diff options
| author | Sebastien Bacher <seb128@ubuntu.com> | 2019-03-12 15:16:42 +0100 |
|---|---|---|
| committer | Sebastien Bacher <seb128@ubuntu.com> | 2019-03-12 15:16:42 +0100 |
| commit | cc4ab276f923ded9f415c1c2bf192994367ab0bb (patch) | |
| tree | ac3a7775665992b27d07eb44186d38ff961a8cd7 /libnm-core/nm-setting-wireless-security.c | |
| parent | bb1cf58350bb34463e9ffc5f96ac4f9b6bf46d28 (diff) | |
| parent | dd428301eb6f02542015121d7b08d9997f137e50 (diff) | |
Update upstream source from tag 'upstream/1.15.91'
Update to upstream version '1.15.91' with Debian dir 74de38245314cab529c6c94cd9d0b874ce0c2994
Diffstat (limited to 'libnm-core/nm-setting-wireless-security.c')
| -rw-r--r-- | libnm-core/nm-setting-wireless-security.c | 62 |
1 files changed, 28 insertions, 34 deletions
diff --git a/libnm-core/nm-setting-wireless-security.c b/libnm-core/nm-setting-wireless-security.c index fe339d9e..f689751e 100644 --- a/libnm-core/nm-setting-wireless-security.c +++ b/libnm-core/nm-setting-wireless-security.c @@ -24,8 +24,6 @@ #include "nm-setting-wireless-security.h" -#include <string.h> - #include "nm-setting-8021x.h" #include "nm-utils.h" #include "nm-utils-private.h" @@ -863,6 +861,15 @@ need_secrets (NMSetting *setting) goto no_secrets; } + /* SAE, used in MESH and WPA3-Personal */ + if (strcmp (priv->key_mgmt, "sae") == 0) { + if (!priv->psk || !*priv->psk) { + g_ptr_array_add (secrets, NM_SETTING_WIRELESS_SECURITY_PSK); + return secrets; + } + goto no_secrets; + } + /* LEAP */ if ( priv->auth_alg && !strcmp (priv->auth_alg, "leap") @@ -894,7 +901,7 @@ verify (NMSetting *setting, NMConnection *connection, GError **error) { NMSettingWirelessSecurity *self = NM_SETTING_WIRELESS_SECURITY (setting); NMSettingWirelessSecurityPrivate *priv = NM_SETTING_WIRELESS_SECURITY_GET_PRIVATE (self); - const char *valid_key_mgmt[] = { "none", "ieee8021x", "wpa-none", "wpa-psk", "wpa-eap", NULL }; + const char *valid_key_mgmt[] = { "none", "ieee8021x", "wpa-none", "wpa-psk", "wpa-eap", "sae", NULL }; const char *valid_auth_algs[] = { "open", "shared", "leap", NULL }; const char *valid_protos[] = { "wpa", "rsn", NULL }; const char *valid_pairwise[] = { "tkip", "ccmp", NULL }; @@ -1072,36 +1079,22 @@ verify (NMSetting *setting, NMConnection *connection, GError **error) if ( NM_IN_SET (priv->pmf, NM_SETTING_WIRELESS_SECURITY_PMF_OPTIONAL, NM_SETTING_WIRELESS_SECURITY_PMF_REQUIRED) - && !NM_IN_STRSET (priv->key_mgmt, "wpa-eap", "wpa-psk")) { + && !NM_IN_STRSET (priv->key_mgmt, "wpa-eap", "wpa-psk", "sae")) { g_set_error (error, NM_CONNECTION_ERROR, NM_CONNECTION_ERROR_INVALID_PROPERTY, - _("'%s' can only be used with '%s=%s' or '%s=%s'"), - priv->pmf == NM_SETTING_WIRELESS_SECURITY_PMF_OPTIONAL ? "optional" : "required", - NM_SETTING_WIRELESS_SECURITY_KEY_MGMT, "wpa-eap", - NM_SETTING_WIRELESS_SECURITY_KEY_MGMT, "wpa-psk"); + _("'%s' can only be used with 'wpa-eap', 'wpa-psk' or 'sae' key management "), + priv->pmf == NM_SETTING_WIRELESS_SECURITY_PMF_OPTIONAL ? "optional" : "required"); g_prefix_error (error, "%s.%s: ", NM_SETTING_WIRELESS_SECURITY_SETTING_NAME, NM_SETTING_WIRELESS_SECURITY_PMF); return FALSE; } - /* WPS */ - if (priv->wps_method > NM_SETTING_WIRELESS_SECURITY_WPS_METHOD_PIN) { - g_set_error_literal (error, - NM_CONNECTION_ERROR, - NM_CONNECTION_ERROR_INVALID_PROPERTY, - _("property is invalid")); - g_prefix_error (error, "%s.%s: ", NM_SETTING_WIRELESS_SECURITY_SETTING_NAME, NM_SETTING_WIRELESS_SECURITY_WPS_METHOD); + if (!_nm_utils_wps_method_validate (priv->wps_method, + NM_SETTING_WIRELESS_SECURITY_SETTING_NAME, + NM_SETTING_WIRELESS_SECURITY_WPS_METHOD, + FALSE, + error)) return FALSE; - } - - if (priv->wps_method & NM_SETTING_WIRELESS_SECURITY_WPS_METHOD_DISABLED && priv->wps_method != NM_SETTING_WIRELESS_SECURITY_WPS_METHOD_DISABLED) { - g_set_error_literal (error, - NM_CONNECTION_ERROR, - NM_CONNECTION_ERROR_INVALID_PROPERTY, - _("can't be simultaneously disabled and enabled")); - g_prefix_error (error, "%s.%s: ", NM_SETTING_WIRELESS_SECURITY_SETTING_NAME, NM_SETTING_WIRELESS_SECURITY_WPS_METHOD); - return FALSE; - } return TRUE; } @@ -1151,7 +1144,9 @@ verify_secrets (NMSetting *setting, NMConnection *connection, GError **error) return FALSE; /* WPA-PSK */ - if (priv->psk && !nm_utils_wpa_psk_valid (priv->psk)) { + if ( priv->psk + && strcmp (priv->key_mgmt, "sae") != 0 + && !nm_utils_wpa_psk_valid (priv->psk)) { g_set_error_literal (error, NM_CONNECTION_ERROR, NM_CONNECTION_ERROR_INVALID_PROPERTY, @@ -1459,8 +1454,8 @@ nm_setting_wireless_security_class_init (NMSettingWirelessSecurityClass *klass) * * Key management used for the connection. One of "none" (WEP), "ieee8021x" * (Dynamic WEP), "wpa-none" (Ad-Hoc WPA-PSK), "wpa-psk" (infrastructure - * WPA-PSK), or "wpa-eap" (WPA-Enterprise). This property must be set for - * any Wi-Fi connection that uses security. + * WPA-PSK), "sae" (SAE) or "wpa-eap" (WPA-Enterprise). + * This property must be set for any Wi-Fi connection that uses security. **/ /* ---ifcfg-rh--- * property: key-mgmt @@ -1734,12 +1729,11 @@ nm_setting_wireless_security_class_init (NMSettingWirelessSecurityClass *klass) /** * NMSettingWirelessSecurity:psk: * - * Pre-Shared-Key for WPA networks. If the key is 64-characters long, it - * must contain only hexadecimal characters and is interpreted as a - * hexadecimal WPA key. Otherwise, the key must be between 8 and 63 ASCII - * characters (as specified in the 802.11i standard) and is interpreted as a - * WPA passphrase, and is hashed to derive the actual WPA-PSK used when - * connecting to the Wi-Fi network. + * Pre-Shared-Key for WPA networks. For WPA-PSK, it's either an ASCII + * passphrase of 8 to 63 characters that is (as specified in the 802.11i + * standard) hashed to derive the actual key, or the key in form of 64 + * hexadecimal character. The WPA3-Personal networks use a passphrase + * of any length for SAE authentication. **/ /* ---ifcfg-rh--- * property: psk |