ifeq ($(LOCAL_VARIANT),full)
ifeq ($(SSL_VARIANT),openssl)
- DRIVER_MAKEOPTS += CONFIG_TLS=openssl
+ DRIVER_MAKEOPTS += CONFIG_TLS=openssl CONFIG_SAE=y
TARGET_LDFLAGS += -lcrypto -lssl
endif
ifeq ($(SSL_VARIANT),wolfssl)
- DRIVER_MAKEOPTS += CONFIG_TLS=wolfssl CONFIG_WPS_NFC=1
+ DRIVER_MAKEOPTS += CONFIG_TLS=wolfssl CONFIG_WPS_NFC=1 CONFIG_SAE=y
TARGET_LDFLAGS += -lwolfssl
endif
endif
}
hostapd_append_wpa_key_mgmt() {
- local auth_type="$(echo $auth_type | tr 'a-z' 'A-Z')"
+ local auth_type_l="$(echo $auth_type | tr 'a-z' 'A-Z')"
- append wpa_key_mgmt "WPA-$auth_type"
- [ "${ieee80211r:-0}" -gt 0 ] && append wpa_key_mgmt "FT-${auth_type}"
- [ "${ieee80211w:-0}" -gt 0 ] && append wpa_key_mgmt "WPA-${auth_type}-SHA256"
+ case "$auth_type" in
+ psk|eap)
+ append wpa_key_mgmt "WPA-$auth_type_l"
+ [ "${ieee80211r:-0}" -gt 0 ] && append wpa_key_mgmt "FT-${auth_type_l}"
+ [ "${ieee80211w:-0}" -gt 0 ] && append wpa_key_mgmt "WPA-${auth_type_l}-SHA256"
+ ;;
+ sae)
+ append wpa_key_mgmt "SAE"
+ [ "${ieee80211r:-0}" -gt 0 ] && append wpa_key_mgmt "FT-SAE"
+ ;;
+ psk-sae)
+ append wpa_key_mgmt "WPA-PSK"
+ [ "${ieee80211r:-0}" -gt 0 ] && append wpa_key_mgmt "FT-PSK"
+ [ "${ieee80211w:-0}" -gt 0 ] && append wpa_key_mgmt "WPA-PSK-SHA256"
+ append wpa_key_mgmt "SAE"
+ [ "${ieee80211r:-0}" -gt 0 ] && append wpa_key_mgmt "FT-SAE"
+ ;;
+ esac
}
hostapd_add_log_config() {
config_add_int mcast_rate
config_add_array basic_rate
config_add_array supported_rates
+
+ config_add_boolean sae_require_mfp
}
hostapd_set_bss_options() {
macfilter ssid wmm uapsd hidden short_preamble rsn_preauth \
iapp_interface eapol_version dynamic_vlan ieee80211w nasid \
acct_server acct_secret acct_port acct_interval \
- bss_load_update_period chan_util_avg_period
+ bss_load_update_period chan_util_avg_period sae_require_mfp
set_default isolate 0
set_default maxassoc 0
append bss_conf "radius_acct_interim_interval=$acct_interval" "$N"
}
+ case "$auth_type" in
+ sae)
+ set_default ieee80211w 2
+ set_default sae_require_mfp 1
+ ;;
+ psk-sae)
+ set_default ieee80211w 1
+ set_default sae_require_mfp 1
+ ;;
+ esac
+ [ -n "$sae_require_mfp" ] && append bss_conf "sae_require_mfp=$sae_require_mfp" "$N"
+
local vlan_possible=""
case "$auth_type" in
# with WPS enabled, we got to be in unconfigured state.
wps_not_configured=1
;;
- psk)
+ psk|sae|psk-sae)
json_get_vars key wpa_psk_file
if [ ${#key} -lt 8 ]; then
wireless_setup_vif_failed INVALID_WPA_PSK
hostapd_append_wep_key network_data
append network_data "wep_tx_keyidx=$wep_keyidx" "$N$T"
;;
- psk)
+ psk|sae|psk-sae)
local passphrase
if [ "$_w_mode" != "mesh" ]; then