]> git.ipfire.org Git - thirdparty/hostap.git/blob - src/rsn_supp/wpa.h
FILS: Add MDE into Authentication frame for FILS+FT
[thirdparty/hostap.git] / src / rsn_supp / wpa.h
1 /*
2 * wpa_supplicant - WPA definitions
3 * Copyright (c) 2003-2015, Jouni Malinen <j@w1.fi>
4 *
5 * This software may be distributed under the terms of the BSD license.
6 * See README for more details.
7 */
8
9 #ifndef WPA_H
10 #define WPA_H
11
12 #include "common/defs.h"
13 #include "common/eapol_common.h"
14 #include "common/wpa_common.h"
15 #include "common/ieee802_11_defs.h"
16
17 struct wpa_sm;
18 struct eapol_sm;
19 struct wpa_config_blob;
20 struct hostapd_freq_params;
21
22 struct wpa_sm_ctx {
23 void *ctx; /* pointer to arbitrary upper level context */
24 void *msg_ctx; /* upper level context for wpa_msg() calls */
25
26 void (*set_state)(void *ctx, enum wpa_states state);
27 enum wpa_states (*get_state)(void *ctx);
28 void (*deauthenticate)(void * ctx, int reason_code);
29 int (*set_key)(void *ctx, enum wpa_alg alg,
30 const u8 *addr, int key_idx, int set_tx,
31 const u8 *seq, size_t seq_len,
32 const u8 *key, size_t key_len);
33 void * (*get_network_ctx)(void *ctx);
34 int (*get_bssid)(void *ctx, u8 *bssid);
35 int (*ether_send)(void *ctx, const u8 *dest, u16 proto, const u8 *buf,
36 size_t len);
37 int (*get_beacon_ie)(void *ctx);
38 void (*cancel_auth_timeout)(void *ctx);
39 u8 * (*alloc_eapol)(void *ctx, u8 type, const void *data, u16 data_len,
40 size_t *msg_len, void **data_pos);
41 int (*add_pmkid)(void *ctx, void *network_ctx, const u8 *bssid,
42 const u8 *pmkid);
43 int (*remove_pmkid)(void *ctx, void *network_ctx, const u8 *bssid,
44 const u8 *pmkid);
45 void (*set_config_blob)(void *ctx, struct wpa_config_blob *blob);
46 const struct wpa_config_blob * (*get_config_blob)(void *ctx,
47 const char *name);
48 int (*mlme_setprotection)(void *ctx, const u8 *addr,
49 int protection_type, int key_type);
50 int (*update_ft_ies)(void *ctx, const u8 *md, const u8 *ies,
51 size_t ies_len);
52 int (*send_ft_action)(void *ctx, u8 action, const u8 *target_ap,
53 const u8 *ies, size_t ies_len);
54 int (*mark_authenticated)(void *ctx, const u8 *target_ap);
55 #ifdef CONFIG_TDLS
56 int (*tdls_get_capa)(void *ctx, int *tdls_supported,
57 int *tdls_ext_setup, int *tdls_chan_switch);
58 int (*send_tdls_mgmt)(void *ctx, const u8 *dst,
59 u8 action_code, u8 dialog_token,
60 u16 status_code, u32 peer_capab,
61 int initiator, const u8 *buf, size_t len);
62 int (*tdls_oper)(void *ctx, int oper, const u8 *peer);
63 int (*tdls_peer_addset)(void *ctx, const u8 *addr, int add, u16 aid,
64 u16 capability, const u8 *supp_rates,
65 size_t supp_rates_len,
66 const struct ieee80211_ht_capabilities *ht_capab,
67 const struct ieee80211_vht_capabilities *vht_capab,
68 u8 qosinfo, int wmm, const u8 *ext_capab,
69 size_t ext_capab_len, const u8 *supp_channels,
70 size_t supp_channels_len,
71 const u8 *supp_oper_classes,
72 size_t supp_oper_classes_len);
73 int (*tdls_enable_channel_switch)(
74 void *ctx, const u8 *addr, u8 oper_class,
75 const struct hostapd_freq_params *params);
76 int (*tdls_disable_channel_switch)(void *ctx, const u8 *addr);
77 #endif /* CONFIG_TDLS */
78 void (*set_rekey_offload)(void *ctx, const u8 *kek, size_t kek_len,
79 const u8 *kck, size_t kck_len,
80 const u8 *replay_ctr);
81 int (*key_mgmt_set_pmk)(void *ctx, const u8 *pmk, size_t pmk_len);
82 void (*fils_hlp_rx)(void *ctx, const u8 *dst, const u8 *src,
83 const u8 *pkt, size_t pkt_len);
84 };
85
86
87 enum wpa_sm_conf_params {
88 RSNA_PMK_LIFETIME /* dot11RSNAConfigPMKLifetime */,
89 RSNA_PMK_REAUTH_THRESHOLD /* dot11RSNAConfigPMKReauthThreshold */,
90 RSNA_SA_TIMEOUT /* dot11RSNAConfigSATimeout */,
91 WPA_PARAM_PROTO,
92 WPA_PARAM_PAIRWISE,
93 WPA_PARAM_GROUP,
94 WPA_PARAM_KEY_MGMT,
95 WPA_PARAM_MGMT_GROUP,
96 WPA_PARAM_RSN_ENABLED,
97 WPA_PARAM_MFP
98 };
99
100 struct rsn_supp_config {
101 void *network_ctx;
102 int peerkey_enabled;
103 int allowed_pairwise_cipher; /* bitfield of WPA_CIPHER_* */
104 int proactive_key_caching;
105 int eap_workaround;
106 void *eap_conf_ctx;
107 const u8 *ssid;
108 size_t ssid_len;
109 int wpa_ptk_rekey;
110 int p2p;
111 int wpa_rsc_relaxation;
112 const u8 *fils_cache_id;
113 };
114
115 #ifndef CONFIG_NO_WPA
116
117 struct wpa_sm * wpa_sm_init(struct wpa_sm_ctx *ctx);
118 void wpa_sm_deinit(struct wpa_sm *sm);
119 void wpa_sm_notify_assoc(struct wpa_sm *sm, const u8 *bssid);
120 void wpa_sm_notify_disassoc(struct wpa_sm *sm);
121 void wpa_sm_set_pmk(struct wpa_sm *sm, const u8 *pmk, size_t pmk_len,
122 const u8 *pmkid, const u8 *bssid);
123 void wpa_sm_set_pmk_from_pmksa(struct wpa_sm *sm);
124 void wpa_sm_set_fast_reauth(struct wpa_sm *sm, int fast_reauth);
125 void wpa_sm_set_scard_ctx(struct wpa_sm *sm, void *scard_ctx);
126 void wpa_sm_set_config(struct wpa_sm *sm, struct rsn_supp_config *config);
127 void wpa_sm_set_own_addr(struct wpa_sm *sm, const u8 *addr);
128 void wpa_sm_set_ifname(struct wpa_sm *sm, const char *ifname,
129 const char *bridge_ifname);
130 void wpa_sm_set_eapol(struct wpa_sm *sm, struct eapol_sm *eapol);
131 int wpa_sm_set_assoc_wpa_ie(struct wpa_sm *sm, const u8 *ie, size_t len);
132 int wpa_sm_set_assoc_wpa_ie_default(struct wpa_sm *sm, u8 *wpa_ie,
133 size_t *wpa_ie_len);
134 int wpa_sm_set_ap_wpa_ie(struct wpa_sm *sm, const u8 *ie, size_t len);
135 int wpa_sm_set_ap_rsn_ie(struct wpa_sm *sm, const u8 *ie, size_t len);
136 int wpa_sm_get_mib(struct wpa_sm *sm, char *buf, size_t buflen);
137
138 int wpa_sm_set_param(struct wpa_sm *sm, enum wpa_sm_conf_params param,
139 unsigned int value);
140
141 int wpa_sm_get_status(struct wpa_sm *sm, char *buf, size_t buflen,
142 int verbose);
143 int wpa_sm_pmf_enabled(struct wpa_sm *sm);
144
145 void wpa_sm_key_request(struct wpa_sm *sm, int error, int pairwise);
146
147 int wpa_parse_wpa_ie(const u8 *wpa_ie, size_t wpa_ie_len,
148 struct wpa_ie_data *data);
149
150 void wpa_sm_aborted_cached(struct wpa_sm *sm);
151 int wpa_sm_rx_eapol(struct wpa_sm *sm, const u8 *src_addr,
152 const u8 *buf, size_t len);
153 int wpa_sm_parse_own_wpa_ie(struct wpa_sm *sm, struct wpa_ie_data *data);
154 int wpa_sm_pmksa_cache_list(struct wpa_sm *sm, char *buf, size_t len);
155 struct rsn_pmksa_cache_entry * wpa_sm_pmksa_cache_head(struct wpa_sm *sm);
156 struct rsn_pmksa_cache_entry *
157 wpa_sm_pmksa_cache_add_entry(struct wpa_sm *sm,
158 struct rsn_pmksa_cache_entry * entry);
159 void wpa_sm_drop_sa(struct wpa_sm *sm);
160 int wpa_sm_has_ptk(struct wpa_sm *sm);
161
162 void wpa_sm_update_replay_ctr(struct wpa_sm *sm, const u8 *replay_ctr);
163
164 void wpa_sm_pmksa_cache_flush(struct wpa_sm *sm, void *network_ctx);
165
166 int wpa_sm_get_p2p_ip_addr(struct wpa_sm *sm, u8 *buf);
167
168 void wpa_sm_set_rx_replay_ctr(struct wpa_sm *sm, const u8 *rx_replay_counter);
169 void wpa_sm_set_ptk_kck_kek(struct wpa_sm *sm,
170 const u8 *ptk_kck, size_t ptk_kck_len,
171 const u8 *ptk_kek, size_t ptk_kek_len);
172
173 #else /* CONFIG_NO_WPA */
174
175 static inline struct wpa_sm * wpa_sm_init(struct wpa_sm_ctx *ctx)
176 {
177 return (struct wpa_sm *) 1;
178 }
179
180 static inline void wpa_sm_deinit(struct wpa_sm *sm)
181 {
182 }
183
184 static inline void wpa_sm_notify_assoc(struct wpa_sm *sm, const u8 *bssid)
185 {
186 }
187
188 static inline void wpa_sm_notify_disassoc(struct wpa_sm *sm)
189 {
190 }
191
192 static inline void wpa_sm_set_pmk(struct wpa_sm *sm, const u8 *pmk,
193 size_t pmk_len, const u8 *pmkid,
194 const u8 *bssid)
195 {
196 }
197
198 static inline void wpa_sm_set_pmk_from_pmksa(struct wpa_sm *sm)
199 {
200 }
201
202 static inline void wpa_sm_set_fast_reauth(struct wpa_sm *sm, int fast_reauth)
203 {
204 }
205
206 static inline void wpa_sm_set_scard_ctx(struct wpa_sm *sm, void *scard_ctx)
207 {
208 }
209
210 static inline void wpa_sm_set_config(struct wpa_sm *sm,
211 struct rsn_supp_config *config)
212 {
213 }
214
215 static inline void wpa_sm_set_own_addr(struct wpa_sm *sm, const u8 *addr)
216 {
217 }
218
219 static inline void wpa_sm_set_ifname(struct wpa_sm *sm, const char *ifname,
220 const char *bridge_ifname)
221 {
222 }
223
224 static inline void wpa_sm_set_eapol(struct wpa_sm *sm, struct eapol_sm *eapol)
225 {
226 }
227
228 static inline int wpa_sm_set_assoc_wpa_ie(struct wpa_sm *sm, const u8 *ie,
229 size_t len)
230 {
231 return -1;
232 }
233
234 static inline int wpa_sm_set_assoc_wpa_ie_default(struct wpa_sm *sm,
235 u8 *wpa_ie,
236 size_t *wpa_ie_len)
237 {
238 return -1;
239 }
240
241 static inline int wpa_sm_set_ap_wpa_ie(struct wpa_sm *sm, const u8 *ie,
242 size_t len)
243 {
244 return -1;
245 }
246
247 static inline int wpa_sm_set_ap_rsn_ie(struct wpa_sm *sm, const u8 *ie,
248 size_t len)
249 {
250 return -1;
251 }
252
253 static inline int wpa_sm_get_mib(struct wpa_sm *sm, char *buf, size_t buflen)
254 {
255 return 0;
256 }
257
258 static inline int wpa_sm_set_param(struct wpa_sm *sm,
259 enum wpa_sm_conf_params param,
260 unsigned int value)
261 {
262 return -1;
263 }
264
265 static inline int wpa_sm_get_status(struct wpa_sm *sm, char *buf,
266 size_t buflen, int verbose)
267 {
268 return 0;
269 }
270
271 static inline int wpa_sm_pmf_enabled(struct wpa_sm *sm)
272 {
273 return 0;
274 }
275
276 static inline void wpa_sm_key_request(struct wpa_sm *sm, int error,
277 int pairwise)
278 {
279 }
280
281 static inline int wpa_parse_wpa_ie(const u8 *wpa_ie, size_t wpa_ie_len,
282 struct wpa_ie_data *data)
283 {
284 return -1;
285 }
286
287 static inline void wpa_sm_aborted_cached(struct wpa_sm *sm)
288 {
289 }
290
291 static inline int wpa_sm_rx_eapol(struct wpa_sm *sm, const u8 *src_addr,
292 const u8 *buf, size_t len)
293 {
294 return -1;
295 }
296
297 static inline int wpa_sm_parse_own_wpa_ie(struct wpa_sm *sm,
298 struct wpa_ie_data *data)
299 {
300 return -1;
301 }
302
303 static inline int wpa_sm_pmksa_cache_list(struct wpa_sm *sm, char *buf,
304 size_t len)
305 {
306 return -1;
307 }
308
309 static inline void wpa_sm_drop_sa(struct wpa_sm *sm)
310 {
311 }
312
313 static inline int wpa_sm_has_ptk(struct wpa_sm *sm)
314 {
315 return 0;
316 }
317
318 static inline void wpa_sm_update_replay_ctr(struct wpa_sm *sm,
319 const u8 *replay_ctr)
320 {
321 }
322
323 static inline void wpa_sm_pmksa_cache_flush(struct wpa_sm *sm,
324 void *network_ctx)
325 {
326 }
327
328 static inline void wpa_sm_set_rx_replay_ctr(struct wpa_sm *sm,
329 const u8 *rx_replay_counter)
330 {
331 }
332
333 static inline void wpa_sm_set_ptk_kck_kek(struct wpa_sm *sm, const u8 *ptk_kck,
334 size_t ptk_kck_len,
335 const u8 *ptk_kek, size_t ptk_kek_len)
336 {
337 }
338
339 #endif /* CONFIG_NO_WPA */
340
341 #ifdef CONFIG_PEERKEY
342 int wpa_sm_stkstart(struct wpa_sm *sm, const u8 *peer);
343 int wpa_sm_rx_eapol_peerkey(struct wpa_sm *sm, const u8 *src_addr,
344 const u8 *buf, size_t len);
345 #else /* CONFIG_PEERKEY */
346 static inline int wpa_sm_stkstart(struct wpa_sm *sm, const u8 *peer)
347 {
348 return -1;
349 }
350
351 static inline int wpa_sm_rx_eapol_peerkey(struct wpa_sm *sm, const u8 *src_addr,
352 const u8 *buf, size_t len)
353 {
354 return 0;
355 }
356 #endif /* CONFIG_PEERKEY */
357
358 #ifdef CONFIG_IEEE80211R
359
360 int wpa_sm_set_ft_params(struct wpa_sm *sm, const u8 *ies, size_t ies_len);
361 int wpa_ft_prepare_auth_request(struct wpa_sm *sm, const u8 *mdie);
362 int wpa_ft_process_response(struct wpa_sm *sm, const u8 *ies, size_t ies_len,
363 int ft_action, const u8 *target_ap,
364 const u8 *ric_ies, size_t ric_ies_len);
365 int wpa_ft_is_completed(struct wpa_sm *sm);
366 void wpa_reset_ft_completed(struct wpa_sm *sm);
367 int wpa_ft_validate_reassoc_resp(struct wpa_sm *sm, const u8 *ies,
368 size_t ies_len, const u8 *src_addr);
369 int wpa_ft_start_over_ds(struct wpa_sm *sm, const u8 *target_ap,
370 const u8 *mdie);
371
372 #else /* CONFIG_IEEE80211R */
373
374 static inline int
375 wpa_sm_set_ft_params(struct wpa_sm *sm, const u8 *ies, size_t ies_len)
376 {
377 return 0;
378 }
379
380 static inline int wpa_ft_prepare_auth_request(struct wpa_sm *sm,
381 const u8 *mdie)
382 {
383 return 0;
384 }
385
386 static inline int
387 wpa_ft_process_response(struct wpa_sm *sm, const u8 *ies, size_t ies_len,
388 int ft_action, const u8 *target_ap)
389 {
390 return 0;
391 }
392
393 static inline int wpa_ft_is_completed(struct wpa_sm *sm)
394 {
395 return 0;
396 }
397
398 static inline void wpa_reset_ft_completed(struct wpa_sm *sm)
399 {
400 }
401
402 static inline int
403 wpa_ft_validate_reassoc_resp(struct wpa_sm *sm, const u8 *ies, size_t ies_len,
404 const u8 *src_addr)
405 {
406 return -1;
407 }
408
409 #endif /* CONFIG_IEEE80211R */
410
411
412 /* tdls.c */
413 void wpa_tdls_ap_ies(struct wpa_sm *sm, const u8 *ies, size_t len);
414 void wpa_tdls_assoc_resp_ies(struct wpa_sm *sm, const u8 *ies, size_t len);
415 int wpa_tdls_start(struct wpa_sm *sm, const u8 *addr);
416 void wpa_tdls_remove(struct wpa_sm *sm, const u8 *addr);
417 int wpa_tdls_teardown_link(struct wpa_sm *sm, const u8 *addr, u16 reason_code);
418 int wpa_tdls_send_discovery_request(struct wpa_sm *sm, const u8 *addr);
419 int wpa_tdls_init(struct wpa_sm *sm);
420 void wpa_tdls_teardown_peers(struct wpa_sm *sm);
421 void wpa_tdls_deinit(struct wpa_sm *sm);
422 void wpa_tdls_enable(struct wpa_sm *sm, int enabled);
423 void wpa_tdls_disable_unreachable_link(struct wpa_sm *sm, const u8 *addr);
424 const char * wpa_tdls_get_link_status(struct wpa_sm *sm, const u8 *addr);
425 int wpa_tdls_is_external_setup(struct wpa_sm *sm);
426 int wpa_tdls_enable_chan_switch(struct wpa_sm *sm, const u8 *addr,
427 u8 oper_class,
428 struct hostapd_freq_params *freq_params);
429 int wpa_tdls_disable_chan_switch(struct wpa_sm *sm, const u8 *addr);
430 #ifdef CONFIG_TDLS_TESTING
431 extern unsigned int tdls_testing;
432 #endif /* CONFIG_TDLS_TESTING */
433
434
435 int wpa_wnmsleep_install_key(struct wpa_sm *sm, u8 subelem_id, u8 *buf);
436 void wpa_sm_set_test_assoc_ie(struct wpa_sm *sm, struct wpabuf *buf);
437
438 struct wpabuf * fils_build_auth(struct wpa_sm *sm, int dh_group, const u8 *md);
439 int fils_process_auth(struct wpa_sm *sm, const u8 *bssid, const u8 *data,
440 size_t len);
441 struct wpabuf * fils_build_assoc_req(struct wpa_sm *sm, const u8 **kek,
442 size_t *kek_len, const u8 **snonce,
443 const u8 **anonce,
444 const struct wpabuf **hlp,
445 unsigned int num_hlp);
446 int fils_process_assoc_resp(struct wpa_sm *sm, const u8 *resp, size_t len);
447 int wpa_fils_is_completed(struct wpa_sm *sm);
448
449 struct wpabuf * owe_build_assoc_req(struct wpa_sm *sm);
450 int owe_process_assoc_resp(struct wpa_sm *sm, const u8 *resp_ies,
451 size_t resp_ies_len);
452
453 #endif /* WPA_H */