178 EVP_MD_CTX *hmac_ctx;
182 uint8_t mip_rk_1[EVP_MAX_MD_SIZE], mip_rk_2[EVP_MAX_MD_SIZE];
183 uint8_t mip_rk[2 * EVP_MAX_MD_SIZE];
184 size_t rk1_len =
sizeof(mip_rk_1), rk2_len =
sizeof(mip_rk_2), rk_len =
sizeof(mip_rk);
189 REDEBUG2(
"No EAP-MSK or EAP-EMSK. Cannot create WiMAX keys");
198 if (!vsa_request && !vsa_reply) {
199 RWDEBUG(
"Vendor-Specific.WiMAX not found in request or reply list, skipping all WiMAX calculations");
207 if (
inst->delete_mppe_keys) {
218 memcpy(usage_data,
"miprk@wimaxforum.org", 21);
219 usage_data[21] = 0x02;
220 usage_data[22] = 0x00;
221 usage_data[23] = 0x01;
226 MEM(hmac_ctx = EVP_MD_CTX_new());
227 MEM(hmac_pkey = EVP_PKEY_new_mac_key(EVP_PKEY_HMAC, NULL, emsk->vp_octets, emsk->vp_length));
228 EVP_DigestSignInit(hmac_ctx, NULL, EVP_sha256(), NULL, hmac_pkey);
230 EVP_DigestSignUpdate(hmac_ctx, &usage_data[0],
sizeof(usage_data));
231 EVP_DigestSignFinal(hmac_ctx, &mip_rk_1[0], &rk1_len);
236 EVP_MD_CTX_reset(hmac_ctx);
237 EVP_DigestSignInit(hmac_ctx, NULL, EVP_sha256(), NULL, hmac_pkey);
239 EVP_DigestSignUpdate(hmac_ctx, (
uint8_t const *) &mip_rk_1, rk1_len);
240 EVP_DigestSignUpdate(hmac_ctx, &usage_data[0],
sizeof(usage_data));
241 EVP_DigestSignFinal(hmac_ctx, &mip_rk_2[0], &rk2_len);
243 memcpy(mip_rk, mip_rk_1, rk1_len);
244 memcpy(mip_rk + rk1_len, mip_rk_2, rk2_len);
245 rk_len = rk1_len + rk2_len;
250 EVP_MD_CTX_reset(hmac_ctx);
251 EVP_PKEY_free(hmac_pkey);
252 MEM(hmac_pkey = EVP_PKEY_new_mac_key(EVP_PKEY_HMAC, NULL, mip_rk, rk_len));
253 EVP_DigestSignInit(hmac_ctx, NULL, EVP_sha256(), NULL, hmac_pkey);
255 EVP_DigestSignUpdate(hmac_ctx, (
uint8_t const *)
"SPI CMIP PMIP", 13);
256 EVP_DigestSignFinal(hmac_ctx, &mip_rk_1[0], &rk1_len);
263 if (mip_spi < 256) mip_spi += 256;
266 REDEBUG2(
"MIP-SPI = %08x", ntohl(mip_spi));
279 RWDEBUG(
"We cannot calculate MN-HA keys");
283 RWDEBUG(
"reply.Vendor-Specific.WiMAX was not found - not calculating WiMAX keys");
294 RWDEBUG(
"Not calculating MN-HA keys");
297 if (
vp)
switch (
vp->vp_uint32) {
312 EVP_MD_CTX_reset(hmac_ctx);
313 EVP_DigestSignInit(hmac_ctx, NULL, EVP_sha1(), NULL, hmac_pkey);
315 EVP_DigestSignUpdate(hmac_ctx, (
uint8_t const *)
"PMIP4 MN HA", 11);
316 EVP_DigestSignUpdate(hmac_ctx, (
uint8_t const *) &ip->vp_ipv4addr, 4);
317 EVP_DigestSignUpdate(hmac_ctx, (
uint8_t const *) &mn_nai->vp_strvalue, mn_nai->vp_length);
318 EVP_DigestSignFinal(hmac_ctx, &mip_rk_1[0], &rk1_len);
330 vp->vp_uint32 = mip_spi + 1;
347 EVP_MD_CTX_reset(hmac_ctx);
348 EVP_DigestSignInit(hmac_ctx, NULL, EVP_sha1(), NULL, hmac_pkey);
350 EVP_DigestSignUpdate(hmac_ctx, (
uint8_t const *)
"CMIP4 MN HA", 11);
351 EVP_DigestSignUpdate(hmac_ctx, (
uint8_t const *) &ip->vp_ipv4addr, 4);
352 EVP_DigestSignUpdate(hmac_ctx, (
uint8_t const *) &mn_nai->vp_strvalue, mn_nai->vp_length);
353 EVP_DigestSignFinal(hmac_ctx, &mip_rk_1[0], &rk1_len);
365 vp->vp_uint32 = mip_spi;
382 EVP_MD_CTX_reset(hmac_ctx);
383 EVP_DigestSignInit(hmac_ctx, NULL, EVP_sha1(), NULL, hmac_pkey);
385 EVP_DigestSignUpdate(hmac_ctx, (
uint8_t const *)
"CMIP6 MN HA", 11);
386 EVP_DigestSignUpdate(hmac_ctx, (
uint8_t const *) &ip->vp_ipv6addr, 16);
387 EVP_DigestSignUpdate(hmac_ctx, (
uint8_t const *) &mn_nai->vp_strvalue, mn_nai->vp_length);
388 EVP_DigestSignFinal(hmac_ctx, &mip_rk_1[0], &rk1_len);
400 vp->vp_uint32 = mip_spi + 2;
413 if (fa_rk && (fa_rk->vp_length <= 1)) {
414 EVP_MD_CTX_reset(hmac_ctx);
415 EVP_DigestSignInit(hmac_ctx, NULL, EVP_sha1(), NULL, hmac_pkey);
417 EVP_DigestSignUpdate(hmac_ctx, (
uint8_t const *)
"FA-RK", 5);
419 EVP_DigestSignFinal(hmac_ctx, &mip_rk_1[0], &rk1_len);
430 vp->vp_uint32 = mip_spi;
442 REDEBUG2(
"Client requested MN-HA key: Should use SPI to look up key from storage");
444 RWDEBUG(
"MN-NAI was not found!");
451 RWDEBUG(
"HA-IP was not found!");
458 if (
vp && (
vp->vp_uint32 == 1)) {
459 REDEBUG2(
"Client requested HA-RK: Should use IP to look it up from storage");
467 EVP_MD_CTX_free(hmac_ctx);
468 EVP_PKEY_free(hmac_pkey);