[PATCH 0/5] introduce new mka configuration options

Jouni Malinen j at w1.fi
Sat Nov 19 14:41:48 PST 2016


On Wed, Nov 02, 2016 at 04:38:34PM +0100, Sabrina Dubroca wrote:
> Patch 1 adds a pre-shared key mode for MKA, so that we don't need to
> setup full authentication. Some switches already use this, and that's
> a pretty easy way to configure a network.
> 
> Patch 2 allows a MKA-PSK agent to stay in stand-by mode indefinitely
> until peers appear on the network, instead of timeouting quickly if no
> peer exists when the agent is started up.
> 
> Patch 3 adds a configuration parameter to enable or disable
> encryption. When encryption is disabled, MACsec will only provide
> integrity.
> 
> Patch 4 implements the encryption control in MKA.
> 
> Patch 5 allows choosing the port component in the SCI. Currently,
> wpa_supplicant only supports port == 1.

Thanks, applied with some fixes and cleanup.
 
-- 
Jouni Malinen                                            PGP id EFC895FA



More information about the Hostap mailing list