+
+def test_ap_ft_r1_key_expiration(dev, apdev):
+ """WPA2-PSK-FT and PMK-R1 expiration"""
+ ssid = "test-ft"
+ passphrase = "12345678"
+
+ params = ft_params1(ssid=ssid, passphrase=passphrase)
+ params['r1_max_key_lifetime'] = "2"
+ hapd0 = hostapd.add_ap(apdev[0], params)
+ params = ft_params2(ssid=ssid, passphrase=passphrase)
+ params['r1_max_key_lifetime'] = "2"
+ hapd1 = hostapd.add_ap(apdev[1], params)
+
+ # This succeeds, but results in having to run another PMK-R1 pull before the
+ # second AP can complete FT protocol.
+ run_roams(dev[0], apdev, hapd0, hapd1, ssid, passphrase, wait_before_roam=4)
+
+def test_ap_ft_r0_key_expiration(dev, apdev):
+ """WPA2-PSK-FT and PMK-R0 expiration"""
+ ssid = "test-ft"
+ passphrase = "12345678"
+
+ params = ft_params1(ssid=ssid, passphrase=passphrase)
+ params['ft_r0_key_lifetime'] = "2"
+ hapd0 = hostapd.add_ap(apdev[0], params)
+ params = ft_params2(ssid=ssid, passphrase=passphrase)
+ params['ft_r0_key_lifetime'] = "2"
+ hapd1 = hostapd.add_ap(apdev[1], params)
+
+ bssid2 = run_roams(dev[0], apdev, hapd0, hapd1, ssid, passphrase,
+ return_after_initial=True)
+ time.sleep(4)
+ dev[0].scan_for_bss(bssid2, freq="2412")
+ if "OK" not in dev[0].request("ROAM " + bssid2):
+ raise Exception("ROAM failed")
+ ev = dev[0].wait_event(["CTRL-EVENT-CONNECTED",
+ "CTRL-EVENT-AUTH-REJECT",
+ "CTRL-EVENT-ASSOC-REJECT"], timeout=5)
+ dev[0].request("DISCONNECT")
+ if ev is None or "CTRL-EVENT-AUTH-REJECT" not in ev:
+ raise Exception("FT protocol failure not reported")
+ if "status_code=53" not in ev:
+ raise Exception("Unexpected status in FT protocol failure: " + ev)
+
+ # Generate a new PMK-R0
+ dev[0].dump_monitor()
+ dev[0].request("RECONNECT")
+ dev[0].wait_connected()