Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Wireshark-dev: [Wireshark-dev] Cannot Decrypt Fast BSS Transition (802.11r) Packets

From: Mohit Khattar <mohit.khattar@xxxxxx>
Date: Wed, 13 May 2020 12:12:46 -0600
Hi,

We (myself and Jeff Hansen, CC'd) have been having trouble decrypting data packets on a monitor-mode capture involving packets between an ath9k client and a Fast BSS Transition-capable wireless network with WPA-EAP encryption. We have tried using the PMK and the PTK from the AP, with no success.
We also tried decrypting data packets on a WPA-PSK wireless network using the passphrase, and were unsuccessful if Fast BSS Transition was enabled on the network.

On wireless networks without fast-transition, we have been able to decrypt both WPA-EAP (using PMK) monitor mode pcaps, as well as WPA-PSK pcaps (using passphrase).

I am using Version 3.2.3 (v3.2.3-0-gf39b50865a13), which is the newest (stable) version currently available.

Is decryption of fast BSS transition data packets supported by Wireshark? If so, could you please suggest what we can do to investigate what is going on?

Thanks,
Mohit Khattar