13ff40c12SJohn Marino /*
23ff40c12SJohn Marino * hostapd / EAP-MD5 server
33ff40c12SJohn Marino * Copyright (c) 2004-2012, Jouni Malinen <j@w1.fi>
43ff40c12SJohn Marino *
53ff40c12SJohn Marino * This software may be distributed under the terms of the BSD license.
63ff40c12SJohn Marino * See README for more details.
73ff40c12SJohn Marino */
83ff40c12SJohn Marino
93ff40c12SJohn Marino #include "includes.h"
103ff40c12SJohn Marino
113ff40c12SJohn Marino #include "common.h"
123ff40c12SJohn Marino #include "crypto/random.h"
133ff40c12SJohn Marino #include "eap_i.h"
143ff40c12SJohn Marino #include "eap_common/chap.h"
153ff40c12SJohn Marino
163ff40c12SJohn Marino
173ff40c12SJohn Marino #define CHALLENGE_LEN 16
183ff40c12SJohn Marino
193ff40c12SJohn Marino struct eap_md5_data {
203ff40c12SJohn Marino u8 challenge[CHALLENGE_LEN];
213ff40c12SJohn Marino enum { CONTINUE, SUCCESS, FAILURE } state;
223ff40c12SJohn Marino };
233ff40c12SJohn Marino
243ff40c12SJohn Marino
eap_md5_init(struct eap_sm * sm)253ff40c12SJohn Marino static void * eap_md5_init(struct eap_sm *sm)
263ff40c12SJohn Marino {
273ff40c12SJohn Marino struct eap_md5_data *data;
283ff40c12SJohn Marino
293ff40c12SJohn Marino data = os_zalloc(sizeof(*data));
303ff40c12SJohn Marino if (data == NULL)
313ff40c12SJohn Marino return NULL;
323ff40c12SJohn Marino data->state = CONTINUE;
333ff40c12SJohn Marino
343ff40c12SJohn Marino return data;
353ff40c12SJohn Marino }
363ff40c12SJohn Marino
373ff40c12SJohn Marino
eap_md5_reset(struct eap_sm * sm,void * priv)383ff40c12SJohn Marino static void eap_md5_reset(struct eap_sm *sm, void *priv)
393ff40c12SJohn Marino {
403ff40c12SJohn Marino struct eap_md5_data *data = priv;
413ff40c12SJohn Marino os_free(data);
423ff40c12SJohn Marino }
433ff40c12SJohn Marino
443ff40c12SJohn Marino
eap_md5_buildReq(struct eap_sm * sm,void * priv,u8 id)453ff40c12SJohn Marino static struct wpabuf * eap_md5_buildReq(struct eap_sm *sm, void *priv, u8 id)
463ff40c12SJohn Marino {
473ff40c12SJohn Marino struct eap_md5_data *data = priv;
483ff40c12SJohn Marino struct wpabuf *req;
493ff40c12SJohn Marino
503ff40c12SJohn Marino if (random_get_bytes(data->challenge, CHALLENGE_LEN)) {
513ff40c12SJohn Marino wpa_printf(MSG_ERROR, "EAP-MD5: Failed to get random data");
523ff40c12SJohn Marino data->state = FAILURE;
533ff40c12SJohn Marino return NULL;
543ff40c12SJohn Marino }
553ff40c12SJohn Marino
563ff40c12SJohn Marino req = eap_msg_alloc(EAP_VENDOR_IETF, EAP_TYPE_MD5, 1 + CHALLENGE_LEN,
573ff40c12SJohn Marino EAP_CODE_REQUEST, id);
583ff40c12SJohn Marino if (req == NULL) {
593ff40c12SJohn Marino wpa_printf(MSG_ERROR, "EAP-MD5: Failed to allocate memory for "
603ff40c12SJohn Marino "request");
613ff40c12SJohn Marino data->state = FAILURE;
623ff40c12SJohn Marino return NULL;
633ff40c12SJohn Marino }
643ff40c12SJohn Marino
653ff40c12SJohn Marino wpabuf_put_u8(req, CHALLENGE_LEN);
663ff40c12SJohn Marino wpabuf_put_data(req, data->challenge, CHALLENGE_LEN);
673ff40c12SJohn Marino wpa_hexdump(MSG_MSGDUMP, "EAP-MD5: Challenge", data->challenge,
683ff40c12SJohn Marino CHALLENGE_LEN);
693ff40c12SJohn Marino
703ff40c12SJohn Marino data->state = CONTINUE;
713ff40c12SJohn Marino
723ff40c12SJohn Marino return req;
733ff40c12SJohn Marino }
743ff40c12SJohn Marino
753ff40c12SJohn Marino
eap_md5_check(struct eap_sm * sm,void * priv,struct wpabuf * respData)763ff40c12SJohn Marino static Boolean eap_md5_check(struct eap_sm *sm, void *priv,
773ff40c12SJohn Marino struct wpabuf *respData)
783ff40c12SJohn Marino {
793ff40c12SJohn Marino const u8 *pos;
803ff40c12SJohn Marino size_t len;
813ff40c12SJohn Marino
823ff40c12SJohn Marino pos = eap_hdr_validate(EAP_VENDOR_IETF, EAP_TYPE_MD5, respData, &len);
833ff40c12SJohn Marino if (pos == NULL || len < 1) {
843ff40c12SJohn Marino wpa_printf(MSG_INFO, "EAP-MD5: Invalid frame");
853ff40c12SJohn Marino return TRUE;
863ff40c12SJohn Marino }
873ff40c12SJohn Marino if (*pos != CHAP_MD5_LEN || 1 + CHAP_MD5_LEN > len) {
883ff40c12SJohn Marino wpa_printf(MSG_INFO, "EAP-MD5: Invalid response "
893ff40c12SJohn Marino "(response_len=%d payload_len=%lu",
903ff40c12SJohn Marino *pos, (unsigned long) len);
913ff40c12SJohn Marino return TRUE;
923ff40c12SJohn Marino }
933ff40c12SJohn Marino
943ff40c12SJohn Marino return FALSE;
953ff40c12SJohn Marino }
963ff40c12SJohn Marino
973ff40c12SJohn Marino
eap_md5_process(struct eap_sm * sm,void * priv,struct wpabuf * respData)983ff40c12SJohn Marino static void eap_md5_process(struct eap_sm *sm, void *priv,
993ff40c12SJohn Marino struct wpabuf *respData)
1003ff40c12SJohn Marino {
1013ff40c12SJohn Marino struct eap_md5_data *data = priv;
1023ff40c12SJohn Marino const u8 *pos;
1033ff40c12SJohn Marino size_t plen;
1043ff40c12SJohn Marino u8 hash[CHAP_MD5_LEN], id;
1053ff40c12SJohn Marino
1063ff40c12SJohn Marino if (sm->user == NULL || sm->user->password == NULL ||
1073ff40c12SJohn Marino sm->user->password_hash) {
1083ff40c12SJohn Marino wpa_printf(MSG_INFO, "EAP-MD5: Plaintext password not "
1093ff40c12SJohn Marino "configured");
1103ff40c12SJohn Marino data->state = FAILURE;
1113ff40c12SJohn Marino return;
1123ff40c12SJohn Marino }
1133ff40c12SJohn Marino
1143ff40c12SJohn Marino pos = eap_hdr_validate(EAP_VENDOR_IETF, EAP_TYPE_MD5, respData, &plen);
1153ff40c12SJohn Marino if (pos == NULL || *pos != CHAP_MD5_LEN || plen < 1 + CHAP_MD5_LEN)
1163ff40c12SJohn Marino return; /* Should not happen - frame already validated */
1173ff40c12SJohn Marino
1183ff40c12SJohn Marino pos++; /* Skip response len */
1193ff40c12SJohn Marino wpa_hexdump(MSG_MSGDUMP, "EAP-MD5: Response", pos, CHAP_MD5_LEN);
1203ff40c12SJohn Marino
1213ff40c12SJohn Marino id = eap_get_id(respData);
1223ff40c12SJohn Marino if (chap_md5(id, sm->user->password, sm->user->password_len,
1233ff40c12SJohn Marino data->challenge, CHALLENGE_LEN, hash)) {
1243ff40c12SJohn Marino wpa_printf(MSG_INFO, "EAP-MD5: CHAP MD5 operation failed");
1253ff40c12SJohn Marino data->state = FAILURE;
1263ff40c12SJohn Marino return;
1273ff40c12SJohn Marino }
1283ff40c12SJohn Marino
129*a1157835SDaniel Fojt if (os_memcmp_const(hash, pos, CHAP_MD5_LEN) == 0) {
1303ff40c12SJohn Marino wpa_printf(MSG_DEBUG, "EAP-MD5: Done - Success");
1313ff40c12SJohn Marino data->state = SUCCESS;
1323ff40c12SJohn Marino } else {
1333ff40c12SJohn Marino wpa_printf(MSG_DEBUG, "EAP-MD5: Done - Failure");
1343ff40c12SJohn Marino data->state = FAILURE;
1353ff40c12SJohn Marino }
1363ff40c12SJohn Marino }
1373ff40c12SJohn Marino
1383ff40c12SJohn Marino
eap_md5_isDone(struct eap_sm * sm,void * priv)1393ff40c12SJohn Marino static Boolean eap_md5_isDone(struct eap_sm *sm, void *priv)
1403ff40c12SJohn Marino {
1413ff40c12SJohn Marino struct eap_md5_data *data = priv;
1423ff40c12SJohn Marino return data->state != CONTINUE;
1433ff40c12SJohn Marino }
1443ff40c12SJohn Marino
1453ff40c12SJohn Marino
eap_md5_isSuccess(struct eap_sm * sm,void * priv)1463ff40c12SJohn Marino static Boolean eap_md5_isSuccess(struct eap_sm *sm, void *priv)
1473ff40c12SJohn Marino {
1483ff40c12SJohn Marino struct eap_md5_data *data = priv;
1493ff40c12SJohn Marino return data->state == SUCCESS;
1503ff40c12SJohn Marino }
1513ff40c12SJohn Marino
1523ff40c12SJohn Marino
eap_server_md5_register(void)1533ff40c12SJohn Marino int eap_server_md5_register(void)
1543ff40c12SJohn Marino {
1553ff40c12SJohn Marino struct eap_method *eap;
1563ff40c12SJohn Marino
1573ff40c12SJohn Marino eap = eap_server_method_alloc(EAP_SERVER_METHOD_INTERFACE_VERSION,
1583ff40c12SJohn Marino EAP_VENDOR_IETF, EAP_TYPE_MD5, "MD5");
1593ff40c12SJohn Marino if (eap == NULL)
1603ff40c12SJohn Marino return -1;
1613ff40c12SJohn Marino
1623ff40c12SJohn Marino eap->init = eap_md5_init;
1633ff40c12SJohn Marino eap->reset = eap_md5_reset;
1643ff40c12SJohn Marino eap->buildReq = eap_md5_buildReq;
1653ff40c12SJohn Marino eap->check = eap_md5_check;
1663ff40c12SJohn Marino eap->process = eap_md5_process;
1673ff40c12SJohn Marino eap->isDone = eap_md5_isDone;
1683ff40c12SJohn Marino eap->isSuccess = eap_md5_isSuccess;
1693ff40c12SJohn Marino
170*a1157835SDaniel Fojt return eap_server_method_register(eap);
1713ff40c12SJohn Marino }
172