Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

hostapd-2.10-2.2 RPM for riscv64

From OpenSuSE Ports Tumbleweed for riscv64

Name: hostapd Distribution: openSUSE Tumbleweed
Version: 2.10 Vendor: openSUSE
Release: 2.2 Build date: Mon Feb 6 03:06:07 2023
Group: Hardware/Wifi Build host: lamb24
Size: 1957019 Source RPM: hostapd-2.10-2.2.src.rpm
Packager: https://bugs.opensuse.org
Url: https://w1.fi/
Summary: Daemon for running a WPA capable Access Point
hostapd is a user space daemon for access point and authentication
servers. It implements IEEE 802.11 access point management, IEEE
802.1X/WPA/WPA2/EAP Authenticators, RADIUS client, EAP server, and
RADIUS authentication server. Currently, hostapd supports HostAP,
madwifi, and prism54 drivers. It also supports wired IEEE 802.1X
authentication via any ethernet driver.

Provides

Requires

License

BSD-3-Clause OR GPL-2.0-only

Changelog

* Fri Mar 11 2022 Clemens Famulla-Conrad <cfamullaconrad@suse.com>
  - Adjust config
    * Enable SAE
    * Enable DPP
    * Enable wired driver
    * Enable Airtime policy support
    * Enable Fast Initial Link Setup (FILS) (IEEE 802.11ai)
* Mon Jan 17 2022 Michael Ströder <michael@stroeder.com>
  - Removed obsolete patches:
    * CVE-2019-16275.patch
    * CVE-2020-12695.patch
    * CVE-2021-30004.patch
  - Update to version 2.10
    * SAE changes
    - improved protection against side channel attacks
      [https://w1.fi/security/2022-1/]
    - added option send SAE Confirm immediately (sae_config_immediate=1)
      after SAE Commit
    - added support for the hash-to-element mechanism (sae_pwe=1 or
      sae_pwe=2)
    - fixed PMKSA caching with OKC
    - added support for SAE-PK
    * EAP-pwd changes
    - improved protection against side channel attacks
      [https://w1.fi/security/2022-1/]
    * fixed WPS UPnP SUBSCRIBE handling of invalid operations
      [https://w1.fi/security/2020-1/]
    * fixed PMF disconnection protection bypass
      [https://w1.fi/security/2019-7/]
    * added support for using OpenSSL 3.0
    * fixed various issues in experimental support for EAP-TEAP server
    * added configuration (max_auth_rounds, max_auth_rounds_short) to
      increase the maximum number of EAP message exchanges (mainly to
      support cases with very large certificates) for the EAP server
    * added support for DPP release 2 (Wi-Fi Device Provisioning Protocol)
    * extended HE (IEEE 802.11ax) support, including 6 GHz support
    * removed obsolete IAPP functionality
    * fixed EAP-FAST server with TLS GCM/CCM ciphers
    * dropped support for libnl 1.1
    * added support for nl80211 control port for EAPOL frame TX/RX
    * fixed OWE key derivation with groups 20 and 21; this breaks backwards
      compatibility for these groups while the default group 19 remains
      backwards compatible; owe_ptk_workaround=1 can be used to enabled a
      a workaround for the group 20/21 backwards compatibility
    * added support for Beacon protection
    * added support for Extended Key ID for pairwise keys
    * removed WEP support from the default build (CONFIG_WEP=y can be used
      to enable it, if really needed)
    * added a build option to remove TKIP support (CONFIG_NO_TKIP=y)
    * added support for Transition Disable mechanism to allow the AP to
      automatically disable transition mode to improve security
    * added support for PASN
    * added EAP-TLS server support for TLS 1.3 (disabled by default for now)
    * a large number of other fixes, cleanup, and extensions
* Fri Nov 26 2021 Clemens Famulla-Conrad <cfamullaconrad@suse.com>
  - Fix AppArmor profile -- allow access to /etc/ssl/openssl.cnf
    (bsc#1192959)
* Fri Oct 15 2021 Johannes Segitz <jsegitz@suse.com>
  - Added hardening to systemd service(s) (bsc#1181400). Modified:
    * hostapd.service
* Wed Jul 14 2021 Michael Ströder <michael@stroeder.com>
  - fixed AppArmor profile
* Tue Apr 06 2021 Clemens Famulla-Conrad <cfamullaconrad@suse.com>
  - Add CVE-2021-30004.patch -- forging attacks may occur because
    AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c
    (bsc#1184348)
* Tue Feb 23 2021 Michael Ströder <michael@stroeder.com>
  - added AppArmor profile (source apparmor-usr.sbin.hostapd)
* Tue Sep 29 2020 Clemens Famulla-Conrad <cfamullaconrad@suse.com>
  - Add CVE-2020-12695.patch -- UPnP SUBSCRIBE misbehavior in hostapd WPS AP
    (bsc#1172700)
* Thu Apr 23 2020 Clemens Famulla-Conrad <cfamullaconrad@suse.com>
  - Add CVE-2019-16275.patch -- AP mode PMF disconnection protection bypass
    (bsc#1150934)
* Thu Sep 05 2019 Michael Ströder <michael@stroeder.com>
  - Update to version 2.9
    * SAE changes
    - disable use of groups using Brainpool curves
    - improved protection against side channel attacks
      [https://w1.fi/security/2019-6/]
    * EAP-pwd changes
    - disable use of groups using Brainpool curves
    - improved protection against side channel attacks
      [https://w1.fi/security/2019-6/]
    * fixed FT-EAP initial mobility domain association using PMKSA caching
    * added configuration of airtime policy
    * fixed FILS to and RSNE into (Re)Association Response frames
    * fixed DPP bootstrapping URI parser of channel list
    * added support for regulatory WMM limitation (for ETSI)
    * added support for MACsec Key Agreement using IEEE 802.1X/PSK
    * added experimental support for EAP-TEAP server (RFC 7170)
    * added experimental support for EAP-TLS server with TLS v1.3
    * added support for two server certificates/keys (RSA/ECC)
    * added AKMSuiteSelector into "STA <addr>" control interface data to
      determine with AKM was used for an association
    * added eap_sim_id parameter to allow EAP-SIM/AKA server pseudonym and
      fast reauthentication use to be disabled
    * fixed an ECDH operation corner case with OpenSSL
* Wed Apr 24 2019 Michael Ströder <michael@stroeder.com>
  - Update to version 2.8
    * SAE changes
    - added support for SAE Password Identifier
    - changed default configuration to enable only group 19
      (i.e., disable groups 20, 21, 25, 26 from default configuration) and
      disable all unsuitable groups completely based on REVmd changes
    - improved anti-clogging token mechanism and SAE authentication
      frame processing during heavy CPU load; this mitigates some issues
      with potential DoS attacks trying to flood an AP with large number
      of SAE messages
    - added Finite Cyclic Group field in status code 77 responses
    - reject use of unsuitable groups based on new implementation guidance
      in REVmd (allow only FFC groups with prime >= 3072 bits and ECC
      groups with prime >= 256)
    - minimize timing and memory use differences in PWE derivation
      [https://w1.fi/security/2019-1/] (CVE-2019-9494)
    - fixed confirm message validation in error cases
      [https://w1.fi/security/2019-3/] (CVE-2019-9496)
    * EAP-pwd changes
    - minimize timing and memory use differences in PWE derivation
      [https://w1.fi/security/2019-2/] (CVE-2019-9495)
    - verify peer scalar/element
      [https://w1.fi/security/2019-4/] (CVE-2019-9497 and CVE-2019-9498)
    - fix message reassembly issue with unexpected fragment
      [https://w1.fi/security/2019-5/]
    - enforce rand,mask generation rules more strictly
    - fix a memory leak in PWE derivation
    - disallow ECC groups with a prime under 256 bits (groups 25, 26, and
      27)
    * Hotspot 2.0 changes
    - added support for release number 3
    - reject release 2 or newer association without PMF
    * added support for RSN operating channel validation
      (CONFIG_OCV=y and configuration parameter ocv=1)
    * added Multi-AP protocol support
    * added FTM responder configuration
    * fixed build with LibreSSL
    * added FT/RRB workaround for short Ethernet frame padding
    * fixed KEK2 derivation for FILS+FT
    * added RSSI-based association rejection from OCE
    * extended beacon reporting functionality
    * VLAN changes
    - allow local VLAN management with remote RADIUS authentication
    - add WPA/WPA2 passphrase/PSK -based VLAN assignment
    * OpenSSL: allow systemwide policies to be overridden
    * extended PEAP to derive EMSK to enable use with ERP/FILS
    * extended WPS to allow SAE configuration to be added automatically
      for PSK (wps_cred_add_sae=1)
    * fixed FT and SA Query Action frame with AP-MLME-in-driver cases
    * OWE: allow Diffie-Hellman Parameter element to be included with DPP
      in preparation for DPP protocol extension
    * RADIUS server: started to accept ERP keyName-NAI as user identity
      automatically without matching EAP database entry
    * fixed PTK rekeying with FILS and FT
    wpa_supplicant:
    * SAE changes
    - added support for SAE Password Identifier
    - changed default configuration to enable only groups 19, 20, 21
      (i.e., disable groups 25 and 26) and disable all unsuitable groups
      completely based on REVmd changes
    - do not regenerate PWE unnecessarily when the AP uses the
      anti-clogging token mechanisms
    - fixed some association cases where both SAE and FT-SAE were enabled
      on both the station and the selected AP
    - started to prefer FT-SAE over SAE AKM if both are enabled
    - started to prefer FT-SAE over FT-PSK if both are enabled
    - fixed FT-SAE when SAE PMKSA caching is used
    - reject use of unsuitable groups based on new implementation guidance
      in REVmd (allow only FFC groups with prime >= 3072 bits and ECC
      groups with prime >= 256)
    - minimize timing and memory use differences in PWE derivation
      [https://w1.fi/security/2019-1/] (CVE-2019-9494)
    * EAP-pwd changes
    - minimize timing and memory use differences in PWE derivation
      [https://w1.fi/security/2019-2/] (CVE-2019-9495)
    - verify server scalar/element
      [https://w1.fi/security/2019-4/] (CVE-2019-9499)
    - fix message reassembly issue with unexpected fragment
      [https://w1.fi/security/2019-5/]
    - enforce rand,mask generation rules more strictly
    - fix a memory leak in PWE derivation
    - disallow ECC groups with a prime under 256 bits (groups 25, 26, and
      27)
    * fixed CONFIG_IEEE80211R=y (FT) build without CONFIG_FILS=y
    * Hotspot 2.0 changes
    - do not indicate release number that is higher than the one
      AP supports
    - added support for release number 3
    - enable PMF automatically for network profiles created from
      credentials
    * fixed OWE network profile saving
    * fixed DPP network profile saving
    * added support for RSN operating channel validation
      (CONFIG_OCV=y and network profile parameter ocv=1)
    * added Multi-AP backhaul STA support
    * fixed build with LibreSSL
    * number of MKA/MACsec fixes and extensions
    * extended domain_match and domain_suffix_match to allow list of values
    * fixed dNSName matching in domain_match and domain_suffix_match when
      using wolfSSL
    * started to prefer FT-EAP-SHA384 over WPA-EAP-SUITE-B-192 AKM if both
      are enabled
    * extended nl80211 Connect and external authentication to support
      SAE, FT-SAE, FT-EAP-SHA384
    * fixed KEK2 derivation for FILS+FT
    * extended client_cert file to allow loading of a chain of PEM
      encoded certificates
    * extended beacon reporting functionality
    * extended D-Bus interface with number of new properties
    * fixed a regression in FT-over-DS with mac80211-based drivers
    * OpenSSL: allow systemwide policies to be overridden
    * extended driver flags indication for separate 802.1X and PSK
      4-way handshake offload capability
    * added support for random P2P Device/Interface Address use
    * extended PEAP to derive EMSK to enable use with ERP/FILS
    * extended WPS to allow SAE configuration to be added automatically
      for PSK (wps_cred_add_sae=1)
    * removed support for the old D-Bus interface (CONFIG_CTRL_IFACE_DBUS)
    * extended domain_match and domain_suffix_match to allow list of values
    * added a RSN workaround for misbehaving PMF APs that advertise
      IGTK/BIP KeyID using incorrect byte order
    * fixed PTK rekeying with FILS and FT

Files

/etc/apparmor.d
/etc/apparmor.d/usr.sbin.hostapd
/etc/hostapd.accept
/etc/hostapd.conf
/etc/hostapd.deny
/etc/hostapd.eap_user
/etc/hostapd.radius_clients
/etc/hostapd.sim_db
/etc/hostapd.vlan
/etc/hostapd.wpa_psk
/usr/lib/systemd/system/hostapd.service
/usr/sbin/hostapd
/usr/sbin/hostapd_cli
/usr/sbin/rchostapd
/usr/share/doc/packages/hostapd
/usr/share/doc/packages/hostapd/ChangeLog
/usr/share/doc/packages/hostapd/README
/usr/share/doc/packages/hostapd/hostapd.conf
/usr/share/doc/packages/hostapd/wired.conf
/usr/share/licenses/hostapd
/usr/share/licenses/hostapd/COPYING
/usr/share/man/man8/hostapd.8.gz


Generated by rpm2html 1.8.1

Fabrice Bellet, Sat Apr 27 23:55:11 2024