wpas_kay.c 9.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433
  1. /*
  2. * IEEE 802.1X-2010 KaY Interface
  3. * Copyright (c) 2013-2014, Qualcomm Atheros, Inc.
  4. *
  5. * This software may be distributed under the terms of the BSD license.
  6. * See README for more details.
  7. */
  8. #include "utils/includes.h"
  9. #include "utils/common.h"
  10. #include "eap_peer/eap.h"
  11. #include "eap_peer/eap_i.h"
  12. #include "eapol_supp/eapol_supp_sm.h"
  13. #include "pae/ieee802_1x_key.h"
  14. #include "pae/ieee802_1x_kay.h"
  15. #include "wpa_supplicant_i.h"
  16. #include "config.h"
  17. #include "config_ssid.h"
  18. #include "driver_i.h"
  19. #include "wpas_kay.h"
  20. #define DEFAULT_KEY_LEN 16
  21. /* secure Connectivity Association Key Name (CKN) */
  22. #define DEFAULT_CKN_LEN 16
  23. static int wpas_macsec_init(void *priv, struct macsec_init_params *params)
  24. {
  25. return wpa_drv_macsec_init(priv, params);
  26. }
  27. static int wpas_macsec_deinit(void *priv)
  28. {
  29. return wpa_drv_macsec_deinit(priv);
  30. }
  31. static int wpas_macsec_get_capability(void *priv, enum macsec_cap *cap)
  32. {
  33. return wpa_drv_macsec_get_capability(priv, cap);
  34. }
  35. static int wpas_enable_protect_frames(void *wpa_s, Boolean enabled)
  36. {
  37. return wpa_drv_enable_protect_frames(wpa_s, enabled);
  38. }
  39. static int wpas_enable_encrypt(void *wpa_s, Boolean enabled)
  40. {
  41. return wpa_drv_enable_encrypt(wpa_s, enabled);
  42. }
  43. static int wpas_set_replay_protect(void *wpa_s, Boolean enabled, u32 window)
  44. {
  45. return wpa_drv_set_replay_protect(wpa_s, enabled, window);
  46. }
  47. static int wpas_set_current_cipher_suite(void *wpa_s, u64 cs)
  48. {
  49. return wpa_drv_set_current_cipher_suite(wpa_s, cs);
  50. }
  51. static int wpas_enable_controlled_port(void *wpa_s, Boolean enabled)
  52. {
  53. return wpa_drv_enable_controlled_port(wpa_s, enabled);
  54. }
  55. static int wpas_get_receive_lowest_pn(void *wpa_s, struct receive_sa *sa)
  56. {
  57. return wpa_drv_get_receive_lowest_pn(wpa_s, sa);
  58. }
  59. static int wpas_get_transmit_next_pn(void *wpa_s, struct transmit_sa *sa)
  60. {
  61. return wpa_drv_get_transmit_next_pn(wpa_s, sa);
  62. }
  63. static int wpas_set_transmit_next_pn(void *wpa_s, struct transmit_sa *sa)
  64. {
  65. return wpa_drv_set_transmit_next_pn(wpa_s, sa);
  66. }
  67. static unsigned int conf_offset_val(enum confidentiality_offset co)
  68. {
  69. switch (co) {
  70. case CONFIDENTIALITY_OFFSET_30:
  71. return 30;
  72. break;
  73. case CONFIDENTIALITY_OFFSET_50:
  74. return 50;
  75. default:
  76. return 0;
  77. }
  78. }
  79. static int wpas_create_receive_sc(void *wpa_s, struct receive_sc *sc,
  80. enum validate_frames vf,
  81. enum confidentiality_offset co)
  82. {
  83. return wpa_drv_create_receive_sc(wpa_s, sc, conf_offset_val(co), vf);
  84. }
  85. static int wpas_delete_receive_sc(void *wpa_s, struct receive_sc *sc)
  86. {
  87. return wpa_drv_delete_receive_sc(wpa_s, sc);
  88. }
  89. static int wpas_create_receive_sa(void *wpa_s, struct receive_sa *sa)
  90. {
  91. return wpa_drv_create_receive_sa(wpa_s, sa);
  92. }
  93. static int wpas_delete_receive_sa(void *wpa_s, struct receive_sa *sa)
  94. {
  95. return wpa_drv_delete_receive_sa(wpa_s, sa);
  96. }
  97. static int wpas_enable_receive_sa(void *wpa_s, struct receive_sa *sa)
  98. {
  99. return wpa_drv_enable_receive_sa(wpa_s, sa);
  100. }
  101. static int wpas_disable_receive_sa(void *wpa_s, struct receive_sa *sa)
  102. {
  103. return wpa_drv_disable_receive_sa(wpa_s, sa);
  104. }
  105. static int
  106. wpas_create_transmit_sc(void *wpa_s, struct transmit_sc *sc,
  107. enum confidentiality_offset co)
  108. {
  109. return wpa_drv_create_transmit_sc(wpa_s, sc, conf_offset_val(co));
  110. }
  111. static int wpas_delete_transmit_sc(void *wpa_s, struct transmit_sc *sc)
  112. {
  113. return wpa_drv_delete_transmit_sc(wpa_s, sc);
  114. }
  115. static int wpas_create_transmit_sa(void *wpa_s, struct transmit_sa *sa)
  116. {
  117. return wpa_drv_create_transmit_sa(wpa_s, sa);
  118. }
  119. static int wpas_delete_transmit_sa(void *wpa_s, struct transmit_sa *sa)
  120. {
  121. return wpa_drv_delete_transmit_sa(wpa_s, sa);
  122. }
  123. static int wpas_enable_transmit_sa(void *wpa_s, struct transmit_sa *sa)
  124. {
  125. return wpa_drv_enable_transmit_sa(wpa_s, sa);
  126. }
  127. static int wpas_disable_transmit_sa(void *wpa_s, struct transmit_sa *sa)
  128. {
  129. return wpa_drv_disable_transmit_sa(wpa_s, sa);
  130. }
  131. int ieee802_1x_alloc_kay_sm(struct wpa_supplicant *wpa_s, struct wpa_ssid *ssid)
  132. {
  133. struct ieee802_1x_kay_ctx *kay_ctx;
  134. struct ieee802_1x_kay *res = NULL;
  135. enum macsec_policy policy;
  136. ieee802_1x_dealloc_kay_sm(wpa_s);
  137. if (!ssid || ssid->macsec_policy == 0)
  138. return 0;
  139. if (ssid->macsec_policy == 1) {
  140. if (ssid->macsec_integ_only == 1)
  141. policy = SHOULD_SECURE;
  142. else
  143. policy = SHOULD_ENCRYPT;
  144. } else {
  145. policy = DO_NOT_SECURE;
  146. }
  147. kay_ctx = os_zalloc(sizeof(*kay_ctx));
  148. if (!kay_ctx)
  149. return -1;
  150. kay_ctx->ctx = wpa_s;
  151. kay_ctx->macsec_init = wpas_macsec_init;
  152. kay_ctx->macsec_deinit = wpas_macsec_deinit;
  153. kay_ctx->macsec_get_capability = wpas_macsec_get_capability;
  154. kay_ctx->enable_protect_frames = wpas_enable_protect_frames;
  155. kay_ctx->enable_encrypt = wpas_enable_encrypt;
  156. kay_ctx->set_replay_protect = wpas_set_replay_protect;
  157. kay_ctx->set_current_cipher_suite = wpas_set_current_cipher_suite;
  158. kay_ctx->enable_controlled_port = wpas_enable_controlled_port;
  159. kay_ctx->get_receive_lowest_pn = wpas_get_receive_lowest_pn;
  160. kay_ctx->get_transmit_next_pn = wpas_get_transmit_next_pn;
  161. kay_ctx->set_transmit_next_pn = wpas_set_transmit_next_pn;
  162. kay_ctx->create_receive_sc = wpas_create_receive_sc;
  163. kay_ctx->delete_receive_sc = wpas_delete_receive_sc;
  164. kay_ctx->create_receive_sa = wpas_create_receive_sa;
  165. kay_ctx->delete_receive_sa = wpas_delete_receive_sa;
  166. kay_ctx->enable_receive_sa = wpas_enable_receive_sa;
  167. kay_ctx->disable_receive_sa = wpas_disable_receive_sa;
  168. kay_ctx->create_transmit_sc = wpas_create_transmit_sc;
  169. kay_ctx->delete_transmit_sc = wpas_delete_transmit_sc;
  170. kay_ctx->create_transmit_sa = wpas_create_transmit_sa;
  171. kay_ctx->delete_transmit_sa = wpas_delete_transmit_sa;
  172. kay_ctx->enable_transmit_sa = wpas_enable_transmit_sa;
  173. kay_ctx->disable_transmit_sa = wpas_disable_transmit_sa;
  174. res = ieee802_1x_kay_init(kay_ctx, policy, ssid->macsec_port,
  175. ssid->mka_priority, wpa_s->ifname,
  176. wpa_s->own_addr);
  177. /* ieee802_1x_kay_init() frees kay_ctx on failure */
  178. if (res == NULL)
  179. return -1;
  180. wpa_s->kay = res;
  181. return 0;
  182. }
  183. void ieee802_1x_dealloc_kay_sm(struct wpa_supplicant *wpa_s)
  184. {
  185. if (!wpa_s->kay)
  186. return;
  187. ieee802_1x_kay_deinit(wpa_s->kay);
  188. wpa_s->kay = NULL;
  189. }
  190. static int ieee802_1x_auth_get_session_id(struct wpa_supplicant *wpa_s,
  191. const u8 *addr, u8 *sid, size_t *len)
  192. {
  193. const u8 *session_id;
  194. size_t id_len, need_len;
  195. session_id = eapol_sm_get_session_id(wpa_s->eapol, &id_len);
  196. if (session_id == NULL) {
  197. wpa_printf(MSG_DEBUG,
  198. "Failed to get SessionID from EAPOL state machines");
  199. return -1;
  200. }
  201. need_len = 1 + 2 * 32 /* random size */;
  202. if (need_len > id_len) {
  203. wpa_printf(MSG_DEBUG, "EAP Session-Id not long enough");
  204. return -1;
  205. }
  206. os_memcpy(sid, session_id, need_len);
  207. *len = need_len;
  208. return 0;
  209. }
  210. static int ieee802_1x_auth_get_msk(struct wpa_supplicant *wpa_s, const u8 *addr,
  211. u8 *msk, size_t *len)
  212. {
  213. u8 key[EAP_MSK_LEN];
  214. size_t keylen;
  215. struct eapol_sm *sm;
  216. int res;
  217. sm = wpa_s->eapol;
  218. if (sm == NULL)
  219. return -1;
  220. keylen = EAP_MSK_LEN;
  221. res = eapol_sm_get_key(sm, key, keylen);
  222. if (res) {
  223. wpa_printf(MSG_DEBUG,
  224. "Failed to get MSK from EAPOL state machines");
  225. return -1;
  226. }
  227. if (keylen > *len)
  228. keylen = *len;
  229. os_memcpy(msk, key, keylen);
  230. *len = keylen;
  231. return 0;
  232. }
  233. void * ieee802_1x_notify_create_actor(struct wpa_supplicant *wpa_s,
  234. const u8 *peer_addr)
  235. {
  236. u8 *sid;
  237. size_t sid_len = 128;
  238. struct mka_key_name *ckn;
  239. struct mka_key *cak;
  240. struct mka_key *msk;
  241. void *res = NULL;
  242. if (!wpa_s->kay || wpa_s->kay->policy == DO_NOT_SECURE)
  243. return NULL;
  244. wpa_printf(MSG_DEBUG,
  245. "IEEE 802.1X: External notification - Create MKA for "
  246. MACSTR, MAC2STR(peer_addr));
  247. msk = os_zalloc(sizeof(*msk));
  248. sid = os_zalloc(sid_len);
  249. ckn = os_zalloc(sizeof(*ckn));
  250. cak = os_zalloc(sizeof(*cak));
  251. if (!msk || !sid || !ckn || !cak)
  252. goto fail;
  253. msk->len = DEFAULT_KEY_LEN;
  254. if (ieee802_1x_auth_get_msk(wpa_s, wpa_s->bssid, msk->key, &msk->len)) {
  255. wpa_printf(MSG_ERROR, "IEEE 802.1X: Could not get MSK");
  256. goto fail;
  257. }
  258. if (ieee802_1x_auth_get_session_id(wpa_s, wpa_s->bssid, sid, &sid_len))
  259. {
  260. wpa_printf(MSG_ERROR,
  261. "IEEE 802.1X: Could not get EAP Session Id");
  262. goto fail;
  263. }
  264. /* Derive CAK from MSK */
  265. cak->len = DEFAULT_KEY_LEN;
  266. if (ieee802_1x_cak_128bits_aes_cmac(msk->key, wpa_s->own_addr,
  267. peer_addr, cak->key)) {
  268. wpa_printf(MSG_ERROR,
  269. "IEEE 802.1X: Deriving CAK failed");
  270. goto fail;
  271. }
  272. wpa_hexdump_key(MSG_DEBUG, "Derived CAK", cak->key, cak->len);
  273. /* Derive CKN from MSK */
  274. ckn->len = DEFAULT_CKN_LEN;
  275. if (ieee802_1x_ckn_128bits_aes_cmac(msk->key, wpa_s->own_addr,
  276. peer_addr, sid, sid_len,
  277. ckn->name)) {
  278. wpa_printf(MSG_ERROR,
  279. "IEEE 802.1X: Deriving CKN failed");
  280. goto fail;
  281. }
  282. wpa_hexdump(MSG_DEBUG, "Derived CKN", ckn->name, ckn->len);
  283. res = ieee802_1x_kay_create_mka(wpa_s->kay, ckn, cak, 0,
  284. EAP_EXCHANGE, FALSE);
  285. fail:
  286. if (msk) {
  287. os_memset(msk, 0, sizeof(*msk));
  288. os_free(msk);
  289. }
  290. os_free(sid);
  291. os_free(ckn);
  292. if (cak) {
  293. os_memset(cak, 0, sizeof(*cak));
  294. os_free(cak);
  295. }
  296. return res;
  297. }
  298. void * ieee802_1x_create_preshared_mka(struct wpa_supplicant *wpa_s,
  299. struct wpa_ssid *ssid)
  300. {
  301. struct mka_key *cak;
  302. struct mka_key_name *ckn;
  303. void *res = NULL;
  304. if ((ssid->mka_psk_set & MKA_PSK_SET) != MKA_PSK_SET)
  305. goto end;
  306. ckn = os_zalloc(sizeof(*ckn));
  307. if (!ckn)
  308. goto end;
  309. cak = os_zalloc(sizeof(*cak));
  310. if (!cak)
  311. goto free_ckn;
  312. if (ieee802_1x_alloc_kay_sm(wpa_s, ssid) < 0 || !wpa_s->kay)
  313. goto free_cak;
  314. if (wpa_s->kay->policy == DO_NOT_SECURE)
  315. goto dealloc;
  316. cak->len = MACSEC_CAK_LEN;
  317. os_memcpy(cak->key, ssid->mka_cak, cak->len);
  318. ckn->len = MACSEC_CKN_LEN;
  319. os_memcpy(ckn->name, ssid->mka_ckn, ckn->len);
  320. res = ieee802_1x_kay_create_mka(wpa_s->kay, ckn, cak, 0, PSK, FALSE);
  321. if (res)
  322. goto free_cak;
  323. dealloc:
  324. /* Failed to create MKA */
  325. ieee802_1x_dealloc_kay_sm(wpa_s);
  326. free_cak:
  327. os_free(cak);
  328. free_ckn:
  329. os_free(ckn);
  330. end:
  331. return res;
  332. }