cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
286
Views
0
Helpful
1
Replies

Null group keys

PaulBullough
Level 1
Level 1

Anyone seen the following problem?

I've set it up for WPA-Enterprise (TKIP) and we get all the way through the authentication and the 4-way handshake, and then it sends me a group key which looks like this:

0xaa 0xaa 0x03 0x00 0x00 0x00 0x88 0x8e 0x01 0x03 0x00 0x5f 0xfe 0x03 0x81

0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x05 0x00 0x00 0x00 0x00 0x00

0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00

0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x10 0xc3 0xc0

0xb8 0x9e 0x27 0xa3 0x94 0x8f 0x72 0x11 0xa6 0x65 0x46 0xa6 0x94 0x00 0x00

0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0xe9

0x0e 0x1d 0xae 0x6b 0x13 0xdb 0x09 0x0f 0x4a 0x0a 0x36 0xfc 0xdc 0xac 0x39

0x00 0x00

which decodes as this:

Version 1, type 3 = EAPOL key, length 0x5F

Descriptor type 0xfe

Key info 0x381:

WPA Key 1/2 -- variant with install for rx only

Descriptor version 1 = no CCMP keys

Key type 0 = not pairwise

Index 0

ACK needed

MIC present

Secure

PTK length 0x0

Replay counter 00-00-00-00-00-00-00-05

Nonce 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00

00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00

Key IV 10-c3-c0-b8-9e-27-a3-94-8f-72-11-a6-65-46-a6-94

Received sequence counter 00-00-00-00-00-00-00-00

Reserved 00-00-00-00-00-00-00-00

MIC e9-0e-1d-ae-6b-13-db-09-0f-4a-0a-36-fc-dc-ac-39

Key data length 0x0

Note the total absence of any kind of actual key in this frame.

Shortly afterwards it deauthenticates us for not responding to this non-existent key.

Note, I know this seems like a bug report and perhaps it should be but I can't find anywhere else on this confusing website to mention it. "On-line support" refuses to answer my questions because I'm not a "reseller" and TAC won't accept it because the serial number is not connected with a particular service contract.

*pulls hair out yet again with Cisco's website*

1 Reply 1

gmarogi
Level 5
Level 5

Group key is the one provided by the access point. So try to reset the access point and try configuring it . Make sure you backup your configuration before you do this.

Review Cisco Networking products for a $25 gift card