Skip to content

nimble/host: add BLE_SM_SEC_REQ_AUTO_PAIR - #2287

Open
tonywestonuk wants to merge 1 commit into
apache:masterfrom
tonywestonuk:sm-sec-req-auto-pair
Open

nimble/host: add BLE_SM_SEC_REQ_AUTO_PAIR#2287
tonywestonuk wants to merge 1 commit into
apache:masterfrom
tonywestonuk:sm-sec-req-auto-pair

Conversation

@tonywestonuk

Copy link
Copy Markdown

When a peer sends a Security Request and no keys are stored for it, the host immediately replies with a Pairing Request from inside ble_sm_sec_req_rx(). Some peripherals (e.g. the Okida OT-2000 BLE module used in older Glen Dimplex/Stoves ovens) send a Security Request as soon as the connection is established and do not respond to a Pairing Request sent that early; pairing then times out. The same devices pair fine when the central initiates pairing a moment later, which the Core Spec allows (Vol 3, Part H, 2.4.6: the central may initiate pairing in response to a Security Request, it is not required to).

Add a syscfg setting BLE_SM_SEC_REQ_AUTO_PAIR (default 1, stock behaviour) mirrored in ble_hs_cfg.sm_sec_req_auto_pair. When cleared, a Security Request from a peer with no stored keys is accepted but no Pairing Request is sent; the application initiates pairing itself with ble_gap_security_initiate(). Store errors other than BLE_HS_ENOENT are still propagated. Peers with stored keys are unaffected.

When a peer sends a Security Request and no keys are stored for it, the
host immediately replies with a Pairing Request from inside
ble_sm_sec_req_rx(). Some peripherals (e.g. the Okida OT-2000 BLE module
used in older Glen Dimplex/Stoves ovens) send a Security Request as soon
as the connection is established and do not respond to a Pairing Request
sent that early; pairing then times out. The same devices pair fine when
the central initiates pairing a moment later, which the Core Spec allows
(Vol 3, Part H, 2.4.6: the central may initiate pairing in response to a
Security Request, it is not required to).

Add a syscfg setting BLE_SM_SEC_REQ_AUTO_PAIR (default 1, stock
behaviour) mirrored in ble_hs_cfg.sm_sec_req_auto_pair. When cleared, a
Security Request from a peer with no stored keys is accepted but no
Pairing Request is sent; the application initiates pairing itself with
ble_gap_security_initiate(). Store errors other than BLE_HS_ENOENT are
still propagated. Peers with stored keys are unaffected.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant