eriptic / uoscore-uedhoc Goto Github PK
View Code? Open in Web Editor NEWC implementations for constrained (and non-constrained) devices of the IETF protocols OSCORE and EDHOC
License: Other
C implementations for constrained (and non-constrained) devices of the IETF protocols OSCORE and EDHOC
License: Other
Hi!
Version: v2.1.4 in samples/linux_edhoc and default configurations without any modifications only commenting out the AddressSanitizer in the makefile in responder and initiator.
# use AddressSanitizer to find memory bugs
# comment this out for better speed
#CFLAGS += -fsanitize=address -fno-omit-frame-pointer
#CXXFLAGS += -fsanitize=address -fno-omit-frame-pointer
#LDFLAGS += -fsanitize=address -static-libasan
According to the RFC only method types: 0, 1, 2, and 3 are valid. When i modify the method type in message 1 and send it, the responder and initiator complete the protocol even if the method type is 8.
m1._message_1_METHOD=8;
TRY_EXPECT(cbor_encode_message_1(rc->msg, rc->msg_len, &m1, &payload_len_out),
true);
rc->msg_len = (uint32_t)payload_len_out;
Initiator creating message 1:
Responder receving message 1:
Sincerely Sabor
I am doing research that involves configuring different key management strategies, such as Pre-shared Keys (PSK), Raw Public Keys (RPK), and dynamically generated keys. I also want to remove the CBOR encoding of the certificates and use an X.509 certificate instead of a C.509 certificate. Is there any built-in support for doing these tasks? If possible, could you please provide me with some guidance on how this can be done? Thank you in advance!
Hi!
Version: v2.1.4 in samples/linux_edhoc and default configurations without any modifications only commenting out the AddressSanitizer in the makefile in responder and initiator.
# use AddressSanitizer to find memory bugs
# comment this out for better speed
#CFLAGS += -fsanitize=address -fno-omit-frame-pointer
#CXXFLAGS += -fsanitize=address -fno-omit-frame-pointer
#LDFLAGS += -fsanitize=address -static-libasan
When i define EDHOC_MESSAGE_4_SUPPORTED in both the responder.c and initiator.c and run them then the initiator gets segmentation fault because of line 186 but the responder finishes successfully.
#define EDHOC_MESSAGE_4_SUPPORTED
Sincerely Sabor
After the recent commits (most likely those of zcbor-0.80.0
) make
in the samples
directory has ceased working.
It works alright for make -C samples/linux_edhoc/initiator
, but fails with various undefined references for e.g. make -C samples/linux_edhoc/responder
(and also for make -C samples/linux_edhoc_oscore/initiator_client
and make -C samples/linux_edhoc_oscore/responder_server
).
Can these also be updated/fixed?
PS. This happens on a Linux Debian 12.5 machine, if it makes any difference.
Hello, I am trying to replicate the steps from https://github.com/eriptic/uoscore-uedhoc/blob/a03997fc698db562527d95ea531985678d7a0954/samples/zephyr_edhoc/README.MD but after flashing onto the ESP-32 that I'm using, I don't see
uart:$ *** Booting Zephyr OS build zephyr-v3.1.0-4283-g5108c4f21d3d ***$ IPv6 server with address 2001:db8::1 started!
[00:00:00.264,709] bt_hci_core: HW Platform: Nordic Semiconductor (0x0002)
[00:00:00.264,739] bt_hci_core: HW Variant: nRF52x (0x0002)
[00:00:00.264,770] bt_hci_core: Firmware: Standard Bluetooth controller (0x00) Version 3.1 Build 99
[00:00:00.265,686] bt_hci_core: Identity: D0:21:3D:B1:36:09 (random)
[00:00:00.265,716] bt_hci_core: HCI: version 5.3 (0x0c) revision 0x0000, manufacturer 0x05f1
[00:00:00.265,716] bt_hci_core: LMP: version 5.3 (0x0c) subver 0xffff
uart:
waiting to receive message 1...
waiting to receive in rx()
but rather, I see
rst:0x1 (POWERON_RESET),boot:0x13 (SPI_FAST_FLASH_BOOT)
configsip: 0, SPIWP:0xee
clk_drv:0x00,q_drv:0x00,d_drv:0x00,cs0_drv:0x00,hd_drv:0x00,wp_drv:0x00
mode:DIO, clock div:2
load:0x3ffbdb60,len:18224
load:0x40080000,len:121216
1162 mmu set 00010000, pos 00010000
1162 mmu set 00020000, pos 00020000
entry 0x4008f364
I (75) boot: ESP Simple boot
I (75) boot: compile time Jun 7 2024 15:10:21
W (75) boot: Unicore bootloader
I (75) spi_flash: detected chip: generic
I (78) spi_flash: flash io: dio
I (81) boot: chip revision: v1.0
I (84) boot.esp32: SPI Speed : 40MHz
I (87) boot.esp32: SPI Mode : DIO
I (91) boot.esp32: SPI Flash Size : 4MB
I (94) boot: Enabling RNG early entropy source...
[esp32] [INF] DRAM: lma 0x00001020 vma 0x3ffbdb60 len 0x4730 (18224)
[esp32] [INF] IRAM: lma 0x00005758 vma 0x40080000 len 0x1d980 (121216)
[esp32] [INF] padd: lma 0x000230e8 vma 0x00000000 len 0xcf10 (53008)
[esp32] [INF] IMAP: lma 0x00030000 vma 0x400d0000 len 0x43ef4 (278260)
[esp32] [INF] padd: lma 0x00073efc vma 0x00000000 len 0xc0fc (49404)
[esp32] [INF] DMAP: lma 0x00080000 vma 0x3f400000 len 0x13724 (79652)
[esp32] [INF] Image with 6 segments
[esp32] [INF] DROM segment: paddr=00080000h, vaddr=3f400000h, size=13724h ( 79652) map
[esp32] [INF] IROM segment: paddr=00030000h, vaddr=400d0000h, size=43EF4h (278260) map
*** Booting Zephyr OS build v3.6.0-5587-g2d44b48cec84 ***
error during socket initialization (error code: -1)waiting to receive message 1...
waiting to receive in rx()
in the serial monitor, do you have an idea what I can do to resolve this issue?
Hello,
We are developing a model learning tool for EDHOC clients and servers and we have used the implementations found in samples/linux_edhoc
and samples/linux_edhoc_oscore
, in order to learn their models and analyze their behavior.
Regarding the samples/linux_edhoc/initiator
of the main branch's commit fbaa96c we observed the following behavior:
The client initiator sends the EDHOC Message 1, receives the EDHOC Message 2 and then sends the final EDHOC Message 3. Interestingly, the client does not wait for a response to the EDHOC Message 3 and terminates immediately.
Is it an issue or is this deliberate ? According to the RFC, shouldn't the client initiator wait for a response to the EDHOC Message 3, in case this response is an (EDHOC) error message ?
I suspect there is a COAP_GET
vs COAP_POST
confusion at this line, because a message with GET
code is not supposed to have payload, or not?
PS. The same issue may be present in other "similar" files - I have not checked this.
Dear all:
I am installing uoscore-uedhoc in a Ubuntu 22.04.1 just for testing in Linux platform so far.
I have been able to compile everything except the example in linux_oscore
In first place, I had a problem since the make execution did not find file zephyr/net/net_pkt.h .
I did a git clone to download the source files of zephyr, but now I got the error below.
I just wondering why this sample it is using zephyr. With the other sample linux_edhoc and linux_edhoc_oscore I did not have this issue.
How could you give some help on this?
Thanks in advance.
In file included from /usr/include/zephyr/toolchain.h:50,
from /usr/include/zephyr/kernel_includes.h:19,
from /usr/include/zephyr/kernel.h:17,
from /usr/include/zephyr/net/buf.h:16,
from /usr/include/zephyr/net/net_pkt.h:22,
from ../../common/sock.h:21,
from ../../common/sock.c:11:
/usr/include/zephyr/toolchain/gcc.h:554:2: error: #error processor architecture not supported
554 | #error processor architecture not supported
| ^~~~~
In file included from /usr/include/zephyr/kernel_includes.h:28,
from /usr/include/zephyr/kernel.h:17,
from /usr/include/zephyr/net/buf.h:16,
from /usr/include/zephyr/net/net_pkt.h:22,
from ../../common/sock.h:21,
from ../../common/sock.c:11:
/usr/include/zephyr/kernel_structs.h:159:26: error: ‘CONFIG_MP_NUM_CPUS’ undeclared here (not in a function)
159 | struct _cpu cpus[CONFIG_MP_NUM_CPUS];
| ^~~~~~~~~~~~~~~~~~
In file included from /usr/include/zephyr/kernel_includes.h:31,
from /usr/include/zephyr/kernel.h:17,
from /usr/include/zephyr/net/buf.h:16,
from /usr/include/zephyr/net/net_pkt.h:22,
from ../../common/sock.h:21,
from ../../common/sock.c:11:
/usr/include/zephyr/syscall.h:11:10: fatal error: syscall_list.h: No such file or directory
11 | #include <syscall_list.h>
| ^~~~~~~~~~~~~~~~
Best Regards.
Hi,
When I'm trying to send a big size payload or response I'm getting this error :
Runtime error: coap2oscore(sendPDU->getPDUPointer(), sendPDU->getPDULength(), buf_oscore, &buf_oscore_len, &c_server) error code 1 at src/main.cpp:322
Hi,
Tests placed in test
directory use Ztest test framework from Zephyr project:
Lines 125 to 196 in 5fe2cb6
From Zephyr 3.1 new Ztest API were introduced with no backward compatibility. From Zephyr 3.4 (with release date set as June 16, 2023), old Ztest API will be deprecated. This could make a problem during building those tests with Zephyr 3.4 or newer.
So if those tests are valuable and there is a plan to maintain them in the future, it should be considered to rewrite them to new Ztest API (or at least add information which Zephyr version should be used for those tests).
New Ztest API description:
https://docs.zephyrproject.org/latest/develop/test/ztest.html
Old (deprecated) Ztest API description:
https://docs.zephyrproject.org/latest/develop/test/ztest_deprecated.html
Example of "migration" to new Ztest API in Zephyr project:
zephyrproject-rtos/zephyr#44761
Common issue in Zephyr project which contains basic instruction and hints for migration:
zephyrproject-rtos/zephyr#47002
Hi!
I guess EDHOC can be used between one server and several clients. Right now if the sender receives message one and some problem occurs when processing it then the responder will terminate and returns some error code. If i want the server to be active again i have to rerun it.
Is this an issue or is this deliberate?
I mean someone who wants to crash the server can just send an invalid message.
Sincerely Sabor
I have some problems to run tests localy. Is the readme file up to date? Maybe description can be splitted into two chapters: embedded devcie and linux host. I tried to run it on dev branch according to the description.
I try to compile the zephyr_edhoc sample in zephyr v3.2.0 by following the README instruction and i get some compile issues when runs in the zephyr_edhoc/initiator
west build -b=nrf52840dk_nrf52840
The error is:
error: #error "<dirent.h> not supported"
10 | #error "<dirent.h> not supported"
| ^~~~~
Could someone please guide me to compile correct the sample?
Issue received per email:
As I see my problems with Observe in Zephyr stems from the following lines in Zephyr coap.c and the fact “inner observe” with OSCORE is zero:
(At least the notifications sent are rejected due to below “age check”)
age = coap_get_option_int(response, COAP_OPTION_OBSERVE);
/* handle observed requests only if received in order */
if (age == -ENOENT || is_newer(r->age, age)) {
r->age = age;
r->reply(response, r, from);
}
I think a work around may be to add an external/outer OSCORE observe value that would pass above check?
Dear all
I got this compiling error or "No such file or directory" messages when compiling different samples. I realized that certainly that , for example, the file sha512.c is not there but _sha512.c , hence the error.
root@h1:/uoscore-uedhoc/samples/linux_edhoc/responder# make
mv: cannot stat '../../../externals/compact25519/src/c25519/sha512.c': No such file or directory
mv: cannot stat '../../../externals/tinycrypt/lib/source/sha256.c': No such file or directory
make: 'build/responder' is up to date.
root@h1:/uoscore-uedhoc/samples/linux_oscore/client# make
mv: cannot stat '../../../externals/compact25519/src/c25519/sha512.c': No such file or directory
gcc -c -m32 -DDEBUG_PRINT -DLINUX_SOCKETS -I../../../inc/ -I../../common/ -I../../../test_vectors/ -I../../../externals/cantcoap/ -I../../../externals/zcbor/include -I../../../externals/mbedtls/library -I../../../externals/mbedtls/include -I../../../externals/mbedtls/include/mbedtls -I../../../externals/mbedtls/include/psa -I../../../externals/compact25519/src/ -I../../../externals/compact25519/src/c25519 -Og -Wall -g -gdwarf-2 -MMD -MP -MF"build/_entropy.d" -DZCBOR_CANONICAL -Wa,-a,-ad,-alms=build/_entropy.lst src/_entropy.c -o build/_entropy.o
gcc: error: unrecognized command-line option '-m32'
make: *** [Makefile:127: build/_entropy.o] Error 1
root@h1:/uoscore-uedhoc/samples/linux_oscore/server# make
mv: cannot stat '../../../externals/compact25519/src/c25519/sha512.c': No such file or directory
gcc -c -m32 -DDEBUG_PRINT -DLINUX_SOCKETS -I../../../inc/ -I../../common/ -I../../../test_vectors/ -I../../../externals/cantcoap/ -I../../../externals/zcbor/include -I../../../externals/mbedtls/library -I../../../externals/mbedtls/include -I../../../externals/mbedtls/include/mbedtls -I../../../externals/mbedtls/include/psa -I../../../externals/compact25519/src/ -I../../../externals/compact25519/src/c25519 -Og -Wall -g -gdwarf-2 -MMD -MP -MF"build/_entropy.d" -DZCBOR_CANONICAL -Wa,-a,-ad,-alms=build/_entropy.lst src/_entropy.c -o build/_entropy.o
gcc: error: unrecognized command-line option '-m32'
make: *** [Makefile:127: build/_entropy.o] Error 1
root@h1:/uoscore-uedhoc/samples/linux_edhoc_oscore/initiator_client# make
mv: cannot stat '../../../externals/compact25519/src/c25519/sha512.c': No such file or directory
make: 'build/initiator_client' is up to date.
root@h1:/uoscore-uedhoc/samples/linux_edhoc_oscore/responder_server# make
mv: cannot stat '../../../externals/compact25519/src/c25519/sha512.c': No such file or directory
mv: cannot stat '../../../externals/tinycrypt/lib/source/sha256.c': No such file or directory
make: 'build/responder_server' is up to date.
Any suggestion?
Thanks in advance.
Hi!
I have tried to run the linux_edhoc sample program in a linux computer. I have tried both the master branch and the tag v.1.0.8.
I cannot complete a handshake successfully.
I have followed these steps:
git clone https://github.com/eriptic/uoscore-uedhoc.git
cd uoscore-uedhoc
git submodule update --init
Then i go to /uoscore-uedhoc/samples/linux_edhoc/responder and run "make".
Then same thing with the initiator, /uoscore-uedhoc/samples/linux_edhoc/initiator.
When i run the responder inside /uoscore-uedhoc/samples/linux_edhoc/responder/build using ./responder then i get this error:
==187946==ERROR: AddressSanitizer failed to allocate 0xdfff0001000 (15392894357504) bytes at address 2008fff7000 (errno: 12)
==187946==ReserveShadowMemoryRange failed while trying to map 0xdfff0001000 bytes. Perhaps you're using ulimit -v
Aborted
Same thing happens when i try to run the initiator.
I went to the make file in initiator and responder and commented out these three lines:
#CFLAGS += -fsanitize=address -fno-omit-frame-pointer
#CXXFLAGS += -fsanitize=address -fno-omit-frame-pointer
#LDFLAGS += -fsanitize=address -static-libasan
Then it is possible to run responder and initiator.
The responder stops at " waiting to receive message 3... "because it is waiting for the third message but the initiator gets:
"Segmentation fault" .
When i debug it, the segmentation fault occurs inside the "enum err encode_int(const int32_t *in, uint32_t in_len, uint8_t *out, uint32_t *out_len) function.
Do you know why this is happening and what i can do to fix it?
I want to use the Initiator-responder sample, but they have to successfully complete the handshake.
Sincerly Sabor
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.