Revisions of wpa_supplicant

Ana Guerrero's avatar Ana Guerrero (anag+factory) accepted request 1202189 from Clemens Famulla-Conrad's avatar Clemens Famulla-Conrad (cfconrad) (revision 97)
- Revert "Mark authorization completed on driver indication
  during 4-way HS offload" because of WPA2-PSK/WPA-SAE connection
  problems with brcmfmac wifi hardware. (bsc#1230797) 
  [+ Revert-Mark-authorization-completed-on-driver-indica.patch]
Ana Guerrero's avatar Ana Guerrero (anag+factory) accepted request 1200682 from Clemens Famulla-Conrad's avatar Clemens Famulla-Conrad (cfconrad) (revision 96)
- update to v2.11:
  * Wi-Fi Easy Connect
    - add support for DPP release 3
    - allow Configurator parameters to be provided during config exchange
  * HE/IEEE 802.11ax/Wi-Fi 6
    - various fixes
  * EHT/IEEE 802.11be/Wi-Fi 7
    - add preliminary support
  * SAE: add support for fetching the password from a RADIUS server
  * support OpenSSL 3.0 API changes
  * support background radar detection and CAC with some additional
    drivers
  * support RADIUS ACL/PSK check during 4-way handshake (wpa_psk_radius=3)
  * EAP-SIM/AKA: support IMSI privacy
  * improve 4-way handshake operations
    - use Secure=1 in message 3 during PTK rekeying
  * OCV: do not check Frequency Segment 1 Channel Number for 160 MHz cases
    to avoid interoperability issues
  * support new SAE AKM suites with variable length keys
  * support new AKM for 802.1X/EAP with SHA384
  * extend PASN support for secure ranging
  * FT: Use SHA256 to derive PMKID for AKM 00-0F-AC:3 (FT-EAP)
    - this is based on additional details being added in the IEEE 802.11
      standard
    - the new implementation is not backwards compatible
  * improved ACS to cover additional channel types/bandwidths
  * extended Multiple BSSID support
  * fix beacon protection with FT protocol (incorrect BIGTK was provided)
  * support unsynchronized service discovery (USD)
  * add preliminary support for RADIUS/TLS
  * add support for explicit SSID protection in 4-way handshake
    (a mitigation for CVE-2023-52424; disabled by default for now, can be
    enabled with ssid_protection=1)
  * fix SAE H2E rejected groups validation to avoid downgrade attacks
  * use stricter validation for some RADIUS messages
  * a large number of other fixes, cleanup, and extensions
- refresh patches:
    wpa_supplicant-dump-certificate-as-PEM-in-debug-mode.diff
    wpa_supplicant-sigusr1-changes-debuglevel.patch
- drop patches:
    CVE-2023-52160.patch 
    dbus-Fix-property-DebugShowKeys-and-DebugTimestamp.patch
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 878125 from Clemens Famulla-Conrad's avatar Clemens Famulla-Conrad (cfconrad) (revision 87)
- Fix systemd device ready dependencies in wpa_supplicant@.service file.
  (see: https://forums.opensuse.org/showthread.php/547186-wpa_supplicant-service-fails-on-boot-succeeds-on-restart?p=2982844#post2982844)
Dominique Leuenberger's avatar Dominique Leuenberger (dimstar_suse) accepted request 797131 from Clemens Famulla-Conrad's avatar Clemens Famulla-Conrad (cfconrad) (revision 79)
- Add CVE-2019-16275.patch -- AP mode PMF disconnection protection bypass
  (bsc#1150934)
Displaying revisions 1 - 20 of 97
openSUSE Build Service is sponsored by