TDLS: Reject TPK-TK reconfiguration

Do not try to reconfigure the same TPK-TK to the driver after it has
been successfully configured. This is an explicit check to avoid issues
related to resetting the TX/RX packet number. There was already a check
for this for TPK M2 (retries of that message are ignored completely), so
that behavior does not get modified.

For TPK M3, the TPK-TK could have been reconfigured, but that was
followed by immediate teardown of the link due to an issue in updating
the STA entry. Furthermore, for TDLS with any real security (i.e.,
ignoring open/WEP), the TPK message exchange is protected on the AP path
and simple replay attacks are not feasible.

As an additional corner case, make sure the local nonce gets updated if
the peer uses a very unlikely "random nonce" of all zeros.

Bug: 65245581
Test: Wifi Integration Suite
Change-Id: Ic94024e8a3bf8f24c77224b4960315b5f8512fc1
Merged-In: Ic94024e8a3bf8f24c77224b4960315b5f8512fc1
Signed-off-by: Jouni Malinen <>
Signed-off-by: Glen Kuhne <>
1 file changed