Repository navigation
Conversation
…ows, never by 802.1X, with protected management frames where offered The network blocks kryptikd writes named no key management, so wpa_supplicant took its default, WPA-PSK and WPA-EAP: an access point offering 802.1X under a saved SSID was joined with EAP, a WPA3 network was never joined with SAE, and management frames went unprotected, so spoofed deauthentication always worked. Each block now names what was saved allows: a passphrase WPA-PSK, WPA-PSK-SHA256 and SAE, a raw key the first two (SAE needs the passphrase), and ieee80211w=1, protection wherever the access point offers it. The parser takes these lines only as kryptikd writes them for the block's psk, or a block from an older kryptikd with neither, and the net zone's start rewrites such a file once in today's form. The zones suite keeps its plain WPA2 access point, where the station joins by its pre-shared key without protection, then offers the same SSID with SAE alone and protection required, which the old file never joins.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What was wrong
The network blocks kryptikd writes for
kryptik wifi addnamed onlyssidandpsk. wpa_supplicant 2.12 then used its defaults (DEFAULT_KEY_MGMTinwpa_supplicant/config_ssid.h:21):WPA-PSK WPA-EAP, with no protected management frames. That meant:What changed
wifi.rs, the new form: each block names its key management from what was saved:key_mgmt=WPA-PSK WPA-PSK-SHA256 SAE;key_mgmt=WPA-PSK WPA-PSK-SHA256(SAE needs the passphrase);ieee80211w=1, protected management frames wherever the access point offers them (SAE always has them).No block names 802.1X.
wifi.rs, reading files back: the parser accepts those lines only exactly as kryptikd writes them for the block's psk. It also accepts a block with neither line, which is what an older kryptikd wrote. Anything else is refused, as before.spawn.rs, upgrades: when the net zone starts, kryptikd rewrites such an older file once in today's form, throughwifi::refresh, with the same 0400 owner. A current, absent or foreign file is left as it is.docs/design/net-zone.md's wireless section.How the run proves it
key_management_follows_what_was_savedchecks the lines per psk form and that none names EAP. It also checks the refusals: SAE for a raw key,key_mgmtwithoutieee80211wand the reverse,WPA-EAP, and a secondieee80211w.older_file_rewritten_with_key_managementchecks that an older file still reads, is rewritten 0400 once, is then left alone, and that a foreign file is not rewritten.wifi-wpa2-plain: after the existing joins, the access point lists the station with AKM00-0f-ac-2and no[MFP]. A saved passphrase still joins WPA2 without protection where none is offered.wifi-sae: the access point then offers the same SSID withkey_mgmt=SAEandieee80211w=2. Within 90 s it lists the station with AKM00-0f-ac-8and[MFP]. The old file's default key management has no SAE, so on the old code the station never joins and the check fails.