Re: Is there a way to manually force the security protocol with IWD?

Bryce Johnson <[email protected]> Fri, 30 Jan 2026 08:01:59 -0700
Newsgroups dev.linux.lists.iwd
Message-ID <CADXxVS+_B2r0yAUKKD5X_xJ6GmfkfkngwW_XHQyti=+9cMmzqg@mail.gmail.com>
Hi James

On Fri, Jan 30, 2026 at 7:48 AM James Prestwood <[email protected]> wrote:
>
> Hi Bryce,
>
> On 1/30/26 6:43 AM, Bryce Johnson wrote:
> > Hi All
> > We are working to get our product through wifi certification.  Our
> > testing company mentioned there was several negative test cases that
> > were failing where IWD was connecting anyways because it would decide
> > on the security type based on the AP.  Is there a way to force IWD to
> > use a security type that is different than the AP so it would fail the
> > connection?  Can we disable WPA1-only connection or force WPA2 only
> > connection?
>
> There unfortunately isn't at the moment. We do have a "developer mode"
> by specifying "-E" to IWD and this seems like it would fall into that
> category, support would need to be added of course.
>
> But I'm somewhat confused (and maybe this is just poor test cases by
> WFA?), why would you need to certify that IWD fails when using a
> different security type than the AP? A client should not ever use a
> security type the AP doesn't advertise support for... This feels like
> its testing the AP, not IWD :)
>

I'm was requesting what test case fails and if I could get a copy of
it.  The only thing I can think of is that they want to disable WPA1
for example and show that the device won't connect to a WPA1 only AP.
Or maybe for a product you only want to connect WPA3 and fail and not
connect or not allow the AP to downgrade the connection.

Maybe it would make sense to allow a blacklist of protocols you won't
allow IWD to use?  For our product we wouldn't allow open or WEP
connections for example (but we perform that check outside of IWD).

> >
> > Thanks
> > Bryce
> >