Explains the OKC technique that allows wireless clients and the WLAN infrastructure to cache only one PMK for client association with a WLAN.
Opportunistic Key Caching (OKC) is an enhancement of the WPA2 Pairwise Master Key ID (PMKID) caching method that
-
allows wireless clients and the WLAN infrastructure to cache only one PMK for client association with a WLAN, even when roaming between multiple APs
-
enables APs to share the original PMK that is used for the WPA2 4-way handshake, and
-
works with WPA2-EAP as a fast roaming technique.
Key characteristics
OKC shares several characteristics with PMKID caching:
-
The initial association to an AP is a regular first-time authentication to the corresponding WLAN, where you must complete the entire 802.1X/EAP authentication for the authentication server, and the 4-way handshake for key generation, before sending data frames.
-
All APs share the original PMK from a client session under a centralized device that caches and distributes the original PMK to all the APs.
-
New encryption keys are generated every time a client reassociates with APs.
OKC support varies by client type:
-
Microsoft and some Android clients support OKC.
-
Apple and few Android clients support 802.11r as an alternative fast roaming method.
OKC configuration characteristics:
-
OKC is enabled by default on a WLAN.
-
Disabling OKC on a WLAN disables the OKC even for the OKC-supported clients.
-
A new configuration is introduced for each WLAN in the controller in Cisco IOS XE Amsterdam 17.2.1, to disable or enable fast and secure roaming with OKC at the corresponding AP.