* Inquiry: Is WPA3-FT Roaming Supported in iwd ver3.9
@ 2025-09-22 21:23 amit kumar
2025-09-22 21:51 ` James Prestwood
0 siblings, 1 reply; 3+ messages in thread
From: amit kumar @ 2025-09-22 21:23 UTC (permalink / raw)
To: iwd
Dear iwd maintainers and community,
I’m currently working with iwd version 3.9 and have been evaluating
Fast Transition (FT) behavior across different security
configurations with standard Cisco AP (It supports FT roaming).
In my testing:
1> With "WPA2-FT only" security configuration, connection and roaming
works flawlessly — the device connects and roams as expected.
2> WPA3-SAE also connects without an issue.
3> However, when the AP is configured with "WPA3-FT only" (AKM suite
00-0F-AC:9), iwd fails to connect, logging:
iwd[440]: autoconnect: No suitable BSSes found.
4> With the same AP's config, wpa_supplicant is able to connect and roam.
Upon reviewing the source code, I noticed that the AKM suite for FT
over SAE (IE_RSN_AKM_SUITE_FT_OVER_SAE_SHA256) is not included in the
logic that identifies WPA3-Personal networks. After adding the
following patch to ie.c, iwd successfully connects to the WPA3-FT AP:
----
diff --git a/src/ie.c b/src/ie.c
--- a/src/ie.c
+++ b/src/ie.c
@@ -1338,7 +1338,8 @@ bool ie_rsne_is_wpa3_personal(const struct
ie_rsn_info *info)
* 3. an AP should enable AKM suite selector: 00-0F-AC:6
* 5. an AP shall set MFPC to 1, MFPR to 0
*/
- if (!(info->akm_suites & IE_RSN_AKM_SUITE_SAE_SHA256))
+ if (!(info->akm_suites & IE_RSN_AKM_SUITE_SAE_SHA256) &&
+ !(info->akm_suites & IE_RSN_AKM_SUITE_FT_OVER_SAE_SHA256))
return false;
if (!info->mfpc)
----
My query:
Does iwd officially support WPA3-FT roaming? If not, is there a
specific reason this AKM suite is excluded — such as spec maturity,
roaming logic limitations, or security concerns?
I’d appreciate any insights into the roadmap or design considerations
around WPA3-FT support. Happy to share logs or test results if
helpful.
Best regards,
[Amit Kumar]
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: Inquiry: Is WPA3-FT Roaming Supported in iwd ver3.9 2025-09-22 21:23 Inquiry: Is WPA3-FT Roaming Supported in iwd ver3.9 amit kumar @ 2025-09-22 21:51 ` James Prestwood 2025-10-26 3:40 ` amit kumar 0 siblings, 1 reply; 3+ messages in thread From: James Prestwood @ 2025-09-22 21:51 UTC (permalink / raw) To: amit kumar, iwd Hi Amit, On 9/22/25 2:23 PM, amit kumar wrote: > Dear iwd maintainers and community, > > I’m currently working with iwd version 3.9 and have been evaluating > Fast Transition (FT) behavior across different security > configurations with standard Cisco AP (It supports FT roaming). > > In my testing: > > 1> With "WPA2-FT only" security configuration, connection and roaming > works flawlessly — the device connects and roams as expected. > 2> WPA3-SAE also connects without an issue. > 3> However, when the AP is configured with "WPA3-FT only" (AKM suite > 00-0F-AC:9), iwd fails to connect, logging: > iwd[440]: autoconnect: No suitable BSSes found. > 4> With the same AP's config, wpa_supplicant is able to connect and roam. > > Upon reviewing the source code, I noticed that the AKM suite for FT > over SAE (IE_RSN_AKM_SUITE_FT_OVER_SAE_SHA256) is not included in the > logic that identifies WPA3-Personal networks. After adding the > following patch to ie.c, iwd successfully connects to the WPA3-FT AP: > > ---- > > diff --git a/src/ie.c b/src/ie.c > --- a/src/ie.c > +++ b/src/ie.c > @@ -1338,7 +1338,8 @@ bool ie_rsne_is_wpa3_personal(const struct > ie_rsn_info *info) > * 3. an AP should enable AKM suite selector: 00-0F-AC:6 > * 5. an AP shall set MFPC to 1, MFPR to 0 > */ > - if (!(info->akm_suites & IE_RSN_AKM_SUITE_SAE_SHA256)) > + if (!(info->akm_suites & IE_RSN_AKM_SUITE_SAE_SHA256) && > + !(info->akm_suites & IE_RSN_AKM_SUITE_FT_OVER_SAE_SHA256)) > return false; > > if (!info->mfpc) > > ---- > > My query: > Does iwd officially support WPA3-FT roaming? If not, is there a > specific reason this AKM suite is excluded — such as spec maturity, > roaming logic limitations, or security concerns? IWD does support WPA3-FT, but based on the spec an AP should never advertise only this AKM. It should include plain SAE as well: 2.2 WPA3-Personal only mode 1. An AP shall enable at least AKM suite selector 00-0F-AC:8 in the BSS This is also in the comment above your diff. I would definitely file a bug report with Cisco if you're able to, or ask what the intention of this configuration is. It really makes no sense IMO to have _only_ FT, i.e. how would you associate initially? I'm unable to find anything online about "WAP3-FT only" and I also checked the settings for the AP vendor we use and there is no such "WPA3-FT only" option. Relaxing this requirement in IWD is of course an option but I suspect Cisco is going to have compatibility issues across the board due to this. Thanks, James > > Id appreciate any insights into the roadmap or design considerations > around WPA3-FT support. Happy to share logs or test results if > helpful. > > Best regards, > [Amit Kumar] > ^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: Inquiry: Is WPA3-FT Roaming Supported in iwd ver3.9 2025-09-22 21:51 ` James Prestwood @ 2025-10-26 3:40 ` amit kumar 0 siblings, 0 replies; 3+ messages in thread From: amit kumar @ 2025-10-26 3:40 UTC (permalink / raw) To: James Prestwood; +Cc: iwd, amitkumar.karwar Hi James, Thanks for the response!! "Cisco Catalyst 9800-L Wireless Controller" router is used for WPA2/WPA3 FT roaming scenario testing. It works well with wpa_supplicant when configured with WPA2/WPA3 FT only configuration. IWD is also working okay with WPA2 FT only. As checked in the spec, the IEEE 802.11-2020 standard defines SAE and FT-SAE as valid AKM suites under RSN. It allows APs to advertise only 00-0f-ac:9 in RSN IE if they intend to support WPA3 with Fast Transition only. Table 9-151—AKM suite selectors from IEEE 802.11-2020 spec doesn't impose any restrictions on using it as the sole AKM suite in RSN IE. The standard does not prohibit using 00-0f-ac:9 as the only AKM suite in the RSN IE. It allows APs to advertise any supported AKM suite(s), including FT-SAE alone, provided the STA supports it. In my opinion, as there is not restriction on WPA2-FT (00-0f-ac:4) to have WPA2-PSK(00-0f-ac:2)for akm suite selection in wiphy_select_akm() thus similar to it WPA3-FT (00-0f-ac:9) should be treated independently. Regards, Amit Kumar On Tue, Sep 23, 2025 at 3:21 AM James Prestwood <prestwoj@gmail.com> wrote: > > Hi Amit, > > On 9/22/25 2:23 PM, amit kumar wrote: > > Dear iwd maintainers and community, > > > > I’m currently working with iwd version 3.9 and have been evaluating > > Fast Transition (FT) behavior across different security > > configurations with standard Cisco AP (It supports FT roaming). > > > > In my testing: > > > > 1> With "WPA2-FT only" security configuration, connection and roaming > > works flawlessly — the device connects and roams as expected. > > 2> WPA3-SAE also connects without an issue. > > 3> However, when the AP is configured with "WPA3-FT only" (AKM suite > > 00-0F-AC:9), iwd fails to connect, logging: > > iwd[440]: autoconnect: No suitable BSSes found. > > 4> With the same AP's config, wpa_supplicant is able to connect and roam. > > > > Upon reviewing the source code, I noticed that the AKM suite for FT > > over SAE (IE_RSN_AKM_SUITE_FT_OVER_SAE_SHA256) is not included in the > > logic that identifies WPA3-Personal networks. After adding the > > following patch to ie.c, iwd successfully connects to the WPA3-FT AP: > > > > ---- > > > > diff --git a/src/ie.c b/src/ie.c > > --- a/src/ie.c > > +++ b/src/ie.c > > @@ -1338,7 +1338,8 @@ bool ie_rsne_is_wpa3_personal(const struct > > ie_rsn_info *info) > > * 3. an AP should enable AKM suite selector: 00-0F-AC:6 > > * 5. an AP shall set MFPC to 1, MFPR to 0 > > */ > > - if (!(info->akm_suites & IE_RSN_AKM_SUITE_SAE_SHA256)) > > + if (!(info->akm_suites & IE_RSN_AKM_SUITE_SAE_SHA256) && > > + !(info->akm_suites & IE_RSN_AKM_SUITE_FT_OVER_SAE_SHA256)) > > return false; > > > > if (!info->mfpc) > > > > ---- > > > > My query: > > Does iwd officially support WPA3-FT roaming? If not, is there a > > specific reason this AKM suite is excluded — such as spec maturity, > > roaming logic limitations, or security concerns? > > IWD does support WPA3-FT, but based on the spec an AP should never > advertise only this AKM. It should include plain SAE as well: > > 2.2 WPA3-Personal only mode > 1. An AP shall enable at least AKM suite selector 00-0F-AC:8 in the BSS > > This is also in the comment above your diff. I would definitely file a > bug report with Cisco if you're able to, or ask what the intention of > this configuration is. It really makes no sense IMO to have _only_ FT, > i.e. how would you associate initially? > > I'm unable to find anything online about "WAP3-FT only" and I also > checked the settings for the AP vendor we use and there is no such > "WPA3-FT only" option. > > Relaxing this requirement in IWD is of course an option but I suspect > Cisco is going to have compatibility issues across the board due to this. > > Thanks, > > James > > > > > Id appreciate any insights into the roadmap or design considerations > > around WPA3-FT support. Happy to share logs or test results if > > helpful. > > > > Best regards, > > [Amit Kumar] > > ^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2025-10-26 3:41 UTC | newest] Thread overview: 3+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2025-09-22 21:23 Inquiry: Is WPA3-FT Roaming Supported in iwd ver3.9 amit kumar 2025-09-22 21:51 ` James Prestwood 2025-10-26 3:40 ` amit kumar
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.