Jouni Malinen 07fe134d9c EAP-SIM peer: Do not accept SIM/Challenge without SIM/Start
EAP-SIM full authentication starts with one or more SIM/Start rounds, so
reject an unexpected SIM/Challenge round without any preceeding
SIM/Start rounds to avoid unexpected behavior. In practice, an attempt
to start with SIM/Challenge would have resulted in different MK being
derived and the Challenge message getting rejected due to mismatching
AT_MAC unless the misbehaving server has access to valid Kc, so the end
result is identical, but it is cleaner to reject the unexpected message
explicitly to avoid any risk of trying to proceed without NONCE_MT.

Signed-off-by: Jouni Malinen <j@w1.fi>
2019-12-23 23:59:16 +02:00
..
2017-03-07 13:19:10 +02:00
2017-03-07 13:19:10 +02:00
2017-03-07 13:19:10 +02:00
2017-03-07 13:19:10 +02:00
2017-03-07 13:19:10 +02:00
2017-03-07 13:19:10 +02:00
2015-04-22 11:44:19 +03:00