1
0

182 Commits

Author SHA256 Message Date
Ana Guerrero
ecd9ce54ad Accepting request 1200682 from hardware
- update to v2.11:
  * Wi-Fi Easy Connect
    - add support for DPP release 3
    - allow Configurator parameters to be provided during config exchange
  * HE/IEEE 802.11ax/Wi-Fi 6
    - various fixes
  * EHT/IEEE 802.11be/Wi-Fi 7
    - add preliminary support
  * SAE: add support for fetching the password from a RADIUS server
  * support OpenSSL 3.0 API changes
  * support background radar detection and CAC with some additional
    drivers
  * support RADIUS ACL/PSK check during 4-way handshake (wpa_psk_radius=3)
  * EAP-SIM/AKA: support IMSI privacy
  * improve 4-way handshake operations
    - use Secure=1 in message 3 during PTK rekeying
  * OCV: do not check Frequency Segment 1 Channel Number for 160 MHz cases
    to avoid interoperability issues
  * support new SAE AKM suites with variable length keys
  * support new AKM for 802.1X/EAP with SHA384
  * extend PASN support for secure ranging
  * FT: Use SHA256 to derive PMKID for AKM 00-0F-AC:3 (FT-EAP)
    - this is based on additional details being added in the IEEE 802.11
      standard
    - the new implementation is not backwards compatible
  * improved ACS to cover additional channel types/bandwidths
  * extended Multiple BSSID support
  * fix beacon protection with FT protocol (incorrect BIGTK was provided)
  * support unsynchronized service discovery (USD)
  * add preliminary support for RADIUS/TLS
  * add support for explicit SSID protection in 4-way handshake
    (a mitigation for CVE-2023-52424; disabled by default for now, can be
    enabled with ssid_protection=1)
  * fix SAE H2E rejected groups validation to avoid downgrade attacks
  * use stricter validation for some RADIUS messages
  * a large number of other fixes, cleanup, and extensions
- refresh patches:
    wpa_supplicant-dump-certificate-as-PEM-in-debug-mode.diff
    wpa_supplicant-sigusr1-changes-debuglevel.patch
- drop patches:
    CVE-2023-52160.patch 
    dbus-Fix-property-DebugShowKeys-and-DebugTimestamp.patch

OBS-URL: https://build.opensuse.org/request/show/1200682
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=96
2024-09-13 12:30:03 +00:00
6c5b387e2e typo in wpa_supplicant.changes
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=146
2024-09-12 15:19:43 +00:00
d3a95bf049 - update to v2.11:
* Wi-Fi Easy Connect
    - add support for DPP release 3
    - allow Configurator parameters to be provided during config exchange
  * HE/IEEE 802.11ax/Wi-Fi 6
    - various fixes
  * EHT/IEEE 802.11be/Wi-Fi 7
    - add preliminary support
  * SAE: add support for fetching the password from a RADIUS server
  * support OpenSSL 3.0 API changes
  * support background radar detection and CAC with some additional
    drivers
  * support RADIUS ACL/PSK check during 4-way handshake (wpa_psk_radius=3)
  * EAP-SIM/AKA: support IMSI privacy
  * improve 4-way handshake operations
    - use Secure=1 in message 3 during PTK rekeying
  * OCV: do not check Frequency Segment 1 Channel Number for 160 MHz cases
    to avoid interoperability issues
  * support new SAE AKM suites with variable length keys
  * support new AKM for 802.1X/EAP with SHA384
  * extend PASN support for secure ranging
  * FT: Use SHA256 to derive PMKID for AKM 00-0F-AC:3 (FT-EAP)
    - this is based on additional details being added in the IEEE 802.11
      standard
    - the new implementation is not backwards compatible
  * improved ACS to cover additional channel types/bandwidths
  * extended Multiple BSSID support
  * fix beacon protection with FT protocol (incorrect BIGTK was provided)
  * support unsynchronized service discovery (USD)
  * add preliminary support for RADIUS/TLS
  * add support for explicit SSID protection in 4-way handshake
    (a mitigation for CVE-2023-52424; disabled by default for now, can be
    enabled with ssid_protection=1)
  * fix SAE H2E rejected groups validation to avoid downgrade attacks
  * use stricter validation for some RADIUS messages
  * a large number of other fixes, cleanup, and extensions
- refresh patches:
    wpa_supplicant-dump-certificate-as-PEM-in-debug-mode.diff
    wpa_supplicant-sigusr1-changes-debuglevel.patch
- drop patches:
    CVE-2023-52160.patche 
    dbus-Fix-property-DebugShowKeys-and-DebugTimestamp.patch

OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=145
2024-09-12 14:00:22 +00:00
Ana Guerrero
a44e5e6dab Accepting request 1147035 from hardware
OBS-URL: https://build.opensuse.org/request/show/1147035
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=95
2024-02-16 20:49:16 +00:00
56df1fbf8b Accepting request 1147033 from home:cfconrad:branches:hardware
- Add CVE-2023-52160.patch - Bypassing WiFi Authentication (bsc#1219975)

OBS-URL: https://build.opensuse.org/request/show/1147033
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=143
2024-02-16 08:23:51 +00:00
Dominique Leuenberger
9977f3b338 Accepting request 1087515 from hardware
OBS-URL: https://build.opensuse.org/request/show/1087515
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=94
2023-05-18 13:18:13 +00:00
5a3f3a56e5 Accepting request 1087472 from home:gmbr3:Active
- Change ctrl_interface from /var/run to %_rundir (/run)

OBS-URL: https://build.opensuse.org/request/show/1087472
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=141
2023-05-17 07:28:02 +00:00
Dominique Leuenberger
6d275a4147 Accepting request 1001384 from hardware
OBS-URL: https://build.opensuse.org/request/show/1001384
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=93
2022-09-07 09:05:30 +00:00
cb5a5701e1 Accepting request 1000701 from home:schubi2
Migration to /usr/etc: Saving user changed configuration files in /etc and restoring them while an RPM update.

OBS-URL: https://build.opensuse.org/request/show/1000701
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=139
2022-09-06 08:30:42 +00:00
Dominique Leuenberger
837091b653 Accepting request 986870 from hardware
OBS-URL: https://build.opensuse.org/request/show/986870
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=92
2022-07-08 12:01:31 +00:00
20be233a72 Accepting request 986868 from home:cfconrad:branches:hardware
- Add dbus-Fix-property-DebugShowKeys-and-DebugTimestamp.patch
  (bsc#1201219)

OBS-URL: https://build.opensuse.org/request/show/986868
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=137
2022-07-05 13:43:43 +00:00
870f6d03c9 OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=136 2022-06-21 12:00:58 +00:00
50bb343a0c Accepting request 984114 from home:gmbr3:Active
no %config for /usr (amend last)

OBS-URL: https://build.opensuse.org/request/show/984114
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=135
2022-06-21 11:57:23 +00:00
288b9b5587 Accepting request 984149 from home:cfconrad:branches:hardware
- Remove Revert-DBus-Add-sae-to-interface-key_mgmt-capabilities.patch
  Fixed in NetworkManager (glfo#NetworkManager/NetworkManager#a0988868). 
  Wifi cards, wich do not support PMF/BIP ciphers, should not use 
  SAE as key management. (bsc#1195312)

OBS-URL: https://build.opensuse.org/request/show/984149
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=134
2022-06-21 11:49:06 +00:00
797db382fd Accepting request 984102 from home:schubi2
- Moved logrotate files from user specif directory /etc/logrotate.d
  to vendor specif directory /usr/etc/logrotate.d.

OBS-URL: https://build.opensuse.org/request/show/984102
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=133
2022-06-21 08:00:55 +00:00
a0ad97358e Accepting request 981333 from home:gmbr3:Active
- Move the dbus-1 system.d file to /usr (bsc#1200342)

OBS-URL: https://build.opensuse.org/request/show/981333
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=132
2022-06-09 07:48:21 +00:00
Dominique Leuenberger
626ccc04fb Accepting request 952645 from hardware
OBS-URL: https://build.opensuse.org/request/show/952645
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=91
2022-02-10 22:11:30 +00:00
4664420d0a Accepting request 952644 from home:dirkmueller:Factory
- Apply Revert-DBus-Add-sae-to-interface-key_mgmt-capabilities.patch
  to fix connect with AVM FB, if WPA3 transition mode is activated,
  e.g. Wifi -> Security: is WPA2 + WPA3, alt. switch to WPA2 (CCMP)
  (bsc#1195312)

- drop restore-old-dbus-interface.patch, wicked has been
  switching to the new dbus interface in version 0.6.66.
- drop wpa_supplicant-getrandom.patch : glibc has been updated
  so the getrandom() wrapper is now there
- config:
  * enable QCA vendor extensions to nl80211
  * enable EAP-EKE
  * Support HT overrides
  * WPA3-Enterprise 
  * TLS v1.1 and TLS v1.2
  * Fast Session Transfer (FST)
  * Automatic Channel Selection
  * Multi Band Operation
  * Fast Initial Link Setup
  * Mesh Networking (IEEE 802.11s)

- config: 
  * Reenable Fast BSS Transition (likely fixing bsc#1195312)
  * Enable OCV, security feature that prevents MITM
    multi-channel attacks
  * Enable OWE for better hotspot support

OBS-URL: https://build.opensuse.org/request/show/952644
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=131
2022-02-08 10:24:23 +00:00
Dominique Leuenberger
5dc06d5e03 Accepting request 948420 from hardware
OBS-URL: https://build.opensuse.org/request/show/948420
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=90
2022-01-26 20:26:39 +00:00
a7a45f374a Accepting request 948384 from home:dirkmueller:Factory
- update to 2.10.0:
  * SAE changes
    - improved protection against side channel attacks
      [https://w1.fi/security/2022-1/]
    - added support for the hash-to-element mechanism (sae_pwe=1 or
      sae_pwe=2); this is currently disabled by default, but will likely
      get enabled by default in the future
    - fixed PMKSA caching with OKC
    - added support for SAE-PK
  * EAP-pwd changes
    - improved protection against side channel attacks
    [https://w1.fi/security/2022-1/]
  * fixed P2P provision discovery processing of a specially constructed
    invalid frame
    [https://w1.fi/security/2021-1/]
  * fixed P2P group information processing of a specially constructed
    invalid frame
    [https://w1.fi/security/2020-2/]
  * fixed PMF disconnection protection bypass in AP mode
    [https://w1.fi/security/2019-7/]
  * added support for using OpenSSL 3.0
  * increased the maximum number of EAP message exchanges (mainly to
    support cases with very large certificates)
  * fixed various issues in experimental support for EAP-TEAP peer
  * added support for DPP release 2 (Wi-Fi Device Provisioning Protocol)
  * a number of MKA/MACsec fixes and extensions
  * added support for SAE (WPA3-Personal) AP mode configuration
  * added P2P support for EDMG (IEEE 802.11ay) channels
  * fixed EAP-FAST peer with TLS GCM/CCM ciphers
  * improved throughput estimation and BSS selection

OBS-URL: https://build.opensuse.org/request/show/948384
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=130
2022-01-24 14:43:51 +00:00
Dominique Leuenberger
1ab7f86383 Accepting request 945257 from hardware
OBS-URL: https://build.opensuse.org/request/show/945257
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=89
2022-01-10 23:01:41 +00:00
41deaf30e9 Accepting request 945228 from home:jsegitz:branches:systemdhardening:hardware
- Added hardening to systemd service(s) (bsc#1181400). Modified:
  * wpa_supplicant.service

OBS-URL: https://build.opensuse.org/request/show/945228
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=129
2022-01-10 10:18:03 +00:00
Richard Brown
102e733879 Accepting request 883362 from hardware
OBS-URL: https://build.opensuse.org/request/show/883362
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=88
2021-04-10 13:26:27 +00:00
4adb0ea4de Accepting request 883361 from home:cfconrad:branches:hardware
- Add CVE-2021-30004.patch -- forging attacks may occur because
  AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c
  (bsc#1184348)

OBS-URL: https://build.opensuse.org/request/show/883361
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=127
2021-04-06 15:47:56 +00:00
Dominique Leuenberger
59e2dcec17 Accepting request 878125 from hardware
- Fix systemd device ready dependencies in wpa_supplicant@.service file.
  (see: https://forums.opensuse.org/showthread.php/547186-wpa_supplicant-service-fails-on-boot-succeeds-on-restart?p=2982844#post2982844)

OBS-URL: https://build.opensuse.org/request/show/878125
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=87
2021-03-12 12:30:17 +00:00
Dominique Leuenberger
f1ed444be5 Accepting request 875681 from hardware
OBS-URL: https://build.opensuse.org/request/show/875681
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=86
2021-03-10 07:48:06 +00:00
e1f02c1fff - Fix systemd device ready dependencies in wpa_supplicant@.service file.
(see: https://forums.opensuse.org/showthread.php/547186-wpa_supplicant-service-fails-on-boot-succeeds-on-restart?p=2982844#post2982844)

OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=124
2021-03-03 15:36:52 +00:00
f57df46bf0 Accepting request 848179 from home:awerlang:branches:openSUSE:Factory
When passing the -i argument to wpa_supplicant, the device needs to be available and ready. This fulfills the dependencies.

See: https://forums.opensuse.org/showthread.php/547186-wpa_supplicant-service-fails-on-boot-succeeds-on-restart?p=2982844#post2982844

OBS-URL: https://build.opensuse.org/request/show/848179
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=123
2021-03-03 15:20:49 +00:00
941d4fb988 Accepting request 875680 from home:cfconrad:branches:hardware
- Add CVE-2021-27803.patch -- P2P provision discovery processing vulnerability
  (bsc#1182805)

OBS-URL: https://build.opensuse.org/request/show/875680
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=122
2021-02-27 23:26:49 +00:00
Dominique Leuenberger
fc08349070 Accepting request 869590 from hardware
OBS-URL: https://build.opensuse.org/request/show/869590
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=85
2021-02-11 11:46:54 +00:00
e4b9de02a1 Accepting request 869589 from home:cfconrad:branches:hardware
- Add CVE-2021-0326.patch -- P2P group information processing vulnerability 
  (bsc#1181777)

OBS-URL: https://build.opensuse.org/request/show/869589
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=120
2021-02-04 22:38:02 +00:00
Dominique Leuenberger
cc048c0f59 Accepting request 844881 from hardware
OBS-URL: https://build.opensuse.org/request/show/844881
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=84
2020-11-02 08:40:26 +00:00
4a7547fe47 Accepting request 844873 from home:cfconrad:branches:hardware
Add bsc references to changelog.
Remove trailing white-space in wpa_supplicant.service file.

Reason: We are going to submit this hardware/wpa_supplicant to SLE-12 and SLE-15. This is a preparation for the submission.

OBS-URL: https://build.opensuse.org/request/show/844873
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=118
2020-10-29 13:43:58 +00:00
Dominique Leuenberger
07560bc1a6 Accepting request 844643 from hardware
OBS-URL: https://build.opensuse.org/request/show/844643
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=83
2020-10-29 08:21:41 +00:00
5ade233f96 Accepting request 844642 from home:cfconrad:branches:hardware
Add missing CVE references to changelog

OBS-URL: https://build.opensuse.org/request/show/844642
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=116
2020-10-28 16:26:39 +00:00
Dominique Leuenberger
6745ba0f93 Accepting request 841440 from hardware
OBS-URL: https://build.opensuse.org/request/show/841440
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=82
2020-10-13 13:32:46 +00:00
53ebe937fe Accepting request 841374 from home:JonathanKang:branches:hardware
add missing changelog entry comparing with SUSE:SLE-15:Update/wpa_supplicant

OBS-URL: https://build.opensuse.org/request/show/841374
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=114
2020-10-13 08:56:10 +00:00
Dominique Leuenberger
ce315d5d06 Accepting request 839970 from hardware
OBS-URL: https://build.opensuse.org/request/show/839970
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=81
2020-10-08 11:09:48 +00:00
35d1871565 Accepting request 839844 from home:sp1rit:testing
- Add wpa_supplicant-p2p_iname_size.diff -- Limit P2P_DEVICE name to appropriate ifname size
  (https://patchwork.ozlabs.org/project/hostap/patch/20200825062902.124600-1-benjamin@sipsolutions.net/)

OBS-URL: https://build.opensuse.org/request/show/839844
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=112
2020-10-07 08:35:57 +00:00
Dominique Leuenberger
5b8a0cf006 Accepting request 836233 from hardware
OBS-URL: https://build.opensuse.org/request/show/836233
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=80
2020-09-25 14:21:07 +00:00
f63f8abb35 Accepting request 836232 from home:cfconrad:branches:hardware
Just use make %{?_smp_mflags} everywhere.

OBS-URL: https://build.opensuse.org/request/show/836232
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=110
2020-09-23 07:50:18 +00:00
8c6d01227d Accepting request 836103 from home:cfconrad:branches:hardware
- Fix spec file for SLE12,  use `make %{?_smp_mflags}` if `%make_build` isn't available

OBS-URL: https://build.opensuse.org/request/show/836103
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=109
2020-09-22 13:58:46 +00:00
091145ab3c Accepting request 836014 from home:JonathanKang:branches:hardware
- Enable SAE support(jsc#SLE-14992).

OBS-URL: https://build.opensuse.org/request/show/836014
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=108
2020-09-22 11:22:29 +00:00
Dominique Leuenberger
f3f5f1884e Accepting request 797131 from hardware
- Add CVE-2019-16275.patch -- AP mode PMF disconnection protection bypass
  (bsc#1150934)

OBS-URL: https://build.opensuse.org/request/show/797131
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=79
2020-04-27 21:30:40 +00:00
ca77b227b2 - Mention CVE-2019-16275.patch file in changelog
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=106
2020-04-24 11:14:03 +00:00
c1f7bb5b81 Accepting request 797068 from home:cfconrad:branches:hardware
- Add patch for CVE-2019-16275 -- AP mode PMF disconnection protection bypass
  (bsc#1150934)

OBS-URL: https://build.opensuse.org/request/show/797068
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=105
2020-04-24 08:53:30 +00:00
Dominique Leuenberger
51b9758396 Accepting request 796019 from hardware
OBS-URL: https://build.opensuse.org/request/show/796019
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=78
2020-04-23 16:29:10 +00:00
f39821cc83 Accepting request 796014 from home:bmwiedemann
Add restore-old-dbus-interface.patch to fix wicked wlan (boo#1156920)
- Restore fi.epitest.hostap.WPASupplicant.service (bsc#1167331)

OBS-URL: https://build.opensuse.org/request/show/796014
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=103
2020-04-21 09:49:29 +00:00
Dominique Leuenberger
2049ed9eaf Accepting request 789823 from hardware
OBS-URL: https://build.opensuse.org/request/show/789823
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/wpa_supplicant?expand=0&rev=77
2020-04-04 10:18:07 +00:00
3e51878eb7 Accepting request 789822 from home:cfconrad:branches:hardware
Change changelog

OBS-URL: https://build.opensuse.org/request/show/789822
OBS-URL: https://build.opensuse.org/package/show/hardware/wpa_supplicant?expand=0&rev=101
2020-03-30 15:15:50 +00:00