From: Johannes Berg <johannes@sipsolutions.net>
To: Christian Lamparter <chunkeey@googlemail.com>
Cc: linux-wireless@vger.kernel.org, linville@tuxdriver.com
Subject: Re: [PATCH] carl9170: connect to 11w protected networks
Date: Mon, 03 Sep 2012 01:18:05 +0200 [thread overview]
Message-ID: <1346627885.10113.11.camel@jlt4.sipsolutions.net> (raw)
In-Reply-To: <201209030053.28945.chunkeey@googlemail.com> (sfid-20120903_005335_540855_3166FD85)
On Mon, 2012-09-03 at 00:53 +0200, Christian Lamparter wrote:
> > > While the documentation hints that there's some
> > > hardware support for offloading MFP "decryption",
> > > this simple implementation relies on the mac80211
> > > stack to do the actual crypto operations.
> >
> > Maybe we need to clarify the documentation...
>
> Something like a special section about converting
> drivers of legacy devices like this one, or more
> general?
Sorry, I got confused. I was thinking of clarifying the *mac80211*
documentation about why the flag exists and what the caveats are that I
described below.
> > You should verify that unicast management frames are properly encrypted
> > and decrypted by the hardware (or punted to software on RX like you do
> > on TX). The danger is that the hardware corrupts CCMP encrypted RX mgmt
> > frames and software can't recover.
> At least for AR9170, there's a bit which tells the
> hardware not do decrypt any management frames:
> AR9170_MAC_ENCRYPTION_MGMT_RX_SOFTWARE
>
> Of course, this 'very' patch sets it. Also,
> in case of carl9170, it was easy to verify as
> the device can easily establish BA sessions with
> the 11w ap and the action mgmt frames are
> properly encrypted on both sides.
Ok, cool! Just making sure ... :-)
johannes
prev parent reply other threads:[~2012-09-02 23:17 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-09-02 12:25 [PATCH] carl9170: connect to 11w protected networks Christian Lamparter
2012-09-02 21:48 ` Johannes Berg
2012-09-02 22:53 ` Christian Lamparter
2012-09-02 23:18 ` Johannes Berg [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1346627885.10113.11.camel@jlt4.sipsolutions.net \
--to=johannes@sipsolutions.net \
--cc=chunkeey@googlemail.com \
--cc=linux-wireless@vger.kernel.org \
--cc=linville@tuxdriver.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.