|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
From 008e224dbb518f44aac46b0c8e55448bd907e43d Mon Sep 17 00:00:00 2001
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
Message-Id: <008e224dbb518f44aac46b0c8e55448bd907e43d.1488376601.git.dcaratti@redhat.com>
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
From: Sabrina Dubroca <sd@queasysnail.net>
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
Date: Wed, 2 Nov 2016 16:38:36 +0100
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
Subject: [PATCH] mka: Disable peer detection timeout for PSK mode
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
The first peer may take a long time to come up. In PSK mode we are
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
basically in a p2p system, and we cannot know when a peer will join the
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
key exchange. Wait indefinitely, and let the administrator decide if
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
they want to abort.
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
Signed-off-by: Sabrina Dubroca <sd@queasysnail.net>
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
---
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
src/pae/ieee802_1x_kay.c | 12 ++++++++++--
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
1 file changed, 10 insertions(+), 2 deletions(-)
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
diff --git a/src/pae/ieee802_1x_kay.c b/src/pae/ieee802_1x_kay.c
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
index 2841b10..19b2c2f 100644
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
--- a/src/pae/ieee802_1x_kay.c
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
+++ b/src/pae/ieee802_1x_kay.c
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
@@ -3339,8 +3339,16 @@ ieee802_1x_kay_create_mka(struct ieee802_1x_kay *kay, struct mka_key_name *ckn,
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
usecs = os_random() % (MKA_HELLO_TIME * 1000);
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
eloop_register_timeout(0, usecs, ieee802_1x_participant_timer,
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
participant, NULL);
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
- participant->mka_life = MKA_LIFE_TIME / 1000 + time(NULL) +
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
- usecs / 1000000;
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
+
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
+ /* Disable MKA lifetime for PSK mode.
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
+ * The peer(s) can take a long time to come up, because we
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
+ * create a "standby" MKA, and we need it to remain live until
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
+ * some peer appears.
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
+ */
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
+ if (mode != PSK) {
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
+ participant->mka_life = MKA_LIFE_TIME / 1000 + time(NULL) +
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
+ usecs / 1000000;
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
+ }
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
return participant;
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
--
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
2.7.4
|
|
![](https://seccdn.libravatar.org/avatar/9c80e75af4e6e1de662a4c2316afef74a76712084faadbeafbce9ee4b039d721?s=16&d=retro) |
fb7f665 |
|