<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Question About Authentication And Encryption in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075908#M140346</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with&amp;nbsp; WPA2 PSK how is the authentication part encrypted?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Nov 2012 15:23:11 GMT</pubDate>
    <dc:creator>Jacob Berger</dc:creator>
    <dc:date>2012-11-07T15:23:11Z</dc:date>
    <item>
      <title>Question About Authentication And Encryption</title>
      <link>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075904#M140342</link>
      <description>&lt;P style="text-align: left; unicode-bidi: embed; direction: ltr;"&gt;If I understand correctly&lt;/P&gt;&lt;P style="text-align: left; unicode-bidi: embed; direction: ltr;"&gt;WPA2 has two parts&lt;/P&gt;&lt;P style="text-align: left; unicode-bidi: embed; direction: ltr;"&gt;Authentication and encryption&lt;/P&gt;&lt;P style="text-align: left; unicode-bidi: embed; direction: ltr;"&gt;If I use WPA2 enterprise with RADIUS server and certificates&lt;/P&gt;&lt;P style="text-align: left; unicode-bidi: embed; direction: ltr;"&gt;The authentication part would take place within an encrypted (TLS or other) session&lt;/P&gt;&lt;P style="text-align: left; unicode-bidi: embed; direction: ltr;"&gt;And data session will be encrypted with say AES.&lt;/P&gt;&lt;P style="text-align: left; unicode-bidi: embed; direction: ltr;"&gt;&lt;/P&gt;&lt;P style="text-align: left; unicode-bidi: embed; direction: ltr;"&gt;Questions&lt;/P&gt;&lt;P style="text-align: left; unicode-bidi: embed; direction: ltr;"&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;•1. Is the above correct?&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;•2. Is the whole session between wireless device and AP encrypted and unhackable?&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;•3. When using WPA2 personal (PSK), is the session also encrypted with AES?&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Sun, 04 Jul 2021 05:59:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075904#M140342</guid>
      <dc:creator>Jacob Berger</dc:creator>
      <dc:date>2021-07-04T05:59:43Z</dc:date>
    </item>
    <item>
      <title>Question About Authentication And Encryption</title>
      <link>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075905#M140343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jacob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Great questions! Always nice to see people deep dive this subject. I like you had all those questions as well. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, Yes and Yes.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are 2 very distinct authentications 802.1X and PSK. Both are part of the 802.11-2007 Standard. If you use radius &amp;lt;802.1X&amp;gt; a EAP type is used for authentication. Each EAP type has its own way of authenticating. Some are a dual authentication like PEAP, while others are not like LEAP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PEAP for example uses MSCHAP V2 and TLS to send the login in a secure manner. Again, picking on LEAP uses MSCHAPV2 only, which is breakable and less secure. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After authentication. Then encryption is negoisated during the 4 WAY handshake. ONLY EAPs thats have dual authentication can do AES and TKIP due to the need for dyamic seeding material. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I blogged about a lot of this at my site &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.my80211.com/8021x/"&gt;http://www.my80211.com/8021x/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;__________________________________________________________________________________________ &lt;BR /&gt;"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin &lt;BR /&gt;__________________________________________________________________________________________ &lt;BR /&gt;‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 14:29:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075905#M140343</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2012-11-07T14:29:02Z</dc:date>
    </item>
    <item>
      <title>Question About Authentication And Encryption</title>
      <link>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075906#M140344</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp; Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to clarify&lt;/P&gt;&lt;P&gt;a plain old home user laptop session on a home wirless router with WPA2 PSK setup, is encrypted for whole length of session?&lt;/P&gt;&lt;P&gt;no option of wireshark or anything to sniff around?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 14:58:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075906#M140344</guid>
      <dc:creator>Jacob Berger</dc:creator>
      <dc:date>2012-11-07T14:58:23Z</dc:date>
    </item>
    <item>
      <title>Question About Authentication And Encryption</title>
      <link>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075907#M140345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct. And each time you logon you will create new seeding material as well &lt;NEW keys=""&gt;. You dont get the same KEY each time. &lt;/NEW&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;__________________________________________________________________________________________ &lt;BR /&gt;"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin &lt;BR /&gt;__________________________________________________________________________________________ &lt;BR /&gt;‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 15:09:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075907#M140345</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2012-11-07T15:09:53Z</dc:date>
    </item>
    <item>
      <title>Question About Authentication And Encryption</title>
      <link>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075908#M140346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with&amp;nbsp; WPA2 PSK how is the authentication part encrypted?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 15:23:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075908#M140346</guid>
      <dc:creator>Jacob Berger</dc:creator>
      <dc:date>2012-11-07T15:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: Question About Authentication And Encryption</title>
      <link>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075909#M140347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good question .. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PSK authentication is open to a hack if you capture 2 parts of the 4 way handshake. But this will not expose your traffic, rather it will expose your PSK key. Look up cow-patty hack. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for the key encryption. During this process KEK,KCK keys are used to protect the keying process. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Read this ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.my80211.com/8021x/2010/10/3/george-stefanick-cwsp-journey-chapter-5-4-way-handshake-post.html" rel="nofollow"&gt;http://www.my80211.com/8021x/2010/10/3/george-stefanick-cwsp-journey-chapter-5-4-way-handshake-post.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;__________________________________________________________________________________________ &lt;BR /&gt;"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin &lt;BR /&gt;__________________________________________________________________________________________ &lt;BR /&gt;‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 15:56:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075909#M140347</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2012-11-07T15:56:33Z</dc:date>
    </item>
    <item>
      <title>Question About Authentication And Encryption</title>
      <link>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075910#M140348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks &lt;/P&gt;&lt;P&gt;Ur the King&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 15:32:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075910#M140348</guid>
      <dc:creator>Jacob Berger</dc:creator>
      <dc:date>2012-11-08T15:32:54Z</dc:date>
    </item>
    <item>
      <title>Question About Authentication And Encryption</title>
      <link>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075911#M140349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No worries. I hope this helps. Stop back if you have issues. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;__________________________________________________________________________________________ &lt;BR /&gt;"Satisfaction does not come from knowing the solution, it comes from knowing why." - Rosalind Franklin &lt;BR /&gt;__________________________________________________________________________________________ &lt;BR /&gt;‎"I'm in a serious relationship with my Wi-Fi. You could say we have a connection."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 15:55:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075911#M140349</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2012-11-08T15:55:24Z</dc:date>
    </item>
    <item>
      <title>Question About Authentication And Encryption</title>
      <link>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075912#M140350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;George &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for opening this thread again&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;above you state&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"The PSK authentication is open to a hack if you capture 2 parts of the 4 way handshake. But this will not expose your traffic, rather it will expose your PSK key. Look up cow-patty hack."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://serverfault.com/questions/149888/wep-wpa-wpa2-and-wifi-sniffing"&gt;http://serverfault.com/questions/149888/wep-wpa-wpa2-and-wifi-sniffing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i understand that if my PSK or CERT is compromised , the traffic encryption is very much in danger.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(also authorized users who know the PSK can sniff other users packets)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2012 14:59:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075912#M140350</guid>
      <dc:creator>Jacob Berger</dc:creator>
      <dc:date>2012-12-17T14:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: Question About Authentication And Encryption</title>
      <link>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075913#M140351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jacob&lt;BR /&gt;&lt;BR /&gt;No worries&lt;BR /&gt;&lt;BR /&gt;The 2 part hack is to get the key. At that point you can't see the traffic.&lt;BR /&gt;&lt;BR /&gt;After you have a valid key and you capture a users authentication you could in theory see that users traffic. Your sniffer would have to allow you to decrypt the packets captured. I've never tried it personally with psk. I have with wep.&lt;BR /&gt;&lt;BR /&gt;As for the cert I've never heard anyone actually breaking wireless in that manner. Not to say it can't happen. But that could take forever to do. You might have a better chance hitting the lottery.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2012 16:00:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/question-about-authentication-and-encryption/m-p/2075913#M140351</guid>
      <dc:creator>George Stefanick</dc:creator>
      <dc:date>2012-12-17T16:00:17Z</dc:date>
    </item>
  </channel>
</rss>

