18d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/* 28d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * IEEE 802.1X-2004 Authenticator - EAPOL state machine 38d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * Copyright (c) 2002-2009, Jouni Malinen <j@w1.fi> 48d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * 5c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * This software may be distributed under the terms of the BSD license. 6c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * See README for more details. 78d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */ 88d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 98d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#ifndef EAPOL_AUTH_SM_H 108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define EAPOL_AUTH_SM_H 118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define EAPOL_SM_PREAUTH BIT(0) 138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define EAPOL_SM_WAIT_START BIT(1) 148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define EAPOL_SM_USES_WPA BIT(2) 158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#define EAPOL_SM_FROM_PMKSA_CACHE BIT(3) 168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct eapol_auth_config { 188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int eap_reauth_period; 198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int wpa; 208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int individual_wep_key_len; 218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int eap_server; 228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt void *ssl_ctx; 238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt void *msg_ctx; 248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt void *eap_sim_db_priv; 258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt char *eap_req_id_text; /* a copy of this will be allocated */ 268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t eap_req_id_text_len; 27fb45fd5cfed8bdccd0859c7fc05449fc187e2d06Dmitry Shmidt int erp_send_reauth_start; 28fb45fd5cfed8bdccd0859c7fc05449fc187e2d06Dmitry Shmidt char *erp_domain; /* a copy of this will be allocated */ 29fb45fd5cfed8bdccd0859c7fc05449fc187e2d06Dmitry Shmidt int erp; /* Whether ERP is enabled on authentication server */ 308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 *pac_opaque_encr_key; 318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 *eap_fast_a_id; 328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t eap_fast_a_id_len; 338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt char *eap_fast_a_id_info; 348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int eap_fast_prov; 358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int pac_key_lifetime; 368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int pac_key_refresh_time; 378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int eap_sim_aka_result_ind; 388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int tnc; 398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct wps_context *wps; 408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int fragment_size; 418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u16 pwd_group; 4287fd279308af3f806848c8f2ab65ef18c6ac4c30Jouni Malinen int pbc_in_m1; 4334af306c42b7ccf956508e7cd23f0ba90606e360Dmitry Shmidt const u8 *server_id; 4434af306c42b7ccf956508e7cd23f0ba90606e360Dmitry Shmidt size_t server_id_len; 458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* Opaque context pointer to owner data for callback functions */ 478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt void *ctx; 488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}; 498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct eap_user; 51fb45fd5cfed8bdccd0859c7fc05449fc187e2d06Dmitry Shmidtstruct eap_server_erp_key; 528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidttypedef enum { 548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt EAPOL_LOGGER_DEBUG, EAPOL_LOGGER_INFO, EAPOL_LOGGER_WARNING 558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} eapol_logger_level; 568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtenum eapol_event { 588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt EAPOL_AUTH_SM_CHANGE, 598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt EAPOL_AUTH_REAUTHENTICATE 608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}; 618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct eapol_auth_cb { 638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt void (*eapol_send)(void *ctx, void *sta_ctx, u8 type, const u8 *data, 648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t datalen); 658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt void (*aaa_send)(void *ctx, void *sta_ctx, const u8 *data, 668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t datalen); 67f21452aea786ac056eb01f1cbba4f553bd502747Dmitry Shmidt void (*finished)(void *ctx, void *sta_ctx, int success, int preauth, 68f21452aea786ac056eb01f1cbba4f553bd502747Dmitry Shmidt int remediation); 698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int (*get_eap_user)(void *ctx, const u8 *identity, size_t identity_len, 708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int phase2, struct eap_user *user); 718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int (*sta_entry_alive)(void *ctx, const u8 *addr); 728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt void (*logger)(void *ctx, const u8 *addr, eapol_logger_level level, 738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt const char *txt); 748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt void (*set_port_authorized)(void *ctx, void *sta_ctx, int authorized); 758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt void (*abort_auth)(void *ctx, void *sta_ctx); 768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt void (*tx_key)(void *ctx, void *sta_ctx); 778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt void (*eapol_event)(void *ctx, void *sta_ctx, enum eapol_event type); 78fb45fd5cfed8bdccd0859c7fc05449fc187e2d06Dmitry Shmidt struct eap_server_erp_key * (*erp_get_key)(void *ctx, 79fb45fd5cfed8bdccd0859c7fc05449fc187e2d06Dmitry Shmidt const char *keyname); 80fb45fd5cfed8bdccd0859c7fc05449fc187e2d06Dmitry Shmidt int (*erp_add_key)(void *ctx, struct eap_server_erp_key *erp); 818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}; 828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct eapol_authenticator * eapol_auth_init(struct eapol_auth_config *conf, 858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct eapol_auth_cb *cb); 868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtvoid eapol_auth_deinit(struct eapol_authenticator *eapol); 878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct eapol_state_machine * 888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidteapol_auth_alloc(struct eapol_authenticator *eapol, const u8 *addr, 898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int flags, const struct wpabuf *assoc_wps_ie, 9061d9df3e62aaa0e87ad05452fcb95142159a17b6Dmitry Shmidt const struct wpabuf *assoc_p2p_ie, void *sta_ctx, 9161d9df3e62aaa0e87ad05452fcb95142159a17b6Dmitry Shmidt const char *identity, const char *radius_cui); 928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtvoid eapol_auth_free(struct eapol_state_machine *sm); 938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtvoid eapol_auth_step(struct eapol_state_machine *sm); 94fb79edc9df1f20461e90e478363d207348213d35Dmitry Shmidtint eapol_auth_dump_state(struct eapol_state_machine *sm, char *buf, 95fb79edc9df1f20461e90e478363d207348213d35Dmitry Shmidt size_t buflen); 968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtint eapol_auth_eap_pending_cb(struct eapol_state_machine *sm, void *ctx); 978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#endif /* EAPOL_AUTH_SM_H */ 99