hostapd.sh 2.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111
  1. hostapd_setup_vif() {
  2. local vif="$1"
  3. local driver="$2"
  4. local hostapd_cfg=
  5. # Examples:
  6. # psk-mixed/tkip => WPA1+2 PSK, TKIP
  7. # wpa-psk2/tkip+aes => WPA2 PSK, CCMP+TKIP
  8. # wpa2/tkip+aes => WPA2 RADIUS, CCMP+TKIP
  9. # ...
  10. # TODO: move this parsing function somewhere generic, so that
  11. # later it can be reused by drivers that don't use hostapd
  12. # crypto defaults: WPA2 vs WPA1
  13. case "$enc" in
  14. wpa2*|WPA2*|*PSK2*|*psk2*)
  15. wpa=2
  16. crypto="CCMP"
  17. ;;
  18. *mixed*)
  19. wpa=3
  20. crypto="CCMP TKIP"
  21. ;;
  22. *)
  23. wpa=1
  24. crypto="TKIP"
  25. ;;
  26. esac
  27. # explicit override for crypto setting
  28. case "$enc" in
  29. *tkip+aes|*TKIP+AES|*tkip+ccmp|*TKIP+CCMP) crypto="CCMP TKIP";;
  30. *tkip|*TKIP) crypto="TKIP";;
  31. *aes|*AES|*ccmp|*CCMP) crypto="CCMP";;
  32. esac
  33. # use crypto/auth settings for building the hostapd config
  34. case "$enc" in
  35. *psk*|*PSK*)
  36. config_get psk "$vif" key
  37. if [ ${#psk} -eq 64 ]; then
  38. append hostapd_cfg "wpa_psk=$psk" "$N"
  39. else
  40. append hostapd_cfg "wpa_passphrase=$psk" "$N"
  41. fi
  42. ;;
  43. *wpa*|*WPA*)
  44. # required fields? formats?
  45. # hostapd is particular, maybe a default configuration for failures
  46. config_get server "$vif" server
  47. append hostapd_cfg "auth_server_addr=$server" "$N"
  48. config_get port "$vif" port
  49. port=${port:-1812}
  50. append hostapd_cfg "auth_server_port=$port" "$N"
  51. config_get secret "$vif" key
  52. append hostapd_cfg "auth_server_shared_secret=$secret" "$N"
  53. config_get nasid "$vif" nasid
  54. append hostapd_cfg "nas_identifier=$nasid" "$N"
  55. append hostapd_cfg "eapol_key_index_workaround=1" "$N"
  56. append hostapd_cfg "radius_acct_interim_interval=300" "$N"
  57. append hostapd_cfg "ieee8021x=1" "$N"
  58. append hostapd_cfg "auth_algs=1" "$N"
  59. append hostapd_cfg "wpa_key_mgmt=WPA-EAP" "$N"
  60. append hostapd_cfg "wpa_group_rekey=300" "$N"
  61. append hostapd_cfg "wpa_gmk_rekey=640" "$N"
  62. ;;
  63. *)
  64. wpa=0
  65. crypto=
  66. ;;
  67. esac
  68. config_get ifname "$vif" ifname
  69. config_get bridge "$vif" bridge
  70. config_get ssid "$vif" ssid
  71. config_get device "$vif" device
  72. config_get channel "$device" channel
  73. config_get hwmode "$device" hwmode
  74. config_get country "$device" country
  75. case "$hwmode" in
  76. 11a) hwmode=a;;
  77. 11b) hwmode=b;;
  78. 11g) hwmode=g;;
  79. 11n)
  80. hwmode=g
  81. append hostapd_cfg "ieee80211n=1" "$N"
  82. config_get ht_capab "$device" ht_capab
  83. ;;
  84. *)
  85. hwmode=
  86. [ "$channel" -gt 14 ] && hwmode=a
  87. ;;
  88. esac
  89. cat > /var/run/hostapd-$ifname.conf <<EOF
  90. ctrl_interface=/var/run/hostapd-$ifname
  91. driver=$driver
  92. interface=$ifname
  93. hw_mode=${hwmode:-g}
  94. channel=$channel
  95. ${bridge:+bridge=$bridge}
  96. ssid=$ssid
  97. debug=0
  98. wpa=$wpa
  99. ${crypto:+wpa_pairwise=$crypto}
  100. ${country:+country_code=$country}
  101. ${ht_capab:+ht_capab=$ht_capab}
  102. $hostapd_cfg
  103. EOF
  104. hostapd -P /var/run/wifi-$ifname.pid -B /var/run/hostapd-$ifname.conf
  105. }