<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://devzone.nordicsemi.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>pairing fail with ncs 2.8.0</title><link>https://devzone.nordicsemi.com/f/nordic-q-a/117338/pairing-fail-with-ncs-2-8-0</link><description>hello Nordic 
 we are working with nrf52832 and nrf 52840 .. migrated to ncs2.7.0 lately and now migrating to ncs 2.8.0 (at the moment building without sysbuild) 
 we did not change anything in the pairing mechanism but suddenly it seems to stop working</description><dc:language>en-US</dc:language><generator>Telligent Community 13</generator><lastBuildDate>Fri, 31 Jan 2025 14:09:08 GMT</lastBuildDate><atom:link rel="self" type="application/rss+xml" href="https://devzone.nordicsemi.com/f/nordic-q-a/117338/pairing-fail-with-ncs-2-8-0" /><item><title>RE: pairing fail with ncs 2.8.0</title><link>https://devzone.nordicsemi.com/thread/520898?ContentTypeID=1</link><pubDate>Fri, 31 Jan 2025 14:09:08 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:a9731d9b-7a0c-4c8f-9d50-0fddb45d0141</guid><dc:creator>Einar Thorsrud</dc:creator><description>&lt;p&gt;Hi&amp;nbsp;Ziv,&lt;/p&gt;
&lt;p&gt;I am not sure I understand the question. By keys I assume you mean the key related to the pairing/bonding? Secrutiy in BLE is handled by the&amp;nbsp;Security Management Protocol.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: pairing fail with ncs 2.8.0</title><link>https://devzone.nordicsemi.com/thread/520643?ContentTypeID=1</link><pubDate>Thu, 30 Jan 2025 06:34:20 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:341f71ab-cbbb-4370-b658-45464043045c</guid><dc:creator>ziv123</dc:creator><description>&lt;p&gt;hi Einar&lt;/p&gt;
&lt;p&gt;as suggested here the issue on the ncs side is the attempt to work with mcumgr befor pairing was completed .. though it is strange to me..&amp;nbsp;&lt;/p&gt;
&lt;p&gt;in what layer/protocol/service the keys should pass between 2 sides to achieve the completion of the pairing before starting to use the smp service /mcumgr ?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;if authentication must occur before working with mcumgr then, how the keys are passed ?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;hope to read you soon&lt;/p&gt;
&lt;p&gt;best regards&lt;/p&gt;
&lt;p&gt;Ziv&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: pairing fail with ncs 2.8.0</title><link>https://devzone.nordicsemi.com/thread/518960?ContentTypeID=1</link><pubDate>Sun, 19 Jan 2025 10:14:44 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:dd44b369-faac-4ada-941d-f71ee5416417</guid><dc:creator>GalBrandwine</dc:creator><description>&lt;p&gt;Hey, I&amp;#39;ve worked on the same problem. I found the issue:&lt;/p&gt;
&lt;p&gt;the client tried to access MCUMGR&amp;nbsp;BT Transport&amp;nbsp;before it was authenticated.&lt;/p&gt;
&lt;p&gt;Hence the LL dropped the connection.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Adding `CONFIG_MCUMGR_TRANSPORT_BT_PERM_RW=y` solved the issue.&lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: pairing fail with ncs 2.8.0</title><link>https://devzone.nordicsemi.com/thread/517990?ContentTypeID=1</link><pubDate>Fri, 10 Jan 2025 15:19:23 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:4536fe9b-4e20-4dfc-8acd-68e1c98b5692</guid><dc:creator>Einar Thorsrud</dc:creator><description>&lt;p&gt;I see. Would it be possible to make sniffer traces of each case so that we can see what happens on air? It could also be interesting to compare those with traces from 2.7 so that we can see what has changed (if any). Hopefully this can point to where to look next.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: pairing fail with ncs 2.8.0</title><link>https://devzone.nordicsemi.com/thread/517527?ContentTypeID=1</link><pubDate>Wed, 08 Jan 2025 15:20:50 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:5b29afb5-afdd-48e3-b4d5-85cad2bb27cd</guid><dc:creator>ziv123</dc:creator><description>[quote userid="7377" url="~/f/nordic-q-a/117338/pairing-fail-with-ncs-2-8-0/517429"]or does it also vary with the same peer device[/quote]
&lt;p&gt;each peer device give the same type of error all the time.. the difference is between different peer devices&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: pairing fail with ncs 2.8.0</title><link>https://devzone.nordicsemi.com/thread/517429?ContentTypeID=1</link><pubDate>Wed, 08 Jan 2025 10:17:54 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:bfb91d05-a653-4a48-913b-3df1662ea4e5</guid><dc:creator>Einar Thorsrud</dc:creator><description>&lt;p&gt;Hi Ziv,&lt;/p&gt;
&lt;p&gt;I understand that this issue appeared after migrating to v2.8.0, but I am not ablet o see any changes that obviously explan this. It is interesting that you get different failures with didfferent error codes. Does it depend on the peer device, or does it also vary with the same peer device? Or is there another pattern here?&amp;nbsp; Are you able to share logs and sniffer traces for some of the specific error codes, so that we can understand more about what happened?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: pairing fail with ncs 2.8.0</title><link>https://devzone.nordicsemi.com/thread/515985?ContentTypeID=1</link><pubDate>Fri, 20 Dec 2024 16:46:55 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:19906542-d685-4af2-8734-222bf35aba37</guid><dc:creator>ziv123</dc:creator><description>&lt;p&gt;Hi Einar&lt;/p&gt;
&lt;p&gt;well debugging is a bit tricky i have another thread open on that and some one suggested allowing local ip ports but from hat i see this is not the issue, i will elaborate on the relevant thread if i manage to solve the issue...&lt;/p&gt;
&lt;p&gt;back to our issue .. i actually got the&amp;nbsp;&lt;span&gt;BT_SECURITY_ERR_UNSPECIFIED by checking with a tool on my laptop that is running the same app as my node devices, and i actually see different results for each device i am attempting to pair with.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;with the tool running on my laptop i get&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;i don&amp;#39;t even get the first pairing completed callback, i get right on start&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;code&gt;bt_smp: pairing failed (peer reason 0xc)&lt;/code&gt;&amp;nbsp;, followed by pairing_failed callback with error&amp;nbsp;&amp;nbsp;&lt;/span&gt;BT_SECURITY_ERR_AUTH_FAIL&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;with one type of node (ble 4.2)&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;i get the callback for pairing completed followed by the &amp;quot;.security_changed&amp;quot; callback with status&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;div&gt;
&lt;div&gt;&lt;span&gt;BT_SECURITY_L2. which looks like it actually working, though i did not see the first &amp;quot;.security_changed&amp;quot; callback which i usually see.&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;&lt;span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;&lt;span&gt;and another node with (ble 5.0) and i think the ble device is actually nrf52840&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;i get &amp;#39;pairing_completed&amp;#39; call back&amp;nbsp;&lt;/span&gt;&lt;span&gt;followed by the initial error i posted (seems the extra config did not solve the issue ) -&amp;gt;&amp;nbsp;&lt;/span&gt;&lt;code&gt;&lt;span&gt;bt_smp: pairing failed (peer reason 0x3) ,&amp;nbsp;&lt;/span&gt;&lt;/code&gt;followed by the &amp;quot;.security_changed&amp;quot; callback giving error&amp;nbsp;&amp;nbsp;&lt;span&gt;BT_SECURITY_ERR_AUTH_REQUIREMENT.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;code&gt;&lt;span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;just to be clear i do not try to connect with all of them at the same time, with each device i did several pairing attempts without the noise of other devices and those were the results&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;regarding the debug the one time it did run i did not get to the break point on the&amp;nbsp;BT_SECURITY_ERR_UNSPECIFIED, which is reasonable since we got different types of errors&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;any ideas ?&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;do i see different results cause of different ble stacks ? or there is something else&lt;/span&gt;&lt;/p&gt;
[quote userid="7377" url="~/f/nordic-q-a/117338/pairing-fail-with-ncs-2-8-0/515662"]No, there has not been significant changes on this part. But this is a common issue that we often see when testing[/quote]
&lt;p&gt;&lt;span&gt;i will point again that before migrating to v2.7.0 and 2.8.0 we did not have an issue with pairing to each one of those node types.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;hope to read you soon&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;best regards&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Ziv&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: pairing fail with ncs 2.8.0</title><link>https://devzone.nordicsemi.com/thread/515662?ContentTypeID=1</link><pubDate>Thu, 19 Dec 2024 08:58:26 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:8497be8c-f8aa-4080-beaf-64179c6425d4</guid><dc:creator>Einar Thorsrud</dc:creator><description>&lt;p&gt;Hi Ziv,&lt;/p&gt;
[quote user="ziv123"].. so by deleting the bond it will mean that the key generation will take place in every connection ?&amp;nbsp;[/quote]
&lt;p&gt;I should have specified better. You can only bond once with the same peer. If allready bonded, the bonding information (key etc) is re-used every time. However, if the peer device lost the bonding information for some reason (typically a user deleted it on a phone or similar), the old bond information is no longer valid. In this case, bonding again is not allowed, as a bond allready exist. I am wondering if that is what has happened here? If so, and i fyou want to allow bondign again even if a bond exist (to gracefully handle the case where the peer device no longer has the bond), you need to explicitly allow it.&lt;/p&gt;
[quote user="ziv123"]can you elaborate a bit on why it is desired and in what ,example ,case can this be undesired ?[/quote]
&lt;p&gt;For usability reasons, you often want to be able to bond again with a device you have an existing bond with, if the bond has been deleted (deliberately or not) on that device without explicitly deletign that bond first. For many products this is in practice a requierment. However, this also opens up the possability that an attacker can spoof the address of another device and replace it&amp;#39;s bond, which is why it is not allowed by default.&lt;/p&gt;
[quote user="ziv123"]&lt;p&gt;and also is this something that was added or changed in ncs 2.7.0 or 2.8.0 that cause this issue to arise for us now ?&lt;/p&gt;
&lt;p&gt;and last but not least .. when added the configs you mentioned to prj.conf i get a different err from my callback implementation for pairing failed -&amp;gt; reason is BT_SECURITY_ERR_UNSPECIFIED .. any ideas what i am doing wrong ?&lt;/p&gt;[/quote]
&lt;p&gt;No, there has not been significant changes on this part. But this is a common issue that we often see when testing, if a bond is deleted during that process. But it seems you are seeing a different issue.&lt;/p&gt;
&lt;p&gt;Can you debug and see where exactly the&amp;nbsp;BT_SECURITY_ERR_UNSPECIFIED comes from? It is not much used, so a simple way to do it could be to set a breakpoint on all lines with &amp;quot;&lt;code&gt;return BT_SECURITY_ERR_UNSPECIFIED;&lt;/code&gt;&amp;quot; in the code.&lt;/p&gt;
&lt;p&gt;Einar&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: pairing fail with ncs 2.8.0</title><link>https://devzone.nordicsemi.com/thread/515577?ContentTypeID=1</link><pubDate>Wed, 18 Dec 2024 17:58:03 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:c349a778-7399-4564-bea5-2812f40d4e7d</guid><dc:creator>ziv123</dc:creator><description>&lt;p&gt;Hi Einar&lt;/p&gt;
[quote userid="7377" url="~/f/nordic-q-a/117338/pairing-fail-with-ncs-2-8-0/515459"]f there is allready an existing bond with the peer? If so, the bond needs to be deleted[/quote]
&lt;p&gt;not sure i follow, because we pair once and then save the generated keys in flash for next pairing,&amp;nbsp; &lt;span&gt;not to go through the process every time.&amp;nbsp;&lt;/span&gt;i don&amp;#39;t think we deliberately unpair, and we do not use multiple ble identities (.. the only scenario that could be is that a device connects with 2 different nodes and has to pair with each one separately and another scenario that is not yet active is pairing with 2 different adaptores on the same node).&lt;/p&gt;
&lt;p&gt;.. so by deleting the bond it will mean that the key generation will take place in every connection ?&amp;nbsp;&lt;/p&gt;
[quote userid="7377" url="~/f/nordic-q-a/117338/pairing-fail-with-ncs-2-8-0/515459"]which is often the desiered behaviour, but not always.[/quote]
&lt;p&gt;can you elaborate a bit on why it is desired and in what ,example ,case can this be undesired ?&lt;/p&gt;
&lt;p&gt;and also is this something that was added or changed in ncs 2.7.0 or 2.8.0 that cause this issue to arise for us now ?&lt;/p&gt;
&lt;p&gt;and last but not least .. when added the configs you mentioned to prj.conf i get a different err from my callback implementation for pairing failed -&amp;gt; reason is BT_SECURITY_ERR_UNSPECIFIED .. any ideas what i am doing wrong ?&lt;/p&gt;
&lt;p&gt;hope to read you soon&lt;/p&gt;
&lt;p&gt;best regards&lt;/p&gt;
&lt;p&gt;Ziv&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: pairing fail with ncs 2.8.0</title><link>https://devzone.nordicsemi.com/thread/515459?ContentTypeID=1</link><pubDate>Wed, 18 Dec 2024 11:54:32 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:fde2959d-8ffc-4592-9d7f-72d82ffb1ff6</guid><dc:creator>Einar Thorsrud</dc:creator><description>&lt;p&gt;Hi Ziv,&lt;/p&gt;
&lt;p&gt;Ah, yes - I missed that. As you get&amp;nbsp;BT_SECURITY_ERR_AUTH_REQUIREMENT I wonder if there is allready an existing bond with the peer? If so, the bond needs to be deleted, or you need to allow re-pairing by adding&amp;nbsp;&lt;code&gt;CONFIG_BT_SMP_ALLOW_UNAUTH_OVERWRITE=y&lt;/code&gt; and&amp;nbsp;&lt;code&gt;CONFIG_BT_ID_UNPAIR_MATCHING_BONDS=y&lt;/code&gt;. This means that bonds can be replaced without specific actions, which is often the desiered behaviour, but not always.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: pairing fail with ncs 2.8.0</title><link>https://devzone.nordicsemi.com/thread/515351?ContentTypeID=1</link><pubDate>Tue, 17 Dec 2024 22:07:45 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:7cadd832-05ad-4af2-a923-5ea9aed4b67a</guid><dc:creator>ziv123</dc:creator><description>&lt;p&gt;Hi Einar&lt;/p&gt;
[quote userid="7377" url="~/f/nordic-q-a/117338/pairing-fail-with-ncs-2-8-0/515289"]I assume the reason you print is an bt_security_err instance (which you get in the pairing_failed callback)[/quote]
&lt;p&gt;in this callback i actually print reason 4 -&amp;gt;&amp;nbsp; BT_SECURITY_ERR_AUTH_REQUIREMENT (still wonder why, and now i know it also happens sometimes with ncs 2.7.0, but we did not had this issue before)&lt;/p&gt;
[quote userid="7377" url="~/f/nordic-q-a/117338/pairing-fail-with-ncs-2-8-0/515289"]That is not an error I would expect unless you are doing OOB pairing?[/quote]
&lt;p&gt;we are not doing out of band pair.&lt;/p&gt;
&lt;p&gt;the peer reason 3 is a print that exist in the ncs itself&amp;nbsp;&lt;/p&gt;
&lt;p&gt;(v2.8.0/zephyr/subsys/bluetooth/host/smp.c , line 1299 and/or line 3811&lt;/p&gt;
&lt;p&gt;&lt;span&gt;(v2.7.0/zephyr/subsys/bluetooth/host/smp.c , line 1236 and/or line 3733&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;any idea what this &amp;#39;3&amp;#39; error is or why i get&amp;nbsp; BT_SECURITY_ERR_AUTH_REQUIREMENT ?&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;hope to read you soon&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;best regards&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;Ziv&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: pairing fail with ncs 2.8.0</title><link>https://devzone.nordicsemi.com/thread/515289?ContentTypeID=1</link><pubDate>Tue, 17 Dec 2024 14:26:56 GMT</pubDate><guid isPermaLink="false">137ad170-7792-4731-bb38-c0d22fbe4515:4f201223-68db-40ee-9ad7-513e80313d75</guid><dc:creator>Einar Thorsrud</dc:creator><description>&lt;p&gt;Hi Ziv,&lt;/p&gt;
&lt;p&gt;I assume the reason you print is an bt_security_err instance (which you get in the pairing_failed callback). And then, reason 3 is&amp;nbsp;BT_SECURITY_ERR_OOB_NOT_AVAILABLE. That is not an error I would expect unless you are doing OOB pairing?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>