public inbox for linux-bluetooth@vger.kernel.org
 help / color / mirror / Atom feed
From: shanevolpe@gmail.com
To: "BlueZ users" <bluez-users@lists.sourceforge.net>
Subject: Re: [Bluez-users] devices always connect with out asking for PIN even with pairing enabled!
Date: Mon, 10 Sep 2007 15:56:28 -0400	[thread overview]
Message-ID: <8c7950360709101256u4a62893dmcd4b342343088a73@mail.gmail.com> (raw)
In-Reply-To: <1189451433.687.59.camel@violet>

Marcel,

I was not trying to do wild guessing with the hci.conf, I have read
the readme's and MAN files on the hcid.conf.   What I'm trying to
better understand is performing secure bluetooth however can't find
documentation on what type of security is available during the initial
paring process.  It seem to me that at the hci level is the correct
place to provide security.

At a minimum I want to provide a unique PIN so that only devices with
that PIN can pair to my unit but I also don't want someone using
hcidump to sit by two of my units that are pairing and get the PIN.

Ideally it would be great to have something similar to ssh were I
could only allow a certain encrypted key to pair to my device.  Then I
could distribute that private encrypted key to all devices that I want
to give connection privilege.   That is what I originally thought the
Auth/Encryption option was for in the hcid.conf but after reading the
MAN page I don't believe that is the case.

FYI:
The hcid.conf MAN page states that encryption in most cases should be
enabled however most default hcid.conf files has it disabled so that
would infer that a user should go in and change the hcid.conf.

I think what I'm finding out (after reading the MAN page again)  is
the best place to get a better understanding of bluetooth security
options is the Bluetooth standards so I will try next to get a copy of
them.

I understand your frustration with the same issues being posted time
and time again and I have tried to avoid doing that by googling the
bluez site and email list.  I will continue to search and try to find
what I have obviously missed!

Regards and sorry,
Shane

On 9/10/07, Marcel Holtmann <marcel@holtmann.org> wrote:
> Hi Shane,
>
> > I have two embedded Linux devices that I'm running a network between
> > using PAN.  I have decided that I would like to enable pairing and
> > eventually encryption for security reasons.
> > Here is what I have done I'm starting pand master with the following:
> > pand --listen --master --role  NAP
> > and the slave with
> > pand --connect 00:A0:96:18:69:D8 --persist
> > were 00:A0:96:18:69:D8 is the masters address.
> >
> > Below are the hci.conf files for both my master and slave device..
>
> don't touch hcid.conf unless you know exactly what you are doing. Wild
> guessing doesn't help here and if you mess it up then it is your fault.
> I mentioned that multiple times, but people keep doing it anyway.
>
> If you wanna have authentication and encryption, then read the manual
> page of pand. It allows you to specify this for the server.
>
> Regards
>
> Marcel
>
>
>
> -------------------------------------------------------------------------
> This SF.net email is sponsored by: Microsoft
> Defy all challenges. Microsoft(R) Visual Studio 2005.
> http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
> _______________________________________________
> Bluez-users mailing list
> Bluez-users@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/bluez-users
>



-- 
Registered Linux User: #293401

-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2005.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________
Bluez-users mailing list
Bluez-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/bluez-users

  reply	other threads:[~2007-09-10 19:56 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-09-06 20:06 [Bluez-users] devices always connect with out asking for PIN even with pairing enabled! shanevolpe
2007-09-10 19:10 ` Marcel Holtmann
2007-09-10 19:56   ` shanevolpe [this message]
2007-09-10 20:56     ` Marcel Holtmann
2007-09-11 12:12       ` shanevolpe
2007-09-11 15:15         ` Marcel Holtmann
2007-09-11 16:00           ` Marcus C. Gottwald

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=8c7950360709101256u4a62893dmcd4b342343088a73@mail.gmail.com \
    --to=shanevolpe@gmail.com \
    --cc=bluez-users@lists.sourceforge.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox