Connectivity Association Key (CAK) derivation from EAP-MSK

James Masiano james.masiano at
Fri Sep 30 09:51:10 PDT 2016

Good morning everyone,

I'm working with wpa_supplicant and MACsec implementation for Linux and I'm trying to
build an infrastructure, composed only by two stations, where a supplicant automatically 
derives the Connectivity Association Key (CAK) from the EAP-MSK after a successful 
authentication with an access point. 

I'm only able to work with pre-shared CAKs and I was asking myself if I can build the above 
reported scenario by using two instances of wpa_supplicant or by using an instance of
wpa_supplicant and an instance of hostapd.


More information about the Hostap mailing list