<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Running WPA3-Enterprise without 192-bit mode - possible on Unleashed? in Unleashed</title>
    <link>https://community.ruckuswireless.com/t5/Unleashed/Running-WPA3-Enterprise-without-192-bit-mode-possible-on/m-p/91089#M6308</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.ruckuswireless.com/t5/user/viewprofilepage/user-id/16564"&gt;@kiler129&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Thank you for your question, in order to help you find accurate data could you please indicate the Unleashed version installed on the aps?&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jul 2024 12:37:26 GMT</pubDate>
    <dc:creator>MariaC862</dc:creator>
    <dc:date>2024-07-19T12:37:26Z</dc:date>
    <item>
      <title>Running WPA3-Enterprise without 192-bit mode - possible on Unleashed?</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/Running-WPA3-Enterprise-without-192-bit-mode-possible-on/m-p/81914#M6171</link>
      <description>&lt;P&gt;While migrating our edu network from WPA2/3-Ent to WPA3-Ent I noticed issues with some older Apple devices. One of such example, which we have many, is 11" iPad Pro (MTXQ2LL/A). Per &lt;A href="https://support.apple.com/en-my/guide/security/sec8a67fa93d/web" target="_self"&gt;Apple's documentation&lt;/A&gt;&amp;nbsp;it appears there should be no problem. Even the enhanced 192-bit mode is supported&lt;EM&gt; "(...) in all iPhone 11 models or later, all iPad models starting with the iPad 7th generation, and all Mac computers with Apple silicon."&amp;nbsp;&lt;/EM&gt;which appears to cover A10X and newer. The iPad in question is a A12X device, which made no sense.&lt;/P&gt;&lt;P&gt;However, until further back and forth, we found that our devices are able to join our UniFi network at a different facility but not the Ruckus network. After investigation, compounded by complete lack of logs on Apple's side beyond EAP daemon crashing, it appears that Apple has a buggy 192-bit implementation in WPA3-Enterprise mode. The only place I found this discussed on &lt;A href="https://community.ruckuswireless.com/t5/Unleashed/WPA2-WPA3-Mixed-192-bit-amp-Transition-Disable-Indication/m-p/56367" target="_self"&gt;the forum here is with regards to WPA2/3 mixed mode&lt;/A&gt;, where&amp;nbsp;&lt;a href="https://community.ruckuswireless.com/t5/user/viewprofilepage/user-id/88"&gt;@sanjay_kumar&lt;/a&gt;&amp;nbsp;was testing this on Android.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to disable 192-bit mode, while keeping the network as WPA3-Enterprise on Ruckus Unleashed?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Edit:&amp;nbsp;&lt;BR /&gt;&lt;/STRONG&gt;Ok, I'm starting to believe there's some renaming/nomenclature-confusion going on here, where I'm getting lost myself &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; Someone from Commscope please correct me, or point to a docs page, if I'm wrong. Preliminarily, &lt;A href="https://www.wi-fi.org/system/files/WPA3%20Specification%20v3.3.pdf" target="_blank" rel="noopener"&gt;looking at official WPA3 specs&lt;/A&gt;&amp;nbsp;and doing 802.11 captures, I think this goes like this:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;WPA&lt;U&gt;2&lt;/U&gt; Enterprise&lt;/STRONG&gt;&lt;UL&gt;&lt;LI&gt;Ruckus "Encryption Method": WPA2&lt;/LI&gt;&lt;LI&gt;PMF/80211w-pmf: disabled&lt;/LI&gt;&lt;LI&gt;AKM: 00-0F-AC:1 (dot1x w/SHA-1) only&lt;/LI&gt;&lt;LI&gt;Effect: all clients use WPA2-Ent security&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;WPA2/3 Enterprise capability/transition mode&lt;/STRONG&gt;&lt;UL&gt;&lt;LI&gt;Ruckus "Encryption Method": &lt;SPAN&gt;WPA2/WPA3-Mixed&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;PMF/80211w-pmf: optional (as set by Unleashed, but can be set to required)&lt;/LI&gt;&lt;LI&gt;AKM: 00-0F-AC:1 (dot1x w/SHA-1)&amp;nbsp;*or* 00:0F:AC:5&amp;nbsp;(dot1x w/SHA-256); however, it appears that per spec ("shall enable AT LEAST...") it can support additional auth types (e.g. 00-0F-AC:12).&lt;/LI&gt;&lt;LI&gt;Effect: WPA2 clients can associate as WPA2, WPA3 ones benefit from WPA3 security, at minimum all clients must support PMF&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;WPA3 Enterprise Only&lt;/STRONG&gt;&lt;UL&gt;&lt;LI&gt;Ruckus "Encryption Method": &lt;SPAN&gt;not available&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;PMF/80211w-pmf: required&lt;/LI&gt;&lt;LI&gt;AKM: 00:0F:AC:5&amp;nbsp;(dot1x w/SHA-256); however, it appears that per spec ("shall enable AT LEAST...") it can support additional auth types (e.g. 00-0F-AC:12) but shall not allow&amp;nbsp;00-0F-AC:1 (dot1x w/SHA-1)&lt;/LI&gt;&lt;LI&gt;Effect: WPA2 clients cannot associate, WPA3 ones benefit from WPA3 security, all clients support PMF anyway&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;WPA3-Enterprise with 192-bit mode&lt;/STRONG&gt;&lt;UL&gt;&lt;LI&gt;Ruckus "Encryption Method": &lt;SPAN&gt;WPA3&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;PMF/80211w-pmf: required&lt;/LI&gt;&lt;LI&gt;AKM: 00:0F:AC:12 (dot1x w/CNSA)&amp;nbsp;&lt;U&gt;only&lt;/U&gt;&lt;/LI&gt;&lt;LI&gt;Effect: WPA2 clients cannot associate, WPA3 clients with EC support can associate, WPA3 clients unable to support CNSA fail&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;So, it appears &lt;STRONG&gt;that "WPA3 Enterprise Only"&lt;/STRONG&gt; where "00-0F-AC:1" is disabled &lt;STRONG&gt;isn't possible on Unleashed&lt;/STRONG&gt;? Also, it's not clear to me if AKM of "00:0F:AC:12" (CNSA) can co-exist with "00:0F:AC:5", offering capable clients 192-bit mode while also serving older ones the older 128-bit mode?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some sources appear to claim that WPA3-Enterprise Only Mode is "WPA2-Ent with PMF required", which is incorrect. Ruckus Unleashed "WPA2/WPA3-Mixed" mode with PMF required is closer to more compatible WPA3, but still doesn't allow dropping of the "00-0F-AC:1". This is a bit of a problem as even eduroam networks should soon be configured to disallow WPA2 compat mode but&amp;nbsp;&lt;STRONG&gt;without&lt;/STRONG&gt; 192-bit mode that is buggy and not widely supported.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 02:33:20 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/Running-WPA3-Enterprise-without-192-bit-mode-possible-on/m-p/81914#M6171</guid>
      <dc:creator>kiler129</dc:creator>
      <dc:date>2024-07-04T02:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: Running WPA3-Enterprise without 192-bit mode - possible on Unleashed?</title>
      <link>https://community.ruckuswireless.com/t5/Unleashed/Running-WPA3-Enterprise-without-192-bit-mode-possible-on/m-p/91089#M6308</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.ruckuswireless.com/t5/user/viewprofilepage/user-id/16564"&gt;@kiler129&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Thank you for your question, in order to help you find accurate data could you please indicate the Unleashed version installed on the aps?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 12:37:26 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/Unleashed/Running-WPA3-Enterprise-without-192-bit-mode-possible-on/m-p/91089#M6308</guid>
      <dc:creator>MariaC862</dc:creator>
      <dc:date>2024-07-19T12:37:26Z</dc:date>
    </item>
  </channel>
</rss>

