18d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt/* 28d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * EAP-IKEv2 peer (RFC 5106) 3fb79edc9df1f20461e90e478363d207348213d35Dmitry Shmidt * Copyright (c) 2007-2014, Jouni Malinen <j@w1.fi> 48d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * 5c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * This software may be distributed under the terms of the BSD license. 6c5ec7f57ead87efa365800228aa0b09a12d9e6c4Dmitry Shmidt * See README for more details. 78d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt */ 88d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 98d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "includes.h" 108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "common.h" 128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "eap_i.h" 138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "eap_common/eap_ikev2_common.h" 148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt#include "ikev2.h" 158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstruct eap_ikev2_data { 188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct ikev2_responder_data ikev2; 198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt enum { WAIT_START, PROC_MSG, WAIT_FRAG_ACK, DONE, FAIL } state; 208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct wpabuf *in_buf; 218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct wpabuf *out_buf; 228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t out_used; 238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t fragment_size; 248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int keys_ready; 258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 keymat[EAP_MSK_LEN + EAP_EMSK_LEN]; 268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int keymat_ok; 278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt}; 288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic const char * eap_ikev2_state_txt(int state) 318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt switch (state) { 338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt case WAIT_START: 348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return "WAIT_START"; 358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt case PROC_MSG: 368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return "PROC_MSG"; 378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt case WAIT_FRAG_ACK: 388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return "WAIT_FRAG_ACK"; 398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt case DONE: 408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return "DONE"; 418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt case FAIL: 428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return "FAIL"; 438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt default: 448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return "?"; 458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic void eap_ikev2_state(struct eap_ikev2_data *data, int state) 508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: %s -> %s", 528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt eap_ikev2_state_txt(data->state), 538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt eap_ikev2_state_txt(state)); 548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->state = state; 558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic void * eap_ikev2_init(struct eap_sm *sm) 598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct eap_ikev2_data *data; 618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt const u8 *identity, *password; 628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t identity_len, password_len; 63fb79edc9df1f20461e90e478363d207348213d35Dmitry Shmidt int fragment_size; 648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt identity = eap_get_config_identity(sm, &identity_len); 668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (identity == NULL) { 678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_INFO, "EAP-IKEV2: No identity available"); 688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data = os_zalloc(sizeof(*data)); 728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data == NULL) 738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->state = WAIT_START; 75fb79edc9df1f20461e90e478363d207348213d35Dmitry Shmidt fragment_size = eap_get_config_fragment_size(sm); 76fb79edc9df1f20461e90e478363d207348213d35Dmitry Shmidt if (fragment_size <= 0) 77fb79edc9df1f20461e90e478363d207348213d35Dmitry Shmidt data->fragment_size = IKEV2_FRAGMENT_SIZE; 78fb79edc9df1f20461e90e478363d207348213d35Dmitry Shmidt else 79fb79edc9df1f20461e90e478363d207348213d35Dmitry Shmidt data->fragment_size = fragment_size; 808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->ikev2.state = SA_INIT; 818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->ikev2.peer_auth = PEER_AUTH_SECRET; 828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->ikev2.key_pad = (u8 *) os_strdup("Key Pad for EAP-IKEv2"); 838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->ikev2.key_pad == NULL) 848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt goto failed; 858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->ikev2.key_pad_len = 21; 868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->ikev2.IDr = os_malloc(identity_len); 878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->ikev2.IDr == NULL) 888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt goto failed; 898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(data->ikev2.IDr, identity, identity_len); 908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->ikev2.IDr_len = identity_len; 918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt password = eap_get_config_password(sm, &password_len); 938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (password) { 948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->ikev2.shared_secret = os_malloc(password_len); 958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->ikev2.shared_secret == NULL) 968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt goto failed; 978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(data->ikev2.shared_secret, password, password_len); 988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->ikev2.shared_secret_len = password_len; 998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 1008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return data; 1028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtfailed: 1048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ikev2_responder_deinit(&data->ikev2); 1058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_free(data); 1068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 1078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 1088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic void eap_ikev2_deinit(struct eap_sm *sm, void *priv) 1118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 1128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct eap_ikev2_data *data = priv; 1138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpabuf_free(data->in_buf); 1148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpabuf_free(data->out_buf); 1158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ikev2_responder_deinit(&data->ikev2); 116c28170251eb54dbf64a9074a07fee377587425b2Dmitry Shmidt bin_clear_free(data, sizeof(*data)); 1178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 1188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int eap_ikev2_peer_keymat(struct eap_ikev2_data *data) 1218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 1228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (eap_ikev2_derive_keymat( 1238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->ikev2.proposal.prf, &data->ikev2.keys, 1248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->ikev2.i_nonce, data->ikev2.i_nonce_len, 1258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->ikev2.r_nonce, data->ikev2.r_nonce_len, 1268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->keymat) < 0) { 1278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Failed to " 1288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "derive key material"); 1298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 1308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 1318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->keymat_ok = 1; 1328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 1338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 1348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic struct wpabuf * eap_ikev2_build_msg(struct eap_ikev2_data *data, 1378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct eap_method_ret *ret, u8 id) 1388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 1398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct wpabuf *resp; 1408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 flags; 1418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t send_len, plen, icv_len = 0; 1428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret->ignore = FALSE; 1448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Generating Response"); 1458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret->allowNotifications = TRUE; 1468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt flags = 0; 1488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt send_len = wpabuf_len(data->out_buf) - data->out_used; 1498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (1 + send_len > data->fragment_size) { 1508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt send_len = data->fragment_size - 1; 1518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt flags |= IKEV2_FLAGS_MORE_FRAGMENTS; 1528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->out_used == 0) { 1538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt flags |= IKEV2_FLAGS_LENGTH_INCLUDED; 1548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt send_len -= 4; 1558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 1568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 1578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt plen = 1 + send_len; 1598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (flags & IKEV2_FLAGS_LENGTH_INCLUDED) 1608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt plen += 4; 1618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->keys_ready) { 1628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt const struct ikev2_integ_alg *integ; 1638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Add Integrity Checksum " 1648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "Data"); 1658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt flags |= IKEV2_FLAGS_ICV_INCLUDED; 1668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt integ = ikev2_get_integ(data->ikev2.proposal.integ); 1678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (integ == NULL) { 1688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Unknown INTEG " 1698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "transform / cannot generate ICV"); 1708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 1718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 1728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt icv_len = integ->hash_len; 1738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt plen += icv_len; 1758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 1768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt resp = eap_msg_alloc(EAP_VENDOR_IETF, EAP_TYPE_IKEV2, plen, 1778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt EAP_CODE_RESPONSE, id); 1788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (resp == NULL) 1798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 1808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpabuf_put_u8(resp, flags); /* Flags */ 1828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (flags & IKEV2_FLAGS_LENGTH_INCLUDED) 1838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpabuf_put_be32(resp, wpabuf_len(data->out_buf)); 1848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpabuf_put_data(resp, wpabuf_head_u8(data->out_buf) + data->out_used, 1868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt send_len); 1878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->out_used += send_len; 1888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (flags & IKEV2_FLAGS_ICV_INCLUDED) { 1908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt const u8 *msg = wpabuf_head(resp); 1918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t len = wpabuf_len(resp); 1928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ikev2_integ_hash(data->ikev2.proposal.integ, 1938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->ikev2.keys.SK_ar, 1948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->ikev2.keys.SK_integ_len, 1958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt msg, len, wpabuf_put(resp, icv_len)); 1968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 1978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 1988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret->methodState = METHOD_MAY_CONT; 1998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret->decision = DECISION_FAIL; 2008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->out_used == wpabuf_len(data->out_buf)) { 2028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Sending out %lu bytes " 2038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "(message sent completely)", 2048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (unsigned long) send_len); 2058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpabuf_free(data->out_buf); 2068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->out_buf = NULL; 2078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->out_used = 0; 2088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt switch (data->ikev2.state) { 2098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt case SA_AUTH: 2108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* SA_INIT was sent out, so message have to be 2118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt * integrity protected from now on. */ 2128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->keys_ready = 1; 2138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt break; 2148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt case IKEV2_DONE: 2158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret->methodState = METHOD_DONE; 2168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->state == FAIL) 2178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt break; 2188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret->decision = DECISION_COND_SUCC; 2198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Authentication " 2208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "completed successfully"); 2218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (eap_ikev2_peer_keymat(data)) 2228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt break; 2238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt eap_ikev2_state(data, DONE); 2248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt break; 2258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt case IKEV2_FAILED: 2268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Authentication " 2278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "failed"); 2288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret->methodState = METHOD_DONE; 2298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret->decision = DECISION_FAIL; 2308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt break; 2318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt default: 2328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt break; 2338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 2348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } else { 2358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Sending out %lu bytes " 2368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "(%lu more to send)", (unsigned long) send_len, 2378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (unsigned long) wpabuf_len(data->out_buf) - 2388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->out_used); 2398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt eap_ikev2_state(data, WAIT_FRAG_ACK); 2408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 2418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return resp; 2438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 2448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int eap_ikev2_process_icv(struct eap_ikev2_data *data, 2478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt const struct wpabuf *reqData, 2485a1480c7c46c4236d93bfd303dde32062bee04acDmitry Shmidt u8 flags, const u8 *pos, const u8 **end, 2495a1480c7c46c4236d93bfd303dde32062bee04acDmitry Shmidt int frag_ack) 2508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 2518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (flags & IKEV2_FLAGS_ICV_INCLUDED) { 2528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt int icv_len = eap_ikev2_validate_icv( 2538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->ikev2.proposal.integ, &data->ikev2.keys, 1, 2548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt reqData, pos, *end); 2558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (icv_len < 0) 2568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 2578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* Hide Integrity Checksum Data from further processing */ 2588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *end -= icv_len; 2595a1480c7c46c4236d93bfd303dde32062bee04acDmitry Shmidt } else if (data->keys_ready && !frag_ack) { 2608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_INFO, "EAP-IKEV2: The message should have " 2618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "included integrity checksum"); 2628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 2638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 2648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 2668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 2678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic int eap_ikev2_process_cont(struct eap_ikev2_data *data, 2708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt const u8 *buf, size_t len) 2718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 2728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* Process continuation of a pending message */ 2738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (len > wpabuf_tailroom(data->in_buf)) { 2748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Fragment overflow"); 2758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt eap_ikev2_state(data, FAIL); 2768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 2778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 2788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpabuf_put_data(data->in_buf, buf, len); 2808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Received %lu bytes, waiting " 2818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "for %lu bytes more", (unsigned long) len, 2828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (unsigned long) wpabuf_tailroom(data->in_buf)); 2838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return 0; 2858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 2868d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 2888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic struct wpabuf * eap_ikev2_process_fragment(struct eap_ikev2_data *data, 2898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct eap_method_ret *ret, 2908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 id, u8 flags, 2918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u32 message_length, 2928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt const u8 *buf, size_t len) 2938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 2948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* Process a fragment that is not the last one of the message */ 2958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->in_buf == NULL && !(flags & IKEV2_FLAGS_LENGTH_INCLUDED)) { 2968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: No Message Length field in " 2978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "a fragmented packet"); 2988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret->ignore = TRUE; 2998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 3008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 3018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->in_buf == NULL) { 3038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* First fragment of the message */ 304fb45fd5cfed8bdccd0859c7fc05449fc187e2d06Dmitry Shmidt if (message_length > 50000) { 305fb45fd5cfed8bdccd0859c7fc05449fc187e2d06Dmitry Shmidt /* Limit maximum memory allocation */ 306fb45fd5cfed8bdccd0859c7fc05449fc187e2d06Dmitry Shmidt wpa_printf(MSG_DEBUG, 307fb45fd5cfed8bdccd0859c7fc05449fc187e2d06Dmitry Shmidt "EAP-IKEV2: Ignore too long message"); 308fb45fd5cfed8bdccd0859c7fc05449fc187e2d06Dmitry Shmidt ret->ignore = TRUE; 309fb45fd5cfed8bdccd0859c7fc05449fc187e2d06Dmitry Shmidt return NULL; 310fb45fd5cfed8bdccd0859c7fc05449fc187e2d06Dmitry Shmidt } 3118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->in_buf = wpabuf_alloc(message_length); 3128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->in_buf == NULL) { 3138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: No memory for " 3148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "message"); 3158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret->ignore = TRUE; 3168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 3178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 3188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpabuf_put_data(data->in_buf, buf, len); 3198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Received %lu bytes in first " 3208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "fragment, waiting for %lu bytes more", 3218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (unsigned long) len, 3228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt (unsigned long) wpabuf_tailroom(data->in_buf)); 3238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 3248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 325fb45fd5cfed8bdccd0859c7fc05449fc187e2d06Dmitry Shmidt ret->ignore = FALSE; 3268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return eap_ikev2_build_frag_ack(id, EAP_CODE_RESPONSE); 3278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 3288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic struct wpabuf * eap_ikev2_process(struct eap_sm *sm, void *priv, 3318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct eap_method_ret *ret, 3328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt const struct wpabuf *reqData) 3338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 3348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct eap_ikev2_data *data = priv; 3358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt const u8 *start, *pos, *end; 3368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt size_t len; 3378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 flags, id; 3388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u32 message_length = 0; 3398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct wpabuf tmpbuf; 3408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt pos = eap_hdr_validate(EAP_VENDOR_IETF, EAP_TYPE_IKEV2, reqData, &len); 3428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (pos == NULL) { 3438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret->ignore = TRUE; 3448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 3458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 3468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt id = eap_get_id(reqData); 3488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt start = pos; 3508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt end = start + len; 3518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (len == 0) 3538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt flags = 0; /* fragment ack */ 3548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt else 3558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt flags = *pos++; 3568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3575a1480c7c46c4236d93bfd303dde32062bee04acDmitry Shmidt if (eap_ikev2_process_icv(data, reqData, flags, pos, &end, 3585a1480c7c46c4236d93bfd303dde32062bee04acDmitry Shmidt data->state == WAIT_FRAG_ACK && len == 0) < 0) 3595a1480c7c46c4236d93bfd303dde32062bee04acDmitry Shmidt { 3608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret->ignore = TRUE; 3618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 3628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 3638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (flags & IKEV2_FLAGS_LENGTH_INCLUDED) { 3658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (end - pos < 4) { 3668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Message underflow"); 3678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret->ignore = TRUE; 3688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 3698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 3708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt message_length = WPA_GET_BE32(pos); 3718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt pos += 4; 3728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (message_length < (u32) (end - pos)) { 3748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Invalid Message " 3758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "Length (%d; %ld remaining in this msg)", 3768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt message_length, (long) (end - pos)); 3778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret->ignore = TRUE; 3788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 3798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 3808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 3818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Received packet: Flags 0x%x " 3838d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "Message Length %u", flags, message_length); 3848d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3858d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->state == WAIT_FRAG_ACK) { 38609f57babfc1e4473db20ced4f58a4c9f082c8ed8Dmitry Shmidt if (len != 0) { 3878d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Unexpected payload " 3888d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "in WAIT_FRAG_ACK state"); 3898d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret->ignore = TRUE; 3908d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 3918d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 3928d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Fragment acknowledged"); 3938d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt eap_ikev2_state(data, PROC_MSG); 3948d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return eap_ikev2_build_msg(data, ret, id); 3958d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 3968d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 3978d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->in_buf && eap_ikev2_process_cont(data, pos, end - pos) < 0) { 3988d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt ret->ignore = TRUE; 3998d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 4008d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4018d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4028d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (flags & IKEV2_FLAGS_MORE_FRAGMENTS) { 4038d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return eap_ikev2_process_fragment(data, ret, id, flags, 4048d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt message_length, pos, 4058d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt end - pos); 4068d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4078d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4088d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->in_buf == NULL) { 4098d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt /* Wrap unfragmented messages as wpabuf without extra copy */ 4108d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpabuf_set(&tmpbuf, pos, end - pos); 4118d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->in_buf = &tmpbuf; 4128d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (ikev2_responder_process(&data->ikev2, data->in_buf) < 0) { 4158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->in_buf == &tmpbuf) 4168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->in_buf = NULL; 4178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt eap_ikev2_state(data, FAIL); 4188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 4198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->in_buf != &tmpbuf) 4228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpabuf_free(data->in_buf); 4238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->in_buf = NULL; 4248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->out_buf == NULL) { 4268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->out_buf = ikev2_responder_build(&data->ikev2); 4278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->out_buf == NULL) { 4288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt wpa_printf(MSG_DEBUG, "EAP-IKEV2: Failed to generate " 4298d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "IKEv2 message"); 4308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 4318d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt data->out_used = 0; 4338d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4348d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4358d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt eap_ikev2_state(data, PROC_MSG); 4368d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return eap_ikev2_build_msg(data, ret, id); 4378d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 4388d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4398d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4408d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic Boolean eap_ikev2_isKeyAvailable(struct eap_sm *sm, void *priv) 4418d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 4428d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct eap_ikev2_data *data = priv; 4438d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return data->state == DONE && data->keymat_ok; 4448d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 4458d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4468d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4478d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic u8 * eap_ikev2_getKey(struct eap_sm *sm, void *priv, size_t *len) 4488d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 4498d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct eap_ikev2_data *data = priv; 4508d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 *key; 4518d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4528d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->state != DONE || !data->keymat_ok) 4538d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 4548d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4558d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt key = os_malloc(EAP_MSK_LEN); 4568d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (key) { 4578d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(key, data->keymat, EAP_MSK_LEN); 4588d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *len = EAP_MSK_LEN; 4598d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4608d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4618d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return key; 4628d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 4638d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4648d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4658d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtstatic u8 * eap_ikev2_get_emsk(struct eap_sm *sm, void *priv, size_t *len) 4668d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 4678d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct eap_ikev2_data *data = priv; 4688d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt u8 *key; 4698d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4708d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (data->state != DONE || !data->keymat_ok) 4718d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return NULL; 4728d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4738d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt key = os_malloc(EAP_EMSK_LEN); 4748d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (key) { 4758d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt os_memcpy(key, data->keymat + EAP_MSK_LEN, EAP_EMSK_LEN); 4768d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt *len = EAP_EMSK_LEN; 4778d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt } 4788d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4798d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return key; 4808d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 4818d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 4828d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 483f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidtstatic u8 * eap_ikev2_get_session_id(struct eap_sm *sm, void *priv, size_t *len) 484f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt{ 485f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt struct eap_ikev2_data *data = priv; 486f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt u8 *sid; 487f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt size_t sid_len; 488f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt size_t offset; 489f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt 490f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt if (data->state != DONE || !data->keymat_ok) 491f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt return NULL; 492f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt 493f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt sid_len = 1 + data->ikev2.i_nonce_len + data->ikev2.r_nonce_len; 494f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt sid = os_malloc(sid_len); 495f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt if (sid) { 496f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt offset = 0; 497f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt sid[offset] = EAP_TYPE_IKEV2; 498f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt offset++; 499f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt os_memcpy(sid + offset, data->ikev2.i_nonce, 500f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt data->ikev2.i_nonce_len); 501f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt offset += data->ikev2.i_nonce_len; 502f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt os_memcpy(sid + offset, data->ikev2.r_nonce, 503f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt data->ikev2.r_nonce_len); 504f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt *len = sid_len; 505f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt wpa_hexdump(MSG_DEBUG, "EAP-IKEV2: Derived Session-Id", 506f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt sid, sid_len); 507f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt } 508f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt 509f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt return sid; 510f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt} 511f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt 512f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt 5138d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidtint eap_peer_ikev2_register(void) 5148d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt{ 5158d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt struct eap_method *eap; 5168d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 5178d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt eap = eap_peer_method_alloc(EAP_PEER_METHOD_INTERFACE_VERSION, 5188d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt EAP_VENDOR_IETF, EAP_TYPE_IKEV2, 5198d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt "IKEV2"); 5208d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt if (eap == NULL) 5218d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt return -1; 5228d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 5238d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt eap->init = eap_ikev2_init; 5248d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt eap->deinit = eap_ikev2_deinit; 5258d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt eap->process = eap_ikev2_process; 5268d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt eap->isKeyAvailable = eap_ikev2_isKeyAvailable; 5278d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt eap->getKey = eap_ikev2_getKey; 5288d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt eap->get_emsk = eap_ikev2_get_emsk; 529f86232838cf712377867cb42417c1613ab5dc425Dmitry Shmidt eap->getSessionId = eap_ikev2_get_session_id; 5308d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt 5311d6bf427f4769edb60865a3999d01eeb8f8fcb19Dmitry Shmidt return eap_peer_method_register(eap); 5328d520ff1dc2da35cdca849e982051b86468016d8Dmitry Shmidt} 533