2008-02-27 20:34:43 -05:00
|
|
|
/*
|
|
|
|
* WPA Supplicant - Common definitions
|
2015-01-25 16:32:01 -05:00
|
|
|
* Copyright (c) 2004-2015, Jouni Malinen <j@w1.fi>
|
2008-02-27 20:34:43 -05:00
|
|
|
*
|
2012-02-11 09:46:35 -05:00
|
|
|
* This software may be distributed under the terms of the BSD license.
|
|
|
|
* See README for more details.
|
2008-02-27 20:34:43 -05:00
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef DEFS_H
|
|
|
|
#define DEFS_H
|
|
|
|
|
|
|
|
#ifdef FALSE
|
|
|
|
#undef FALSE
|
|
|
|
#endif
|
|
|
|
#ifdef TRUE
|
|
|
|
#undef TRUE
|
|
|
|
#endif
|
|
|
|
typedef enum { FALSE = 0, TRUE = 1 } Boolean;
|
|
|
|
|
|
|
|
|
|
|
|
#define WPA_CIPHER_NONE BIT(0)
|
|
|
|
#define WPA_CIPHER_WEP40 BIT(1)
|
|
|
|
#define WPA_CIPHER_WEP104 BIT(2)
|
|
|
|
#define WPA_CIPHER_TKIP BIT(3)
|
|
|
|
#define WPA_CIPHER_CCMP BIT(4)
|
|
|
|
#define WPA_CIPHER_AES_128_CMAC BIT(5)
|
2012-08-29 04:52:15 -04:00
|
|
|
#define WPA_CIPHER_GCMP BIT(6)
|
2012-09-30 13:26:55 -04:00
|
|
|
#define WPA_CIPHER_SMS4 BIT(7)
|
2013-12-24 15:21:04 -05:00
|
|
|
#define WPA_CIPHER_GCMP_256 BIT(8)
|
|
|
|
#define WPA_CIPHER_CCMP_256 BIT(9)
|
|
|
|
#define WPA_CIPHER_BIP_GMAC_128 BIT(11)
|
|
|
|
#define WPA_CIPHER_BIP_GMAC_256 BIT(12)
|
|
|
|
#define WPA_CIPHER_BIP_CMAC_256 BIT(13)
|
2013-07-23 14:24:05 -04:00
|
|
|
#define WPA_CIPHER_GTK_NOT_USED BIT(14)
|
2008-02-27 20:34:43 -05:00
|
|
|
|
|
|
|
#define WPA_KEY_MGMT_IEEE8021X BIT(0)
|
|
|
|
#define WPA_KEY_MGMT_PSK BIT(1)
|
|
|
|
#define WPA_KEY_MGMT_NONE BIT(2)
|
|
|
|
#define WPA_KEY_MGMT_IEEE8021X_NO_WPA BIT(3)
|
|
|
|
#define WPA_KEY_MGMT_WPA_NONE BIT(4)
|
|
|
|
#define WPA_KEY_MGMT_FT_IEEE8021X BIT(5)
|
|
|
|
#define WPA_KEY_MGMT_FT_PSK BIT(6)
|
2008-08-31 15:57:28 -04:00
|
|
|
#define WPA_KEY_MGMT_IEEE8021X_SHA256 BIT(7)
|
|
|
|
#define WPA_KEY_MGMT_PSK_SHA256 BIT(8)
|
2008-11-23 12:34:26 -05:00
|
|
|
#define WPA_KEY_MGMT_WPS BIT(9)
|
2012-09-30 12:51:07 -04:00
|
|
|
#define WPA_KEY_MGMT_SAE BIT(10)
|
|
|
|
#define WPA_KEY_MGMT_FT_SAE BIT(11)
|
2012-09-30 13:26:55 -04:00
|
|
|
#define WPA_KEY_MGMT_WAPI_PSK BIT(12)
|
|
|
|
#define WPA_KEY_MGMT_WAPI_CERT BIT(13)
|
|
|
|
#define WPA_KEY_MGMT_CCKM BIT(14)
|
2013-07-23 14:23:25 -04:00
|
|
|
#define WPA_KEY_MGMT_OSEN BIT(15)
|
2014-11-16 06:20:51 -05:00
|
|
|
#define WPA_KEY_MGMT_IEEE8021X_SUITE_B BIT(16)
|
2015-01-25 16:32:01 -05:00
|
|
|
#define WPA_KEY_MGMT_IEEE8021X_SUITE_B_192 BIT(17)
|
2015-09-01 10:50:04 -04:00
|
|
|
#define WPA_KEY_MGMT_FILS_SHA256 BIT(18)
|
|
|
|
#define WPA_KEY_MGMT_FILS_SHA384 BIT(19)
|
|
|
|
#define WPA_KEY_MGMT_FT_FILS_SHA256 BIT(20)
|
|
|
|
#define WPA_KEY_MGMT_FT_FILS_SHA384 BIT(21)
|
2008-08-31 15:57:28 -04:00
|
|
|
|
|
|
|
static inline int wpa_key_mgmt_wpa_ieee8021x(int akm)
|
|
|
|
{
|
2011-04-08 12:11:54 -04:00
|
|
|
return !!(akm & (WPA_KEY_MGMT_IEEE8021X |
|
|
|
|
WPA_KEY_MGMT_FT_IEEE8021X |
|
2012-09-30 13:26:55 -04:00
|
|
|
WPA_KEY_MGMT_CCKM |
|
2013-07-23 14:23:25 -04:00
|
|
|
WPA_KEY_MGMT_OSEN |
|
2014-11-16 06:20:51 -05:00
|
|
|
WPA_KEY_MGMT_IEEE8021X_SHA256 |
|
2015-01-25 16:32:01 -05:00
|
|
|
WPA_KEY_MGMT_IEEE8021X_SUITE_B |
|
2015-09-01 10:50:04 -04:00
|
|
|
WPA_KEY_MGMT_IEEE8021X_SUITE_B_192 |
|
|
|
|
WPA_KEY_MGMT_FILS_SHA256 |
|
|
|
|
WPA_KEY_MGMT_FILS_SHA384 |
|
|
|
|
WPA_KEY_MGMT_FT_FILS_SHA256 |
|
|
|
|
WPA_KEY_MGMT_FT_FILS_SHA384));
|
2008-08-31 15:57:28 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
static inline int wpa_key_mgmt_wpa_psk(int akm)
|
|
|
|
{
|
2011-04-08 12:11:54 -04:00
|
|
|
return !!(akm & (WPA_KEY_MGMT_PSK |
|
|
|
|
WPA_KEY_MGMT_FT_PSK |
|
2012-09-30 12:51:07 -04:00
|
|
|
WPA_KEY_MGMT_PSK_SHA256 |
|
2013-12-28 06:41:02 -05:00
|
|
|
WPA_KEY_MGMT_SAE |
|
|
|
|
WPA_KEY_MGMT_FT_SAE));
|
2008-08-31 15:57:28 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
static inline int wpa_key_mgmt_ft(int akm)
|
|
|
|
{
|
2011-04-08 12:11:54 -04:00
|
|
|
return !!(akm & (WPA_KEY_MGMT_FT_PSK |
|
2012-09-30 12:51:07 -04:00
|
|
|
WPA_KEY_MGMT_FT_IEEE8021X |
|
2015-09-01 10:50:04 -04:00
|
|
|
WPA_KEY_MGMT_FT_SAE |
|
|
|
|
WPA_KEY_MGMT_FT_FILS_SHA256 |
|
|
|
|
WPA_KEY_MGMT_FT_FILS_SHA384));
|
2012-09-30 12:51:07 -04:00
|
|
|
}
|
|
|
|
|
2016-09-24 16:53:42 -04:00
|
|
|
static inline int wpa_key_mgmt_ft_psk(int akm)
|
|
|
|
{
|
|
|
|
return !!(akm & WPA_KEY_MGMT_FT_PSK);
|
|
|
|
}
|
|
|
|
|
2012-09-30 12:51:07 -04:00
|
|
|
static inline int wpa_key_mgmt_sae(int akm)
|
|
|
|
{
|
|
|
|
return !!(akm & (WPA_KEY_MGMT_SAE |
|
|
|
|
WPA_KEY_MGMT_FT_SAE));
|
2008-08-31 15:57:28 -04:00
|
|
|
}
|
|
|
|
|
2015-09-01 10:50:04 -04:00
|
|
|
static inline int wpa_key_mgmt_fils(int akm)
|
|
|
|
{
|
|
|
|
return !!(akm & (WPA_KEY_MGMT_FILS_SHA256 |
|
|
|
|
WPA_KEY_MGMT_FILS_SHA384 |
|
|
|
|
WPA_KEY_MGMT_FT_FILS_SHA256 |
|
|
|
|
WPA_KEY_MGMT_FT_FILS_SHA384));
|
|
|
|
}
|
|
|
|
|
2008-08-31 15:57:28 -04:00
|
|
|
static inline int wpa_key_mgmt_sha256(int akm)
|
|
|
|
{
|
2011-04-08 12:11:54 -04:00
|
|
|
return !!(akm & (WPA_KEY_MGMT_PSK_SHA256 |
|
2013-07-23 14:23:25 -04:00
|
|
|
WPA_KEY_MGMT_IEEE8021X_SHA256 |
|
2014-11-16 06:20:51 -05:00
|
|
|
WPA_KEY_MGMT_OSEN |
|
2015-09-01 10:50:04 -04:00
|
|
|
WPA_KEY_MGMT_IEEE8021X_SUITE_B |
|
|
|
|
WPA_KEY_MGMT_FILS_SHA256 |
|
|
|
|
WPA_KEY_MGMT_FT_FILS_SHA256));
|
2014-11-16 06:20:51 -05:00
|
|
|
}
|
|
|
|
|
2015-01-25 16:32:01 -05:00
|
|
|
static inline int wpa_key_mgmt_sha384(int akm)
|
|
|
|
{
|
2015-09-01 10:50:04 -04:00
|
|
|
return !!(akm & (WPA_KEY_MGMT_IEEE8021X_SUITE_B_192 |
|
|
|
|
WPA_KEY_MGMT_FILS_SHA384 |
|
|
|
|
WPA_KEY_MGMT_FT_FILS_SHA384));
|
2015-01-25 16:32:01 -05:00
|
|
|
}
|
|
|
|
|
2014-11-16 06:20:51 -05:00
|
|
|
static inline int wpa_key_mgmt_suite_b(int akm)
|
|
|
|
{
|
2015-01-25 16:32:01 -05:00
|
|
|
return !!(akm & (WPA_KEY_MGMT_IEEE8021X_SUITE_B |
|
|
|
|
WPA_KEY_MGMT_IEEE8021X_SUITE_B_192));
|
2008-08-31 15:57:28 -04:00
|
|
|
}
|
|
|
|
|
2010-11-08 14:14:32 -05:00
|
|
|
static inline int wpa_key_mgmt_wpa(int akm)
|
|
|
|
{
|
|
|
|
return wpa_key_mgmt_wpa_ieee8021x(akm) ||
|
2013-12-28 06:41:02 -05:00
|
|
|
wpa_key_mgmt_wpa_psk(akm) ||
|
2015-09-01 10:50:04 -04:00
|
|
|
wpa_key_mgmt_fils(akm) ||
|
2013-12-28 06:41:02 -05:00
|
|
|
wpa_key_mgmt_sae(akm);
|
2010-11-08 14:14:32 -05:00
|
|
|
}
|
|
|
|
|
2011-11-24 15:46:14 -05:00
|
|
|
static inline int wpa_key_mgmt_wpa_any(int akm)
|
|
|
|
{
|
|
|
|
return wpa_key_mgmt_wpa(akm) || (akm & WPA_KEY_MGMT_WPA_NONE);
|
|
|
|
}
|
|
|
|
|
2012-09-30 13:26:55 -04:00
|
|
|
static inline int wpa_key_mgmt_cckm(int akm)
|
|
|
|
{
|
|
|
|
return akm == WPA_KEY_MGMT_CCKM;
|
|
|
|
}
|
|
|
|
|
2008-02-27 20:34:43 -05:00
|
|
|
|
|
|
|
#define WPA_PROTO_WPA BIT(0)
|
|
|
|
#define WPA_PROTO_RSN BIT(1)
|
2012-09-30 13:26:55 -04:00
|
|
|
#define WPA_PROTO_WAPI BIT(2)
|
2013-07-23 14:23:25 -04:00
|
|
|
#define WPA_PROTO_OSEN BIT(3)
|
2008-02-27 20:34:43 -05:00
|
|
|
|
|
|
|
#define WPA_AUTH_ALG_OPEN BIT(0)
|
|
|
|
#define WPA_AUTH_ALG_SHARED BIT(1)
|
|
|
|
#define WPA_AUTH_ALG_LEAP BIT(2)
|
2010-03-07 14:02:55 -05:00
|
|
|
#define WPA_AUTH_ALG_FT BIT(3)
|
2012-09-30 12:51:07 -04:00
|
|
|
#define WPA_AUTH_ALG_SAE BIT(4)
|
2015-09-01 10:50:04 -04:00
|
|
|
#define WPA_AUTH_ALG_FILS BIT(5)
|
2008-02-27 20:34:43 -05:00
|
|
|
|
|
|
|
|
2009-12-26 03:35:08 -05:00
|
|
|
enum wpa_alg {
|
|
|
|
WPA_ALG_NONE,
|
|
|
|
WPA_ALG_WEP,
|
|
|
|
WPA_ALG_TKIP,
|
|
|
|
WPA_ALG_CCMP,
|
|
|
|
WPA_ALG_IGTK,
|
2012-08-29 04:52:15 -04:00
|
|
|
WPA_ALG_PMK,
|
2012-09-30 13:26:55 -04:00
|
|
|
WPA_ALG_GCMP,
|
|
|
|
WPA_ALG_SMS4,
|
2013-12-24 15:21:04 -05:00
|
|
|
WPA_ALG_KRK,
|
|
|
|
WPA_ALG_GCMP_256,
|
|
|
|
WPA_ALG_CCMP_256,
|
|
|
|
WPA_ALG_BIP_GMAC_128,
|
|
|
|
WPA_ALG_BIP_GMAC_256,
|
|
|
|
WPA_ALG_BIP_CMAC_256
|
2009-12-26 03:35:08 -05:00
|
|
|
};
|
|
|
|
|
2008-02-27 20:34:43 -05:00
|
|
|
/**
|
|
|
|
* enum wpa_states - wpa_supplicant state
|
|
|
|
*
|
|
|
|
* These enumeration values are used to indicate the current wpa_supplicant
|
|
|
|
* state (wpa_s->wpa_state). The current state can be retrieved with
|
|
|
|
* wpa_supplicant_get_state() function and the state can be changed by calling
|
|
|
|
* wpa_supplicant_set_state(). In WPA state machine (wpa.c and preauth.c), the
|
|
|
|
* wrapper functions wpa_sm_get_state() and wpa_sm_set_state() should be used
|
|
|
|
* to access the state variable.
|
|
|
|
*/
|
2009-12-26 03:35:08 -05:00
|
|
|
enum wpa_states {
|
2008-02-27 20:34:43 -05:00
|
|
|
/**
|
|
|
|
* WPA_DISCONNECTED - Disconnected state
|
|
|
|
*
|
|
|
|
* This state indicates that client is not associated, but is likely to
|
|
|
|
* start looking for an access point. This state is entered when a
|
|
|
|
* connection is lost.
|
|
|
|
*/
|
|
|
|
WPA_DISCONNECTED,
|
|
|
|
|
2010-05-23 03:27:32 -04:00
|
|
|
/**
|
|
|
|
* WPA_INTERFACE_DISABLED - Interface disabled
|
|
|
|
*
|
2015-08-06 03:04:51 -04:00
|
|
|
* This state is entered if the network interface is disabled, e.g.,
|
2010-05-23 03:27:32 -04:00
|
|
|
* due to rfkill. wpa_supplicant refuses any new operations that would
|
|
|
|
* use the radio until the interface has been enabled.
|
|
|
|
*/
|
|
|
|
WPA_INTERFACE_DISABLED,
|
|
|
|
|
2008-02-27 20:34:43 -05:00
|
|
|
/**
|
|
|
|
* WPA_INACTIVE - Inactive state (wpa_supplicant disabled)
|
|
|
|
*
|
|
|
|
* This state is entered if there are no enabled networks in the
|
|
|
|
* configuration. wpa_supplicant is not trying to associate with a new
|
|
|
|
* network and external interaction (e.g., ctrl_iface call to add or
|
|
|
|
* enable a network) is needed to start association.
|
|
|
|
*/
|
|
|
|
WPA_INACTIVE,
|
|
|
|
|
|
|
|
/**
|
|
|
|
* WPA_SCANNING - Scanning for a network
|
|
|
|
*
|
|
|
|
* This state is entered when wpa_supplicant starts scanning for a
|
|
|
|
* network.
|
|
|
|
*/
|
|
|
|
WPA_SCANNING,
|
|
|
|
|
2009-03-20 16:26:41 -04:00
|
|
|
/**
|
|
|
|
* WPA_AUTHENTICATING - Trying to authenticate with a BSS/SSID
|
|
|
|
*
|
|
|
|
* This state is entered when wpa_supplicant has found a suitable BSS
|
|
|
|
* to authenticate with and the driver is configured to try to
|
|
|
|
* authenticate with this BSS. This state is used only with drivers
|
|
|
|
* that use wpa_supplicant as the SME.
|
|
|
|
*/
|
|
|
|
WPA_AUTHENTICATING,
|
|
|
|
|
2008-02-27 20:34:43 -05:00
|
|
|
/**
|
|
|
|
* WPA_ASSOCIATING - Trying to associate with a BSS/SSID
|
|
|
|
*
|
|
|
|
* This state is entered when wpa_supplicant has found a suitable BSS
|
|
|
|
* to associate with and the driver is configured to try to associate
|
|
|
|
* with this BSS in ap_scan=1 mode. When using ap_scan=2 mode, this
|
|
|
|
* state is entered when the driver is configured to try to associate
|
|
|
|
* with a network using the configured SSID and security policy.
|
|
|
|
*/
|
|
|
|
WPA_ASSOCIATING,
|
|
|
|
|
|
|
|
/**
|
|
|
|
* WPA_ASSOCIATED - Association completed
|
|
|
|
*
|
|
|
|
* This state is entered when the driver reports that association has
|
|
|
|
* been successfully completed with an AP. If IEEE 802.1X is used
|
|
|
|
* (with or without WPA/WPA2), wpa_supplicant remains in this state
|
|
|
|
* until the IEEE 802.1X/EAPOL authentication has been completed.
|
|
|
|
*/
|
|
|
|
WPA_ASSOCIATED,
|
|
|
|
|
|
|
|
/**
|
|
|
|
* WPA_4WAY_HANDSHAKE - WPA 4-Way Key Handshake in progress
|
|
|
|
*
|
|
|
|
* This state is entered when WPA/WPA2 4-Way Handshake is started. In
|
|
|
|
* case of WPA-PSK, this happens when receiving the first EAPOL-Key
|
|
|
|
* frame after association. In case of WPA-EAP, this state is entered
|
|
|
|
* when the IEEE 802.1X/EAPOL authentication has been completed.
|
|
|
|
*/
|
|
|
|
WPA_4WAY_HANDSHAKE,
|
|
|
|
|
|
|
|
/**
|
|
|
|
* WPA_GROUP_HANDSHAKE - WPA Group Key Handshake in progress
|
|
|
|
*
|
|
|
|
* This state is entered when 4-Way Key Handshake has been completed
|
|
|
|
* (i.e., when the supplicant sends out message 4/4) and when Group
|
|
|
|
* Key rekeying is started by the AP (i.e., when supplicant receives
|
|
|
|
* message 1/2).
|
|
|
|
*/
|
|
|
|
WPA_GROUP_HANDSHAKE,
|
|
|
|
|
|
|
|
/**
|
|
|
|
* WPA_COMPLETED - All authentication completed
|
|
|
|
*
|
|
|
|
* This state is entered when the full authentication process is
|
|
|
|
* completed. In case of WPA2, this happens when the 4-Way Handshake is
|
|
|
|
* successfully completed. With WPA, this state is entered after the
|
|
|
|
* Group Key Handshake; with IEEE 802.1X (non-WPA) connection is
|
|
|
|
* completed after dynamic keys are received (or if not used, after
|
|
|
|
* the EAP authentication has been completed). With static WEP keys and
|
|
|
|
* plaintext connections, this state is entered when an association
|
|
|
|
* has been completed.
|
|
|
|
*
|
|
|
|
* This state indicates that the supplicant has completed its
|
|
|
|
* processing for the association phase and that data connection is
|
|
|
|
* fully configured.
|
|
|
|
*/
|
|
|
|
WPA_COMPLETED
|
2009-12-26 03:35:08 -05:00
|
|
|
};
|
2008-02-27 20:34:43 -05:00
|
|
|
|
|
|
|
#define MLME_SETPROTECTION_PROTECT_TYPE_NONE 0
|
|
|
|
#define MLME_SETPROTECTION_PROTECT_TYPE_RX 1
|
|
|
|
#define MLME_SETPROTECTION_PROTECT_TYPE_TX 2
|
|
|
|
#define MLME_SETPROTECTION_PROTECT_TYPE_RX_TX 3
|
|
|
|
|
|
|
|
#define MLME_SETPROTECTION_KEY_TYPE_GROUP 0
|
|
|
|
#define MLME_SETPROTECTION_KEY_TYPE_PAIRWISE 1
|
|
|
|
|
2009-03-26 10:06:15 -04:00
|
|
|
|
2010-01-03 14:02:51 -05:00
|
|
|
/**
|
|
|
|
* enum mfp_options - Management frame protection (IEEE 802.11w) options
|
|
|
|
*/
|
2009-03-26 10:06:15 -04:00
|
|
|
enum mfp_options {
|
2010-01-03 14:02:51 -05:00
|
|
|
NO_MGMT_FRAME_PROTECTION = 0,
|
|
|
|
MGMT_FRAME_PROTECTION_OPTIONAL = 1,
|
2012-11-24 15:21:29 -05:00
|
|
|
MGMT_FRAME_PROTECTION_REQUIRED = 2,
|
2009-03-26 10:06:15 -04:00
|
|
|
};
|
2012-11-24 15:21:29 -05:00
|
|
|
#define MGMT_FRAME_PROTECTION_DEFAULT 3
|
2009-03-26 10:06:15 -04:00
|
|
|
|
2010-01-03 13:49:48 -05:00
|
|
|
/**
|
|
|
|
* enum hostapd_hw_mode - Hardware mode
|
|
|
|
*/
|
2009-12-26 03:35:08 -05:00
|
|
|
enum hostapd_hw_mode {
|
2009-04-03 12:04:20 -04:00
|
|
|
HOSTAPD_MODE_IEEE80211B,
|
|
|
|
HOSTAPD_MODE_IEEE80211G,
|
|
|
|
HOSTAPD_MODE_IEEE80211A,
|
2012-12-18 04:50:35 -05:00
|
|
|
HOSTAPD_MODE_IEEE80211AD,
|
2015-05-08 13:53:08 -04:00
|
|
|
HOSTAPD_MODE_IEEE80211ANY,
|
2009-04-03 12:04:20 -04:00
|
|
|
NUM_HOSTAPD_MODES
|
2009-12-26 03:35:08 -05:00
|
|
|
};
|
2009-04-03 12:04:20 -04:00
|
|
|
|
2011-10-24 12:00:19 -04:00
|
|
|
/**
|
|
|
|
* enum wpa_ctrl_req_type - Control interface request types
|
|
|
|
*/
|
|
|
|
enum wpa_ctrl_req_type {
|
2011-10-24 12:04:40 -04:00
|
|
|
WPA_CTRL_REQ_UNKNOWN,
|
2011-10-24 12:00:19 -04:00
|
|
|
WPA_CTRL_REQ_EAP_IDENTITY,
|
|
|
|
WPA_CTRL_REQ_EAP_PASSWORD,
|
|
|
|
WPA_CTRL_REQ_EAP_NEW_PASSWORD,
|
|
|
|
WPA_CTRL_REQ_EAP_PIN,
|
|
|
|
WPA_CTRL_REQ_EAP_OTP,
|
|
|
|
WPA_CTRL_REQ_EAP_PASSPHRASE,
|
2013-10-19 10:32:05 -04:00
|
|
|
WPA_CTRL_REQ_SIM,
|
2015-03-28 05:05:13 -04:00
|
|
|
WPA_CTRL_REQ_PSK_PASSPHRASE,
|
EAP peer: External server certificate chain validation
This adds support for optional functionality to validate server
certificate chain in TLS-based EAP methods in an external program.
wpa_supplicant control interface is used to indicate when such
validation is needed and what the result of the external validation is.
This external validation can extend or replace the internal validation.
When ca_cert or ca_path parameter is set, the internal validation is
used. If these parameters are omitted, only the external validation is
used. It needs to be understood that leaving those parameters out will
disable most of the validation steps done with the TLS library and that
configuration is not really recommend.
By default, the external validation is not used. It can be enabled by
addingtls_ext_cert_check=1 into the network profile phase1 parameter.
When enabled, external validation is required through the CTRL-REQ/RSP
mechanism similarly to other EAP authentication parameters through the
control interface.
The request to perform external validation is indicated by the following
event:
CTRL-REQ-EXT_CERT_CHECK-<id>:External server certificate validation needed for SSID <ssid>
Before that event, the server certificate chain is provided with the
CTRL-EVENT-EAP-PEER-CERT events that include the cert=<hexdump>
parameter. depth=# indicates which certificate is in question (0 for the
server certificate, 1 for its issues, and so on).
The result of the external validation is provided with the following
command:
CTRL-RSP-EXT_CERT_CHECK-<id>:<good|bad>
It should be noted that this is currently enabled only for OpenSSL (and
BoringSSL/LibreSSL). Due to the constraints in the library API, the
validation result from external processing cannot be reported cleanly
with TLS alert. In other words, if the external validation reject the
server certificate chain, the pending TLS handshake is terminated
without sending more messages to the server.
Signed-off-by: Jouni Malinen <j@w1.fi>
2015-12-12 11:16:54 -05:00
|
|
|
WPA_CTRL_REQ_EXT_CERT_CHECK,
|
2011-10-24 12:00:19 -04:00
|
|
|
NUM_WPA_CTRL_REQS
|
|
|
|
};
|
|
|
|
|
2011-11-17 13:06:33 -05:00
|
|
|
/* Maximum number of EAP methods to store for EAP server user information */
|
|
|
|
#define EAP_MAX_METHODS 8
|
|
|
|
|
2014-09-01 00:23:23 -04:00
|
|
|
enum mesh_plink_state {
|
2016-06-28 15:53:05 -04:00
|
|
|
PLINK_IDLE = 1,
|
|
|
|
PLINK_OPN_SNT,
|
|
|
|
PLINK_OPN_RCVD,
|
2014-09-01 00:23:23 -04:00
|
|
|
PLINK_CNF_RCVD,
|
|
|
|
PLINK_ESTAB,
|
|
|
|
PLINK_HOLDING,
|
2016-06-28 15:53:05 -04:00
|
|
|
PLINK_BLOCKED, /* not defined in the IEEE 802.11 standard */
|
2014-09-01 00:23:23 -04:00
|
|
|
};
|
|
|
|
|
2015-07-27 06:14:22 -04:00
|
|
|
enum set_band {
|
|
|
|
WPA_SETBAND_AUTO,
|
|
|
|
WPA_SETBAND_5G,
|
|
|
|
WPA_SETBAND_2G
|
|
|
|
};
|
|
|
|
|
2016-02-20 06:46:10 -05:00
|
|
|
enum wpa_radio_work_band {
|
|
|
|
BAND_2_4_GHZ = BIT(0),
|
|
|
|
BAND_5_GHZ = BIT(1),
|
|
|
|
BAND_60_GHZ = BIT(2),
|
|
|
|
};
|
|
|
|
|
2016-11-22 04:10:35 -05:00
|
|
|
enum beacon_rate_type {
|
|
|
|
BEACON_RATE_LEGACY,
|
|
|
|
BEACON_RATE_HT,
|
|
|
|
BEACON_RATE_VHT
|
|
|
|
};
|
|
|
|
|
2008-02-27 20:34:43 -05:00
|
|
|
#endif /* DEFS_H */
|