hostapd: introduce new default-off option "auth_cache" which controls PMKSA and Oppor...
[openwrt/openwrt.git] / package / hostapd / files / hostapd.sh
index 3fbe734871341f7e3b6773d90de2244298daed75..fc84ec50fc86d425789165718d70386fce588e3e 100644 (file)
@@ -1,10 +1,13 @@
 hostapd_set_bss_options() {
        local var="$1"
        local vif="$2"
-       local enc wpa_group_rekey wps_possible
+       local enc wep_rekey wpa_group_rekey wpa_pair_rekey wpa_master_rekey wps_possible
 
        config_get enc "$vif" encryption
-       config_get wpa_group_rekey "$vif" wpa_group_rekey
+       config_get wep_rekey        "$vif" wep_rekey        # 300
+       config_get wpa_group_rekey  "$vif" wpa_group_rekey  # 300
+       config_get wpa_pair_rekey   "$vif" wpa_pair_rekey   # 300
+       config_get wpa_master_rekey "$vif" wpa_master_rekey # 640
        config_get_bool ap_isolate "$vif" isolate 0
 
        config_get device "$vif" device
@@ -64,6 +67,9 @@ hostapd_set_bss_options() {
                                append "$var" "wpa_passphrase=$psk" "$N"
                        fi
                        wps_possible=1
+                       [ -n "$wpa_group_rekey"  ] && append "$var" "wpa_group_rekey=$wpa_group_rekey" "$N"
+                       [ -n "$wpa_pair_rekey"   ] && append "$var" "wpa_ptk_rekey=$wpa_pair_rekey"    "$N"
+                       [ -n "$wpa_master_rekey" ] && append "$var" "wpa_gmk_rekey=$wpa_master_rekey"  "$N"
                ;;
                *wpa*)
                        # required fields? formats?
@@ -78,6 +84,9 @@ hostapd_set_bss_options() {
                        config_get auth_secret "$vif" auth_secret
                        [ -z "$auth_secret" ] && config_get auth_secret "$vif" key
                        append "$var" "auth_server_shared_secret=$auth_secret" "$N"
+                       config_get_bool auth_cache "$vif" auth_cache 0
+                       [ "$auth_cache" -gt 0 ] || append "$var" "disable_pmksa_caching=1" "$N"
+                       [ "$auth_cache" -gt 0 ] || append "$var" "okc=0" "$N"
                        config_get acct_server "$vif" acct_server
                        [ -n "$acct_server" ] && append "$var" "acct_server_addr=$acct_server" "$N"
                        config_get acct_port "$vif" acct_port
@@ -88,11 +97,11 @@ hostapd_set_bss_options() {
                        config_get nasid "$vif" nasid
                        append "$var" "nas_identifier=$nasid" "$N"
                        append "$var" "eapol_key_index_workaround=1" "$N"
-                       append "$var" "radius_acct_interim_interval=300" "$N"
                        append "$var" "ieee8021x=1" "$N"
                        append "$var" "wpa_key_mgmt=WPA-EAP" "$N"
-                       append "$var" "wpa_group_rekey=300" "$N"
-                       append "$var" "wpa_gmk_rekey=640" "$N"
+                       [ -n "$wpa_group_rekey"  ] && append "$var" "wpa_group_rekey=$wpa_group_rekey" "$N"
+                       [ -n "$wpa_pair_rekey"   ] && append "$var" "wpa_ptk_rekey=$wpa_pair_rekey"    "$N"
+                       [ -n "$wpa_master_rekey" ] && append "$var" "wpa_gmk_rekey=$wpa_master_rekey"  "$N"
                ;;
                *wep*)
                        config_get key "$vif" key
@@ -111,6 +120,7 @@ hostapd_set_bss_options() {
                                *)
                                        append "$var" "wep_key0=$(prepare_key_wep "$key")" "$N"
                                        append "$var" "wep_default_key=0" "$N"
+                                       [ -n "$wep_rekey" ] && append "$var" "wep_rekey_period=$wep_rekey" "$N"
                                ;;
                        esac
                        case "$enc" in
@@ -167,7 +177,7 @@ hostapd_set_bss_options() {
        if [ "$wpa" -ge "2" ]
        then
                # RSN -> allow preauthentication
-               config_get rsn_preauth "$vif" rsn_preauth
+               config_get_bool rsn_preauth "$vif" rsn_preauth "$auth_cache"
                if [ -n "$bridge" -a "$rsn_preauth" = 1 ]
                then
                        append "$var" "rsn_preauth=1" "$N"