18d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/* 28d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * WPA Supplicant / PC/SC smartcard interface for USIM, GSM SIM 304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt * Copyright (c) 2004-2007, 2012, Jouni Malinen <j@w1.fi> 48d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * 5c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * This software may be distributed under the terms of the BSD license. 6c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * See README for more details. 78d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * 88d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * This file implements wrapper functions for accessing GSM SIM and 3GPP USIM 98d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * cards through PC/SC smartcard library. These functions are used to implement 108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * authentication routines for EAP-SIM and EAP-AKA. 118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */ 128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "includes.h" 148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include <winscard.h> 158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "common.h" 178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "pcsc_funcs.h" 188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/* See ETSI GSM 11.11 and ETSI TS 102 221 for details. 218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * SIM commands: 228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Command APDU: CLA INS P1 P2 P3 Data 238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * CLA (class of instruction): A0 for GSM, 00 for USIM 248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * INS (instruction) 258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * P1 P2 P3 (parameters, P3 = length of Data) 268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Response APDU: Data SW1 SW2 278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * SW1 SW2 (Status words) 288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Commands (INS P1 P2 P3): 298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * SELECT: A4 00 00 02 <file_id, 2 bytes> 308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * GET RESPONSE: C0 00 00 <len> 318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * RUN GSM ALG: 88 00 00 00 <RAND len = 10> 328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * RUN UMTS ALG: 88 00 81 <len=0x22> data: 0x10 | RAND | 0x10 | AUTN 338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * P1 = ID of alg in card 348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * P2 = ID of secret key 358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * READ BINARY: B0 <offset high> <offset low> <len> 368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * READ RECORD: B2 <record number> <mode> <len> 378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * P2 (mode) = '02' (next record), '03' (previous record), 388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * '04' (absolute mode) 398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * VERIFY CHV: 20 00 <CHV number> 08 408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * CHANGE CHV: 24 00 <CHV number> 10 418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * DISABLE CHV: 26 00 01 08 428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * ENABLE CHV: 28 00 01 08 438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * UNBLOCK CHV: 2C 00 <00=CHV1, 02=CHV2> 10 448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * SLEEP: FA 00 00 00 458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */ 468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/* GSM SIM commands */ 488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SIM_CMD_SELECT 0xa0, 0xa4, 0x00, 0x00, 0x02 498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SIM_CMD_RUN_GSM_ALG 0xa0, 0x88, 0x00, 0x00, 0x10 508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SIM_CMD_GET_RESPONSE 0xa0, 0xc0, 0x00, 0x00 518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SIM_CMD_READ_BIN 0xa0, 0xb0, 0x00, 0x00 528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SIM_CMD_READ_RECORD 0xa0, 0xb2, 0x00, 0x00 538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SIM_CMD_VERIFY_CHV1 0xa0, 0x20, 0x00, 0x01, 0x08 548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/* USIM commands */ 568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define USIM_CLA 0x00 578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define USIM_CMD_RUN_UMTS_ALG 0x00, 0x88, 0x00, 0x81, 0x22 588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define USIM_CMD_GET_RESPONSE 0x00, 0xc0, 0x00, 0x00 598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SIM_RECORD_MODE_ABSOLUTE 0x04 618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define USIM_FSP_TEMPL_TAG 0x62 638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define USIM_TLV_FILE_DESC 0x82 658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define USIM_TLV_FILE_ID 0x83 668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define USIM_TLV_DF_NAME 0x84 678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define USIM_TLV_PROPR_INFO 0xA5 688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define USIM_TLV_LIFE_CYCLE_STATUS 0x8A 698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define USIM_TLV_FILE_SIZE 0x80 708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define USIM_TLV_TOTAL_FILE_SIZE 0x81 718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define USIM_TLV_PIN_STATUS_TEMPLATE 0xC6 728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define USIM_TLV_SHORT_FILE_ID 0x88 7304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#define USIM_TLV_SECURITY_ATTR_8B 0x8B 7404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#define USIM_TLV_SECURITY_ATTR_8C 0x8C 7504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#define USIM_TLV_SECURITY_ATTR_AB 0xAB 768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define USIM_PS_DO_TAG 0x90 788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define AKA_RAND_LEN 16 808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define AKA_AUTN_LEN 16 818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define AKA_AUTS_LEN 14 828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define RES_MAX_LEN 16 838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define IK_LEN 16 848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define CK_LEN 16 858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 8704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt/* GSM files 8804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt * File type in first octet: 8904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt * 3F = Master File 9004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt * 7F = Dedicated File 9104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt * 2F = Elementary File under the Master File 9204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt * 6F = Elementary File under a Dedicated File 9304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt */ 9404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#define SCARD_FILE_MF 0x3F00 9504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#define SCARD_FILE_GSM_DF 0x7F20 9604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#define SCARD_FILE_UMTS_DF 0x7F50 9704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#define SCARD_FILE_GSM_EF_IMSI 0x6F07 9804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#define SCARD_FILE_GSM_EF_AD 0x6FAD 9904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#define SCARD_FILE_EF_DIR 0x2F00 10004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#define SCARD_FILE_EF_ICCID 0x2FE2 10104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#define SCARD_FILE_EF_CK 0x6FE1 10204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#define SCARD_FILE_EF_IK 0x6FE2 10304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 10404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#define SCARD_CHV1_OFFSET 13 10504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#define SCARD_CHV1_FLAG 0x80 10604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 10704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 1088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidttypedef enum { SCARD_GSM_SIM, SCARD_USIM } sim_types; 1098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct scard_data { 1118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt SCARDCONTEXT ctx; 1128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt SCARDHANDLE card; 1138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt DWORD protocol; 1148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt sim_types sim_type; 1158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int pin1_required; 1168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}; 1178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#ifdef __MINGW32_VERSION 1198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/* MinGW does not yet support WinScard, so load the needed functions 1208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * dynamically from winscard.dll for now. */ 1218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic HINSTANCE dll = NULL; /* winscard.dll */ 1238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic const SCARD_IO_REQUEST *dll_g_rgSCardT0Pci, *dll_g_rgSCardT1Pci; 1258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#undef SCARD_PCI_T0 1268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SCARD_PCI_T0 (dll_g_rgSCardT0Pci) 1278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#undef SCARD_PCI_T1 1288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SCARD_PCI_T1 (dll_g_rgSCardT1Pci) 1298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic WINSCARDAPI LONG WINAPI 1328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt(*dll_SCardEstablishContext)(IN DWORD dwScope, 1338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt IN LPCVOID pvReserved1, 1348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt IN LPCVOID pvReserved2, 1358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt OUT LPSCARDCONTEXT phContext); 1368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SCardEstablishContext dll_SCardEstablishContext 1378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic long (*dll_SCardReleaseContext)(long hContext); 1398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SCardReleaseContext dll_SCardReleaseContext 1408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic WINSCARDAPI LONG WINAPI 1428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt(*dll_SCardListReadersA)(IN SCARDCONTEXT hContext, 1438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt IN LPCSTR mszGroups, 1448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt OUT LPSTR mszReaders, 1458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt IN OUT LPDWORD pcchReaders); 1468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#undef SCardListReaders 1478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SCardListReaders dll_SCardListReadersA 1488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic WINSCARDAPI LONG WINAPI 1508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt(*dll_SCardConnectA)(IN SCARDCONTEXT hContext, 1518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt IN LPCSTR szReader, 1528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt IN DWORD dwShareMode, 1538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt IN DWORD dwPreferredProtocols, 1548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt OUT LPSCARDHANDLE phCard, 1558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt OUT LPDWORD pdwActiveProtocol); 1568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#undef SCardConnect 1578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SCardConnect dll_SCardConnectA 1588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic WINSCARDAPI LONG WINAPI 1608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt(*dll_SCardDisconnect)(IN SCARDHANDLE hCard, 1618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt IN DWORD dwDisposition); 1628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SCardDisconnect dll_SCardDisconnect 1638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic WINSCARDAPI LONG WINAPI 1658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt(*dll_SCardTransmit)(IN SCARDHANDLE hCard, 1668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt IN LPCSCARD_IO_REQUEST pioSendPci, 1678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt IN LPCBYTE pbSendBuffer, 1688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt IN DWORD cbSendLength, 1698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt IN OUT LPSCARD_IO_REQUEST pioRecvPci, 1708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt OUT LPBYTE pbRecvBuffer, 1718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt IN OUT LPDWORD pcbRecvLength); 1728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SCardTransmit dll_SCardTransmit 1738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic WINSCARDAPI LONG WINAPI 1758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt(*dll_SCardBeginTransaction)(IN SCARDHANDLE hCard); 1768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SCardBeginTransaction dll_SCardBeginTransaction 1778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic WINSCARDAPI LONG WINAPI 1798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt(*dll_SCardEndTransaction)(IN SCARDHANDLE hCard, IN DWORD dwDisposition); 1808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define SCardEndTransaction dll_SCardEndTransaction 1818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int mingw_load_symbols(void) 1848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 1858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt char *sym; 1868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (dll) 1888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 1898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt dll = LoadLibrary("winscard"); 1918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (dll == NULL) { 1928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "WinSCard: Could not load winscard.dll " 1938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "library"); 1948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 1958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 1968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define LOADSYM(s) \ 1988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt sym = #s; \ 1998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt dll_ ## s = (void *) GetProcAddress(dll, sym); \ 2008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (dll_ ## s == NULL) \ 2018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt goto fail; 2028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt LOADSYM(SCardEstablishContext); 2048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt LOADSYM(SCardReleaseContext); 2058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt LOADSYM(SCardListReadersA); 2068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt LOADSYM(SCardConnectA); 2078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt LOADSYM(SCardDisconnect); 2088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt LOADSYM(SCardTransmit); 2098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt LOADSYM(SCardBeginTransaction); 2108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt LOADSYM(SCardEndTransaction); 2118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt LOADSYM(g_rgSCardT0Pci); 2128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt LOADSYM(g_rgSCardT1Pci); 2138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#undef LOADSYM 2158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 2178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtfail: 2198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "WinSCard: Could not get address for %s from " 2208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "winscard.dll", sym); 2218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt FreeLibrary(dll); 2228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt dll = NULL; 2238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 2248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 2258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic void mingw_unload_symbols(void) 2288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 2298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (dll == NULL) 2308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return; 2318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt FreeLibrary(dll); 2338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt dll = NULL; 2348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 2358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#else /* __MINGW32_VERSION */ 2378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define mingw_load_symbols() 0 2398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define mingw_unload_symbols() do { } while (0) 2408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#endif /* __MINGW32_VERSION */ 2428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int _scard_select_file(struct scard_data *scard, unsigned short file_id, 2458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char *buf, size_t *buf_len, 2468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt sim_types sim_type, unsigned char *aid, 2478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t aidlen); 2488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int scard_select_file(struct scard_data *scard, unsigned short file_id, 2498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char *buf, size_t *buf_len); 2508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int scard_verify_pin(struct scard_data *scard, const char *pin); 2518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int scard_get_record_len(struct scard_data *scard, 2528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char recnum, unsigned char mode); 2538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int scard_read_record(struct scard_data *scard, 2548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char *data, size_t len, 2558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char recnum, unsigned char mode); 2568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int scard_parse_fsp_templ(unsigned char *buf, size_t buf_len, 2598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int *ps_do, int *file_len) 2608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 26104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt unsigned char *pos, *end; 26204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 26304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if (ps_do) 26404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt *ps_do = -1; 26504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if (file_len) 26604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt *file_len = -1; 26704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 26804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt pos = buf; 26904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt end = pos + buf_len; 27004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if (*pos != USIM_FSP_TEMPL_TAG) { 27104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: file header did not " 27204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt "start with FSP template tag"); 27304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt return -1; 27404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt } 27504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt pos++; 27604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if (pos >= end) 27704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt return -1; 27804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if ((pos + pos[0]) < end) 27904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt end = pos + 1 + pos[0]; 28004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt pos++; 28104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: file header FSP template", 28204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt pos, end - pos); 28304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 28404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt while (pos + 1 < end) { 28504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_printf(MSG_MSGDUMP, "SCARD: file header TLV 0x%02x len=%d", 28604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt pos[0], pos[1]); 28704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if (pos + 2 + pos[1] > end) 28804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt break; 2898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 29004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt switch (pos[0]) { 29104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt case USIM_TLV_FILE_DESC: 29204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_hexdump(MSG_MSGDUMP, "SCARD: File Descriptor TLV", 29304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt pos + 2, pos[1]); 29404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt break; 29504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt case USIM_TLV_FILE_ID: 29604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_hexdump(MSG_MSGDUMP, "SCARD: File Identifier TLV", 29704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt pos + 2, pos[1]); 29804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt break; 29904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt case USIM_TLV_DF_NAME: 30004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_hexdump(MSG_MSGDUMP, "SCARD: DF name (AID) TLV", 30104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt pos + 2, pos[1]); 30204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt break; 30304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt case USIM_TLV_PROPR_INFO: 30404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_hexdump(MSG_MSGDUMP, "SCARD: Proprietary " 30504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt "information TLV", pos + 2, pos[1]); 30604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt break; 30704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt case USIM_TLV_LIFE_CYCLE_STATUS: 30804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_hexdump(MSG_MSGDUMP, "SCARD: Life Cycle Status " 30904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt "Integer TLV", pos + 2, pos[1]); 31004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt break; 31104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt case USIM_TLV_FILE_SIZE: 31204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_hexdump(MSG_MSGDUMP, "SCARD: File size TLV", 31304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt pos + 2, pos[1]); 31404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if ((pos[1] == 1 || pos[1] == 2) && file_len) { 3158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (pos[1] == 1) 3168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *file_len = (int) pos[2]; 3178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt else 3188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *file_len = ((int) pos[2] << 8) | 3198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (int) pos[3]; 3208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: file_size=%d", 3218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *file_len); 3228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 32304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt break; 32404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt case USIM_TLV_TOTAL_FILE_SIZE: 32504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_hexdump(MSG_MSGDUMP, "SCARD: Total file size TLV", 32604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt pos + 2, pos[1]); 32704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt break; 32804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt case USIM_TLV_PIN_STATUS_TEMPLATE: 32904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_hexdump(MSG_MSGDUMP, "SCARD: PIN Status Template " 33004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt "DO TLV", pos + 2, pos[1]); 33104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if (pos[1] >= 2 && pos[2] == USIM_PS_DO_TAG && 3328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt pos[3] >= 1 && ps_do) { 3338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: PS_DO=0x%02x", 3348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt pos[4]); 3358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *ps_do = (int) pos[4]; 3368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 33704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt break; 33804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt case USIM_TLV_SHORT_FILE_ID: 33904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_hexdump(MSG_MSGDUMP, "SCARD: Short File " 34004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt "Identifier (SFI) TLV", pos + 2, pos[1]); 34104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt break; 34204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt case USIM_TLV_SECURITY_ATTR_8B: 34304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt case USIM_TLV_SECURITY_ATTR_8C: 34404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt case USIM_TLV_SECURITY_ATTR_AB: 34504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_hexdump(MSG_MSGDUMP, "SCARD: Security attribute " 34604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt "TLV", pos + 2, pos[1]); 34704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt break; 34804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt default: 34904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_hexdump(MSG_MSGDUMP, "SCARD: Unrecognized TLV", 35004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt pos, 2 + pos[1]); 35104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt break; 35204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt } 3538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 35404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt pos += 2 + pos[1]; 3558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 35604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if (pos == end) 35704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt return 0; 35804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt } 35904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt return -1; 3608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 3618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int scard_pin_needed(struct scard_data *scard, 3648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char *hdr, size_t hlen) 3658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 3668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard->sim_type == SCARD_GSM_SIM) { 3678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (hlen > SCARD_CHV1_OFFSET && 3688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt !(hdr[SCARD_CHV1_OFFSET] & SCARD_CHV1_FLAG)) 3698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 1; 3708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 3718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 3728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard->sim_type == SCARD_USIM) { 3748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int ps_do; 3758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard_parse_fsp_templ(hdr, hlen, &ps_do, NULL)) 3768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 3778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* TODO: there could be more than one PS_DO entry because of 3788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * multiple PINs in key reference.. */ 3798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ps_do > 0 && (ps_do & 0x80)) 3808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 1; 3818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 3828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 3838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 3858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 3868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int scard_get_aid(struct scard_data *scard, unsigned char *aid, 3898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t maxlen) 3908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 3918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int rlen, rec; 3928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct efdir { 3938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char appl_template_tag; /* 0x61 */ 3948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char appl_template_len; 3958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char appl_id_tag; /* 0x4f */ 3968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char aid_len; 3978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char rid[5]; 3988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char appl_code[2]; /* 0x1002 for 3G USIM */ 3998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } *efdir; 40004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt unsigned char buf[127]; 4018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t blen; 4028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt efdir = (struct efdir *) buf; 4048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt blen = sizeof(buf); 4058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard_select_file(scard, SCARD_FILE_EF_DIR, buf, &blen)) { 4068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Failed to read EF_DIR"); 4078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 4088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: EF_DIR select", buf, blen); 4108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt for (rec = 1; rec < 10; rec++) { 4128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt rlen = scard_get_record_len(scard, rec, 4138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt SIM_RECORD_MODE_ABSOLUTE); 4148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (rlen < 0) { 4158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Failed to get EF_DIR " 4168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "record length"); 4178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 4188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt blen = sizeof(buf); 4208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (rlen > (int) blen) { 4218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Too long EF_DIR record"); 4228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 4238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard_read_record(scard, buf, rlen, rec, 4258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt SIM_RECORD_MODE_ABSOLUTE) < 0) { 4268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Failed to read " 4278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "EF_DIR record %d", rec); 4288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 4298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: EF_DIR record", buf, rlen); 4318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (efdir->appl_template_tag != 0x61) { 4338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Unexpected application " 4348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "template tag 0x%x", 4358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt efdir->appl_template_tag); 4368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt continue; 4378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (efdir->appl_template_len > rlen - 2) { 4408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Too long application " 4418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "template (len=%d rlen=%d)", 4428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt efdir->appl_template_len, rlen); 4438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt continue; 4448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (efdir->appl_id_tag != 0x4f) { 4478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Unexpected application " 4488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "identifier tag 0x%x", efdir->appl_id_tag); 4498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt continue; 4508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (efdir->aid_len < 1 || efdir->aid_len > 16) { 4538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Invalid AID length %d", 4548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt efdir->aid_len); 4558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt continue; 4568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: AID from EF_DIR record", 4598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt efdir->rid, efdir->aid_len); 4608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (efdir->appl_code[0] == 0x10 && 4628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt efdir->appl_code[1] == 0x02) { 4638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: 3G USIM app found from " 4648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "EF_DIR record %d", rec); 4658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt break; 4668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (rec >= 10) { 4708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: 3G USIM app not found " 4718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "from EF_DIR records"); 4728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 4738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (efdir->aid_len > maxlen) { 4768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Too long AID"); 4778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 4788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(aid, efdir->rid, efdir->aid_len); 4818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return efdir->aid_len; 4838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 4848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/** 4878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * scard_init - Initialize SIM/USIM connection using PC/SC 4888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @sim_type: Allowed SIM types (SIM, USIM, or both) 48904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt * @reader: Reader name prefix to search for 4908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: Pointer to private data structure, or %NULL on failure 4918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * 4928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * This function is used to initialize SIM/USIM connection. PC/SC is used to 4938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * open connection to the SIM/USIM card and the card is verified to support the 4948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * selected sim_type. In addition, local flag is set if a PIN is needed to 4958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * access some of the card functions. Once the connection is not needed 4968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * anymore, scard_deinit() can be used to close it. 4978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */ 49804949598a23f501be6eec21697465fd46a28840aDmitry Shmidtstruct scard_data * scard_init(scard_sim_type sim_type, const char *reader) 4998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 5008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt long ret; 50104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt unsigned long len, pos; 5028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct scard_data *scard; 5038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#ifdef CONFIG_NATIVE_WINDOWS 5048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt TCHAR *readers = NULL; 5058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#else /* CONFIG_NATIVE_WINDOWS */ 5068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt char *readers = NULL; 5078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#endif /* CONFIG_NATIVE_WINDOWS */ 5088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char buf[100]; 5098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t blen; 5108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int transaction = 0; 5118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int pin_needed; 5128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 5138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: initializing smart card interface"); 5148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (mingw_load_symbols()) 5158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 5168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt scard = os_zalloc(sizeof(*scard)); 5178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard == NULL) 5188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 5198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 5208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = SCardEstablishContext(SCARD_SCOPE_SYSTEM, NULL, NULL, 5218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt &scard->ctx); 5228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS) { 5238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Could not establish smart card " 5248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "context (err=%ld)", ret); 5258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt goto failed; 5268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 5278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 5288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = SCardListReaders(scard->ctx, NULL, NULL, &len); 5298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS) { 5308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: SCardListReaders failed " 5318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "(err=%ld)", ret); 5328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt goto failed; 5338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 5348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 5358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#ifdef UNICODE 5368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt len *= 2; 5378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#endif /* UNICODE */ 5388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt readers = os_malloc(len); 5398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (readers == NULL) { 5408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_INFO, "SCARD: malloc failed\n"); 5418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt goto failed; 5428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 5438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 5448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = SCardListReaders(scard->ctx, NULL, readers, &len); 5458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS) { 5468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: SCardListReaders failed(2) " 5478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "(err=%ld)", ret); 5488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt goto failed; 5498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 5508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (len < 3) { 5518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: No smart card readers " 5528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "available."); 5538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt goto failed; 5548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 55504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_hexdump_ascii(MSG_DEBUG, "SCARD: Readers", (u8 *) readers, len); 55604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt /* 55704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt * readers is a list of available readers. The last entry is terminated 55804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt * with double null. 55904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt */ 56004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt pos = 0; 56104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#ifdef UNICODE 56204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt /* TODO */ 56304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#else /* UNICODE */ 56404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt while (pos < len) { 56504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if (reader == NULL || 56604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt os_strncmp(&readers[pos], reader, os_strlen(reader)) == 0) 56704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt break; 56804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt while (pos < len && readers[pos]) 56904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt pos++; 57004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt pos++; /* skip separating null */ 57104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if (pos < len && readers[pos] == '\0') 57204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt pos = len; /* double null terminates list */ 57304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt } 57404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt#endif /* UNICODE */ 57504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if (pos >= len) { 57604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: No reader with prefix '%s' " 57704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt "found", reader); 57804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt goto failed; 57904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt } 58004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 5818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#ifdef UNICODE 58204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Selected reader='%S'", &readers[pos]); 5838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#else /* UNICODE */ 58404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Selected reader='%s'", &readers[pos]); 5858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#endif /* UNICODE */ 5868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 58704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt ret = SCardConnect(scard->ctx, &readers[pos], SCARD_SHARE_SHARED, 58804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt SCARD_PROTOCOL_T0 | SCARD_PROTOCOL_T1, 58904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt &scard->card, &scard->protocol); 5908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS) { 5918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret == (long) SCARD_E_NO_SMARTCARD) 5928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_INFO, "No smart card inserted."); 5938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt else 5948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_WARNING, "SCardConnect err=%lx", ret); 5958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt goto failed; 5968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 5978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 5988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_free(readers); 5998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt readers = NULL; 6008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 6018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: card=0x%x active_protocol=%lu (%s)", 6028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (unsigned int) scard->card, scard->protocol, 6038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt scard->protocol == SCARD_PROTOCOL_T0 ? "T0" : "T1"); 6048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 6058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = SCardBeginTransaction(scard->card); 6068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS) { 6078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Could not begin transaction: " 6088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "0x%x", (unsigned int) ret); 6098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt goto failed; 6108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 6118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt transaction = 1; 6128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 6138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt blen = sizeof(buf); 6148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 6158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt scard->sim_type = SCARD_GSM_SIM; 6168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (sim_type == SCARD_USIM_ONLY || sim_type == SCARD_TRY_BOTH) { 6178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: verifying USIM support"); 6188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (_scard_select_file(scard, SCARD_FILE_MF, buf, &blen, 6198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt SCARD_USIM, NULL, 0)) { 6208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: USIM is not supported"); 6218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (sim_type == SCARD_USIM_ONLY) 6228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt goto failed; 6238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Trying to use GSM SIM"); 6248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt scard->sim_type = SCARD_GSM_SIM; 6258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } else { 6268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: USIM is supported"); 6278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt scard->sim_type = SCARD_USIM; 6288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 6298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 6308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 6318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard->sim_type == SCARD_GSM_SIM) { 6328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt blen = sizeof(buf); 6338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard_select_file(scard, SCARD_FILE_MF, buf, &blen)) { 6348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Failed to read MF"); 6358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt goto failed; 6368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 6378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 6388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt blen = sizeof(buf); 6398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard_select_file(scard, SCARD_FILE_GSM_DF, buf, &blen)) { 6408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Failed to read GSM DF"); 6418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt goto failed; 6428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 6438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } else { 6448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char aid[32]; 6458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int aid_len; 6468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 6478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt aid_len = scard_get_aid(scard, aid, sizeof(aid)); 6488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (aid_len < 0) { 6498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Failed to find AID for " 6508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "3G USIM app - try to use standard 3G RID"); 6518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(aid, "\xa0\x00\x00\x00\x87", 5); 6528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt aid_len = 5; 6538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 6548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: 3G USIM AID", aid, aid_len); 6558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 6568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* Select based on AID = 3G RID from EF_DIR. This is usually 6578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * starting with A0 00 00 00 87. */ 6588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt blen = sizeof(buf); 6598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (_scard_select_file(scard, 0, buf, &blen, scard->sim_type, 6608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt aid, aid_len)) { 6618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_INFO, "SCARD: Failed to read 3G USIM " 6628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "app"); 6638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_INFO, "SCARD: 3G USIM AID", 6648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt aid, aid_len); 6658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt goto failed; 6668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 6678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 6688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 6698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* Verify whether CHV1 (PIN1) is needed to access the card. */ 6708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt pin_needed = scard_pin_needed(scard, buf, blen); 6718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (pin_needed < 0) { 6728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Failed to determine whether PIN " 6738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "is needed"); 6748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt goto failed; 6758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 6768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (pin_needed) { 6778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt scard->pin1_required = 1; 67804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_printf(MSG_DEBUG, "PIN1 needed for SIM access (retry " 67904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt "counter=%d)", scard_get_pin_retry_counter(scard)); 6808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 6818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 6828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = SCardEndTransaction(scard->card, SCARD_LEAVE_CARD); 6838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS) { 6848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Could not end transaction: " 6858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "0x%x", (unsigned int) ret); 6868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 6878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 6888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return scard; 6898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 6908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtfailed: 6918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (transaction) 6928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt SCardEndTransaction(scard->card, SCARD_LEAVE_CARD); 6938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_free(readers); 6948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt scard_deinit(scard); 6958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 6968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 6978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 6988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 6998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/** 7008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * scard_set_pin - Set PIN (CHV1/PIN1) code for accessing SIM/USIM commands 7018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @scard: Pointer to private data from scard_init() 7028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @pin: PIN code as an ASCII string (e.g., "1234") 7038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: 0 on success, -1 on failure 7048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */ 7058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtint scard_set_pin(struct scard_data *scard, const char *pin) 7068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 7078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard == NULL) 7088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 7098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 7108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* Verify whether CHV1 (PIN1) is needed to access the card. */ 7118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard->pin1_required) { 7128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (pin == NULL) { 7138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "No PIN configured for SIM " 7148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "access"); 7158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 7168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 7178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard_verify_pin(scard, pin)) { 7188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_INFO, "PIN verification failed for " 7198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "SIM access"); 7208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 7218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 7228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 7238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 7248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 7258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 7268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 7278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 7288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/** 7298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * scard_deinit - Deinitialize SIM/USIM connection 7308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @scard: Pointer to private data from scard_init() 7318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * 7328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * This function closes the SIM/USIM connect opened with scard_init(). 7338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */ 7348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtvoid scard_deinit(struct scard_data *scard) 7358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 7368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt long ret; 7378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 7388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard == NULL) 7398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return; 7408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 7418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: deinitializing smart card interface"); 7428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard->card) { 7438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = SCardDisconnect(scard->card, SCARD_UNPOWER_CARD); 7448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS) { 7458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Failed to disconnect " 7468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "smart card (err=%ld)", ret); 7478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 7488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 7498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 7508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard->ctx) { 7518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = SCardReleaseContext(scard->ctx); 7528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS) { 7538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "Failed to release smart card " 7548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "context (err=%ld)", ret); 7558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 7568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 7578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_free(scard); 7588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt mingw_unload_symbols(); 7598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 7608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 7618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 7628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic long scard_transmit(struct scard_data *scard, 7638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char *_send, size_t send_len, 7648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char *_recv, size_t *recv_len) 7658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 7668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt long ret; 7678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned long rlen; 7688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 7698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump_key(MSG_DEBUG, "SCARD: scard_transmit: send", 7708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt _send, send_len); 7718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt rlen = *recv_len; 7728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = SCardTransmit(scard->card, 7738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt scard->protocol == SCARD_PROTOCOL_T1 ? 7748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt SCARD_PCI_T1 : SCARD_PCI_T0, 7758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt _send, (unsigned long) send_len, 7768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt NULL, _recv, &rlen); 7778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *recv_len = rlen; 7788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret == SCARD_S_SUCCESS) { 7798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: scard_transmit: recv", 7808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt _recv, rlen); 7818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } else { 7828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: SCardTransmit failed " 7838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "(err=0x%lx)", ret); 7848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 7858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return ret; 7868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 7878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 7888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 7898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int _scard_select_file(struct scard_data *scard, unsigned short file_id, 7908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char *buf, size_t *buf_len, 7918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt sim_types sim_type, unsigned char *aid, 7928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t aidlen) 7938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 7948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt long ret; 7958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char resp[3]; 7968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char cmd[50] = { SIM_CMD_SELECT }; 7978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int cmdlen; 7988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char get_resp[5] = { SIM_CMD_GET_RESPONSE }; 7998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t len, rlen; 8008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 8018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (sim_type == SCARD_USIM) { 8028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[0] = USIM_CLA; 8038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[3] = 0x04; 8048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt get_resp[0] = USIM_CLA; 8058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 8068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 8078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: select file %04x", file_id); 8088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (aid) { 8098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: select file by AID", 8108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt aid, aidlen); 8118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (5 + aidlen > sizeof(cmd)) 8128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 8138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[2] = 0x04; /* Select by AID */ 8148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[4] = aidlen; /* len */ 8158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(cmd + 5, aid, aidlen); 8168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmdlen = 5 + aidlen; 8178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } else { 8188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[5] = file_id >> 8; 8198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[6] = file_id & 0xff; 8208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmdlen = 7; 8218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 8228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt len = sizeof(resp); 8238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = scard_transmit(scard, cmd, cmdlen, resp, &len); 8248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS) { 8258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: SCardTransmit failed " 8268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "(err=0x%lx)", ret); 8278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 8288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 8298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 8308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (len != 2) { 8318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: unexpected resp len " 8328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "%d (expected 2)", (int) len); 8338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 8348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 8358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 8368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (resp[0] == 0x98 && resp[1] == 0x04) { 8378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* Security status not satisfied (PIN_WLAN) */ 8388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: Security status not satisfied " 8398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "(PIN_WLAN)"); 8408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 8418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 8428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 8438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (resp[0] == 0x6e) { 8448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: used CLA not supported"); 8458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 8468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 8478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 8488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (resp[0] != 0x6c && resp[0] != 0x9f && resp[0] != 0x61) { 8498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: unexpected response 0x%02x " 8508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "(expected 0x61, 0x6c, or 0x9f)", resp[0]); 8518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 8528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 8538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* Normal ending of command; resp[1] bytes available */ 8548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt get_resp[4] = resp[1]; 8558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: trying to get response (%d bytes)", 8568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt resp[1]); 8578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 8588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt rlen = *buf_len; 8598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = scard_transmit(scard, get_resp, sizeof(get_resp), buf, &rlen); 8608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret == SCARD_S_SUCCESS) { 8618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *buf_len = resp[1] < rlen ? resp[1] : rlen; 8628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 8638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 8648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 8658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: SCardTransmit err=0x%lx\n", ret); 8668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 8678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 8688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 8698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 8708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int scard_select_file(struct scard_data *scard, unsigned short file_id, 8718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char *buf, size_t *buf_len) 8728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 8738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return _scard_select_file(scard, file_id, buf, buf_len, 8748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt scard->sim_type, NULL, 0); 8758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 8768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 8778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 8788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int scard_get_record_len(struct scard_data *scard, unsigned char recnum, 8798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char mode) 8808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 8818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char buf[255]; 8828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char cmd[5] = { SIM_CMD_READ_RECORD /* , len */ }; 8838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t blen; 8848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt long ret; 8858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 8868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard->sim_type == SCARD_USIM) 8878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[0] = USIM_CLA; 8888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[2] = recnum; 8898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[3] = mode; 8908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[4] = sizeof(buf); 8918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 8928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt blen = sizeof(buf); 8938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = scard_transmit(scard, cmd, sizeof(cmd), buf, &blen); 8948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS) { 8958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: failed to determine file " 8968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "length for record %d", recnum); 8978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 8988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 8998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: file length determination response", 9018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt buf, blen); 9028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9031f69aa52ea2e0a73ac502565df8c666ee49cab6aDmitry Shmidt if (blen < 2 || (buf[0] != 0x6c && buf[0] != 0x67)) { 9048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: unexpected response to file " 9058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "length determination"); 9068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 9078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 9088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return buf[1]; 9108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 9118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int scard_read_record(struct scard_data *scard, 9148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char *data, size_t len, 9158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char recnum, unsigned char mode) 9168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 9178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char cmd[5] = { SIM_CMD_READ_RECORD /* , len */ }; 9188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t blen = len + 3; 9198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char *buf; 9208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt long ret; 9218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard->sim_type == SCARD_USIM) 9238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[0] = USIM_CLA; 9248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[2] = recnum; 9258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[3] = mode; 9268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[4] = len; 9278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt buf = os_malloc(blen); 9298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (buf == NULL) 9308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 9318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = scard_transmit(scard, cmd, sizeof(cmd), buf, &blen); 9338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS) { 9348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_free(buf); 9358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -2; 9368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 9378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (blen != len + 2) { 9388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: record read returned unexpected " 9398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "length %ld (expected %ld)", 9408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (long) blen, (long) len + 2); 9418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_free(buf); 9428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -3; 9438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 9448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (buf[len] != 0x90 || buf[len + 1] != 0x00) { 9468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: record read returned unexpected " 9478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "status %02x %02x (expected 90 00)", 9488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt buf[len], buf[len + 1]); 9498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_free(buf); 9508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -4; 9518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 9528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(data, buf, len); 9548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_free(buf); 9558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 9578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 9588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int scard_read_file(struct scard_data *scard, 9618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char *data, size_t len) 9628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 9638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char cmd[5] = { SIM_CMD_READ_BIN /* , len */ }; 9648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t blen = len + 3; 9658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char *buf; 9668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt long ret; 9678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[4] = len; 9698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt buf = os_malloc(blen); 9718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (buf == NULL) 9728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 9738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard->sim_type == SCARD_USIM) 9758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[0] = USIM_CLA; 9768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = scard_transmit(scard, cmd, sizeof(cmd), buf, &blen); 9778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS) { 9788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_free(buf); 9798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -2; 9808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 9818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (blen != len + 2) { 9828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: file read returned unexpected " 9838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "length %ld (expected %ld)", 9848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (long) blen, (long) len + 2); 9858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_free(buf); 9868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -3; 9878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 9888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (buf[len] != 0x90 || buf[len + 1] != 0x00) { 9908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: file read returned unexpected " 9918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "status %02x %02x (expected 90 00)", 9928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt buf[len], buf[len + 1]); 9938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_free(buf); 9948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -4; 9958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 9968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 9978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(data, buf, len); 9988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_free(buf); 9998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 10008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 10018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 10028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 10038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 10048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int scard_verify_pin(struct scard_data *scard, const char *pin) 10058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 10068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt long ret; 10078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char resp[3]; 10088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char cmd[5 + 8] = { SIM_CMD_VERIFY_CHV1 }; 10098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t len; 10108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 10118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: verifying PIN"); 10128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 10138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (pin == NULL || os_strlen(pin) > 8) 10148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 10158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 10168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard->sim_type == SCARD_USIM) 10178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[0] = USIM_CLA; 10188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(cmd + 5, pin, os_strlen(pin)); 10198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memset(cmd + 5 + os_strlen(pin), 0xff, 8 - os_strlen(pin)); 10208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 10218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt len = sizeof(resp); 10228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = scard_transmit(scard, cmd, sizeof(cmd), resp, &len); 10238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS) 10248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -2; 10258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 10268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (len != 2 || resp[0] != 0x90 || resp[1] != 0x00) { 10278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: PIN verification failed"); 10288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 10298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 10308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 10318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: PIN verified successfully"); 10328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 10338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 10348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 10358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 103604949598a23f501be6eec21697465fd46a28840aDmitry Shmidtint scard_get_pin_retry_counter(struct scard_data *scard) 103704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt{ 103804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt long ret; 103904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt unsigned char resp[3]; 104004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt unsigned char cmd[5] = { SIM_CMD_VERIFY_CHV1 }; 104104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt size_t len; 104204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt u16 val; 104304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 104404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: fetching PIN retry counter"); 104504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 104604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if (scard->sim_type == SCARD_USIM) 104704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt cmd[0] = USIM_CLA; 104804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt cmd[4] = 0; /* Empty data */ 104904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 105004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt len = sizeof(resp); 105104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt ret = scard_transmit(scard, cmd, sizeof(cmd), resp, &len); 105204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if (ret != SCARD_S_SUCCESS) 105304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt return -2; 105404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 105504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if (len != 2) { 105604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: failed to fetch PIN retry " 105704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt "counter"); 105804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt return -1; 105904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt } 106004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 106104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt val = WPA_GET_BE16(resp); 106204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if (val == 0x63c0 || val == 0x6983) { 106304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: PIN has been blocked"); 106404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt return 0; 106504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt } 106604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 106704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt if (val >= 0x63c0 && val <= 0x63cf) 106804949598a23f501be6eec21697465fd46a28840aDmitry Shmidt return val & 0x000f; 106904949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 107004949598a23f501be6eec21697465fd46a28840aDmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Unexpected PIN retry counter response " 107104949598a23f501be6eec21697465fd46a28840aDmitry Shmidt "value 0x%x", val); 107204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt return 0; 107304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt} 107404949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 107504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 10768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/** 10778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * scard_get_imsi - Read IMSI from SIM/USIM card 10788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @scard: Pointer to private data from scard_init() 10798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @imsi: Buffer for IMSI 10808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @len: Length of imsi buffer; set to IMSI length on success 10818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: 0 on success, -1 if IMSI file cannot be selected, -2 if IMSI file 10828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * selection returns invalid result code, -3 if parsing FSP template file fails 10838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * (USIM only), -4 if IMSI does not fit in the provided imsi buffer (len is set 10848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * to needed length), -5 if reading IMSI file fails. 10858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * 10868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * This function can be used to read IMSI from the SIM/USIM card. If the IMSI 10878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * file is PIN protected, scard_set_pin() must have been used to set the 10888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * correct PIN code before calling scard_get_imsi(). 10898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */ 10908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtint scard_get_imsi(struct scard_data *scard, char *imsi, size_t *len) 10918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 10928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char buf[100]; 10938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t blen, imsilen, i; 10948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt char *pos; 10958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 10968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: reading IMSI from (GSM) EF-IMSI"); 10978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt blen = sizeof(buf); 10988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard_select_file(scard, SCARD_FILE_GSM_EF_IMSI, buf, &blen)) 10998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 11008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (blen < 4) { 11018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: too short (GSM) EF-IMSI " 11028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "header (len=%ld)", (long) blen); 11038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -2; 11048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 11058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 11068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard->sim_type == SCARD_GSM_SIM) { 11078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt blen = (buf[2] << 8) | buf[3]; 11088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } else { 11098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int file_size; 11108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard_parse_fsp_templ(buf, blen, NULL, &file_size)) 11118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -3; 11128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt blen = file_size; 11138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 11148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (blen < 2 || blen > sizeof(buf)) { 11158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: invalid IMSI file length=%ld", 11168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (long) blen); 11178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -3; 11188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 11198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 11208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt imsilen = (blen - 2) * 2 + 1; 11218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: IMSI file length=%ld imsilen=%ld", 11228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (long) blen, (long) imsilen); 11238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (blen < 2 || imsilen > *len) { 11248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *len = imsilen; 11258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -4; 11268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 11278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 11288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard_read_file(scard, buf, blen)) 11298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -5; 11308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 11318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt pos = imsi; 11328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *pos++ = '0' + (buf[1] >> 4 & 0x0f); 11338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt for (i = 2; i < blen; i++) { 11348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char digit; 11358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 11368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt digit = buf[i] & 0x0f; 11378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (digit < 10) 11388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *pos++ = '0' + digit; 11398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt else 11408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt imsilen--; 11418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 11428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt digit = buf[i] >> 4 & 0x0f; 11438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (digit < 10) 11448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *pos++ = '0' + digit; 11458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt else 11468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt imsilen--; 11478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 11488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *len = imsilen; 11498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 11508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 11518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 11528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 11538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 11548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/** 1155c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * scard_get_mnc_len - Read length of MNC in the IMSI from SIM/USIM card 1156c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * @scard: Pointer to private data from scard_init() 1157c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * Returns: length (>0) on success, -1 if administrative data file cannot be 1158c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * selected, -2 if administrative data file selection returns invalid result 1159c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * code, -3 if parsing FSP template file fails (USIM only), -4 if length of 1160c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * the file is unexpected, -5 if reading file fails, -6 if MNC length is not 1161c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * in range (i.e. 2 or 3), -7 if MNC length is not available. 1162c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * 1163c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt */ 1164c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidtint scard_get_mnc_len(struct scard_data *scard) 1165c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt{ 1166c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt unsigned char buf[100]; 1167c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt size_t blen; 1168c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt int file_size; 1169c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt 1170c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: reading MNC len from (GSM) EF-AD"); 1171c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt blen = sizeof(buf); 1172c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt if (scard_select_file(scard, SCARD_FILE_GSM_EF_AD, buf, &blen)) 1173c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt return -1; 1174c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt if (blen < 4) { 1175c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: too short (GSM) EF-AD " 1176c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt "header (len=%ld)", (long) blen); 1177c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt return -2; 1178c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt } 1179c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt 1180c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt if (scard->sim_type == SCARD_GSM_SIM) { 1181c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt file_size = (buf[2] << 8) | buf[3]; 1182c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt } else { 1183c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt if (scard_parse_fsp_templ(buf, blen, NULL, &file_size)) 1184c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt return -3; 1185c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt } 1186c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt if (file_size == 3) { 1187c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: MNC length not available"); 1188c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt return -7; 1189c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt } 1190c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt if (file_size < 4 || file_size > (int) sizeof(buf)) { 1191c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: invalid file length=%ld", 1192c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt (long) file_size); 1193c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt return -4; 1194c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt } 1195c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt 1196c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt if (scard_read_file(scard, buf, file_size)) 1197c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt return -5; 1198c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt buf[3] = buf[3] & 0x0f; /* upper nibble reserved for future use */ 1199c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt if (buf[3] < 2 || buf[3] > 3) { 1200c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: invalid MNC length=%ld", 1201c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt (long) buf[3]); 1202c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt return -6; 1203c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt } 1204c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: MNC length=%ld", (long) buf[3]); 1205c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt return buf[3]; 1206c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt} 1207c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt 1208c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt 1209c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt/** 12108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * scard_gsm_auth - Run GSM authentication command on SIM card 12118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @scard: Pointer to private data from scard_init() 12128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @_rand: 16-byte RAND value from HLR/AuC 12138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @sres: 4-byte buffer for SRES 12148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @kc: 8-byte buffer for Kc 12158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: 0 on success, -1 if SIM/USIM connection has not been initialized, 12168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * -2 if authentication command execution fails, -3 if unknown response code 12178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * for authentication command is received, -4 if reading of response fails, 12188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * -5 if if response data is of unexpected length 12198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * 12208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * This function performs GSM authentication using SIM/USIM card and the 12218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * provided RAND value from HLR/AuC. If authentication command can be completed 12228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * successfully, SRES and Kc values will be written into sres and kc buffers. 12238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */ 12248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtint scard_gsm_auth(struct scard_data *scard, const unsigned char *_rand, 12258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char *sres, unsigned char *kc) 12268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 12278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char cmd[5 + 1 + 16] = { SIM_CMD_RUN_GSM_ALG }; 12288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int cmdlen; 12298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char get_resp[5] = { SIM_CMD_GET_RESPONSE }; 12308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char resp[3], buf[12 + 3 + 2]; 12318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t len; 12328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt long ret; 12338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 12348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard == NULL) 12358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 12368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 12378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: GSM auth - RAND", _rand, 16); 12388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard->sim_type == SCARD_GSM_SIM) { 12398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmdlen = 5 + 16; 12408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(cmd + 5, _rand, 16); 12418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } else { 12428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmdlen = 5 + 1 + 16; 12438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[0] = USIM_CLA; 12448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[3] = 0x80; 12458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[4] = 17; 12468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[5] = 16; 12478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(cmd + 6, _rand, 16); 12488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 12498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt len = sizeof(resp); 12508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = scard_transmit(scard, cmd, cmdlen, resp, &len); 12518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS) 12528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -2; 12538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 12548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if ((scard->sim_type == SCARD_GSM_SIM && 12558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (len != 2 || resp[0] != 0x9f || resp[1] != 0x0c)) || 12568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (scard->sim_type == SCARD_USIM && 12578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (len != 2 || resp[0] != 0x61 || resp[1] != 0x0e))) { 12588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: unexpected response for GSM " 12598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "auth request (len=%ld resp=%02x %02x)", 12608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (long) len, resp[0], resp[1]); 12618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -3; 12628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 12638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt get_resp[4] = resp[1]; 12648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 12658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt len = sizeof(buf); 12668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = scard_transmit(scard, get_resp, sizeof(get_resp), buf, &len); 12678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS) 12688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -4; 12698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 12708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard->sim_type == SCARD_GSM_SIM) { 12718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (len != 4 + 8 + 2) { 12728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: unexpected data " 12738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "length for GSM auth (len=%ld, expected 14)", 12748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (long) len); 12758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -5; 12768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 12778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(sres, buf, 4); 12788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(kc, buf + 4, 8); 12798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } else { 12808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (len != 1 + 4 + 1 + 8 + 2) { 12818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: unexpected data " 12828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "length for USIM auth (len=%ld, " 12838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "expected 16)", (long) len); 12848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -5; 12858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 12868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (buf[0] != 4 || buf[5] != 8) { 12878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: unexpected SREC/Kc " 12888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "length (%d %d, expected 4 8)", 12898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt buf[0], buf[5]); 12908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 12918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(sres, buf + 1, 4); 12928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(kc, buf + 6, 8); 12938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 12948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 12958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: GSM auth - SRES", sres, 4); 12968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: GSM auth - Kc", kc, 8); 12978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 12988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 12998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 13008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 13018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 13028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/** 13038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * scard_umts_auth - Run UMTS authentication command on USIM card 13048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @scard: Pointer to private data from scard_init() 13058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @_rand: 16-byte RAND value from HLR/AuC 13068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @autn: 16-byte AUTN value from HLR/AuC 13078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @res: 16-byte buffer for RES 13088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @res_len: Variable that will be set to RES length 13098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @ik: 16-byte buffer for IK 13108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @ck: 16-byte buffer for CK 13118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * @auts: 14-byte buffer for AUTS 13128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Returns: 0 on success, -1 on failure, or -2 if USIM reports synchronization 13138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * failure 13148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * 13158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * This function performs AKA authentication using USIM card and the provided 13168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * RAND and AUTN values from HLR/AuC. If authentication command can be 13178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * completed successfully, RES, IK, and CK values will be written into provided 13188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * buffers and res_len is set to length of received RES value. If USIM reports 13198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * synchronization failure, the received AUTS value will be written into auts 13208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * buffer. In this case, RES, IK, and CK are not valid. 13218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */ 13228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtint scard_umts_auth(struct scard_data *scard, const unsigned char *_rand, 13238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt const unsigned char *autn, 13248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char *res, size_t *res_len, 13258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char *ik, unsigned char *ck, unsigned char *auts) 13268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 13278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char cmd[5 + 1 + AKA_RAND_LEN + 1 + AKA_AUTN_LEN] = 13288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt { USIM_CMD_RUN_UMTS_ALG }; 13298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char get_resp[5] = { USIM_CMD_GET_RESPONSE }; 13308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt unsigned char resp[3], buf[64], *pos, *end; 13318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t len; 13328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt long ret; 13338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 13348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard == NULL) 13358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 13368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 13378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (scard->sim_type == SCARD_GSM_SIM) { 13388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_ERROR, "SCARD: Non-USIM card - cannot do UMTS " 13398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "auth"); 13408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 13418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 13428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 13438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: UMTS auth - RAND", _rand, AKA_RAND_LEN); 13448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: UMTS auth - AUTN", autn, AKA_AUTN_LEN); 13458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[5] = AKA_RAND_LEN; 13468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(cmd + 6, _rand, AKA_RAND_LEN); 13478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt cmd[6 + AKA_RAND_LEN] = AKA_AUTN_LEN; 13488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(cmd + 6 + AKA_RAND_LEN + 1, autn, AKA_AUTN_LEN); 13498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 13508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt len = sizeof(resp); 13518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = scard_transmit(scard, cmd, sizeof(cmd), resp, &len); 13528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS) 13538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 13548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 13558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (len <= sizeof(resp)) 13568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: UMTS alg response", resp, len); 13578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 13588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (len == 2 && resp[0] == 0x98 && resp[1] == 0x62) { 13598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: UMTS auth failed - " 13608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "MAC != XMAC"); 13618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 13628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } else if (len != 2 || resp[0] != 0x61) { 13638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_WARNING, "SCARD: unexpected response for UMTS " 13648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "auth request (len=%ld resp=%02x %02x)", 13658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (long) len, resp[0], resp[1]); 13668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 13678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 13688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt get_resp[4] = resp[1]; 13698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 13708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt len = sizeof(buf); 13718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret = scard_transmit(scard, get_resp, sizeof(get_resp), buf, &len); 13728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ret != SCARD_S_SUCCESS || len > sizeof(buf)) 13738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 13748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 13758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: UMTS get response result", buf, len); 13768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (len >= 2 + AKA_AUTS_LEN && buf[0] == 0xdc && 13778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt buf[1] == AKA_AUTS_LEN) { 13788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: UMTS Synchronization-Failure"); 13798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(auts, buf + 2, AKA_AUTS_LEN); 13808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: AUTS", auts, AKA_AUTS_LEN); 13818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -2; 13828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } else if (len >= 6 + IK_LEN + CK_LEN && buf[0] == 0xdb) { 13838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt pos = buf + 1; 13848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt end = buf + len; 13858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 13868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* RES */ 13878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (pos[0] > RES_MAX_LEN || pos + pos[0] > end) { 13888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Invalid RES"); 13898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 13908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 13918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *res_len = *pos++; 13928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(res, pos, *res_len); 13938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt pos += *res_len; 13948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: RES", res, *res_len); 13958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 13968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* CK */ 13978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (pos[0] != CK_LEN || pos + CK_LEN > end) { 13988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Invalid CK"); 13998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 14008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 14018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt pos++; 14028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(ck, pos, CK_LEN); 14038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt pos += CK_LEN; 14048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: CK", ck, CK_LEN); 14058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 14068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* IK */ 14078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (pos[0] != IK_LEN || pos + IK_LEN > end) { 14088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Invalid IK"); 14098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 14108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 14118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt pos++; 14128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(ik, pos, IK_LEN); 14138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt pos += IK_LEN; 14148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "SCARD: IK", ik, IK_LEN); 14158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 14168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 14178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 14188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 14198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "SCARD: Unrecognized response"); 14208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 14218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 142204949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 142304949598a23f501be6eec21697465fd46a28840aDmitry Shmidt 142404949598a23f501be6eec21697465fd46a28840aDmitry Shmidtint scard_supports_umts(struct scard_data *scard) 142504949598a23f501be6eec21697465fd46a28840aDmitry Shmidt{ 142604949598a23f501be6eec21697465fd46a28840aDmitry Shmidt return scard->sim_type == SCARD_USIM; 142704949598a23f501be6eec21697465fd46a28840aDmitry Shmidt} 1428