  257. if "OK" not in dev[0].request("PMKSA_ADD %d %s" % (id, entry)):
  258. raise Exception("Failed to add PMKSA entry")
  259. bssid2 = apdev[1]['bssid']
  260. params = hostapd.wpa2_eap_params(ssid="fils")
  261. params['wpa_key_mgmt'] = "FILS-SHA384"
  262. params['auth_server_port'] = "18128"
  263. params['erp_send_reauth_start'] = '1'
  264. params['erp_domain'] = 'example.com'
  265. params['fils_realm'] = 'example.com'
  266. params['fils_cache_id'] = "ffee"
  267. hapd2 = hostapd.add_ap(apdev[1]['ifname'], params)
  268. dev[0].scan_for_bss(bssid2, freq=2412)
  269. dev[0].set_network(id, "bssid", bssid2)
  270. dev[0].select_network(id, freq=2412)
  271. ev = dev[0].wait_connected()
  272. if bssid2 not in ev:
  273. raise Exception("Unexpected BSS selected")
  274. def test_fils_sk_erp(dev, apdev):
  275. """FILS SK using ERP"""
  276. run_fils_sk_erp(dev, apdev, "FILS-SHA256")
  277. def test_fils_sk_erp_sha384(dev, apdev):
  278. """FILS SK using ERP and SHA384"""
  279. run_fils_sk_erp(dev, apdev, "FILS-SHA384")
  280. def run_fils_sk_erp(dev, apdev, key_mgmt):
  281. check_fils_capa(dev[0])
  282. check_erp_capa(dev[0])
  283. start_erp_as(apdev[1])
  284. bssid = apdev[0]['bssid']
  285. params = hostapd.wpa2_eap_params(ssid="fils")
  286. params['wpa_key_mgmt'] = key_mgmt
  287. params['auth_server_port'] = "18128"
  288. params['erp_domain'] = 'example.com'
  289. params['fils_realm'] = 'example.com'
  290. params['disable_pmksa_caching'] = '1'
  291. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  292. dev[0].scan_for_bss(bssid, freq=2412)
  293. dev[0].request("ERP_FLUSH")
  294. id = dev[0].connect("fils", key_mgmt=key_mgmt,
  295. eap="PSK", identity="psk.user@example.com",
  296. password_hex="0123456789abcdef0123456789abcdef",
  297. erp="1", scan_freq="2412")
  298. dev[0].request("DISCONNECT")
  299. dev[0].wait_disconnected()
  300. dev[0].dump_monitor()
  301. dev[0].select_network(id, freq=2412)
  302. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  303. "EVENT-ASSOC-REJECT",
  304. "CTRL-EVENT-CONNECTED"], timeout=10)
  305. if ev is None:
  306. raise Exception("Connection using FILS/ERP timed out")
  307. if "CTRL-EVENT-EAP-STARTED" in ev:
  308. raise Exception("Unexpected EAP exchange")
  309. if "EVENT-ASSOC-REJECT" in ev:
  310. raise Exception("Association failed")
  311. hwsim_utils.test_connectivity(dev[0], hapd)
  312. def test_fils_sk_erp_another_ssid(dev, apdev):
  313. """FILS SK using ERP and roam to another SSID"""
  314. check_fils_capa(dev[0])
  315. check_erp_capa(dev[0])
  316. start_erp_as(apdev[1])
  317. bssid = apdev[0]['bssid']
  318. params = hostapd.wpa2_eap_params(ssid="fils")
  319. params['wpa_key_mgmt'] = "FILS-SHA256"
  320. params['auth_server_port'] = "18128"
  321. params['erp_domain'] = 'example.com'
  322. params['fils_realm'] = 'example.com'
  323. params['disable_pmksa_caching'] = '1'
  324. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  325. dev[0].scan_for_bss(bssid, freq=2412)
  326. dev[0].request("ERP_FLUSH")
  327. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  328. eap="PSK", identity="psk.user@example.com",
  329. password_hex="0123456789abcdef0123456789abcdef",
  330. erp="1", scan_freq="2412")
  331. dev[0].request("DISCONNECT")
  332. dev[0].wait_disconnected()
  333. hapd.disable()
  334. dev[0].flush_scan_cache()
  335. if "FAIL" in dev[0].request("PMKSA_FLUSH"):
  336. raise Exception("PMKSA_FLUSH failed")
  337. params = hostapd.wpa2_eap_params(ssid="fils2")
  338. params['wpa_key_mgmt'] = "FILS-SHA256"
  339. params['auth_server_port'] = "18128"
  340. params['erp_domain'] = 'example.com'
  341. params['fils_realm'] = 'example.com'
  342. params['disable_pmksa_caching'] = '1'
  343. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  344. dev[0].scan_for_bss(bssid, freq=2412)
  345. dev[0].dump_monitor()
  346. id = dev[0].connect("fils2", key_mgmt="FILS-SHA256",
  347. eap="PSK", identity="psk.user@example.com",
  348. password_hex="0123456789abcdef0123456789abcdef",
  349. erp="1", scan_freq="2412", wait_connect=False)
  350. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  351. "EVENT-ASSOC-REJECT",
  352. "CTRL-EVENT-CONNECTED"], timeout=10)
  353. if ev is None:
  354. raise Exception("Connection using FILS/ERP timed out")
  355. if "CTRL-EVENT-EAP-STARTED" in ev:
  356. raise Exception("Unexpected EAP exchange")
  357. if "EVENT-ASSOC-REJECT" in ev:
  358. raise Exception("Association failed")
  359. hwsim_utils.test_connectivity(dev[0], hapd)
  360. def test_fils_sk_multiple_realms(dev, apdev):
  361. """FILS SK and multiple realms"""
  362. check_fils_capa(dev[0])
  363. check_erp_capa(dev[0])
  364. start_erp_as(apdev[1])
  365. bssid = apdev[0]['bssid']
  366. params = hostapd.wpa2_eap_params(ssid="fils")
  367. params['wpa_key_mgmt'] = "FILS-SHA256"
  368. params['auth_server_port'] = "18128"
  369. params['erp_domain'] = 'example.com'
  370. fils_realms = [ 'r1.example.org', 'r2.EXAMPLE.org', 'r3.example.org',
  371. 'r4.example.org', 'r5.example.org', 'r6.example.org',
  372. 'r7.example.org', 'r8.example.org',
  373. 'example.com',
  374. 'r9.example.org', 'r10.example.org', 'r11.example.org',
  375. 'r12.example.org', 'r13.example.org', 'r14.example.org',
  376. 'r15.example.org', 'r16.example.org' ]
  377. params['fils_realm'] = fils_realms
  378. params['fils_cache_id'] = "1234"
  379. params['hessid'] = bssid
  380. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  381. dev[0].scan_for_bss(bssid, freq=2412)
  382. if "OK" not in dev[0].request("ANQP_GET " + bssid + " 275"):
  383. raise Exception("ANQP_GET command failed")
  384. ev = dev[0].wait_event(["GAS-QUERY-DONE"], timeout=10)
  385. if ev is None:
  386. raise Exception("GAS query timed out")
  387. bss = dev[0].get_bss(bssid)
  388. if 'fils_info' not in bss:
  389. raise Exception("FILS Indication element information missing")
  390. if bss['fils_info'] != '02b8':
  391. raise Exception("Unexpected FILS Information: " + bss['fils_info'])
  392. if 'fils_cache_id' not in bss:
  393. raise Exception("FILS Cache Identifier missing")
  394. if bss['fils_cache_id'] != '1234':
  395. raise Exception("Unexpected FILS Cache Identifier: " + bss['fils_cache_id'])
  396. if 'fils_realms' not in bss:
  397. raise Exception("FILS Realm Identifiers missing")
  398. expected = ''
  399. count = 0
  400. for realm in fils_realms:
  401. hash = hashlib.sha256(realm.lower()).digest()
  402. expected += binascii.hexlify(hash[0:2])
  403. count += 1
  404. if count == 7:
  405. break
  406. if bss['fils_realms'] != expected:
  407. raise Exception("Unexpected FILS Realm Identifiers: " + bss['fils_realms'])
  408. if 'anqp_fils_realm_info' not in bss:
  409. raise Exception("FILS Realm Information ANQP-element not seen")
  410. info = bss['anqp_fils_realm_info'];
  411. expected = ''
  412. for realm in fils_realms:
  413. hash = hashlib.sha256(realm.lower()).digest()
  414. expected += binascii.hexlify(hash[0:2])
  415. if info != expected:
  416. raise Exception("Unexpected FILS Realm Info ANQP-element: " + info)
  417. dev[0].request("ERP_FLUSH")
  418. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  419. eap="PSK", identity="psk.user@example.com",
  420. password_hex="0123456789abcdef0123456789abcdef",
  421. erp="1", scan_freq="2412")
  422. dev[0].request("DISCONNECT")
  423. dev[0].wait_disconnected()
  424. dev[0].dump_monitor()
  425. dev[0].select_network(id, freq=2412)
  426. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  427. "EVENT-ASSOC-REJECT",
  428. "CTRL-EVENT-CONNECTED"], timeout=10)
  429. if ev is None:
  430. raise Exception("Connection using FILS/ERP timed out")
  431. if "CTRL-EVENT-EAP-STARTED" in ev:
  432. raise Exception("Unexpected EAP exchange")
  433. if "EVENT-ASSOC-REJECT" in ev:
  434. raise Exception("Association failed")
  435. hwsim_utils.test_connectivity(dev[0], hapd)
  436. # DHCP message op codes
  437. BOOTREQUEST=1
  438. BOOTREPLY=2
  439. OPT_PAD=0
  440. OPT_DHCP_MESSAGE_TYPE=53
  441. OPT_RAPID_COMMIT=80
  442. OPT_END=255
  443. DHCPDISCOVER=1
  444. DHCPOFFER=2
  445. DHCPREQUEST=3
  446. DHCPDECLINE=4
  447. DHCPACK=5
  448. DHCPNAK=6
  449. DHCPRELEASE=7
  450. DHCPINFORM=8
  451. def build_dhcp(req, dhcp_msg, chaddr, giaddr="0.0.0.0",
  452. ip_src="0.0.0.0", ip_dst="255.255.255.255",
  453. rapid_commit=True, override_op=None, magic_override=None,
  454. opt_end=True, extra_op=None):
  455. proto = '\x08\x00' # IPv4
  456. _ip_src = socket.inet_pton(socket.AF_INET, ip_src)
  457. _ip_dst = socket.inet_pton(socket.AF_INET, ip_dst)
  458. _ciaddr = '\x00\x00\x00\x00'
  459. _yiaddr = '\x00\x00\x00\x00'
  460. _siaddr = '\x00\x00\x00\x00'
  461. _giaddr = socket.inet_pton(socket.AF_INET, giaddr)
  462. _chaddr = binascii.unhexlify(chaddr.replace(':','')) + 10*'\x00'
  463. htype = 1 # Hardware address type; 1 = Ethernet
  464. hlen = 6 # Hardware address length
  465. hops = 0
  466. xid = 123456
  467. secs = 0
  468. flags = 0
  469. if req:
  470. op = BOOTREQUEST
  471. src_port = 68
  472. dst_port = 67
  473. else:
  474. op = BOOTREPLY
  475. src_port = 67
  476. dst_port = 68
  477. if override_op is not None:
  478. op = override_op
  479. payload = struct.pack('>BBBBLHH', op, htype, hlen, hops, xid, secs, flags)
  480. sname = 64*'\x00'
  481. file = 128*'\x00'
  482. payload += _ciaddr + _yiaddr + _siaddr + _giaddr + _chaddr + sname + file
  483. # magic - DHCP
  484. if magic_override is not None:
  485. payload += magic_override
  486. else:
  487. payload += '\x63\x82\x53\x63'
  488. # Option: DHCP Message Type
  489. if dhcp_msg is not None:
  490. payload += struct.pack('BBB', OPT_DHCP_MESSAGE_TYPE, 1, dhcp_msg)
  491. if rapid_commit:
  492. # Option: Rapid Commit
  493. payload += struct.pack('BB', OPT_RAPID_COMMIT, 0)
  494. if extra_op:
  495. payload += extra_op
  496. # End Option
  497. if opt_end:
  498. payload += struct.pack('B', OPT_END)
  499. udp = struct.pack('>HHHH', src_port, dst_port,
  500. 8 + len(payload), 0) + payload
  501. tot_len = 20 + len(udp)
  502. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  503. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  504. csum = ip_checksum(ipv4)
  505. ipv4 = start + csum + _ip_src + _ip_dst
  506. return proto + ipv4 + udp
  507. def fils_hlp_config(fils_hlp_wait_time=10000):
  508. params = hostapd.wpa2_eap_params(ssid="fils")
  509. params['wpa_key_mgmt'] = "FILS-SHA256"
  510. params['auth_server_port'] = "18128"
  511. params['erp_domain'] = 'example.com'
  512. params['fils_realm'] = 'example.com'
  513. params['disable_pmksa_caching'] = '1'
  514. params['own_ip_addr'] = '127.0.0.3'
  515. params['dhcp_server'] = '127.0.0.2'
  516. params['fils_hlp_wait_time'] = str(fils_hlp_wait_time)
  517. return params
  518. def test_fils_sk_hlp(dev, apdev):
  519. """FILS SK HLP (rapid commit server)"""
  520. run_fils_sk_hlp(dev, apdev, True)
  521. def test_fils_sk_hlp_no_rapid_commit(dev, apdev):
  522. """FILS SK HLP (no rapid commit server)"""
  523. run_fils_sk_hlp(dev, apdev, False)
  524. def run_fils_sk_hlp(dev, apdev, rapid_commit_server):
  525. check_fils_capa(dev[0])
  526. check_erp_capa(dev[0])
  527. start_erp_as(apdev[1])
  528. sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
  529. sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
  530. sock.settimeout(5)
  531. sock.bind(("127.0.0.2", 67))
  532. bssid = apdev[0]['bssid']
  533. params = fils_hlp_config()
  534. params['fils_hlp_wait_time'] = '10000'
  535. if not rapid_commit_server:
  536. params['dhcp_rapid_commit_proxy'] = '1'
  537. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  538. dev[0].scan_for_bss(bssid, freq=2412)
  539. dev[0].request("ERP_FLUSH")
  540. if "OK" not in dev[0].request("FILS_HLP_REQ_FLUSH"):
  541. raise Exception("Failed to flush pending FILS HLP requests")
  542. tests = [ "",
  543. "q",
  544. "ff:ff:ff:ff:ff:ff",
  545. "ff:ff:ff:ff:ff:ff q" ]
  546. for t in tests:
  547. if "FAIL" not in dev[0].request("FILS_HLP_REQ_ADD " + t):
  548. raise Exception("Invalid FILS_HLP_REQ_ADD accepted: " + t)
  549. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  550. chaddr=dev[0].own_addr())
  551. tests = [ "ff:ff:ff:ff:ff:ff aabb",
  552. "ff:ff:ff:ff:ff:ff " + 255*'cc',
  553. hapd.own_addr() + " ddee010203040506070809",
  554. "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc) ]
  555. for t in tests:
  556. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + t):
  557. raise Exception("FILS_HLP_REQ_ADD failed: " + t)
  558. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  559. eap="PSK", identity="psk.user@example.com",
  560. password_hex="0123456789abcdef0123456789abcdef",
  561. erp="1", scan_freq="2412")
  562. dev[0].request("DISCONNECT")
  563. dev[0].wait_disconnected()
  564. dev[0].dump_monitor()
  565. dev[0].select_network(id, freq=2412)
  566. (msg,addr) = sock.recvfrom(1000)
  567. logger.debug("Received DHCP message from %s" % str(addr))
  568. if rapid_commit_server:
  569. # TODO: Proper rapid commit response
  570. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPACK,
  571. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  572. sock.sendto(dhcpdisc[2+20+8:], addr)
  573. else:
  574. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  575. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  576. sock.sendto(dhcpdisc[2+20+8:], addr)
  577. (msg,addr) = sock.recvfrom(1000)
  578. logger.debug("Received DHCP message from %s" % str(addr))
  579. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPACK, rapid_commit=False,
  580. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  581. sock.sendto(dhcpdisc[2+20+8:], addr)
  582. ev = dev[0].wait_event(["FILS-HLP-RX"], timeout=10)
  583. if ev is None:
  584. raise Exception("FILS HLP response not reported")
  585. vals = ev.split(' ')
  586. frame = binascii.unhexlify(vals[3].split('=')[1])
  587. proto, = struct.unpack('>H', frame[0:2])
  588. if proto != 0x0800:
  589. raise Exception("Unexpected ethertype in HLP response: %d" % proto)
  590. frame = frame[2:]
  591. ip = frame[0:20]
  592. if ip_checksum(ip) != '\x00\x00':
  593. raise Exception("IP header checksum mismatch in HLP response")
  594. frame = frame[20:]
  595. udp = frame[0:8]
  596. frame = frame[8:]
  597. sport, dport, ulen, ucheck = struct.unpack('>HHHH', udp)
  598. if sport != 67 or dport != 68:
  599. raise Exception("Unexpected UDP port in HLP response")
  600. dhcp = frame[0:28]
  601. frame = frame[28:]
  602. op,htype,hlen,hops,xid,secs,flags,ciaddr,yiaddr,siaddr,giaddr = struct.unpack('>4BL2H4L', dhcp)
  603. chaddr = frame[0:16]
  604. frame = frame[16:]
  605. sname = frame[0:64]
  606. frame = frame[64:]
  607. file = frame[0:128]
  608. frame = frame[128:]
  609. options = frame
  610. if options[0:4] != '\x63\x82\x53\x63':
  611. raise Exception("No DHCP magic seen in HLP response")
  612. options = options[4:]
  613. # TODO: fully parse and validate DHCPACK options
  614. if struct.pack('BBB', OPT_DHCP_MESSAGE_TYPE, 1, DHCPACK) not in options:
  615. raise Exception("DHCPACK not in HLP response")
  616. dev[0].wait_connected()
  617. dev[0].request("FILS_HLP_REQ_FLUSH")
  618. def test_fils_sk_hlp_timeout(dev, apdev):
  619. """FILS SK HLP (rapid commit server timeout)"""
  620. check_fils_capa(dev[0])
  621. check_erp_capa(dev[0])
  622. start_erp_as(apdev[1])
  623. sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
  624. sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
  625. sock.settimeout(5)
  626. sock.bind(("127.0.0.2", 67))
  627. bssid = apdev[0]['bssid']
  628. params = fils_hlp_config(fils_hlp_wait_time=30)
  629. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  630. dev[0].scan_for_bss(bssid, freq=2412)
  631. dev[0].request("ERP_FLUSH")
  632. if "OK" not in dev[0].request("FILS_HLP_REQ_FLUSH"):
  633. raise Exception("Failed to flush pending FILS HLP requests")
  634. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  635. chaddr=dev[0].own_addr())
  636. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc)):
  637. raise Exception("FILS_HLP_REQ_ADD failed")
  638. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  639. eap="PSK", identity="psk.user@example.com",
  640. password_hex="0123456789abcdef0123456789abcdef",
  641. erp="1", scan_freq="2412")
  642. dev[0].request("DISCONNECT")
  643. dev[0].wait_disconnected()
  644. dev[0].dump_monitor()
  645. dev[0].select_network(id, freq=2412)
  646. (msg,addr) = sock.recvfrom(1000)
  647. logger.debug("Received DHCP message from %s" % str(addr))
  648. # Wait for HLP wait timeout to hit
  649. # FILS: HLP response timeout - continue with association response
  650. dev[0].wait_connected()
  651. dev[0].request("FILS_HLP_REQ_FLUSH")
  652. def test_fils_sk_hlp_oom(dev, apdev):
  653. """FILS SK HLP and hostapd OOM"""
  654. check_fils_capa(dev[0])
  655. check_erp_capa(dev[0])
  656. start_erp_as(apdev[1])
  657. sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
  658. sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
  659. sock.settimeout(5)
  660. sock.bind(("127.0.0.2", 67))
  661. bssid = apdev[0]['bssid']
  662. params = fils_hlp_config(fils_hlp_wait_time=500)
  663. params['dhcp_rapid_commit_proxy'] = '1'
  664. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  665. dev[0].scan_for_bss(bssid, freq=2412)
  666. dev[0].request("ERP_FLUSH")
  667. if "OK" not in dev[0].request("FILS_HLP_REQ_FLUSH"):
  668. raise Exception("Failed to flush pending FILS HLP requests")
  669. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  670. chaddr=dev[0].own_addr())
  671. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc)):
  672. raise Exception("FILS_HLP_REQ_ADD failed")
  673. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  674. eap="PSK", identity="psk.user@example.com",
  675. password_hex="0123456789abcdef0123456789abcdef",
  676. erp="1", scan_freq="2412")
  677. dev[0].request("DISCONNECT")
  678. dev[0].wait_disconnected()
  679. dev[0].dump_monitor()
  680. with alloc_fail(hapd, 1, "fils_process_hlp"):
  681. dev[0].select_network(id, freq=2412)
  682. dev[0].wait_connected()
  683. dev[0].request("DISCONNECT")
  684. dev[0].wait_disconnected()
  685. dev[0].dump_monitor()
  686. with alloc_fail(hapd, 1, "fils_process_hlp_dhcp"):
  687. dev[0].select_network(id, freq=2412)
  688. dev[0].wait_connected()
  689. dev[0].request("DISCONNECT")
  690. dev[0].wait_disconnected()
  691. dev[0].dump_monitor()
  692. with alloc_fail(hapd, 1, "wpabuf_alloc;fils_process_hlp_dhcp"):
  693. dev[0].select_network(id, freq=2412)
  694. dev[0].wait_connected()
  695. dev[0].request("DISCONNECT")
  696. dev[0].wait_disconnected()
  697. dev[0].dump_monitor()
  698. with alloc_fail(hapd, 1, "wpabuf_alloc;fils_dhcp_handler"):
  699. dev[0].select_network(id, freq=2412)
  700. (msg,addr) = sock.recvfrom(1000)
  701. logger.debug("Received DHCP message from %s" % str(addr))
  702. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPACK,
  703. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  704. sock.sendto(dhcpdisc[2+20+8:], addr)
  705. dev[0].wait_connected()
  706. dev[0].request("DISCONNECT")
  707. dev[0].wait_disconnected()
  708. dev[0].dump_monitor()
  709. with alloc_fail(hapd, 1, "wpabuf_resize;fils_dhcp_handler"):
  710. dev[0].select_network(id, freq=2412)
  711. (msg,addr) = sock.recvfrom(1000)
  712. logger.debug("Received DHCP message from %s" % str(addr))
  713. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPACK,
  714. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  715. sock.sendto(dhcpdisc[2+20+8:], addr)
  716. dev[0].wait_connected()
  717. dev[0].request("DISCONNECT")
  718. dev[0].wait_disconnected()
  719. dev[0].dump_monitor()
  720. dev[0].select_network(id, freq=2412)
  721. (msg,addr) = sock.recvfrom(1000)
  722. logger.debug("Received DHCP message from %s" % str(addr))
  723. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  724. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  725. with alloc_fail(hapd, 1, "wpabuf_resize;fils_dhcp_request"):
  726. sock.sendto(dhcpoffer[2+20+8:], addr)
  727. dev[0].wait_connected()
  728. dev[0].request("DISCONNECT")
  729. dev[0].wait_disconnected()
  730. dev[0].request("FILS_HLP_REQ_FLUSH")
  731. def test_fils_sk_hlp_req_parsing(dev, apdev):
  732. """FILS SK HLP request parsing"""
  733. check_fils_capa(dev[0])
  734. check_erp_capa(dev[0])
  735. start_erp_as(apdev[1])
  736. bssid = apdev[0]['bssid']
  737. params = fils_hlp_config(fils_hlp_wait_time=30)
  738. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  739. dev[0].scan_for_bss(bssid, freq=2412)
  740. dev[0].request("ERP_FLUSH")
  741. if "OK" not in dev[0].request("FILS_HLP_REQ_FLUSH"):
  742. raise Exception("Failed to flush pending FILS HLP requests")
  743. tot_len = 20 + 1
  744. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  745. _ip_src = '\x00\x00\x00\x00'
  746. _ip_dst = '\x00\x00\x00\x00'
  747. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  748. csum = ip_checksum(ipv4)
  749. ipv4_overflow = start + csum + _ip_src + _ip_dst
  750. tot_len = 20
  751. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 123)
  752. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  753. csum = ip_checksum(ipv4)
  754. ipv4_unknown_proto = start + csum + _ip_src + _ip_dst
  755. tot_len = 20
  756. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  757. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  758. csum = ip_checksum(ipv4)
  759. ipv4_missing_udp_hdr = start + csum + _ip_src + _ip_dst
  760. src_port = 68
  761. dst_port = 67
  762. udp = struct.pack('>HHHH', src_port, dst_port, 8 + 1, 0)
  763. tot_len = 20 + len(udp)
  764. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  765. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  766. csum = ip_checksum(ipv4)
  767. udp_overflow = start + csum + _ip_src + _ip_dst + udp
  768. udp = struct.pack('>HHHH', src_port, dst_port, 7, 0)
  769. tot_len = 20 + len(udp)
  770. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  771. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  772. csum = ip_checksum(ipv4)
  773. udp_underflow = start + csum + _ip_src + _ip_dst + udp
  774. src_port = 123
  775. dst_port = 456
  776. udp = struct.pack('>HHHH', src_port, dst_port, 8, 0)
  777. tot_len = 20 + len(udp)
  778. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  779. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  780. csum = ip_checksum(ipv4)
  781. udp_unknown_port = start + csum + _ip_src + _ip_dst + udp
  782. src_port = 68
  783. dst_port = 67
  784. udp = struct.pack('>HHHH', src_port, dst_port, 8, 0)
  785. tot_len = 20 + len(udp)
  786. start = struct.pack('>BBHHBBBB', 0x45, 0, tot_len, 0, 0, 0, 128, 17)
  787. ipv4 = start + '\x00\x00' + _ip_src + _ip_dst
  788. csum = ip_checksum(ipv4)
  789. dhcp_missing_data = start + csum + _ip_src + _ip_dst + udp
  790. dhcp_not_req = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  791. chaddr=dev[0].own_addr(), override_op=BOOTREPLY)
  792. dhcp_no_magic = build_dhcp(req=True, dhcp_msg=None,
  793. chaddr=dev[0].own_addr(), magic_override='',
  794. rapid_commit=False, opt_end=False)
  795. dhcp_unknown_magic = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  796. chaddr=dev[0].own_addr(),
  797. magic_override='\x00\x00\x00\x00')
  798. dhcp_opts = build_dhcp(req=True, dhcp_msg=DHCPNAK,
  799. chaddr=dev[0].own_addr(),
  800. extra_op='\x00\x11', opt_end=False)
  801. dhcp_opts2 = build_dhcp(req=True, dhcp_msg=DHCPNAK,
  802. chaddr=dev[0].own_addr(),
  803. extra_op='\x11\x01', opt_end=False)
  804. dhcp_valid = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  805. chaddr=dev[0].own_addr())
  806. tests = [ "ff",
  807. "0800",
  808. "0800" + 20*"00",
  809. "0800" + binascii.hexlify(ipv4_overflow),
  810. "0800" + binascii.hexlify(ipv4_unknown_proto),
  811. "0800" + binascii.hexlify(ipv4_missing_udp_hdr),
  812. "0800" + binascii.hexlify(udp_overflow),
  813. "0800" + binascii.hexlify(udp_underflow),
  814. "0800" + binascii.hexlify(udp_unknown_port),
  815. "0800" + binascii.hexlify(dhcp_missing_data),
  816. binascii.hexlify(dhcp_not_req),
  817. binascii.hexlify(dhcp_no_magic),
  818. binascii.hexlify(dhcp_unknown_magic) ]
  819. for t in tests:
  820. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD ff:ff:ff:ff:ff:ff " + t):
  821. raise Exception("FILS_HLP_REQ_ADD failed: " + t)
  822. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  823. eap="PSK", identity="psk.user@example.com",
  824. password_hex="0123456789abcdef0123456789abcdef",
  825. erp="1", scan_freq="2412")
  826. dev[0].request("DISCONNECT")
  827. dev[0].wait_disconnected()
  828. dev[0].dump_monitor()
  829. dev[0].select_network(id, freq=2412)
  830. dev[0].wait_connected()
  831. dev[0].request("DISCONNECT")
  832. dev[0].wait_disconnected()
  833. dev[0].request("FILS_HLP_REQ_FLUSH")
  834. tests = [ binascii.hexlify(dhcp_opts),
  835. binascii.hexlify(dhcp_opts2) ]
  836. for t in tests:
  837. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD ff:ff:ff:ff:ff:ff " + t):
  838. raise Exception("FILS_HLP_REQ_ADD failed: " + t)
  839. dev[0].dump_monitor()
  840. dev[0].select_network(id, freq=2412)
  841. dev[0].wait_connected()
  842. dev[0].request("DISCONNECT")
  843. dev[0].wait_disconnected()
  844. dev[0].request("FILS_HLP_REQ_FLUSH")
  845. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcp_valid)):
  846. raise Exception("FILS_HLP_REQ_ADD failed")
  847. hapd.set("own_ip_addr", "0.0.0.0")
  848. dev[0].select_network(id, freq=2412)
  849. dev[0].wait_connected()
  850. dev[0].request("DISCONNECT")
  851. dev[0].wait_disconnected()
  852. hapd.set("dhcp_server", "0.0.0.0")
  853. dev[0].select_network(id, freq=2412)
  854. dev[0].wait_connected()
  855. dev[0].request("DISCONNECT")
  856. dev[0].wait_disconnected()
  857. # FILS: Failed to bind DHCP socket: Address already in use
  858. sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
  859. sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
  860. sock.settimeout(5)
  861. sock.bind(("127.0.0.2", 67))
  862. hapd.set("own_ip_addr", "127.0.0.2")
  863. hapd.set("dhcp_server", "127.0.0.2")
  864. dev[0].select_network(id, freq=2412)
  865. dev[0].wait_connected()
  866. dev[0].request("DISCONNECT")
  867. dev[0].wait_disconnected()
  868. # FILS: DHCP sendto failed: Invalid argument
  869. hapd.set("own_ip_addr", "127.0.0.3")
  870. hapd.set("dhcp_server", "127.0.0.2")
  871. hapd.set("dhcp_relay_port", "0")
  872. hapd.set("dhcp_server_port", "0")
  873. dev[0].select_network(id, freq=2412)
  874. dev[0].wait_connected()
  875. dev[0].request("DISCONNECT")
  876. dev[0].wait_disconnected()
  877. dev[0].request("FILS_HLP_REQ_FLUSH")
  878. def test_fils_sk_hlp_dhcp_parsing(dev, apdev):
  879. """FILS SK HLP and DHCP response parsing"""
  880. check_fils_capa(dev[0])
  881. check_erp_capa(dev[0])
  882. start_erp_as(apdev[1])
  883. sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM, socket.IPPROTO_UDP)
  884. sock.setsockopt(socket.SOL_SOCKET, socket.SO_REUSEADDR, 1)
  885. sock.settimeout(5)
  886. sock.bind(("127.0.0.2", 67))
  887. bssid = apdev[0]['bssid']
  888. params = fils_hlp_config(fils_hlp_wait_time=30)
  889. params['dhcp_rapid_commit_proxy'] = '1'
  890. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  891. dev[0].scan_for_bss(bssid, freq=2412)
  892. dev[0].request("ERP_FLUSH")
  893. if "OK" not in dev[0].request("FILS_HLP_REQ_FLUSH"):
  894. raise Exception("Failed to flush pending FILS HLP requests")
  895. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  896. chaddr=dev[0].own_addr())
  897. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc)):
  898. raise Exception("FILS_HLP_REQ_ADD failed")
  899. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  900. eap="PSK", identity="psk.user@example.com",
  901. password_hex="0123456789abcdef0123456789abcdef",
  902. erp="1", scan_freq="2412")
  903. dev[0].request("DISCONNECT")
  904. dev[0].wait_disconnected()
  905. dev[0].dump_monitor()
  906. with alloc_fail(hapd, 1, "fils_process_hlp"):
  907. dev[0].select_network(id, freq=2412)
  908. dev[0].wait_connected()
  909. dev[0].request("DISCONNECT")
  910. dev[0].wait_disconnected()
  911. dev[0].dump_monitor()
  912. dev[0].select_network(id, freq=2412)
  913. (msg,addr) = sock.recvfrom(1000)
  914. logger.debug("Received DHCP message from %s" % str(addr))
  915. dhcpdisc = build_dhcp(req=False, dhcp_msg=DHCPACK,
  916. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  917. #sock.sendto(dhcpdisc[2+20+8:], addr)
  918. chaddr = binascii.unhexlify(dev[0].own_addr().replace(':','')) + 10*'\x00'
  919. tests = [ "\x00",
  920. "\x02" + 500 * "\x00",
  921. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + 500 * "\x00",
  922. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + 16*"\x00" + 64*"\x00" + 128*"\x00" + "\x63\x82\x53\x63",
  923. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + 16*"\x00" + 64*"\x00" + 128*"\x00" + "\x63\x82\x53\x63" + "\x00\x11",
  924. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + 16*"\x00" + 64*"\x00" + 128*"\x00" + "\x63\x82\x53\x63" + "\x11\x01",
  925. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + chaddr + 64*"\x00" + 128*"\x00" + "\x63\x82\x53\x63" + "\x35\x00\xff",
  926. "\x02\x00\x00\x00" + 20*"\x00" + "\x7f\x00\x00\x03" + chaddr + 64*"\x00" + 128*"\x00" + "\x63\x82\x53\x63" + "\x35\x01\x00\xff",
  927. 1501 * "\x00" ]
  928. for t in tests:
  929. sock.sendto(t, addr)
  930. dev[0].wait_connected()
  931. dev[0].request("DISCONNECT")
  932. dev[0].wait_disconnected()
  933. # FILS: DHCP sendto failed: Invalid argument for second DHCP TX in proxy
  934. dev[0].dump_monitor()
  935. dev[0].select_network(id, freq=2412)
  936. (msg,addr) = sock.recvfrom(1000)
  937. logger.debug("Received DHCP message from %s" % str(addr))
  938. hapd.set("dhcp_server_port", "0")
  939. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  940. chaddr=dev[0].own_addr(), giaddr="127.0.0.3")
  941. sock.sendto(dhcpoffer[2+20+8:], addr)
  942. dev[0].wait_connected()
  943. dev[0].request("DISCONNECT")
  944. dev[0].wait_disconnected()
  945. hapd.set("dhcp_server_port", "67")
  946. # Options in DHCPOFFER
  947. dev[0].dump_monitor()
  948. dev[0].select_network(id, freq=2412)
  949. (msg,addr) = sock.recvfrom(1000)
  950. logger.debug("Received DHCP message from %s" % str(addr))
  951. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  952. chaddr=dev[0].own_addr(), giaddr="127.0.0.3",
  953. extra_op="\x00\x11", opt_end=False)
  954. sock.sendto(dhcpoffer[2+20+8:], addr)
  955. (msg,addr) = sock.recvfrom(1000)
  956. logger.debug("Received DHCP message from %s" % str(addr))
  957. dev[0].wait_connected()
  958. dev[0].request("DISCONNECT")
  959. dev[0].wait_disconnected()
  960. # Options in DHCPOFFER (2)
  961. dev[0].dump_monitor()
  962. dev[0].select_network(id, freq=2412)
  963. (msg,addr) = sock.recvfrom(1000)
  964. logger.debug("Received DHCP message from %s" % str(addr))
  965. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  966. chaddr=dev[0].own_addr(), giaddr="127.0.0.3",
  967. extra_op="\x11\x01", opt_end=False)
  968. sock.sendto(dhcpoffer[2+20+8:], addr)
  969. (msg,addr) = sock.recvfrom(1000)
  970. logger.debug("Received DHCP message from %s" % str(addr))
  971. dev[0].wait_connected()
  972. dev[0].request("DISCONNECT")
  973. dev[0].wait_disconnected()
  974. # Server ID in DHCPOFFER
  975. dev[0].dump_monitor()
  976. dev[0].select_network(id, freq=2412)
  977. (msg,addr) = sock.recvfrom(1000)
  978. logger.debug("Received DHCP message from %s" % str(addr))
  979. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  980. chaddr=dev[0].own_addr(), giaddr="127.0.0.3",
  981. extra_op="\x36\x01\x30")
  982. sock.sendto(dhcpoffer[2+20+8:], addr)
  983. (msg,addr) = sock.recvfrom(1000)
  984. logger.debug("Received DHCP message from %s" % str(addr))
  985. dev[0].wait_connected()
  986. dev[0].request("DISCONNECT")
  987. dev[0].wait_disconnected()
  988. # FILS: Could not update DHCPDISCOVER
  989. dev[0].request("FILS_HLP_REQ_FLUSH")
  990. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  991. chaddr=dev[0].own_addr(),
  992. extra_op="\x00\x11", opt_end=False)
  993. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc)):
  994. raise Exception("FILS_HLP_REQ_ADD failed")
  995. dev[0].dump_monitor()
  996. dev[0].select_network(id, freq=2412)
  997. (msg,addr) = sock.recvfrom(1000)
  998. logger.debug("Received DHCP message from %s" % str(addr))
  999. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  1000. chaddr=dev[0].own_addr(), giaddr="127.0.0.3",
  1001. extra_op="\x36\x01\x30")
  1002. sock.sendto(dhcpoffer[2+20+8:], addr)
  1003. dev[0].wait_connected()
  1004. dev[0].request("DISCONNECT")
  1005. dev[0].wait_disconnected()
  1006. # FILS: Could not update DHCPDISCOVER (2)
  1007. dev[0].request("FILS_HLP_REQ_FLUSH")
  1008. dhcpdisc = build_dhcp(req=True, dhcp_msg=DHCPDISCOVER,
  1009. chaddr=dev[0].own_addr(),
  1010. extra_op="\x11\x01", opt_end=False)
  1011. if "OK" not in dev[0].request("FILS_HLP_REQ_ADD " + "ff:ff:ff:ff:ff:ff " + binascii.hexlify(dhcpdisc)):
  1012. raise Exception("FILS_HLP_REQ_ADD failed")
  1013. dev[0].dump_monitor()
  1014. dev[0].select_network(id, freq=2412)
  1015. (msg,addr) = sock.recvfrom(1000)
  1016. logger.debug("Received DHCP message from %s" % str(addr))
  1017. dhcpoffer = build_dhcp(req=False, dhcp_msg=DHCPOFFER, rapid_commit=False,
  1018. chaddr=dev[0].own_addr(), giaddr="127.0.0.3",
  1019. extra_op="\x36\x01\x30")
  1020. sock.sendto(dhcpoffer[2+20+8:], addr)
  1021. dev[0].wait_connected()
  1022. dev[0].request("DISCONNECT")
  1023. dev[0].wait_disconnected()
  1024. dev[0].request("FILS_HLP_REQ_FLUSH")
  1025. def test_fils_sk_erp_and_reauth(dev, apdev):
  1026. """FILS SK using ERP and AP going away"""
  1027. check_fils_capa(dev[0])
  1028. check_erp_capa(dev[0])
  1029. start_erp_as(apdev[1])
  1030. bssid = apdev[0]['bssid']
  1031. params = hostapd.wpa2_eap_params(ssid="fils")
  1032. params['wpa_key_mgmt'] = "FILS-SHA256"
  1033. params['auth_server_port'] = "18128"
  1034. params['erp_domain'] = 'example.com'
  1035. params['fils_realm'] = 'example.com'
  1036. params['disable_pmksa_caching'] = '1'
  1037. params['broadcast_deauth'] = '0'
  1038. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1039. dev[0].scan_for_bss(bssid, freq=2412)
  1040. dev[0].request("ERP_FLUSH")
  1041. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1042. eap="PSK", identity="psk.user@example.com",
  1043. password_hex="0123456789abcdef0123456789abcdef",
  1044. erp="1", scan_freq="2412")
  1045. hapd.disable()
  1046. dev[0].wait_disconnected()
  1047. dev[0].dump_monitor()
  1048. hapd.enable()
  1049. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  1050. "EVENT-ASSOC-REJECT",
  1051. "CTRL-EVENT-CONNECTED"], timeout=10)
  1052. if ev is None:
  1053. raise Exception("Reconnection using FILS/ERP timed out")
  1054. if "CTRL-EVENT-EAP-STARTED" in ev:
  1055. raise Exception("Unexpected EAP exchange")
  1056. if "EVENT-ASSOC-REJECT" in ev:
  1057. raise Exception("Association failed")
  1058. def test_fils_sk_erp_sim(dev, apdev):
  1059. """FILS SK using ERP with SIM"""
  1060. check_fils_capa(dev[0])
  1061. check_erp_capa(dev[0])
  1062. realm='wlan.mnc001.mcc232.3gppnetwork.org'
  1063. start_erp_as(apdev[1], erp_domain=realm)
  1064. bssid = apdev[0]['bssid']
  1065. params = hostapd.wpa2_eap_params(ssid="fils")
  1066. params['wpa_key_mgmt'] = "FILS-SHA256"
  1067. params['auth_server_port'] = "18128"
  1068. params['fils_realm'] = realm
  1069. params['disable_pmksa_caching'] = '1'
  1070. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1071. dev[0].scan_for_bss(bssid, freq=2412)
  1072. dev[0].request("ERP_FLUSH")
  1073. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1074. eap="SIM", identity="1232010000000000@" + realm,
  1075. password="90dca4eda45b53cf0f12d7c9c3bc6a89:cb9cccc4b9258e6dca4760379fb82581",
  1076. erp="1", scan_freq="2412")
  1077. hapd.disable()
  1078. dev[0].wait_disconnected()
  1079. dev[0].dump_monitor()
  1080. hapd.enable()
  1081. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  1082. "EVENT-ASSOC-REJECT",
  1083. "CTRL-EVENT-CONNECTED"], timeout=10)
  1084. if ev is None:
  1085. raise Exception("Reconnection using FILS/ERP timed out")
  1086. if "CTRL-EVENT-EAP-STARTED" in ev:
  1087. raise Exception("Unexpected EAP exchange")
  1088. if "EVENT-ASSOC-REJECT" in ev:
  1089. raise Exception("Association failed")
  1090. def test_fils_sk_pfs_19(dev, apdev):
  1091. """FILS SK with PFS (DH group 19)"""
  1092. rul_fils_sk_pfs(dev, apdev, "19")
  1093. def test_fils_sk_pfs_20(dev, apdev):
  1094. """FILS SK with PFS (DH group 20)"""
  1095. rul_fils_sk_pfs(dev, apdev, "20")
  1096. def test_fils_sk_pfs_21(dev, apdev):
  1097. """FILS SK with PFS (DH group 21)"""
  1098. rul_fils_sk_pfs(dev, apdev, "21")
  1099. def test_fils_sk_pfs_25(dev, apdev):
  1100. """FILS SK with PFS (DH group 25)"""
  1101. rul_fils_sk_pfs(dev, apdev, "25")
  1102. def test_fils_sk_pfs_26(dev, apdev):
  1103. """FILS SK with PFS (DH group 26)"""
  1104. rul_fils_sk_pfs(dev, apdev, "26")
  1105. def test_fils_sk_pfs_27(dev, apdev):
  1106. """FILS SK with PFS (DH group 27)"""
  1107. rul_fils_sk_pfs(dev, apdev, "27")
  1108. def test_fils_sk_pfs_28(dev, apdev):
  1109. """FILS SK with PFS (DH group 28)"""
  1110. rul_fils_sk_pfs(dev, apdev, "28")
  1111. def test_fils_sk_pfs_29(dev, apdev):
  1112. """FILS SK with PFS (DH group 29)"""
  1113. rul_fils_sk_pfs(dev, apdev, "29")
  1114. def test_fils_sk_pfs_30(dev, apdev):
  1115. """FILS SK with PFS (DH group 30)"""
  1116. rul_fils_sk_pfs(dev, apdev, "30")
  1117. def rul_fils_sk_pfs(dev, apdev, group):
  1118. check_fils_capa(dev[0])
  1119. check_erp_capa(dev[0])
  1120. tls = dev[0].request("GET tls_library")
  1121. if int(group) in [ 27, 28, 29, 30 ]:
  1122. if not (tls.startswith("OpenSSL") and ("build=OpenSSL 1.0.2" in tls or "build=OpenSSL 1.1" in tls) and ("run=OpenSSL 1.0.2" in tls or "run=OpenSSL 1.1" in tls)):
  1123. raise HwsimSkip("Brainpool EC group not supported")
  1124. start_erp_as(apdev[1])
  1125. bssid = apdev[0]['bssid']
  1126. params = hostapd.wpa2_eap_params(ssid="fils")
  1127. params['wpa_key_mgmt'] = "FILS-SHA256"
  1128. params['auth_server_port'] = "18128"
  1129. params['erp_domain'] = 'example.com'
  1130. params['fils_realm'] = 'example.com'
  1131. params['disable_pmksa_caching'] = '1'
  1132. params['fils_dh_group'] = group
  1133. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1134. dev[0].scan_for_bss(bssid, freq=2412)
  1135. dev[0].request("ERP_FLUSH")
  1136. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1137. eap="PSK", identity="psk.user@example.com",
  1138. password_hex="0123456789abcdef0123456789abcdef",
  1139. erp="1", fils_dh_group=group, scan_freq="2412")
  1140. dev[0].request("DISCONNECT")
  1141. dev[0].wait_disconnected()
  1142. dev[0].dump_monitor()
  1143. dev[0].select_network(id, freq=2412)
  1144. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  1145. "EVENT-ASSOC-REJECT",
  1146. "CTRL-EVENT-CONNECTED"], timeout=10)
  1147. if ev is None:
  1148. raise Exception("Connection using FILS/ERP timed out")
  1149. if "CTRL-EVENT-EAP-STARTED" in ev:
  1150. raise Exception("Unexpected EAP exchange")
  1151. if "EVENT-ASSOC-REJECT" in ev:
  1152. raise Exception("Association failed")
  1153. hwsim_utils.test_connectivity(dev[0], hapd)
  1154. def test_fils_sk_pfs_group_mismatch(dev, apdev):
  1155. """FILS SK PFS DH group mismatch"""
  1156. check_fils_capa(dev[0])
  1157. check_erp_capa(dev[0])
  1158. start_erp_as(apdev[1])
  1159. bssid = apdev[0]['bssid']
  1160. params = hostapd.wpa2_eap_params(ssid="fils")
  1161. params['wpa_key_mgmt'] = "FILS-SHA256"
  1162. params['auth_server_port'] = "18128"
  1163. params['erp_domain'] = 'example.com'
  1164. params['fils_realm'] = 'example.com'
  1165. params['disable_pmksa_caching'] = '1'
  1166. params['fils_dh_group'] = "20"
  1167. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1168. dev[0].scan_for_bss(bssid, freq=2412)
  1169. dev[0].request("ERP_FLUSH")
  1170. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1171. eap="PSK", identity="psk.user@example.com",
  1172. password_hex="0123456789abcdef0123456789abcdef",
  1173. erp="1", fils_dh_group="19", scan_freq="2412")
  1174. dev[0].request("DISCONNECT")
  1175. dev[0].wait_disconnected()
  1176. dev[0].dump_monitor()
  1177. dev[0].select_network(id, freq=2412)
  1178. ev = dev[0].wait_event(["CTRL-EVENT-AUTH-REJECT"], timeout=10)
  1179. dev[0].request("DISCONNECT")
  1180. if ev is None:
  1181. raise Exception("Authentication rejection not seen")
  1182. if "auth_type=5 auth_transaction=2 status_code=77" not in ev:
  1183. raise Exception("Unexpected auth reject value: " + ev)
  1184. def test_fils_sk_auth_mismatch(dev, apdev):
  1185. """FILS SK authentication type mismatch (PFS not supported)"""
  1186. check_fils_capa(dev[0])
  1187. check_erp_capa(dev[0])
  1188. start_erp_as(apdev[1])
  1189. bssid = apdev[0]['bssid']
  1190. params = hostapd.wpa2_eap_params(ssid="fils")
  1191. params['wpa_key_mgmt'] = "FILS-SHA256"
  1192. params['auth_server_port'] = "18128"
  1193. params['erp_domain'] = 'example.com'
  1194. params['fils_realm'] = 'example.com'
  1195. params['disable_pmksa_caching'] = '1'
  1196. hapd = hostapd.add_ap(apdev[0]['ifname'], params)
  1197. dev[0].scan_for_bss(bssid, freq=2412)
  1198. dev[0].request("ERP_FLUSH")
  1199. id = dev[0].connect("fils", key_mgmt="FILS-SHA256",
  1200. eap="PSK", identity="psk.user@example.com",
  1201. password_hex="0123456789abcdef0123456789abcdef",
  1202. erp="1", fils_dh_group="19", scan_freq="2412")
  1203. dev[0].request("DISCONNECT")
  1204. dev[0].wait_disconnected()
  1205. dev[0].dump_monitor()
  1206. dev[0].select_network(id, freq=2412)
  1207. ev = dev[0].wait_event(["CTRL-EVENT-EAP-STARTED",
  1208. "EVENT-ASSOC-REJECT",
  1209. "CTRL-EVENT-CONNECTED"], timeout=10)
  1210. if ev is None:
  1211. raise Exception("Connection using FILS/ERP timed out")
  1212. if "CTRL-EVENT-EAP-STARTED" not in ev:
  1213. raise Exception("No EAP exchange seen")
  1214. dev[0].wait_connected()
  1215. hwsim_utils.test_connectivity(dev[0], hapd)