wpa_supplicant

wpa_supplicant is a free software implementation of an IEEE 802.11i supplicant for Linux, FreeBSD, NetBSD, QNX, AROS, Microsoft Windows, Solaris, OS/2 (including eComStation) and Haiku.[2] In addition to being a fully featured WPA2 supplicant, it also implements WPA and older wireless LAN security protocols.

wpa_supplicant
Screenshot of wpa_gui
Developer(s)Jouni Malinen and others
Initial releaseApril 5, 2003 (2003-04-05)
Stable release
2.9[1] / August 7, 2019 (2019-08-07)
Repository
Written inC
Operating systemCross-platform
TypeWLAN tools
LicenseBSD
Websitew1.fi/wpa_supplicant/

Features

Features include:[3]

  • WPA and full IEEE 802.11i/RSN/WPA2
  • WPA-PSK and WPA2-PSK ("WPA-Personal", pre-shared key)
  • WPA with EAP ("WPA-Enterprise", for example with RADIUS authentication server)
  • key management for CCMP, TKIP, WEP (both 104/128- and 40/64-bit)
  • RSN: PMKSA caching, pre-authentication
  • IEEE 802.11r
  • IEEE 802.11w
  • Wi-Fi Protected Setup (WPS)

Included with the supplicant are a GUI and a command-line utility for interacting with the running supplicant. From either of these interfaces it is possible to review a list of currently visible networks, select one of them, provide any additional security information needed to authenticate with the network (for example, a passphrase, or username and password) and add it to the preference list to enable automatic reconnection in the future.[4]

The graphical user interface is built on top of the Qt library.

wpa_supplicant can authenticate with any of the following EAP (Extensible Authentication Protocol) methods: EAP-TLS, EAP-PEAP (both PEAPv0 and PEAPv1), EAP-TTLS, EAP-SIM, EAP-AKA, EAP-AKA', EAP-pwd, EAP-EKE, EAP-PSK (experimental), EAP-FAST, EAP-PAX, EAP-SAKE, EAP-GPSK, EAP-IKEv2, EAP-MD5, EAP-MSCHAPv2, and LEAP (requires special functions in the driver).[4]

Vulnerability to KRACK

wpa_supplicant was especially susceptible to KRACK, as it can be manipulated to install an all-zeros encryption key, effectively nullifying WPA2 protection in a man-in-the-middle attack.[5] Version 2.7 fixed KRACK and several other vulnerabilities.

gollark: ... if I can find it, actually.
gollark: Anyway, I figure I'll start on the whole project *now* by creating a folderâ„¢ containing all the potatOS code.
gollark: Plus verifying the checksums and such.
gollark: I think all the updater thing would need to do is:on the non-CC side, just track what files changed since the last release, generate a checksum, and either generate an archive or a bunch of URLs for it.on the CC side, periodically check a manifest file, store its own version locally, check if a newer version is available on the server, and if so download the files which have changed.
gollark: Probably gitget.

See also

References

  1. "Index of /releases". w1.fi. 2019-08-07. Retrieved 2019-10-23.
  2. haiku/wpa_supplicant, Haiku, 2019-03-17, retrieved 2020-03-07
  3. "wpa_supplicant(8) - Linux man page". Retrieved 2020-03-07.
  4. "Linux WPA Supplicant (IEEE 802.1X, WPA, WPA2, RSN, IEEE 802.11i)". w1.fi. Retrieved 2014-07-04.
  5. "Key Reinstallation Attacks disclosure website". KRACK Attacks. Retrieved 26 September 2018. Linux's wpa_supplicant v2.6 is also vulnerable to the installation of an all-zero encryption key in the 4-way handshake.
This article is issued from Wikipedia. The text is licensed under Creative Commons - Attribution - Sharealike. Additional terms may apply for the media files.