From: Johannes Berg <johannes@sipsolutions.net>
To: Denis Kenzior <denkenz@gmail.com>,
Arend van Spriel <arend@broadcom.com>, Jouni Malinen <j@w1.fi>
Cc: Avraham Stern <avraham.stern@intel.com>,
linux-wireless <linux-wireless@vger.kernel.org>
Subject: Re: ROAM/CONNECT event with PORT_AUTHORIZED
Date: Thu, 14 Sep 2017 21:22:44 +0200 [thread overview]
Message-ID: <1505416964.31630.17.camel@sipsolutions.net> (raw)
In-Reply-To: <6f177c6d-ff79-bc9b-6ed6-e91a1ad96899@gmail.com> (sfid-20170914_210836_116060_CBC37968)
Hi,
> Yep, but I seem to recall there was some vague language that said the
> AP would delete the PMKSA if the client disconnected.
Ok, not sure about that. But even if the AP does, we could try to send
it and it just can't use it :)
> operstates.txt states that for new connections, operstate should be
> dormant until 802.1x is complete & successful. So the !eapol-over-
> nl condition would violate that, no?
As I just wrote in my other email, I think I'm totally confused
regarding this, and the supplicant already does it correctly - and you
can ignore the whole "!eapol-over-nl" conditions, and just read it like
what I thought we could only do in the eapol-over-nl case.
No idea how I ended up with the idea that you could only send data
frames when the netdev was IF_OPER_UP - that doesn't seem to have any
basis in reality.
> > > > - initialize 1X state machines/timeouts
> > > > - 1X handshake
> > > > - send PMK to device for 4-way-HS
> > > > - AUTHORIZED event
> > > > - [if eapol-over-nl: toggle oper state up]
> > > >
>
> Given your explanation above, should this be [if !eapol-over-nl ..?
> So I agree that OPERSTATE_UP should not change on a roam. I think
> we're both in agreement here.
Great.
> My earlier point is that software roams need to have the exact same
> behavior as well. And my understanding is that when we try to
> Fast-Transition (e.g. issue a CMD_ASSOCIATE), operstate is no longer
> UP.
I'm not sure - I don't know what the state machine in wpa_s goes
through here. Probably easier to test than try to reason about the
code...
> At the very least there's lots of confusion with what is supposed to
> happen with operstate and when. So if we can work out & document a
> consistent behavior, I'm all for it.
:-)
johannes
next prev parent reply other threads:[~2017-09-14 19:22 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-09-14 8:39 ROAM/CONNECT event with PORT_AUTHORIZED Johannes Berg
2017-09-14 11:21 ` Arend van Spriel
2017-09-14 11:44 ` Johannes Berg
2017-09-14 18:37 ` Denis Kenzior
2017-09-14 19:17 ` Johannes Berg
2017-09-14 19:34 ` Denis Kenzior
2017-09-14 19:38 ` Ben Greear
2017-09-14 20:05 ` Denis Kenzior
2017-09-14 20:08 ` Ben Greear
2017-09-14 20:26 ` Denis Kenzior
2017-09-14 20:29 ` Ben Greear
2017-09-14 20:35 ` Denis Kenzior
2017-09-14 20:47 ` Ben Greear
2017-09-14 21:35 ` Denis Kenzior
2017-09-14 22:15 ` Ben Greear
2017-09-14 22:42 ` Denis Kenzior
2017-09-14 22:57 ` Ben Greear
2017-09-15 7:23 ` Johannes Berg
2017-09-15 7:20 ` Johannes Berg
2017-09-14 19:39 ` Johannes Berg
2017-09-14 18:27 ` Denis Kenzior
2017-09-14 18:36 ` Johannes Berg
2017-09-14 19:08 ` Denis Kenzior
2017-09-14 19:22 ` Johannes Berg [this message]
2017-09-14 19:37 ` Denis Kenzior
2017-09-14 19:41 ` Johannes Berg
2017-09-14 19:42 ` Johannes Berg
2017-09-14 19:54 ` Denis Kenzior
2017-09-15 7:19 ` Johannes Berg
2017-09-15 12:50 ` Denis Kenzior
2017-09-15 13:29 ` Johannes Berg
2017-09-15 13:50 ` Denis Kenzior
2017-09-15 14:20 ` Johannes Berg
2017-09-15 14:27 ` Denis Kenzior
2017-09-15 14:52 ` Johannes Berg
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1505416964.31630.17.camel@sipsolutions.net \
--to=johannes@sipsolutions.net \
--cc=arend@broadcom.com \
--cc=avraham.stern@intel.com \
--cc=denkenz@gmail.com \
--cc=j@w1.fi \
--cc=linux-wireless@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).