<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Client able to connect due to invalid PMKID in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5313280#M285008</link>
    <description>&lt;P&gt;Answers -&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. what invalid pmkid says? Invalid password? If can someone clear here about what is pmkid and why it's needed.&lt;BR /&gt;Ans - PMKID is an unique identifier which gets generated as part of the auth mechanism between a client and AP. This ID identifies the PMK used for encrypting comm between and client and AP. During the 4 way handshake the first key that gets generated is MSK. PMK gets derived from MSK.&amp;nbsp;The PMKID is derived from this key and exchanged as part of the handshake process. During fast roaming process, this&amp;nbsp;PMKID allows clients to quickly and securely reconnect to different APs without re-authenticating from scratch.&lt;/P&gt;
&lt;P&gt;2. How do I validate what makes pmkid being invalid? Does it have expiry time to be valid?&lt;BR /&gt;Ans - We do have option to validate but not east to figure out as it need OTA, WLC internal RA trace and EPC. Every single new auth will generate a new PMKID.&lt;BR /&gt;&lt;BR /&gt;Coming back to your scenario, when the user is already connected to SSID and in RUN state, that means PMKID is already generated. This will come in picture if the device tries to roam. Although it might be physically not moving but if the driver is sensitive and getting signals from multiple APs with almost same signals strength, it can try to roam. Now when WLC says invalid pmkid, there could be 2 possibilities - either device is sending a wrong PMKID which WLC/AP is not aware of. Or else device is sending a correct PMKID, however WLC/AP is reporting it in wrong way. So in your scenario first thing that need to validated if the device is roaming across different APs while physically located in one place. If that's happening and you don't want that, data rates/power levels can be tweaked to see if you can stop that. If that gets stopped, roaming won't happen and subsequently no further issue for PMKID mismatch.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Jul 2025 04:18:41 GMT</pubDate>
    <dc:creator>Saikat Nandy</dc:creator>
    <dc:date>2025-07-24T04:18:41Z</dc:date>
    <item>
      <title>Client able to connect due to invalid PMKID</title>
      <link>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5312563#M284962</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm facing client disconnection , it tries to connect to the AP and the user is steady and not moving. Captured RA traces and found out the it is happening due to PMKID is sent during authentication.&lt;/P&gt;&lt;P&gt;Client sending authentication request to AP and AP sending back authentication response with status invalid pmkid.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Two concerns here,&lt;/P&gt;&lt;P&gt;1. what invalid pmkid says? Invalid password? If can someone clear here about what is pmkid and why it's needed.&lt;/P&gt;&lt;P&gt;2. How do I validate what makes pmkid being invalid? Does it have expiry time to be valid?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 21:50:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5312563#M284962</guid>
      <dc:creator>Maccarony</dc:creator>
      <dc:date>2025-07-22T21:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Client able to connect due to invalid PMKID</title>
      <link>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5312718#M284970</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; -&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1900455"&gt;@Maccarony&lt;/a&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;What software &lt;STRONG&gt;version&lt;/STRONG&gt; are you using on the 9800 controller ?&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; + Checkout these&lt;FONT color="#FF6600"&gt;&lt;EM&gt; bug reports :&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch?pf=prdNm&amp;amp;prdNam=Cisco%20Catalyst%209800%20Series%20Wireless%20Controllers&amp;amp;kw=pmkid&amp;amp;bt=custV&amp;amp;sb=anfr" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch?pf=prdNm&amp;amp;prdNam=Cisco%20Catalyst%209800%20Series%20Wireless%20Controllers&amp;amp;kw=pmkid&amp;amp;bt=custV&amp;amp;sb=anfr&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; M.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 06:20:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5312718#M284970</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2025-07-23T06:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: Client able to connect due to invalid PMKID</title>
      <link>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5312795#M284979</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1900455"&gt;@Maccarony&lt;/a&gt;&amp;nbsp;you can get some undestanding of how PMK, GTK and authentication process work from following link&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://mrncciew.com/2014/09/11/cwsp-pmk-caching-preauthentication/" target="_blank"&gt;https://mrncciew.com/2014/09/11/cwsp-pmk-caching-preauthentication/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 09:38:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5312795#M284979</guid>
      <dc:creator>srimal99</dc:creator>
      <dc:date>2025-07-23T09:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: Client able to connect due to invalid PMKID</title>
      <link>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5313037#M284985</link>
      <description>&lt;P&gt;Thanks for sharing , I understand its a unique key mutual between AP to station, my concern is it related to password practically when we try to login to wireless network and shown up window with user/password.&lt;/P&gt;&lt;P&gt;So invalid password says invalid pmkid?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 16:54:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5313037#M284985</guid>
      <dc:creator>Maccarony</dc:creator>
      <dc:date>2025-07-23T16:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Client able to connect due to invalid PMKID</title>
      <link>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5313042#M284986</link>
      <description>&lt;P&gt;Only make sure wifi client add correct password.&lt;/P&gt;
&lt;P&gt;If yoh use symbols in password try change it.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 17:02:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5313042#M284986</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-23T17:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Client able to connect due to invalid PMKID</title>
      <link>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5313068#M284990</link>
      <description>&lt;P&gt;So invalid pmkid means incorrect password?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 17:41:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5313068#M284990</guid>
      <dc:creator>Maccarony</dc:creator>
      <dc:date>2025-07-23T17:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Client able to connect due to invalid PMKID</title>
      <link>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5313077#M284991</link>
      <description>&lt;P&gt;If you not do roaming' then it can be issue of wrong password.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 18:02:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5313077#M284991</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-23T18:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: Client able to connect due to invalid PMKID</title>
      <link>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5313280#M285008</link>
      <description>&lt;P&gt;Answers -&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. what invalid pmkid says? Invalid password? If can someone clear here about what is pmkid and why it's needed.&lt;BR /&gt;Ans - PMKID is an unique identifier which gets generated as part of the auth mechanism between a client and AP. This ID identifies the PMK used for encrypting comm between and client and AP. During the 4 way handshake the first key that gets generated is MSK. PMK gets derived from MSK.&amp;nbsp;The PMKID is derived from this key and exchanged as part of the handshake process. During fast roaming process, this&amp;nbsp;PMKID allows clients to quickly and securely reconnect to different APs without re-authenticating from scratch.&lt;/P&gt;
&lt;P&gt;2. How do I validate what makes pmkid being invalid? Does it have expiry time to be valid?&lt;BR /&gt;Ans - We do have option to validate but not east to figure out as it need OTA, WLC internal RA trace and EPC. Every single new auth will generate a new PMKID.&lt;BR /&gt;&lt;BR /&gt;Coming back to your scenario, when the user is already connected to SSID and in RUN state, that means PMKID is already generated. This will come in picture if the device tries to roam. Although it might be physically not moving but if the driver is sensitive and getting signals from multiple APs with almost same signals strength, it can try to roam. Now when WLC says invalid pmkid, there could be 2 possibilities - either device is sending a wrong PMKID which WLC/AP is not aware of. Or else device is sending a correct PMKID, however WLC/AP is reporting it in wrong way. So in your scenario first thing that need to validated if the device is roaming across different APs while physically located in one place. If that's happening and you don't want that, data rates/power levels can be tweaked to see if you can stop that. If that gets stopped, roaming won't happen and subsequently no further issue for PMKID mismatch.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 04:18:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5313280#M285008</guid>
      <dc:creator>Saikat Nandy</dc:creator>
      <dc:date>2025-07-24T04:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: Client able to connect due to invalid PMKID</title>
      <link>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5313282#M285009</link>
      <description>&lt;P&gt;are you using fast transition ? if yes disable and test again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 04:22:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5313282#M285009</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2025-07-24T04:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: Client able to connect due to invalid PMKID</title>
      <link>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5313827#M285016</link>
      <description>&lt;P&gt;is this an intune managed device? What authentication method is being used: EAP-TLS, EAP-PEAP with MSChapv2&lt;BR /&gt;are these windows 11 devices with credential guard enabled&lt;/P&gt;
&lt;P&gt;what is PMK cache set to if intune managed devices&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Had situation where PMK cache was set to 5min and this caused similar issues. Also EAP-PEAP is not supported if Credential Guard is enabled from Microsoft&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 23:20:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/client-able-to-connect-due-to-invalid-pmkid/m-p/5313827#M285016</guid>
      <dc:creator>Haydn Andrews</dc:creator>
      <dc:date>2025-07-24T23:20:10Z</dc:date>
    </item>
  </channel>
</rss>

