1/* 2 * EAP server/peer: EAP-pwd shared definitions 3 * Copyright (c) 2009, Dan Harkins <dharkins@lounge.org> 4 * 5 * This software may be distributed under the terms of the BSD license. 6 * See README for more details. 7 */ 8 9#ifndef EAP_PWD_COMMON_H 10#define EAP_PWD_COMMON_H 11 12#include <openssl/bn.h> 13#include <openssl/ec.h> 14#include <openssl/evp.h> 15 16/* 17 * definition of a finite cyclic group 18 * TODO: support one based on a prime field 19 */ 20typedef struct group_definition_ { 21 u16 group_num; 22 EC_GROUP *group; 23 EC_POINT *pwe; 24 BIGNUM *order; 25 BIGNUM *prime; 26} EAP_PWD_group; 27 28/* 29 * EAP-pwd header, included on all payloads 30 * L(1 bit) | M(1 bit) | exch(6 bits) | total_length(if L is set) 31 */ 32#define EAP_PWD_HDR_SIZE 1 33 34#define EAP_PWD_OPCODE_ID_EXCH 1 35#define EAP_PWD_OPCODE_COMMIT_EXCH 2 36#define EAP_PWD_OPCODE_CONFIRM_EXCH 3 37#define EAP_PWD_GET_LENGTH_BIT(x) ((x) & 0x80) 38#define EAP_PWD_SET_LENGTH_BIT(x) ((x) |= 0x80) 39#define EAP_PWD_GET_MORE_BIT(x) ((x) & 0x40) 40#define EAP_PWD_SET_MORE_BIT(x) ((x) |= 0x40) 41#define EAP_PWD_GET_EXCHANGE(x) ((x) & 0x3f) 42#define EAP_PWD_SET_EXCHANGE(x,y) ((x) |= (y)) 43 44/* EAP-pwd-ID payload */ 45struct eap_pwd_id { 46 be16 group_num; 47 u8 random_function; 48#define EAP_PWD_DEFAULT_RAND_FUNC 1 49 u8 prf; 50#define EAP_PWD_DEFAULT_PRF 1 51 u8 token[4]; 52 u8 prep; 53#define EAP_PWD_PREP_NONE 0 54#define EAP_PWD_PREP_MS 1 55 u8 identity[0]; /* length inferred from payload */ 56} STRUCT_PACKED; 57 58/* common routines */ 59int compute_password_element(EAP_PWD_group *grp, u16 num, 60 const u8 *password, size_t password_len, 61 const u8 *id_server, size_t id_server_len, 62 const u8 *id_peer, size_t id_peer_len, 63 const u8 *token); 64int compute_keys(EAP_PWD_group *grp, BN_CTX *bnctx, const BIGNUM *k, 65 const BIGNUM *peer_scalar, const BIGNUM *server_scalar, 66 const u8 *confirm_peer, const u8 *confirm_server, 67 const u32 *ciphersuite, u8 *msk, u8 *emsk, u8 *session_id); 68struct crypto_hash * eap_pwd_h_init(void); 69void eap_pwd_h_update(struct crypto_hash *hash, const u8 *data, size_t len); 70void eap_pwd_h_final(struct crypto_hash *hash, u8 *digest); 71 72#endif /* EAP_PWD_COMMON_H */ 73