2 * Copyright (c) 1996, 2003 VIA Networking Technologies, Inc.
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by
7 * the Free Software Foundation; either version 2 of the License, or
8 * (at your option) any later version.
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
15 * You should have received a copy of the GNU General Public License along
16 * with this program; if not, write to the Free Software Foundation, Inc.,
17 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
22 * Purpose: Handles the Basic Service Set & Node Database functions
28 * Author: Yiching Chen
38 /*--------------------- Static Definitions -------------------------*/
39 static int msglevel
= MSG_LEVEL_INFO
;
40 /*--------------------- Static Classes ----------------------------*/
42 /*--------------------- Static Variables --------------------------*/
44 static const unsigned char abyOUIGK
[4] = { 0x00, 0x0F, 0xAC, 0x00 };
45 static const unsigned char abyOUIWEP40
[4] = { 0x00, 0x0F, 0xAC, 0x01 };
46 static const unsigned char abyOUIWEP104
[4] = { 0x00, 0x0F, 0xAC, 0x05 };
47 static const unsigned char abyOUITKIP
[4] = { 0x00, 0x0F, 0xAC, 0x02 };
48 static const unsigned char abyOUICCMP
[4] = { 0x00, 0x0F, 0xAC, 0x04 };
50 static const unsigned char abyOUI8021X
[4] = { 0x00, 0x0F, 0xAC, 0x01 };
51 static const unsigned char abyOUIPSK
[4] = { 0x00, 0x0F, 0xAC, 0x02 };
53 /*--------------------- Static Functions --------------------------*/
55 /*--------------------- Export Variables --------------------------*/
57 /*--------------------- Export Functions --------------------------*/
62 * Clear RSN information in BSSList.
66 * pBSSNode - BSS list.
80 pBSSNode
->bWPA2Valid
= false;
82 pBSSNode
->byCSSGK
= WLAN_11i_CSS_CCMP
;
83 for (ii
= 0; ii
< 4; ii
++)
84 pBSSNode
->abyCSSPK
[ii
] = WLAN_11i_CSS_CCMP
;
85 pBSSNode
->wCSSPKCount
= 1;
86 for (ii
= 0; ii
< 4; ii
++)
87 pBSSNode
->abyAKMSSAuthType
[ii
] = WLAN_11i_AKMSS_802_1X
;
88 pBSSNode
->wAKMSSAuthCount
= 1;
89 pBSSNode
->sRSNCapObj
.bRSNCapExist
= false;
90 pBSSNode
->sRSNCapObj
.wRSNCap
= 0;
100 * pBSSNode - BSS list.
101 * pRSN - Pointer to the RSN IE.
105 * Return Value: none.
115 unsigned short m
= 0, n
= 0;
116 unsigned char *pbyOUI
;
119 DBG_PRT(MSG_LEVEL_DEBUG
, KERN_INFO
"WPA2_ParseRSN: [%d]\n", pRSN
->len
);
121 WPA2_ClearRSN(pBSSNode
);
123 if (pRSN
->len
== 2) { // ver(2)
124 if ((pRSN
->byElementID
== WLAN_EID_RSN
) && (pRSN
->wVersion
== 1))
125 pBSSNode
->bWPA2Valid
= true;
130 if (pRSN
->len
< 6) { // ver(2) + GK(4)
131 // invalid CSS, P802.11i/D10.0, p31
135 // information element header makes sense
136 if ((pRSN
->byElementID
== WLAN_EID_RSN
) &&
137 (pRSN
->wVersion
== 1)) {
138 DBG_PRT(MSG_LEVEL_DEBUG
, KERN_INFO
"Legal 802.11i RSN\n");
140 pbyOUI
= &(pRSN
->abyRSN
[0]);
141 if (!memcmp(pbyOUI
, abyOUIWEP40
, 4))
142 pBSSNode
->byCSSGK
= WLAN_11i_CSS_WEP40
;
143 else if (!memcmp(pbyOUI
, abyOUITKIP
, 4))
144 pBSSNode
->byCSSGK
= WLAN_11i_CSS_TKIP
;
145 else if (!memcmp(pbyOUI
, abyOUICCMP
, 4))
146 pBSSNode
->byCSSGK
= WLAN_11i_CSS_CCMP
;
147 else if (!memcmp(pbyOUI
, abyOUIWEP104
, 4))
148 pBSSNode
->byCSSGK
= WLAN_11i_CSS_WEP104
;
149 else if (!memcmp(pbyOUI
, abyOUIGK
, 4)) {
150 // invalid CSS, P802.11i/D10.0, p32
153 // any vendor checks here
154 pBSSNode
->byCSSGK
= WLAN_11i_CSS_UNKNOWN
;
156 DBG_PRT(MSG_LEVEL_DEBUG
, KERN_INFO
"802.11i CSS: %X\n", pBSSNode
->byCSSGK
);
158 if (pRSN
->len
== 6) {
159 pBSSNode
->bWPA2Valid
= true;
163 if (pRSN
->len
>= 8) { // ver(2) + GK(4) + PK count(2)
164 pBSSNode
->wCSSPKCount
= *((unsigned short *)&(pRSN
->abyRSN
[4]));
166 pbyOUI
= &(pRSN
->abyRSN
[6]);
168 for (i
= 0; (i
< pBSSNode
->wCSSPKCount
) && (j
< sizeof(pBSSNode
->abyCSSPK
)/sizeof(unsigned char)); i
++) {
169 if (pRSN
->len
>= 8+i
*4+4) { // ver(2)+GK(4)+PKCnt(2)+PKS(4*i)
170 if (!memcmp(pbyOUI
, abyOUIGK
, 4)) {
171 pBSSNode
->abyCSSPK
[j
++] = WLAN_11i_CSS_USE_GROUP
;
173 } else if (!memcmp(pbyOUI
, abyOUIWEP40
, 4)) {
174 // Invalid CSS, continue to parsing
175 } else if (!memcmp(pbyOUI
, abyOUITKIP
, 4)) {
176 if (pBSSNode
->byCSSGK
!= WLAN_11i_CSS_CCMP
)
177 pBSSNode
->abyCSSPK
[j
++] = WLAN_11i_CSS_TKIP
;
179 ; // Invalid CSS, continue to parsing
180 } else if (!memcmp(pbyOUI
, abyOUICCMP
, 4)) {
181 pBSSNode
->abyCSSPK
[j
++] = WLAN_11i_CSS_CCMP
;
182 } else if (!memcmp(pbyOUI
, abyOUIWEP104
, 4)) {
183 // Invalid CSS, continue to parsing
185 // any vendor checks here
186 pBSSNode
->abyCSSPK
[j
++] = WLAN_11i_CSS_UNKNOWN
;
189 DBG_PRT(MSG_LEVEL_DEBUG
, KERN_INFO
"abyCSSPK[%d]: %X\n", j
-1, pBSSNode
->abyCSSPK
[j
-1]);
196 // invalid CSS, This should be only PK CSS.
199 if (pBSSNode
->byCSSGK
== WLAN_11i_CSS_CCMP
) {
200 // invalid CSS, If CCMP is enable , PK can't be CSSGK.
204 if ((pBSSNode
->wCSSPKCount
!= 0) && (j
== 0)) {
205 // invalid CSS, No valid PK.
208 pBSSNode
->wCSSPKCount
= (unsigned short)j
;
209 DBG_PRT(MSG_LEVEL_DEBUG
, KERN_INFO
"wCSSPKCount: %d\n", pBSSNode
->wCSSPKCount
);
212 m
= *((unsigned short *)&(pRSN
->abyRSN
[4]));
214 if (pRSN
->len
>= 10+m
*4) { // ver(2) + GK(4) + PK count(2) + PKS(4*m) + AKMSS count(2)
215 pBSSNode
->wAKMSSAuthCount
= *((unsigned short *)&(pRSN
->abyRSN
[6+4*m
]));
217 pbyOUI
= &(pRSN
->abyRSN
[8+4*m
]);
218 for (i
= 0; (i
< pBSSNode
->wAKMSSAuthCount
) && (j
< sizeof(pBSSNode
->abyAKMSSAuthType
)/sizeof(unsigned char)); i
++) {
219 if (pRSN
->len
>= 10+(m
+i
)*4+4) { // ver(2)+GK(4)+PKCnt(2)+PKS(4*m)+AKMSS(2)+AKS(4*i)
220 if (!memcmp(pbyOUI
, abyOUI8021X
, 4))
221 pBSSNode
->abyAKMSSAuthType
[j
++] = WLAN_11i_AKMSS_802_1X
;
222 else if (!memcmp(pbyOUI
, abyOUIPSK
, 4))
223 pBSSNode
->abyAKMSSAuthType
[j
++] = WLAN_11i_AKMSS_PSK
;
225 // any vendor checks here
226 pBSSNode
->abyAKMSSAuthType
[j
++] = WLAN_11i_AKMSS_UNKNOWN
;
227 DBG_PRT(MSG_LEVEL_DEBUG
, KERN_INFO
"abyAKMSSAuthType[%d]: %X\n", j
-1, pBSSNode
->abyAKMSSAuthType
[j
-1]);
231 pBSSNode
->wAKMSSAuthCount
= (unsigned short)j
;
232 DBG_PRT(MSG_LEVEL_DEBUG
, KERN_INFO
"wAKMSSAuthCount: %d\n", pBSSNode
->wAKMSSAuthCount
);
234 n
= *((unsigned short *)&(pRSN
->abyRSN
[6+4*m
]));
235 if (pRSN
->len
>= 12 + 4 * m
+ 4 * n
) { // ver(2)+GK(4)+PKCnt(2)+PKS(4*m)+AKMSSCnt(2)+AKMSS(4*n)+Cap(2)
236 pBSSNode
->sRSNCapObj
.bRSNCapExist
= true;
237 pBSSNode
->sRSNCapObj
.wRSNCap
= *((unsigned short *)&(pRSN
->abyRSN
[8+4*m
+4*n
]));
240 //ignore PMKID lists bcs only (Re)Assocrequest has this field
241 pBSSNode
->bWPA2Valid
= true;
252 * pMgmtHandle - Pointer to management object
254 * pRSNIEs - Pointer to the RSN IE to set.
256 * Return Value: length of IEs.
265 PSMgmtObject pMgmt
= (PSMgmtObject
) pMgmtHandle
;
266 unsigned char *pbyBuffer
= NULL
;
268 unsigned short *pwPMKID
= NULL
;
273 if (((pMgmt
->eAuthenMode
== WMAC_AUTH_WPA2
) ||
274 (pMgmt
->eAuthenMode
== WMAC_AUTH_WPA2PSK
)) &&
275 (pMgmt
->pCurrBSS
!= NULL
)) {
277 pbyBuffer
= (unsigned char *)pRSNIEs
;
278 pRSNIEs
->byElementID
= WLAN_EID_RSN
;
279 pRSNIEs
->len
= 6; //Version(2)+GK(4)
280 pRSNIEs
->wVersion
= 1;
281 //Group Key Cipher Suite
282 pRSNIEs
->abyRSN
[0] = 0x00;
283 pRSNIEs
->abyRSN
[1] = 0x0F;
284 pRSNIEs
->abyRSN
[2] = 0xAC;
285 if (pMgmt
->byCSSGK
== KEY_CTL_WEP
)
286 pRSNIEs
->abyRSN
[3] = pMgmt
->pCurrBSS
->byCSSGK
;
287 else if (pMgmt
->byCSSGK
== KEY_CTL_TKIP
)
288 pRSNIEs
->abyRSN
[3] = WLAN_11i_CSS_TKIP
;
289 else if (pMgmt
->byCSSGK
== KEY_CTL_CCMP
)
290 pRSNIEs
->abyRSN
[3] = WLAN_11i_CSS_CCMP
;
292 pRSNIEs
->abyRSN
[3] = WLAN_11i_CSS_UNKNOWN
;
294 // Pairwise Key Cipher Suite
295 pRSNIEs
->abyRSN
[4] = 1;
296 pRSNIEs
->abyRSN
[5] = 0;
297 pRSNIEs
->abyRSN
[6] = 0x00;
298 pRSNIEs
->abyRSN
[7] = 0x0F;
299 pRSNIEs
->abyRSN
[8] = 0xAC;
300 if (pMgmt
->byCSSPK
== KEY_CTL_TKIP
)
301 pRSNIEs
->abyRSN
[9] = WLAN_11i_CSS_TKIP
;
302 else if (pMgmt
->byCSSPK
== KEY_CTL_CCMP
)
303 pRSNIEs
->abyRSN
[9] = WLAN_11i_CSS_CCMP
;
304 else if (pMgmt
->byCSSPK
== KEY_CTL_NONE
)
305 pRSNIEs
->abyRSN
[9] = WLAN_11i_CSS_USE_GROUP
;
307 pRSNIEs
->abyRSN
[9] = WLAN_11i_CSS_UNKNOWN
;
311 // Auth Key Management Suite
312 pRSNIEs
->abyRSN
[10] = 1;
313 pRSNIEs
->abyRSN
[11] = 0;
314 pRSNIEs
->abyRSN
[12] = 0x00;
315 pRSNIEs
->abyRSN
[13] = 0x0F;
316 pRSNIEs
->abyRSN
[14] = 0xAC;
317 if (pMgmt
->eAuthenMode
== WMAC_AUTH_WPA2PSK
)
318 pRSNIEs
->abyRSN
[15] = WLAN_11i_AKMSS_PSK
;
319 else if (pMgmt
->eAuthenMode
== WMAC_AUTH_WPA2
)
320 pRSNIEs
->abyRSN
[15] = WLAN_11i_AKMSS_802_1X
;
322 pRSNIEs
->abyRSN
[15] = WLAN_11i_AKMSS_UNKNOWN
;
327 if (pMgmt
->pCurrBSS
->sRSNCapObj
.bRSNCapExist
== true) {
328 memcpy(&pRSNIEs
->abyRSN
[16], &pMgmt
->pCurrBSS
->sRSNCapObj
.wRSNCap
, 2);
330 pRSNIEs
->abyRSN
[16] = 0;
331 pRSNIEs
->abyRSN
[17] = 0;
335 if ((pMgmt
->gsPMKIDCache
.BSSIDInfoCount
> 0) &&
337 (pMgmt
->eAuthenMode
== WMAC_AUTH_WPA2
)) {
339 pwPMKID
= (unsigned short *)(&pRSNIEs
->abyRSN
[18]); // Point to PMKID count
340 *pwPMKID
= 0; // Initialize PMKID count
341 pbyBuffer
= &pRSNIEs
->abyRSN
[20]; // Point to PMKID list
342 for (ii
= 0; ii
< pMgmt
->gsPMKIDCache
.BSSIDInfoCount
; ii
++) {
343 if (!memcmp(&pMgmt
->gsPMKIDCache
.BSSIDInfo
[ii
].abyBSSID
[0], pMgmt
->abyCurrBSSID
, ETH_ALEN
)) {
345 memcpy(pbyBuffer
, pMgmt
->gsPMKIDCache
.BSSIDInfo
[ii
].abyPMKID
, 16);
350 pRSNIEs
->len
+= (2 + (*pwPMKID
)*16);
352 pbyBuffer
= &pRSNIEs
->abyRSN
[18];
354 return pRSNIEs
->len
+ WLAN_IEHDR_LEN
;