2 * hostapd / EAP-TLS (RFC 2716)
3 * Copyright (c) 2004-2008, Jouni Malinen <j@w1.fi>
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License version 2 as
7 * published by the Free Software Foundation.
9 * Alternatively, this software may be distributed under the terms of BSD
12 * See README and COPYING for more details.
19 #include "eap_tls_common.h"
23 static void eap_tls_reset(struct eap_sm *sm, void *priv);
27 struct eap_ssl_data ssl;
28 enum { START, CONTINUE, SUCCESS, FAILURE } state;
32 static void * eap_tls_init(struct eap_sm *sm)
34 struct eap_tls_data *data;
36 data = os_zalloc(sizeof(*data));
41 if (eap_server_tls_ssl_init(sm, &data->ssl, 1)) {
42 wpa_printf(MSG_INFO, "EAP-TLS: Failed to initialize SSL.");
43 eap_tls_reset(sm, data);
51 static void eap_tls_reset(struct eap_sm *sm, void *priv)
53 struct eap_tls_data *data = priv;
56 eap_server_tls_ssl_deinit(sm, &data->ssl);
61 static struct wpabuf * eap_tls_build_start(struct eap_sm *sm,
62 struct eap_tls_data *data, u8 id)
66 req = eap_msg_alloc(EAP_VENDOR_IETF, EAP_TYPE_TLS, 1, EAP_CODE_REQUEST,
69 wpa_printf(MSG_ERROR, "EAP-TLS: Failed to allocate memory for "
71 data->state = FAILURE;
75 wpabuf_put_u8(req, EAP_TLS_FLAGS_START);
77 data->state = CONTINUE;
83 static struct wpabuf * eap_tls_buildReq(struct eap_sm *sm, void *priv, u8 id)
85 struct eap_tls_data *data = priv;
88 if (data->ssl.state == FRAG_ACK) {
89 return eap_server_tls_build_ack(id, EAP_TYPE_TLS, 0);
92 if (data->ssl.state == WAIT_FRAG_ACK) {
93 return eap_server_tls_build_msg(&data->ssl, EAP_TYPE_TLS, 0,
97 switch (data->state) {
99 return eap_tls_build_start(sm, data, id);
101 if (tls_connection_established(sm->ssl_ctx, data->ssl.conn)) {
102 wpa_printf(MSG_DEBUG, "EAP-TLS: Done");
103 data->state = SUCCESS;
107 wpa_printf(MSG_DEBUG, "EAP-TLS: %s - unexpected state %d",
108 __func__, data->state);
112 return eap_server_tls_build_msg(&data->ssl, EAP_TYPE_TLS, 0, id);
116 static Boolean eap_tls_check(struct eap_sm *sm, void *priv,
117 struct wpabuf *respData)
122 pos = eap_hdr_validate(EAP_VENDOR_IETF, EAP_TYPE_TLS, respData, &len);
123 if (pos == NULL || len < 1) {
124 wpa_printf(MSG_INFO, "EAP-TLS: Invalid frame");
132 static void eap_tls_process_msg(struct eap_sm *sm, void *priv,
133 const struct wpabuf *respData)
135 struct eap_tls_data *data = priv;
136 if (eap_server_tls_phase1(sm, &data->ssl) < 0)
137 data->state = FAILURE;
141 static void eap_tls_process(struct eap_sm *sm, void *priv,
142 struct wpabuf *respData)
144 struct eap_tls_data *data = priv;
145 if (eap_server_tls_process(sm, &data->ssl, respData, data,
146 EAP_TYPE_TLS, NULL, eap_tls_process_msg) <
148 data->state = FAILURE;
152 static Boolean eap_tls_isDone(struct eap_sm *sm, void *priv)
154 struct eap_tls_data *data = priv;
155 return data->state == SUCCESS || data->state == FAILURE;
159 static u8 * eap_tls_getKey(struct eap_sm *sm, void *priv, size_t *len)
161 struct eap_tls_data *data = priv;
164 if (data->state != SUCCESS)
167 eapKeyData = eap_server_tls_derive_key(sm, &data->ssl,
168 "client EAP encryption",
171 *len = EAP_TLS_KEY_LEN;
172 wpa_hexdump(MSG_DEBUG, "EAP-TLS: Derived key",
173 eapKeyData, EAP_TLS_KEY_LEN);
175 wpa_printf(MSG_DEBUG, "EAP-TLS: Failed to derive key");
182 static u8 * eap_tls_get_emsk(struct eap_sm *sm, void *priv, size_t *len)
184 struct eap_tls_data *data = priv;
185 u8 *eapKeyData, *emsk;
187 if (data->state != SUCCESS)
190 eapKeyData = eap_server_tls_derive_key(sm, &data->ssl,
191 "client EAP encryption",
192 EAP_TLS_KEY_LEN + EAP_EMSK_LEN);
194 emsk = os_malloc(EAP_EMSK_LEN);
196 os_memcpy(emsk, eapKeyData + EAP_TLS_KEY_LEN,
204 wpa_hexdump(MSG_DEBUG, "EAP-TLS: Derived EMSK",
207 wpa_printf(MSG_DEBUG, "EAP-TLS: Failed to derive EMSK");
214 static Boolean eap_tls_isSuccess(struct eap_sm *sm, void *priv)
216 struct eap_tls_data *data = priv;
217 return data->state == SUCCESS;
221 int eap_server_tls_register(void)
223 struct eap_method *eap;
226 eap = eap_server_method_alloc(EAP_SERVER_METHOD_INTERFACE_VERSION,
227 EAP_VENDOR_IETF, EAP_TYPE_TLS, "TLS");
231 eap->init = eap_tls_init;
232 eap->reset = eap_tls_reset;
233 eap->buildReq = eap_tls_buildReq;
234 eap->check = eap_tls_check;
235 eap->process = eap_tls_process;
236 eap->isDone = eap_tls_isDone;
237 eap->getKey = eap_tls_getKey;
238 eap->isSuccess = eap_tls_isSuccess;
239 eap->get_emsk = eap_tls_get_emsk;
241 ret = eap_server_method_register(eap);
243 eap_server_method_free(eap);