[PATCH] PR: Use DH group 19 for OOB and allow multiple pairwise ciphers on responder

Jouni Malinen j at w1.fi
Sun Aug 23 03:26:38 PDT 2026


On Thu, Aug 20, 2026 at 06:58:15AM +0000, Emily Xia wrote:
> According to the P2P Proximity Ranging specification D1.8, unauthenticated
> mode PASN with DH group 19 is the mandatory baseline supported by all
> devices.
> 
> For peers discovered via Out-of-Band (OOB) mechanism, peer capabilities
> in dev->pr_caps are not known in advance, so defaulting to DH group 19
> and CCMP ensures spec compliance and cross-device interoperability.
> 
> Additionally, on the responder side, set pasn->rsn_pairwise to accept
> both WPA_CIPHER_CCMP and WPA_CIPHER_GCMP_256 so that the responder does
> not reject an initiator using CCMP (e.g. in OOB mode) with
> WLAN_STATUS_INVALID_RSNE (72) even if DH group 20 is locally supported.

Thanks, applied.
 
-- 
Jouni Malinen                                            PGP id EFC895FA



More information about the Hostap mailing list