libeap.git
14 years agowpa_supplicant AP mode: Add function for enabling MAC address filtering
Jouni Malinen [Sun, 11 Apr 2010 17:08:00 +0000 (20:08 +0300)]
wpa_supplicant AP mode: Add function for enabling MAC address filtering

This can be used to allow only a specific station to associate.

14 years agoMake sure AP interface is initialize before accepting WPS commands
Jouni Malinen [Sun, 11 Apr 2010 17:06:12 +0000 (20:06 +0300)]
Make sure AP interface is initialize before accepting WPS commands

14 years agowpa_supplicant AP: More thorough AP mode deinit
Jouni Malinen [Sun, 11 Apr 2010 17:03:39 +0000 (20:03 +0300)]
wpa_supplicant AP: More thorough AP mode deinit

14 years agoAdd more wpa_supplicant AP mode parameters for the driver wrapper
Jouni Malinen [Sun, 11 Apr 2010 17:02:01 +0000 (20:02 +0300)]
Add more wpa_supplicant AP mode parameters for the driver wrapper

This makes it easier to configure AP mode for drivers that take care
of WPA/RSN IE generation.

14 years agoAdd registerable callback for wpa_supplicant AP mode completion
Jouni Malinen [Sun, 11 Apr 2010 16:59:33 +0000 (19:59 +0300)]
Add registerable callback for wpa_supplicant AP mode completion

14 years agoTry to start a new scan more quickly after driver rejection
Jouni Malinen [Sun, 11 Apr 2010 16:56:23 +0000 (19:56 +0300)]
Try to start a new scan more quickly after driver rejection

This speeds up recovery from some cases where the driver may refuse
a new scan request command temporarily.

14 years agoAdd an option to request a connection without a new scan
Jouni Malinen [Sun, 11 Apr 2010 16:55:40 +0000 (19:55 +0300)]
Add an option to request a connection without a new scan

14 years agoAdd option for overriding scan result handler for a single scan
Jouni Malinen [Sun, 11 Apr 2010 16:53:31 +0000 (19:53 +0300)]
Add option for overriding scan result handler for a single scan

14 years agoFT: Fix wpa_sm_set_ft_params wrapper for non-FT build
Jouni Malinen [Sun, 11 Apr 2010 16:49:32 +0000 (19:49 +0300)]
FT: Fix wpa_sm_set_ft_params wrapper for non-FT build

14 years agoAllow driver wrappers to indicate maximum remain-on-channel duration
Jouni Malinen [Sun, 11 Apr 2010 16:42:37 +0000 (19:42 +0300)]
Allow driver wrappers to indicate maximum remain-on-channel duration

14 years agonl80211: Fix key configuration in wpa_supplicant AP mode
Jouni Malinen [Sun, 11 Apr 2010 16:35:24 +0000 (19:35 +0300)]
nl80211: Fix key configuration in wpa_supplicant AP mode

14 years agonl80211: Remove forgotten Action frame registration example
Jouni Malinen [Sun, 11 Apr 2010 16:32:07 +0000 (19:32 +0300)]
nl80211: Remove forgotten Action frame registration example

14 years agoAvoid dropping ctrl_iface on ENOBUFS error burst
Jouni Malinen [Sun, 11 Apr 2010 16:29:24 +0000 (19:29 +0300)]
Avoid dropping ctrl_iface on ENOBUFS error burst

These bursts can result in control interface monitors being detached
even if the external program is still working properly. Use much larger
error threshold for ENOBUFS to avoid this.

14 years agoDeauthenticate instead of disassociate on disconnect command
Jouni Malinen [Sun, 11 Apr 2010 16:27:41 +0000 (19:27 +0300)]
Deauthenticate instead of disassociate on disconnect command

This clears up authentication state in the driver and in case of
cfg80211, unlocks the BSS entry for the previously used AP.

14 years agoSimplify driver_ops for virtual interface add/remove
Jouni Malinen [Sun, 11 Apr 2010 16:23:09 +0000 (19:23 +0300)]
Simplify driver_ops for virtual interface add/remove

There is no absolute requirement for separating address allocation
into separate functions, so simplify the driver wrapper interface
to use just if_add and if_remove instead of adding the new
alloc_interface_addr() and release_interface_addr() functions.

if_add() can now indicate if the driver forced a different interface
name or address on the virtual interface.

14 years agoAllow sub-second resolution for scan requests
Jouni Malinen [Sun, 11 Apr 2010 16:10:01 +0000 (19:10 +0300)]
Allow sub-second resolution for scan requests

This is in preparation to use cases that may benefit from more frequent
scanning.

14 years agoOptimize post-WPS scan based on channel used during provisioning
Jouni Malinen [Sun, 11 Apr 2010 16:06:42 +0000 (19:06 +0300)]
Optimize post-WPS scan based on channel used during provisioning

Scan only the frequency that was used during provisioning during the
first five scans for the connection. This speeds up connection in the
most likely case where the AP remains on the same channel. If the AP is
not found after these initial scans, all channels will be scanned.

14 years agoEAP-MD5: Use conditional success decision
Jouni Malinen [Sun, 11 Apr 2010 10:43:17 +0000 (13:43 +0300)]
EAP-MD5: Use conditional success decision

The server may still reject authentication at this point, so better
use conditional success decision. This allows the potentially
following EAP-Failure message to be processed properly. [Bug 354]

14 years agonl80211: Fix memory leak on send_action error path
Jouni Malinen [Sun, 11 Apr 2010 09:29:16 +0000 (12:29 +0300)]
nl80211: Fix memory leak on send_action error path

14 years agoUse unsigned bitfield for 1-bit values
Jouni Malinen [Sun, 11 Apr 2010 09:27:13 +0000 (12:27 +0300)]
Use unsigned bitfield for 1-bit values

14 years agoSME: Handle association without own extra IEs
Jouni Malinen [Sun, 11 Apr 2010 09:19:02 +0000 (12:19 +0300)]
SME: Handle association without own extra IEs

Need to check for this before calling ieee802_11_parse_elems().

14 years agoFix wpa_sm_has_ptk() no-WPA wrapper location
Jouni Malinen [Sun, 11 Apr 2010 08:39:14 +0000 (11:39 +0300)]
Fix wpa_sm_has_ptk() no-WPA wrapper location

14 years agoAllow advertising of U-APSD functionality in Beacon
Yogesh Ashok Powar [Sun, 11 Apr 2010 08:32:15 +0000 (11:32 +0300)]
Allow advertising of U-APSD functionality in Beacon

hostapd does not implement UAPSD functionality. However, if U-APSD
functionality is implemented outside hostapd, add support to advertise
the functionality in beacon.

Signed-off-by: yogeshp@marvell.com
14 years agoAdd ctrl_iface command for triggering a roam to a specific BSS
Jouni Malinen [Sat, 10 Apr 2010 19:56:55 +0000 (22:56 +0300)]
Add ctrl_iface command for triggering a roam to a specific BSS

'wpa_cli roam <bssid>' can now be used to test roaming within an ESS
(e.g., for FT over-the-air). This command will bypass a new scan and
will select the BSS based on the specified BSSID. It is responsibility
of the caller to make sure that the target AP is in the BSS table.
This can be done, e.g., by running a scan before the roam command,
if needed.

14 years agoFix error messages to print ASCII MAC address, not the parse buffer
Jouni Malinen [Sat, 10 Apr 2010 19:46:54 +0000 (22:46 +0300)]
Fix error messages to print ASCII MAC address, not the parse buffer

14 years agoFT: Validate MDIE and FTIE in FT 4-way handshake message 2/4
Jouni Malinen [Sat, 10 Apr 2010 19:40:35 +0000 (22:40 +0300)]
FT: Validate MDIE and FTIE in FT 4-way handshake message 2/4

14 years agoSME: Do not try to use FT over-the-air if PTK is not available
Jouni Malinen [Sat, 10 Apr 2010 19:39:49 +0000 (22:39 +0300)]
SME: Do not try to use FT over-the-air if PTK is not available

14 years agoFT: Verify that MDIE and FTIE matches between AssocResp and EAPOL-Key 3/4
Jouni Malinen [Sat, 10 Apr 2010 19:06:13 +0000 (22:06 +0300)]
FT: Verify that MDIE and FTIE matches between AssocResp and EAPOL-Key 3/4

14 years agoSplit EAPOL-Key msg 3/4 Key Data validation into helper functions
Jouni Malinen [Sat, 10 Apr 2010 18:55:29 +0000 (21:55 +0300)]
Split EAPOL-Key msg 3/4 Key Data validation into helper functions

14 years agoFT: Add FTIE, TIE[ReassocDeadline], TIE[KeyLifetime] to EAPOL-Key 3/4
Jouni Malinen [Sat, 10 Apr 2010 18:42:54 +0000 (21:42 +0300)]
FT: Add FTIE, TIE[ReassocDeadline], TIE[KeyLifetime] to EAPOL-Key 3/4

These are mandatory IEs to be included in the FT 4-Way Handshake
Message 3.

14 years agoAdd more verbose debugging for EAPOL-Key Key Data field IEs/KDEs
Jouni Malinen [Sat, 10 Apr 2010 18:42:01 +0000 (21:42 +0300)]
Add more verbose debugging for EAPOL-Key Key Data field IEs/KDEs

14 years agoFT: Copy MDIE and FTIE from (Re)Association Response into EAPOL-Key 2/4
Jouni Malinen [Sat, 10 Apr 2010 13:48:40 +0000 (16:48 +0300)]
FT: Copy MDIE and FTIE from (Re)Association Response into EAPOL-Key 2/4

IEEE Std 802.11r-2008 requires that the message 2 includes FTIE and
MDIE from the AP's (Re)Association Response frame in the Key Data
field.

14 years agoMake wpa_compare_rsn_ie() handle missing IEs
Jouni Malinen [Sat, 10 Apr 2010 13:47:29 +0000 (16:47 +0300)]
Make wpa_compare_rsn_ie() handle missing IEs

14 years agoParse EAPOL-Key msg 2/4 Key Data IEs/KDEs before checking RSN/WPA IE
Jouni Malinen [Sat, 10 Apr 2010 13:46:17 +0000 (16:46 +0300)]
Parse EAPOL-Key msg 2/4 Key Data IEs/KDEs before checking RSN/WPA IE

This is needed to avoid incorrect validation errors on RSN/WPA IE
when using FT since there may be more than a single IE in the
Key Data field.

14 years agoFT: Clean up wpa_sm_set_ft_params() by using common parse
Jouni Malinen [Sat, 10 Apr 2010 08:36:35 +0000 (11:36 +0300)]
FT: Clean up wpa_sm_set_ft_params() by using common parse

Instead of parsing the IEs in the callers, use the already existing
parser in wpa_ft.c to handle MDIE and FTIE from initial MD association
response. In addition, this provides more complete access to association
response IEs to FT code which will be needed to fix FT 4-way handshake
message 2/4.

14 years agoFT: Validate FTIE fields in Reassociation Request
Jouni Malinen [Fri, 9 Apr 2010 14:14:27 +0000 (17:14 +0300)]
FT: Validate FTIE fields in Reassociation Request

ANonce, SNonce, R0KH-ID, and R1KH-ID must match with the values
used in the previous FT authentication sequence message per
IEEE Std 802.11r-2008, 11A.8.4.

14 years agoFT: Validate protect IE count in FTIE MIC Control
Jouni Malinen [Fri, 9 Apr 2010 14:08:16 +0000 (17:08 +0300)]
FT: Validate protect IE count in FTIE MIC Control

14 years agoFT: Validate SNonce and ANonce values during FT Protocol in supplicant
Jouni Malinen [Fri, 9 Apr 2010 14:02:13 +0000 (17:02 +0300)]
FT: Validate SNonce and ANonce values during FT Protocol in supplicant

14 years agoFT: Deauthenticate in case of Reassoc Response validation error
Jouni Malinen [Fri, 9 Apr 2010 13:59:27 +0000 (16:59 +0300)]
FT: Deauthenticate in case of Reassoc Response validation error

If validation of the Reassociation Response frame fails during FT
Protocol, do not allow association to be completed; instead, force
deauthentication.

14 years agoFT: Set FT Capability and Policy properly in MDIE during initial MD assoc
Jouni Malinen [Fri, 9 Apr 2010 13:41:57 +0000 (16:41 +0300)]
FT: Set FT Capability and Policy properly in MDIE during initial MD assoc

This field needs to be copied from the scan results for the AP
per IEEE Std 802.11r-2008, 11A.4.2.

14 years agoFT: Copy FT Capability and Policy to MDIE from target AP
Jouni Malinen [Fri, 9 Apr 2010 13:26:20 +0000 (16:26 +0300)]
FT: Copy FT Capability and Policy to MDIE from target AP

This sets the FT Capability and Policy field in the MDIE to the values
received from the target AP (if available). This fixes the MDIE contents
during FT Protocol, but the correct value may not yet be used in initial
mobility domain association.

14 years agoFT: Add R1KH-ID into FT auth seq 3rd message (Reassoc Req)
Jouni Malinen [Fri, 9 Apr 2010 13:08:50 +0000 (16:08 +0300)]
FT: Add R1KH-ID into FT auth seq 3rd message (Reassoc Req)

This is a mandatory subelement per IEEE Std 802.11r-2008, 11A.8.4.

14 years agoFT: Fix Reassociation Response in FT Protocol to include ANonce/SNonce
Jouni Malinen [Fri, 9 Apr 2010 10:36:06 +0000 (13:36 +0300)]
FT: Fix Reassociation Response in FT Protocol to include ANonce/SNonce

These values are required to be included in the frame per
IEEE Std 802.11r-2008, 11A.8.5.

14 years agoFT: Do not add MIC to FTIE during initial MD association
Jouni Malinen [Fri, 9 Apr 2010 10:30:49 +0000 (13:30 +0300)]
FT: Do not add MIC to FTIE during initial MD association

We do not have any keys set at this point so there is no point in
adding the MIC. In addition, IEEE Std 802.11r-2008, 11A.4.2
describes this frame to have MIC IE count of 0 and MIC of 0.

14 years agoFix compiler warning on non-802.11r build
Jouni Malinen [Thu, 8 Apr 2010 09:25:19 +0000 (12:25 +0300)]
Fix compiler warning on non-802.11r build

14 years agonl80211: Start using NL80211_ATTR_LOCAL_STATE_CHANGE
Jouni Malinen [Thu, 8 Apr 2010 08:31:37 +0000 (11:31 +0300)]
nl80211: Start using NL80211_ATTR_LOCAL_STATE_CHANGE

This removes transmission of some unnecessary Deauthentication
frames in cases where we only need to clear the local state. In
addition, this resolves issues for 802.11r FT-over-DS by allowing
authentication state to be set locally even when no actual
Authentication frame is to be transmitted.

14 years agoSync with wireless-testing.git include/linux/nl80211.h
Jouni Malinen [Thu, 8 Apr 2010 08:29:54 +0000 (11:29 +0300)]
Sync with wireless-testing.git include/linux/nl80211.h

This adds NL80211_ATTR_LOCAL_STATE_CHANGE.

14 years agoFT: Fix GTK subelement format in FTIE
Jouni Malinen [Wed, 7 Apr 2010 20:57:39 +0000 (23:57 +0300)]
FT: Fix GTK subelement format in FTIE

The Key Info field was changed from 1-octet field to 2-octet field
in 802.11r/D7.0, but that had not been updated in the implementation.

14 years agoFT: Fix FT 4-Way Handshake to include PMKR1Name in messages 2 and 3
Jouni Malinen [Wed, 7 Apr 2010 18:04:13 +0000 (21:04 +0300)]
FT: Fix FT 4-Way Handshake to include PMKR1Name in messages 2 and 3

IEEE Std 802.11r-2008, 11A.4.2 describes FT initial mobility domain
association in an RSN to include PMKR1Name in the PMKID-List field
in RSN IE in messages 2/4 and 3/4. This makes the RSN IE not be
bitwise identical with the values used in Beacon, Probe Response,
(Re)association Request frames.

The previous versions of wpa_supplicant and hostapd did not add the
PMKR1Name value in EAPOL-Key frame and did not accept it if added
(due to bitwise comparison of RSN IEs). This commit fixes the
implementation to be compliant with the standard by adding the
PMKR1Name value into EAPOL-Key messages during FT 4-Way Handshake and
by verifying that the received value matches with the value derived
locally.

This breaks interoperability with previous wpa_supplicant/hostapd
versions.

14 years agoFT: Do not include RSN IE in (Re)Assoc Resp during initial MD association
Jouni Malinen [Wed, 7 Apr 2010 14:27:46 +0000 (17:27 +0300)]
FT: Do not include RSN IE in (Re)Assoc Resp during initial MD association

RSN IE is only supposed to be included in Reassociation Response frames
and only when they are part of a fast BSS transition.

14 years agoUse more os.h wrapper functions in hostapd_cli
Jouni Malinen [Wed, 7 Apr 2010 08:40:34 +0000 (11:40 +0300)]
Use more os.h wrapper functions in hostapd_cli

14 years agoAdd support for action scripts in hostapd_cli
Gregory Detal [Wed, 7 Apr 2010 08:14:54 +0000 (11:14 +0300)]
Add support for action scripts in hostapd_cli

14 years agoAP: Add wpa_msg() events for EAP server state machine
Gregory Detal [Wed, 7 Apr 2010 08:13:14 +0000 (11:13 +0300)]
AP: Add wpa_msg() events for EAP server state machine

14 years agoFix SME to update WPA/RSN IE for rsn_supp module based on AssocReq
Jouni Malinen [Wed, 7 Apr 2010 07:31:06 +0000 (10:31 +0300)]
Fix SME to update WPA/RSN IE for rsn_supp module based on AssocReq

When using wpa_supplicant SME (i.e., using nl80211), the rsn_supp
module was not informed of the WPA/RSN IE that was used in
(Re)Association Request frame. This broke roaming between APs that
use different security policy (e.g., changing between WPA/TKIP and
WPA2/CCMP APs) or when using PMKSA caching.

14 years agoAvoid hostapd segfault on invalid driver association event
Jouni Malinen [Wed, 7 Apr 2010 07:01:49 +0000 (10:01 +0300)]
Avoid hostapd segfault on invalid driver association event

Running hostapd and wpa_supplicant on the same interface at the same
time is not expected to work, but it should not cause hostapd to crash.
Ignore station mode association events (no addr field) to avoid this.

14 years agoFix WPA/RSN IE update on reconfig with set_generic_elem()
Andriy Tkachuk [Tue, 6 Apr 2010 17:44:26 +0000 (20:44 +0300)]
Fix WPA/RSN IE update on reconfig with set_generic_elem()

IF WPA/RSN parameters were changed or WPA/RSN was disabled, the
WPA/RSN IE in Beacon/Probe Response frames was only update with
set_beacon(). We need to do this with set_generic_elem(), too, to
work with all driver wrappers.

14 years agoWPS: Fix WPS IE update in Beacon frames for nl80211
Jouni Malinen [Tue, 6 Apr 2010 15:04:30 +0000 (18:04 +0300)]
WPS: Fix WPS IE update in Beacon frames for nl80211

Call ieee802_11_set_beacon() in addition to set_ap_wps_ie() when
processing WPS IE updates. This is needed with drivers that use
set_beacon() instead of set_ap_wps_ie() (i.e., nl80211).

14 years agohostapd: Use cp -f in make install
Michael Buesch [Tue, 6 Apr 2010 14:12:17 +0000 (17:12 +0300)]
hostapd: Use cp -f in make install

If hostapd is running, a make install fails with
cp: cannot create regular file `/usr/local/bin/hostapd': Text file busy

Use cp -f to avoid this error and force-override the file.

Signed-off-by: Michael Buesch <mb@bu3sch.de>
14 years agoWPS: Add a workaround for incorrect NewWLANEventMAC format
Jouni Malinen [Tue, 6 Apr 2010 07:38:37 +0000 (10:38 +0300)]
WPS: Add a workaround for incorrect NewWLANEventMAC format

Some ER implementation (e.g., some versions of Intel PROSet) seem to
use incorrect format for WLANEventMAC variable in PutWLANResponse.
Work around this by allowing various MAC address formats to be used
in this variable (debug message will be shown if the colon-deliminated
format specified in WFA WLANConfig 1.0 is not used).

14 years agoAdd a more flexible version of hwaddr_aton: hwaddr_aton2()
Jouni Malinen [Tue, 6 Apr 2010 07:37:13 +0000 (10:37 +0300)]
Add a more flexible version of hwaddr_aton: hwaddr_aton2()

This version of the MAC address parser allows number of different
string formats for the address (e.g., 00:11:22:33:44:55, 0011.2233.4455,
001122334455, 00-11-22-33-44-55). It returns the number of characters
used from the input string in case of success.

14 years agoFT: Re-set PTK on reassociation
Jouni Malinen [Sun, 4 Apr 2010 06:34:14 +0000 (09:34 +0300)]
FT: Re-set PTK on reassociation

It turns out that this is needed for both FT-over-DS and FT-over-air
when using mac80211, so it looks easiest to just unconditionally
re-configure the keys after reassociation when FT is used.

14 years agoFT: Use bridge interface (if set) for RRB connection
Jouni Malinen [Sun, 4 Apr 2010 06:31:13 +0000 (09:31 +0300)]
FT: Use bridge interface (if set) for RRB connection

This fixes receiving of RRB messages between FT APs

14 years agoFT: Set WLAN_AUTH_FT auth_alg on FT-over-DS case
Jouni Malinen [Sun, 4 Apr 2010 06:17:57 +0000 (09:17 +0300)]
FT: Set WLAN_AUTH_FT auth_alg on FT-over-DS case

This is needed to allow reassociation processing to skip 4-way handshake
when FT-over-DS is used with an AP that has a previous association state
with the STA.

14 years agoFT: Force key configuration after association in FT-over-DS
Jouni Malinen [Sun, 4 Apr 2010 06:16:11 +0000 (09:16 +0300)]
FT: Force key configuration after association in FT-over-DS

This seems to be needed at least with mac80211 when a STA is using
FT-over-DS to reassociate back to the AP when the AP still has the
previous association state.

14 years agoAdd AP-STA-DISCONNECT event for driver-based MLME
Jouni Malinen [Sat, 3 Apr 2010 18:05:50 +0000 (21:05 +0300)]
Add AP-STA-DISCONNECT event for driver-based MLME

14 years agoAllow hostapd_notif_assoc() to be called with all IEs
Jouni Malinen [Sat, 3 Apr 2010 18:03:13 +0000 (21:03 +0300)]
Allow hostapd_notif_assoc() to be called with all IEs

This makes the call simpler for driver wrappers since there is no need
to parse the IEs anymore before indicating association. In addition,
this allows association processing to be extended to use other IEs
in the future.

14 years agoFix Windows compilation issues with AP mode code
Jouni Malinen [Sat, 3 Apr 2010 16:37:21 +0000 (18:37 +0200)]
Fix Windows compilation issues with AP mode code

14 years agoAdd address to hostapd_logger output in wpa_supplicant as AP case
Jouni Malinen [Sat, 3 Apr 2010 16:36:49 +0000 (18:36 +0200)]
Add address to hostapd_logger output in wpa_supplicant as AP case

14 years agoWPS: Do not include Label in default Config Methods
Jouni Malinen [Sat, 3 Apr 2010 16:35:42 +0000 (18:35 +0200)]
WPS: Do not include Label in default Config Methods

This avoids conflict with both Label and Display being included at
the same time (which would make it difficult to figure out which
PIN was actually used).

14 years agoWPS: Fix PBC session overlap detection to use Device Password Id
Jouni Malinen [Sat, 3 Apr 2010 16:34:44 +0000 (18:34 +0200)]
WPS: Fix PBC session overlap detection to use Device Password Id

Active PBC mode is indicated by Device Password Id == 4, not Config Methods
attribute.

14 years agodriver_osx: Update set_key arguments to fix build
Jouni Malinen [Sat, 3 Apr 2010 16:14:29 +0000 (09:14 -0700)]
driver_osx: Update set_key arguments to fix build

14 years agoMFP: Fix IGTK PN in group rekeying
Jouni Malinen [Tue, 30 Mar 2010 05:57:10 +0000 (22:57 -0700)]
MFP: Fix IGTK PN in group rekeying

IGTK get_seqnum needs to be skipped in the same way as GTK one when
rekeying group keys. Previously, the old PN value (the one from the
previous key) was indicated and that resulted in MMIE replay detection
at the station.

14 years agoAdd a drop_sa command to allow 802.11w testing
Jouni Malinen [Mon, 29 Mar 2010 22:42:04 +0000 (15:42 -0700)]
Add a drop_sa command to allow 802.11w testing

This drops PTK and PMK without notifying the AP.

14 years agoMFP: Add SA Query Request processing in AP mode
Jouni Malinen [Mon, 29 Mar 2010 21:05:25 +0000 (14:05 -0700)]
MFP: Add SA Query Request processing in AP mode

14 years agoAdd test commands for sending deauth/disassoc without dropping state
Jouni Malinen [Mon, 29 Mar 2010 19:01:40 +0000 (12:01 -0700)]
Add test commands for sending deauth/disassoc without dropping state

This can be used to test 802.11w by sending a protected or unprotected
deauth/disassoc frame.

hostapd_cli deauth <dst addr> test=<0/1>
hostapd_cli disassoc <dst addr> test=<0/1>

test=0: unprotected
test=1: protected

14 years agoAdd deauthenticate/disassociate ctrl_iface commands
Jouni Malinen [Mon, 29 Mar 2010 18:14:57 +0000 (11:14 -0700)]
Add deauthenticate/disassociate ctrl_iface commands

14 years agoMFP: Add MFPR flag into station RSN IE if 802.11w is mandatory
Jouni Malinen [Mon, 29 Mar 2010 17:48:01 +0000 (10:48 -0700)]
MFP: Add MFPR flag into station RSN IE if 802.11w is mandatory

14 years agoFix ctrl_iface get-STA-MIB for WPS disabled case
Jouni Malinen [Mon, 29 Mar 2010 16:59:16 +0000 (09:59 -0700)]
Fix ctrl_iface get-STA-MIB for WPS disabled case

The previous version would crash here on NULL pointer dereference if
WPS was disabled.

14 years agobgscan: Add signal strength change events
Jouni Malinen [Sun, 28 Mar 2010 22:32:34 +0000 (15:32 -0700)]
bgscan: Add signal strength change events

This allows bgscan modules to use more information to decide on when
to perform background scans. bgscan_simple can now change between
short and long background scan intervals based on signal strength
and in addition, it can trigger immediate scans when the signal
strength is detected to be dropping.

bgscan_simple takes following parameters now:
short interval:signal strength threshold:long interval
For example:
bgscan="simple:30:-45:300"

14 years agoAdd driver command and event for signal strength monitoring
Jouni Malinen [Sun, 28 Mar 2010 22:31:04 +0000 (15:31 -0700)]
Add driver command and event for signal strength monitoring

14 years agonl80211: Parse CQM events
Jouni Malinen [Sun, 28 Mar 2010 20:56:40 +0000 (13:56 -0700)]
nl80211: Parse CQM events

14 years agoSync with wireless-testing.git include/linux/nl80211.h
Jouni Malinen [Sun, 28 Mar 2010 19:47:17 +0000 (12:47 -0700)]
Sync with wireless-testing.git include/linux/nl80211.h

14 years agonl80211: Fix WEP key configuration for prior to authentication
Holger Schurig [Sun, 28 Mar 2010 05:22:17 +0000 (22:22 -0700)]
nl80211: Fix WEP key configuration for prior to authentication

The driver data was changed from struct wpa_driver_nl80211_data * to
struct i802_bss * and the internal call will need to match that change.

14 years agoFix wpa_auth_iface_iter() to skip BSSes without Authenticator
Jouni Malinen [Sat, 27 Mar 2010 06:26:24 +0000 (23:26 -0700)]
Fix wpa_auth_iface_iter() to skip BSSes without Authenticator

This could cause NULL pointer deference if multi-BSS configuration
was used with OKC in some cases.

14 years agoAdd freq_list network configuration parameter
Jouni Malinen [Sat, 27 Mar 2010 05:45:50 +0000 (22:45 -0700)]
Add freq_list network configuration parameter

This can be used to limit which frequencies are considered when
selecting a BSS. This is somewhat similar to scan_freq, but will
also affect any scan results regardless of which program triggered
the scan.

14 years agonl80211: Add more debug information about scan request parameters
Jouni Malinen [Sat, 27 Mar 2010 05:22:38 +0000 (22:22 -0700)]
nl80211: Add more debug information about scan request parameters

14 years agonl80211: Silence set_key ENOLINK failure messages on key clearing
Jouni Malinen [Sat, 27 Mar 2010 04:58:31 +0000 (21:58 -0700)]
nl80211: Silence set_key ENOLINK failure messages on key clearing

This happens in common case and is expected, so there is no need to
include the potentially confusing failure message in the debug log.

14 years agoFT: Fix Authorized flag setting for FT protocol
Jouni Malinen [Sat, 13 Mar 2010 19:43:00 +0000 (21:43 +0200)]
FT: Fix Authorized flag setting for FT protocol

4-way handshake or EAPOL is not used in this case, so we must
force Authorized flag to be set at the conclusion of successful
FT protocol run.

14 years agoFT: Clean EAPOL supp portValid to force re-entry to AUTHENTICATED
Jouni Malinen [Sat, 13 Mar 2010 19:40:44 +0000 (21:40 +0200)]
FT: Clean EAPOL supp portValid to force re-entry to AUTHENTICATED

This fixed FT-over-DS to end up in Authorized state when the EAPOL
PAE state machine re-enters AUTHENTICATED.

14 years agoFT: Process reassoc resp FT IEs when using wpa_supplicant SME
Jouni Malinen [Sat, 13 Mar 2010 19:13:18 +0000 (21:13 +0200)]
FT: Process reassoc resp FT IEs when using wpa_supplicant SME

14 years agoFT: Fix PTK configuration in authenticator
Jouni Malinen [Sat, 13 Mar 2010 19:11:26 +0000 (21:11 +0200)]
FT: Fix PTK configuration in authenticator

Must update sm->pairwise when fetching PMK-R1 SA.
Add a workaround for drivers that cannot set keys before association
(e.g., cfg80211/mac80211): retry PTK configuration after association.

14 years agoFT: Add driver op for marking a STA authenticated
Jouni Malinen [Sat, 13 Mar 2010 16:28:15 +0000 (18:28 +0200)]
FT: Add driver op for marking a STA authenticated

This can be used with FT-over-DS where FT Action frame exchange
triggers transition to State 2 (authenticated) without Authentication
frame exchange.

14 years agoFT: Update SME frequency info before sme_associate() call
Jouni Malinen [Sat, 13 Mar 2010 16:26:25 +0000 (18:26 +0200)]
FT: Update SME frequency info before sme_associate() call

This is needed to allow FT-over-DS to request correct channel for
the reassociation with the target AP.

14 years agoFT: Add a workaround to set PTK after reassociation
Jouni Malinen [Sat, 13 Mar 2010 15:15:38 +0000 (17:15 +0200)]
FT: Add a workaround to set PTK after reassociation

If the PTK configuration prior to association fails, allow reassociation
attempt to continue and configure PTK after association. This is a
workaround for drivers that do not allow PTK to be configured before
association (e.g., current cfg80211/mac80211).

14 years agoFT: Request reassociation after successful FT Action frame exchange
Jouni Malinen [Sat, 13 Mar 2010 15:14:41 +0000 (17:14 +0200)]
FT: Request reassociation after successful FT Action frame exchange

14 years agoFix WPS IE in Probe Response frame to include proper Config Methods values
Jouni Malinen [Sat, 13 Mar 2010 11:39:22 +0000 (13:39 +0200)]
Fix WPS IE in Probe Response frame to include proper Config Methods values

This attribute is supposed to indicate which methods the AP supports as
an Enrollee for adding external Registrars. It was left to 0 when the
AP code did not yet support external Registrars and was forgotten when
the ER support was added.

14 years agowpa_cli: Improved command parameter tab completion
Jouni Malinen [Fri, 12 Mar 2010 17:43:15 +0000 (19:43 +0200)]
wpa_cli: Improved command parameter tab completion

14 years agowpa_cli: Fix detach race with forked monitor process
Jouni Malinen [Fri, 12 Mar 2010 15:34:56 +0000 (17:34 +0200)]
wpa_cli: Fix detach race with forked monitor process

Need to kill the monitor process before running detach command on
the monitor connection to avoid race where the monitor process may
end up getting the detach command result.

14 years agowpa_cli: Redisplay readline edit after event messages
Jouni Malinen [Fri, 12 Mar 2010 15:24:50 +0000 (17:24 +0200)]
wpa_cli: Redisplay readline edit after event messages

14 years agoFT: Add preliminary processing of FT Action Response from EVENT_RX_ACTION
Jouni Malinen [Thu, 11 Mar 2010 22:43:00 +0000 (00:43 +0200)]
FT: Add preliminary processing of FT Action Response from EVENT_RX_ACTION

Previously, this was only done with userspace MLME (i.e., driver_test.c);
now, driver_nl80211.c can deliver the FT Action Response (FT-over-DS)
for processing. The reassociation after successful FT Action frame
exchange is not yet implemented.