2 * WPA Supplicant / EAP-TLV (draft-josefsson-pppext-eap-tls-eap-07.txt)
3 * Copyright (c) 2004-2005, Jouni Malinen <jkmaline@cc.hut.fi>
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License version 2 as
7 * published by the Free Software Foundation.
9 * Alternatively, this software may be distributed under the terms of BSD
12 * See README and COPYING for more details.
20 #include "wpa_supplicant.h"
26 * eap_tlv_build_nak - Build EAP-TLV NAK message
27 * @id: EAP identifier for the header
28 * @nak_type: TLV type (EAP_TLV_*)
29 * @resp_len: Buffer for returning the response length
30 * Returns: Buffer to the allocated EAP-TLV NAK message or %NULL on failure
32 * This funtion builds an EAP-TLV NAK message. The caller is responsible for
33 * freeing the returned buffer.
35 u8 * eap_tlv_build_nak(int id, u16 nak_type, size_t *resp_len)
40 *resp_len = sizeof(struct eap_hdr) + 1 + 10;
41 hdr = malloc(*resp_len);
45 hdr->code = EAP_CODE_RESPONSE;
47 hdr->length = host_to_be16(*resp_len);
48 pos = (u8 *) (hdr + 1);
49 *pos++ = EAP_TYPE_TLV;
50 *pos++ = 0x80; /* Mandatory */
51 *pos++ = EAP_TLV_NAK_TLV;
61 WPA_PUT_BE16(pos, nak_type);
68 * eap_tlv_build_result - Build EAP-TLV Result message
69 * @id: EAP identifier for the header
70 * @status: Status (EAP_TLV_RESULT_SUCCESS or EAP_TLV_RESULT_FAILURE)
71 * @resp_len: Buffer for returning the response length
72 * Returns: Buffer to the allocated EAP-TLV Result message or %NULL on failure
74 * This funtion builds an EAP-TLV Result message. The caller is responsible for
75 * freeing the returned buffer.
77 u8 * eap_tlv_build_result(int id, u16 status, size_t *resp_len)
82 *resp_len = sizeof(struct eap_hdr) + 1 + 6;
83 hdr = malloc(*resp_len);
87 hdr->code = EAP_CODE_RESPONSE;
89 hdr->length = host_to_be16(*resp_len);
90 pos = (u8 *) (hdr + 1);
91 *pos++ = EAP_TYPE_TLV;
92 *pos++ = 0x80; /* Mandatory */
93 *pos++ = EAP_TLV_RESULT_TLV;
98 WPA_PUT_BE16(pos, status);
105 * eap_tlv_process - Process a received EAP-TLV message and generate a response
106 * @sm: Pointer to EAP state machine allocated with eap_sm_init()
107 * @ret: Return values from EAP request validation and processing
108 * @hdr: EAP-TLV request to be processed. The caller must have validated that
109 * the buffer is large enough to contain full request (hdr->length bytes) and
110 * that the EAP type is EAP_TYPE_TLV.
111 * @resp: Buffer to return a pointer to the allocated response message. This
112 * field should be initialized to %NULL before the call. The value will be
113 * updated if a response message is generated. The caller is responsible for
114 * freeing the allocated message.
115 * @resp_len: Buffer for returning the response length
116 * Returns: 0 on success, -1 on failure
118 int eap_tlv_process(struct eap_sm *sm, struct eap_method_ret *ret,
119 const struct eap_hdr *hdr, u8 **resp, size_t *resp_len)
123 const u8 *result_tlv = NULL;
124 size_t result_tlv_len = 0;
125 int tlv_type, mandatory, tlv_len;
128 left = be_to_host16(hdr->length) - sizeof(struct eap_hdr) - 1;
129 pos = (const u8 *) (hdr + 1);
131 wpa_hexdump(MSG_DEBUG, "EAP-TLV: Received TLVs", pos, left);
133 mandatory = !!(pos[0] & 0x80);
134 tlv_type = WPA_GET_BE16(pos) & 0x3fff;
136 tlv_len = WPA_GET_BE16(pos);
139 if (tlv_len > left) {
140 wpa_printf(MSG_DEBUG, "EAP-TLV: TLV underrun "
141 "(tlv_len=%d left=%lu)", tlv_len,
142 (unsigned long) left);
146 case EAP_TLV_RESULT_TLV:
148 result_tlv_len = tlv_len;
151 wpa_printf(MSG_DEBUG, "EAP-TLV: Unsupported TLV Type "
153 mandatory ? " (mandatory)" : "");
155 /* NAK TLV and ignore all TLVs in this packet.
157 *resp = eap_tlv_build_nak(hdr->identifier,
159 return *resp == NULL ? -1 : 0;
161 /* Ignore this TLV, but process other TLVs */
169 wpa_printf(MSG_DEBUG, "EAP-TLV: Last TLV too short in "
170 "Request (left=%lu)", (unsigned long) left);
174 /* Process supported TLVs */
176 int status, resp_status;
177 wpa_hexdump(MSG_DEBUG, "EAP-TLV: Result TLV",
178 result_tlv, result_tlv_len);
179 if (result_tlv_len < 2) {
180 wpa_printf(MSG_INFO, "EAP-TLV: Too short Result TLV "
182 (unsigned long) result_tlv_len);
185 status = WPA_GET_BE16(result_tlv);
186 if (status == EAP_TLV_RESULT_SUCCESS) {
187 wpa_printf(MSG_INFO, "EAP-TLV: TLV Result - Success "
188 "- EAP-TLV/Phase2 Completed");
189 resp_status = EAP_TLV_RESULT_SUCCESS;
190 ret->decision = DECISION_UNCOND_SUCC;
191 } else if (status == EAP_TLV_RESULT_FAILURE) {
192 wpa_printf(MSG_INFO, "EAP-TLV: TLV Result - Failure");
193 resp_status = EAP_TLV_RESULT_FAILURE;
194 ret->decision = DECISION_FAIL;
196 wpa_printf(MSG_INFO, "EAP-TLV: Unknown TLV Result "
197 "Status %d", status);
198 resp_status = EAP_TLV_RESULT_FAILURE;
199 ret->decision = DECISION_FAIL;
201 ret->methodState = METHOD_DONE;
203 *resp = eap_tlv_build_result(hdr->identifier, resp_status,