139beb93cSSam Leffler /* 239beb93cSSam Leffler * EAP peer method: EAP-GTC (RFC 3748) 339beb93cSSam Leffler * Copyright (c) 2004-2006, Jouni Malinen <j@w1.fi> 439beb93cSSam Leffler * 5f05cddf9SRui Paulo * This software may be distributed under the terms of the BSD license. 6f05cddf9SRui Paulo * See README for more details. 739beb93cSSam Leffler */ 839beb93cSSam Leffler 939beb93cSSam Leffler #include "includes.h" 1039beb93cSSam Leffler 1139beb93cSSam Leffler #include "common.h" 1239beb93cSSam Leffler #include "eap_i.h" 1339beb93cSSam Leffler 1439beb93cSSam Leffler 1539beb93cSSam Leffler struct eap_gtc_data { 1639beb93cSSam Leffler int prefix; 1739beb93cSSam Leffler }; 1839beb93cSSam Leffler 1939beb93cSSam Leffler 2039beb93cSSam Leffler static void * eap_gtc_init(struct eap_sm *sm) 2139beb93cSSam Leffler { 2239beb93cSSam Leffler struct eap_gtc_data *data; 2339beb93cSSam Leffler data = os_zalloc(sizeof(*data)); 2439beb93cSSam Leffler if (data == NULL) 2539beb93cSSam Leffler return NULL; 2639beb93cSSam Leffler 2739beb93cSSam Leffler if (sm->m && sm->m->vendor == EAP_VENDOR_IETF && 2839beb93cSSam Leffler sm->m->method == EAP_TYPE_FAST) { 2939beb93cSSam Leffler wpa_printf(MSG_DEBUG, "EAP-GTC: EAP-FAST tunnel - use prefix " 3039beb93cSSam Leffler "with challenge/response"); 3139beb93cSSam Leffler data->prefix = 1; 3239beb93cSSam Leffler } 3339beb93cSSam Leffler return data; 3439beb93cSSam Leffler } 3539beb93cSSam Leffler 3639beb93cSSam Leffler 3739beb93cSSam Leffler static void eap_gtc_deinit(struct eap_sm *sm, void *priv) 3839beb93cSSam Leffler { 3939beb93cSSam Leffler struct eap_gtc_data *data = priv; 4039beb93cSSam Leffler os_free(data); 4139beb93cSSam Leffler } 4239beb93cSSam Leffler 4339beb93cSSam Leffler 4439beb93cSSam Leffler static struct wpabuf * eap_gtc_process(struct eap_sm *sm, void *priv, 4539beb93cSSam Leffler struct eap_method_ret *ret, 4639beb93cSSam Leffler const struct wpabuf *reqData) 4739beb93cSSam Leffler { 4839beb93cSSam Leffler struct eap_gtc_data *data = priv; 4939beb93cSSam Leffler struct wpabuf *resp; 5039beb93cSSam Leffler const u8 *pos, *password, *identity; 5139beb93cSSam Leffler size_t password_len, identity_len, len, plen; 5239beb93cSSam Leffler int otp; 5339beb93cSSam Leffler u8 id; 5439beb93cSSam Leffler 5539beb93cSSam Leffler pos = eap_hdr_validate(EAP_VENDOR_IETF, EAP_TYPE_GTC, reqData, &len); 5639beb93cSSam Leffler if (pos == NULL) { 5739beb93cSSam Leffler ret->ignore = TRUE; 5839beb93cSSam Leffler return NULL; 5939beb93cSSam Leffler } 6039beb93cSSam Leffler id = eap_get_id(reqData); 6139beb93cSSam Leffler 6239beb93cSSam Leffler wpa_hexdump_ascii(MSG_MSGDUMP, "EAP-GTC: Request message", pos, len); 6339beb93cSSam Leffler if (data->prefix && 6439beb93cSSam Leffler (len < 10 || os_memcmp(pos, "CHALLENGE=", 10) != 0)) { 6539beb93cSSam Leffler wpa_printf(MSG_DEBUG, "EAP-GTC: Challenge did not start with " 6639beb93cSSam Leffler "expected prefix"); 6739beb93cSSam Leffler 6839beb93cSSam Leffler /* Send an empty response in order to allow tunneled 6939beb93cSSam Leffler * acknowledgement of the failure. This will also cover the 7039beb93cSSam Leffler * error case which seems to use EAP-MSCHAPv2 like error 7139beb93cSSam Leffler * reporting with EAP-GTC inside EAP-FAST tunnel. */ 7239beb93cSSam Leffler resp = eap_msg_alloc(EAP_VENDOR_IETF, EAP_TYPE_GTC, 7339beb93cSSam Leffler 0, EAP_CODE_RESPONSE, id); 7439beb93cSSam Leffler return resp; 7539beb93cSSam Leffler } 7639beb93cSSam Leffler 7739beb93cSSam Leffler password = eap_get_config_otp(sm, &password_len); 7839beb93cSSam Leffler if (password) 7939beb93cSSam Leffler otp = 1; 8039beb93cSSam Leffler else { 8139beb93cSSam Leffler password = eap_get_config_password(sm, &password_len); 8239beb93cSSam Leffler otp = 0; 8339beb93cSSam Leffler } 8439beb93cSSam Leffler 8539beb93cSSam Leffler if (password == NULL) { 8639beb93cSSam Leffler wpa_printf(MSG_INFO, "EAP-GTC: Password not configured"); 8739beb93cSSam Leffler eap_sm_request_otp(sm, (const char *) pos, len); 8839beb93cSSam Leffler ret->ignore = TRUE; 8939beb93cSSam Leffler return NULL; 9039beb93cSSam Leffler } 9139beb93cSSam Leffler 9239beb93cSSam Leffler ret->ignore = FALSE; 9339beb93cSSam Leffler 9439beb93cSSam Leffler ret->methodState = data->prefix ? METHOD_MAY_CONT : METHOD_DONE; 9539beb93cSSam Leffler ret->decision = DECISION_COND_SUCC; 9639beb93cSSam Leffler ret->allowNotifications = FALSE; 9739beb93cSSam Leffler 9839beb93cSSam Leffler plen = password_len; 9939beb93cSSam Leffler identity = eap_get_config_identity(sm, &identity_len); 10039beb93cSSam Leffler if (identity == NULL) 10139beb93cSSam Leffler return NULL; 10239beb93cSSam Leffler if (data->prefix) 10339beb93cSSam Leffler plen += 9 + identity_len + 1; 10439beb93cSSam Leffler resp = eap_msg_alloc(EAP_VENDOR_IETF, EAP_TYPE_GTC, plen, 10539beb93cSSam Leffler EAP_CODE_RESPONSE, id); 10639beb93cSSam Leffler if (resp == NULL) 10739beb93cSSam Leffler return NULL; 10839beb93cSSam Leffler if (data->prefix) { 10939beb93cSSam Leffler wpabuf_put_data(resp, "RESPONSE=", 9); 11039beb93cSSam Leffler wpabuf_put_data(resp, identity, identity_len); 11139beb93cSSam Leffler wpabuf_put_u8(resp, '\0'); 11239beb93cSSam Leffler } 11339beb93cSSam Leffler wpabuf_put_data(resp, password, password_len); 11439beb93cSSam Leffler wpa_hexdump_ascii_key(MSG_MSGDUMP, "EAP-GTC: Response", 11539beb93cSSam Leffler wpabuf_head_u8(resp) + sizeof(struct eap_hdr) + 11639beb93cSSam Leffler 1, plen); 11739beb93cSSam Leffler 11839beb93cSSam Leffler if (otp) { 11939beb93cSSam Leffler wpa_printf(MSG_DEBUG, "EAP-GTC: Forgetting used password"); 12039beb93cSSam Leffler eap_clear_config_otp(sm); 12139beb93cSSam Leffler } 12239beb93cSSam Leffler 12339beb93cSSam Leffler return resp; 12439beb93cSSam Leffler } 12539beb93cSSam Leffler 12639beb93cSSam Leffler 12739beb93cSSam Leffler int eap_peer_gtc_register(void) 12839beb93cSSam Leffler { 12939beb93cSSam Leffler struct eap_method *eap; 13039beb93cSSam Leffler 13139beb93cSSam Leffler eap = eap_peer_method_alloc(EAP_PEER_METHOD_INTERFACE_VERSION, 13239beb93cSSam Leffler EAP_VENDOR_IETF, EAP_TYPE_GTC, "GTC"); 13339beb93cSSam Leffler if (eap == NULL) 13439beb93cSSam Leffler return -1; 13539beb93cSSam Leffler 13639beb93cSSam Leffler eap->init = eap_gtc_init; 13739beb93cSSam Leffler eap->deinit = eap_gtc_deinit; 13839beb93cSSam Leffler eap->process = eap_gtc_process; 13939beb93cSSam Leffler 140*780fb4a2SCy Schubert return eap_peer_method_register(eap); 14139beb93cSSam Leffler } 142