mirror of
https://github.com/vanhoefm/fragattacks.git
synced 2024-11-25 08:48:31 -05:00
mka: Some bug fixes for MACsec in PSK mode
Issue: ------ The test setup has 2 peers running MACsec in PSK mode, Peer A with MAC address higher than MAC Address of peer B. Test sequence is 1. Peer B starts with actor_priority 255 2. Peer A starts with priority 16, becomes key server. 3. Peer A stops.. 4. Peer A restarts with priority 255, but because of the stale values participant->is_key_server(=TRUE) and participant->is_elected(=TRUE) it continues to remain as Key Server. 5. For peer B, key server election happens and since it has lower MAC address as compared to MAC address of A, it becomes the key server. Now we have 2 key servers in CA and is not correct. Root-cause & fix: ----------------- When number of live peers become 0, the flags such lrx, ltx, orx, otx, etc. need to be cleared. In MACsec PSK mode, these stale values create problems while re-establishing CA. Signed-off-by: Badrish Adiga H R <badrish.adigahr@gmail.com>
This commit is contained in:
parent
7faf403f9f
commit
e54691106b
@ -2378,6 +2378,12 @@ static void ieee802_1x_participant_timer(void *eloop_ctx, void *timeout_ctx)
|
||||
participant->advised_capability =
|
||||
MACSEC_CAP_NOT_IMPLEMENTED;
|
||||
participant->to_use_sak = FALSE;
|
||||
participant->ltx = FALSE;
|
||||
participant->lrx = FALSE;
|
||||
participant->otx = FALSE;
|
||||
participant->orx = FALSE;
|
||||
participant->is_key_server = FALSE;
|
||||
participant->is_elected = FALSE;
|
||||
kay->authenticated = TRUE;
|
||||
kay->secured = FALSE;
|
||||
kay->failed = FALSE;
|
||||
|
Loading…
Reference in New Issue
Block a user