WPA3-Enterprise reported as WPA2?

Post new topic   Reply to topic    DD-WRT Forum Index -> Marvell MVEBU based Hardware (WRT1900AC etc.)
Author Message
o2bad455
DD-WRT User


Joined: 08 Oct 2015
Posts: 252

PostPosted: Sun Aug 29, 2021 2:06    Post subject: WPA3-Enterprise reported as WPA2? Reply with quote
Background: I've been using WPA3-Enterprise (without any WPA2 fallback) from older client radios (circa 2013 with 2016-17 drivers) that worked fine but reported it as WPA2. That is, in network authentication on the WRT1900ACSv1 and ACSv2 dd-wrt routers, I only have the "WPA3 Enterprise" and "CCMP-128 (AES)" checkboxes enabled for some VAPs. An even older client radio (circa 2012, which I just retired) could not connect to a WPA3-only VAP at all, but could connect to a comparable WPA2-only VAP (with 802.11w MFP set to Auto).

Upgrade: I recently replaced that older radio with a WPA3-capable Intel AX210 WIFI-6E card (with latest 2021-06-29 driver) in a Lenovo Win10 Pro laptop PC and tested r47256 with it. When I connected that PC to a WPA3-Personal VAP on either router, Windows wifi properties correctly identified the connection as "WPA3" security. So far, so good.

Problem: However, when I connected that same PC with latest radio and driver to a WPA3-Enterprise VAP on either router, Windows still identified the connection as only "WPA2" security.

EDIT: Per wikipedia, "The new standard uses an equivalent 192-bit cryptographic strength in WPA3-Enterprise mode (AES-256 in GCM mode with SHA-384 as HMAC)". I guess WPA3 Enterprise with AES-128 CCM allowed is exactly the same as WPA2 Enterprise with AES-128 CCM but also with the WPA2-optional 802.11w Management Frame Protection (MFP) required in WPA3, so there's actually no difference from the client's perspective unless it could tell that MFP is required on the AP. I assume that if the router and firmware both supported AES-256 GCM we could require that and then the client would know it must be WPA3, but since we don't have that option (yet?), it can't. Any chance of adding AES-256 GCM as an available WPA algorithm to the Marvell dd-wrt builds? If not, it seems like WPA3-Enterprise isn't truly supported on these routers, so the Intel AX210 is correctly reporting it as only WPA2 Enterprise.

_________________
My DD-WRT Routers:
Linksys WRT3200ACM - Marvell
Linksys WRT1900ACS - Marvell
Netgear R9000 - Atheros
Netgear R7000 - Broadcom
PC x86-64 VM - Atheros
Sponsor
blkt
DD-WRT Guru


Joined: 20 Jan 2019
Posts: 5700

PostPosted: Sun Aug 29, 2021 23:25    Post subject: Reply with quote
I am certain Marvell WRT series do not support WPA3 at all due to abandoned mwlwifi driver and binary blobs.

Unless NXP decides to publicly provide miracles, it is safe to assume new features and fixes will never happen.
o2bad455
DD-WRT User


Joined: 08 Oct 2015
Posts: 252

PostPosted: Mon Aug 30, 2021 1:46    Post subject: Reply with quote
Thanks and understood for WPA3-Enterprise(EAP). For the record, WPA3-Personal(SAE) is working great on both of our WRT1900ACS units (v1 & v2) under r47256.
_________________
My DD-WRT Routers:
Linksys WRT3200ACM - Marvell
Linksys WRT1900ACS - Marvell
Netgear R9000 - Atheros
Netgear R7000 - Broadcom
PC x86-64 VM - Atheros
blkt
DD-WRT Guru


Joined: 20 Jan 2019
Posts: 5700

PostPosted: Mon Aug 30, 2021 2:18    Post subject: Reply with quote
Apparently I am wrong. This might be useful. https://github.com/kaloz/mwlwifi/issues/389
oliver44
DD-WRT Guru


Joined: 01 Jun 2016
Posts: 504

PostPosted: Mon Aug 30, 2021 5:55    Post subject: Reply with quote
I think the problem is on the part of the open source driver developer!
a little test I did with the latest version of openwrt with custom packages...

http://s.go.ro/4fk0f6ej
https://github.com/kaloz/mwlwifi/issues/391

_________________
Internet provider https://en.wikipedia.org/wiki/RCS_%26_RDS 1Gbps
WDR3600 rev.1.5 - DD-Wrt
Linksys WRT1900ACS v.2 DD-Wrt/-OpenWrt



https://ipv6.chappell-family.com/ipv6tcptest/
https://en.internet.nl/connection/e91f490fe1c54cb2b78145c0ab0d2b5a/results
http://www.dnssec-or-not.com/
https://dnscheck.tools/#results
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Marvell MVEBU based Hardware (WRT1900AC etc.) All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum