[PATCH] PR: Use DH group 19 for OOB and allow multiple pairwise ciphers on responder
Jouni Malinen
j at w1.fi
Sun Aug 23 03:26:38 PDT 2026
On Thu, Aug 20, 2026 at 06:58:15AM +0000, Emily Xia wrote:
> According to the P2P Proximity Ranging specification D1.8, unauthenticated
> mode PASN with DH group 19 is the mandatory baseline supported by all
> devices.
>
> For peers discovered via Out-of-Band (OOB) mechanism, peer capabilities
> in dev->pr_caps are not known in advance, so defaulting to DH group 19
> and CCMP ensures spec compliance and cross-device interoperability.
>
> Additionally, on the responder side, set pasn->rsn_pairwise to accept
> both WPA_CIPHER_CCMP and WPA_CIPHER_GCMP_256 so that the responder does
> not reject an initiator using CCMP (e.g. in OOB mode) with
> WLAN_STATUS_INVALID_RSNE (72) even if DH group 20 is locally supported.
Thanks, applied.
--
Jouni Malinen PGP id EFC895FA
More information about the Hostap
mailing list