Cannot connect to open WLAN with 1.36.0-1ubuntu2 on Jammy

Bug #1964100 reported by Isaac True
18
This bug affects 4 people
Affects Status Importance Assigned to Milestone
network-manager (Ubuntu)
New
High
Unassigned

Bug Description

I'm trying to connect to an open (i.e. no ecryption) WLAN with network-manager 1.36.0-1ubuntu2 on 22.04 but it's failing with the following error message (after selecting the network from the network-manager applet prompt):

Mär 08 10:50:04 Isaac-Laptop NetworkManager[31754]: <info> [1646733004.4425] audit: op="connection-add-activate" pid=12122 uid=1000 result="fail" reason="802-11-wireless-security.key-mgmt: Access point does not support PSK but setting requires it"

I haven't changed any of the default settings for network-manager and this network worked on 20.04.

Tags: jammy
Revision history for this message
Sebastien Bacher (seb128) wrote :

Thank you for your bug report. Which desktop environment do you use? Could you try to connect and then do

$ journalctl -b 0 > log

and attach the 'log' file to the report?

https://archived.forum.manjaro.org/t/cant-connect-to-eduroam-wifi/122684 also sounds similar, did you try to provide a certificate?

Changed in network-manager (Ubuntu):
importance: Undecided → High
status: New → Incomplete
Revision history for this message
Isaac True (itrue) wrote (last edit ):

I've attached the journalctl output.

I'm running Kubuntu with plasma-nm 5.24.2-0ubuntu1.

I haven't provided a certificate or any authentication details, and the security is set to none in the settings.

Revision history for this message
Isaac True (itrue) wrote :

This seems to be related to OWE (https://en.wikipedia.org/wiki/Opportunistic_Wireless_Encryption). If I disable this in the router, then I can connect without any issues.

Revision history for this message
Sebastien Bacher (seb128) wrote :

there were some recent fixes around owe on bug #1963906 but that's on a GNOME session, unsure if that matches your issue?

Changed in network-manager (Ubuntu):
status: Incomplete → New
Revision history for this message
Sebastien Bacher (seb128) wrote :

Could you try if that's an issue under GNOME? There is a similar report on https://forum.endeavouros.com/t/wpa3-networkmanager-plasma-nm-weirdness/10439 which suggests it could be an issue with plasma

Changed in network-manager (Ubuntu):
status: New → Incomplete
Revision history for this message
Isaac True (itrue) wrote :

Hi @seb128,

Sorry I haven't yet had the chance to test it with GNOME, but I can confirm that it works if I manually add the connection with nmcli, without adding any particular arguments:

    nmcli c add type wifi ssid "<ssid>"

It does seem to indeed be an issue with plasma-nm.

Cheers,
Isaac

Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for network-manager (Ubuntu) because there has been no activity for 60 days.]

Changed in network-manager (Ubuntu):
status: Incomplete → Expired
Revision history for this message
Kenneth Hanson (khanson679) wrote :

Bug is still present with network-manager 1.40.0-1ubuntu2 on Kubuntu 23.04. Just experienced this for the first time today.

Revision history for this message
Dirk Rydvan (rydvan) wrote (last edit ):

Hello everybody!

I face the same issue with an unencrypted Wifi Network "ffm.freifunk.net". This Wifi works well with a android mobile phone.

"802-11-wireless-security.key-mgmt: Access point does not support PSK but setting requires it"

Is there a workaround available?

Apr 17 12:25:27 workstation NetworkManager[900]: <info> [1713349527.4391] audit: op="statistics" interface="wlp58s0" ifindex=2 args="2000" pid=1776 uid=1000 result="success"
Apr 17 12:26:57 workstation NetworkManager[900]: <info> [1713349617.3632] audit: op="statistics" interface="wlp58s0" ifindex=2 args="0" pid=1776 uid=1000 result="success"
Apr 17 12:26:58 workstation NetworkManager[900]: <info> [1713349618.1159] audit: op="statistics" interface="wlp58s0" ifindex=2 args="2000" pid=1776 uid=1000 result="success"
Apr 17 12:26:59 workstation NetworkManager[900]: <info> [1713349619.4491] audit: op="statistics" interface="wlp58s0" ifindex=2 args="0" pid=1776 uid=1000 result="success"
Apr 17 12:27:01 workstation NetworkManager[900]: <info> [1713349621.5788] audit: op="statistics" interface="wlp58s0" ifindex=2 args="2000" pid=1776 uid=1000 result="success"
Apr 17 12:27:02 workstation NetworkManager[900]: <info> [1713349622.6890] audit: op="statistics" interface="wlp58s0" ifindex=2 args="0" pid=1776 uid=1000 result="success"
Apr 17 12:27:04 workstation NetworkManager[900]: <info> [1713349624.3895] audit: op="statistics" interface="wlp58s0" ifindex=2 args="2000" pid=1776 uid=1000 result="success"
Apr 17 12:27:07 workstation NetworkManager[900]: <info> [1713349627.9540] audit: op="connection-add-activate" pid=1776 uid=1000 result="fail" reason="802-11-wireless-security.key-mgmt: Access point does not support PSK but setting requires it"
Apr 17 12:27:15 workstation NetworkManager[900]: <info> [1713349635.4389] audit: op="connection-add-activate" pid=1776 uid=1000 result="fail" reason="802-11-wireless-security.key-mgmt: Access point does not support PSK but setting requires it"
Apr 17 12:27:26 workstation NetworkManager[900]: <info> [1713349646.4014] audit: op="connection-add-activate" pid=1776 uid=1000 result="fail" reason="802-11-wireless-security.key-mgmt: Access point does not support PSK but setting requires it"
Apr 17 12:27:32 workstation NetworkManager[900]: <info> [1713349652.2236] audit: op="connection-add-activate" pid=1776 uid=1000 result="fail" reason="802-11-wireless-security.key-mgmt: Access point does not support PSK but setting requires it"

Revision history for this message
Dirk Rydvan (rydvan) wrote :

Just a update to a workaround to Freifunk "Access point does not support PSK but setting requires it".
It is a unecrypted wifi wlan. So PSK makes no sense with encryption type "none"

Here is the only working workaround:

root@bash# nmcli device wifi connect ffm.freifunk.net
Device 'wlp58s0' successfully activated with 'db.....2'.

Isaac True (itrue)
Changed in network-manager (Ubuntu):
status: Expired → New
Revision history for this message
Dirk Rydvan (rydvan) wrote :
Download full text (6.6 KiB)

Additional hint - the issue occurs with owe networks (https://en.wikipedia.org/wiki/Opportunistic_Wireless_Encryption)

bash$ nmcli dev wifi
IN-USE BSSID SSID MODE CHAN RATE SIGNAL BARS SECURITY
        DE:83:89:1B:D6:A8 ffm.freifunk.net Infra 1 130 Mbit/s 90 ▂▄▆█ OWE
        DE:83:89:1B:D6:AA owe.ffm.freifunk.net Infra 1 130 Mbit/s 90 ▂▄▆█ OWE

Here an example network wifi scan:

BSS xx:xx:xx:xx:d6:aa(on wlp58s0)
        last seen: 207.252s [boottime]
        TSF: 18034688076 usec (0d, 05:00:34)
        freq: 2412
        beacon interval: 100 TUs
        capability: ESS Privacy ShortPreamble ShortSlotTime RadioMeasure (0x1431)
        signal: -51.00 dBm
        last seen: 10296 ms ago
        SSID:
        Supported rates: 6.0* 9.0 12.0* 18.0 24.0* 36.0 48.0 54.0
        DS Parameter set: channel 1
        TIM: DTIM Count 1 DTIM Period 2 Bitmap Control 0x0 Bitmap[0] 0x0
        Country: DE Environment: Indoor/Outdoor
                Channels [1 - 13] @ 20 dBm
        ERP: <no flags>
        RSN: * Version: 1
                 * Group cipher: CCMP
                 * Pairwise ciphers: CCMP
                 * Authentication suites: OWE
                 * Capabilities: 16-PTKSA-RC 1-GTKSA-RC MFP-required MFP-capable (0x00cc)
        BSS Load:
                 * station count: 0
                 * channel utilisation: 23/255
                 * available admission capacity: 0 [*32us]
        RM enabled capabilities:
                Capabilities: 0x73 0x00 0x00 0x00 0x00
                        Link Measurement
                        Neighbor Report
                        Beacon Passive Measurement
                        Beacon Active Measurement
                        Beacon Table Measurement
                Nonoperating Channel Max Measurement Duration: 0
                Measurement Pilot Capability: 0
        Supported operating classes:
                 * current operating class: 81
        HT capabilities:
                Capabilities: 0x1ec
                        HT20
                        SM Power Save disabled
                        RX HT20 SGI
                        RX HT40 SGI
                        TX STBC
                        RX STBC 1-stream
                        Max AMSDU length: 3839 bytes
                        No DSSS/CCK HT40
                Maximum RX AMPDU length 65535 bytes (exponent: 0x003)
                Minimum RX AMPDU time spacing: No restriction (0x00)
                HT TX/RX MCS rate indexes supported: 0-15
        HT operation:
                 * primary channel: 1
                 * secondary channel offset: no secondary
                 * STA channel width: 20 MHz
                 * RIFS: 0
                 * HT protection: no
                 * non-GF present: 0
                 * OBSS non-GF present: 0
                 * dual beacon: 0
                 * dual CTS protection: 0
                 * STBC beacon: 0
                 * L-SIG TXOP Prot: 0
                 * PCO active: 0
                 * PCO phase: 0
        Extended capabilities:
                 * Extended Channel Switching...

Read more...

Revision history for this message
Dirk Rydvan (rydvan) wrote :

see Kubuntu Plasma Network Manager Bug:
https://bugs.kde.org/show_bug.cgi?id=486499

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Bug attachments

Remote bug watches

Bug watches keep track of this bug in other bug trackers.