LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 01-12-2017, 10:35 AM   #1
navigium
Member
 
Registered: Aug 2014
Location: Switzerland
Distribution: Slackware, FreeBSD
Posts: 119

Rep: Reputation: 58
EAP-PWD in wpa_supplicant


Is there a reason wpa_supplicant isn't compiled with

Code:
CONFIG_EAP_PWD="y"
?

I'm aware that there was a security problem in wpa_supplicant 2.4 which could be solved by removing support for eap-pwd as indicated in the changelog:

Code:
Tue May 12 07:17:33 UTC 2015
n/wpa_supplicant-2.4-x86_64-2.txz: Rebuilt.
       This update fixes potential denial of service issues.
       For more information, see:
       http://w1.fi/security/2015-1/wpa_supplicant-p2p-ssid-overflow.txt
       http://w1.fi/security/2015-2/wps-upnp-http-chunked-transfer-encoding.txt
       http://w1.fi/security/2015-3/integer-underflow-in-ap-mode-wmm-action-frame.txt
       http://w1.fi/security/2015-4/eap-pwd-missing-payload-length-validation.txt
       http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1863
       (* Security fix *)
However, this is solved in wpa_supplicant 2.5 which ships with Slackware 14.2. I recompiled wpa_supplicant with this enabled to be able to access eduroam using wpa-pwd, but I'd prefer to have Slackware supporting it without recompiling - unless there is a reason not to, then I'd probably want to stick with the default package.
 
Old 01-13-2017, 08:47 AM   #2
ponce
LQ Guru
 
Registered: Aug 2004
Location: Pisa, Italy
Distribution: Slackware
Posts: 7,122

Rep: Reputation: 4192Reputation: 4192Reputation: 4192Reputation: 4192Reputation: 4192Reputation: 4192Reputation: 4192Reputation: 4192Reputation: 4192Reputation: 4192Reputation: 4192
YMMV but, here (and in other universities) I don't need wpa-pwd but just PEAP/MsCHAPv2 for using eduroam...
Code:
network={
   scan_ssid=1
   ssid="eduroam"
   key_mgmt=WPA-EAP
   eap=PEAP
   identity="me@example.com"
   password="mysupersecretpassword"
   phase1="peaplabel=0"
   phase2="auth=MSCHAPV2"
}
 
3 members found this post helpful.
Old 01-14-2017, 11:35 AM   #3
navigium
Member
 
Registered: Aug 2014
Location: Switzerland
Distribution: Slackware, FreeBSD
Posts: 119

Original Poster
Rep: Reputation: 58
Quote:
Originally Posted by ponce View Post
YMMV but, here (and in other universities) I don't need wpa-pwd but just PEAP/MsCHAPv2 for using eduroam...
I know, I tested EAP PEAP and TTLS and both work flawlessly. The point is that EAP-PWD is a lot easier because you don't have to worry about the ca certificate. That's why I was wondering why Slackware doesn't support this out of the box.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
wpa_supplicant don't reach freeradius in wired 802.1x EAP-TLS julie7 Linux - Networking 3 08-21-2015 03:40 AM
to check the lsdk version on which the hostapd for EAP SIM and EAP AKA support d.vivek_88@yahoo.co.in Linux - Software 1 03-19-2014 09:15 AM
Do all WPA wireless devices support WPA-EAP via wpa_supplicant engr04 Linux - Wireless Networking 3 04-03-2012 04:15 PM
wpa_supplicant and EAP-MSCHAP v2 rabidus Linux - Wireless Networking 0 10-20-2005 10:16 AM
reset pwd to root's current pwd? ataraktos2 Linux - General 10 04-26-2005 04:13 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 05:25 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration