Passpoint® Specification v3.2
© 2020 Wi-Fi Alliance. All Rights Reserved.
Used with the permission of Wi-Fi Alliance under the terms as stated in this document.
Page 4 of 202
6 MOBILE DEVICE PROCEDURES ............................................................................................................................. 50
6.1 Discovery state procedures ........................................................................................................................ 50
6.1.1 Home SP identification and connecting to Home SP hotspot ........................................................ 50
6.1.2 Mobile device support for user preferences ................................................................................... 51
6.1.3 Venue Information .......................................................................................................................... 51
6.2 Registration state procedures ..................................................................................................................... 52
6.3 Provisioning state procedures ..................................................................................................................... 52
6.4 Access state procedures ............................................................................................................................. 52
6.4.1 Subscription expiry ......................................................................................................................... 53
6.4.2 Expiry of the subscription update timer .......................................................................................... 53
6.4.3 Expiry of the policy update timer .................................................................................................... 53
6.4.4 EAP authentication failure .............................................................................................................. 53
6.4.5 Association failure .......................................................................................................................... 53
6.4.6 Acceptance of Legal Requirements ............................................................................................... 54
6.4.7 Advice of charge ............................................................................................................................ 54
6.5 Filtering frames encrypted using the GTK .................................................................................................. 54
6.6 Roaming Consortium membership ............................................................................................................. 54
6.7 Protection of ANQP response information .................................................................................................. 54
7 ONLINE SIGN UP AND CERTIFICATE MANAGEMENT .......................................................................................... 55
7.1 Overview and goals ..................................................................................................................................... 55
7.2 Trust model ................................................................................................................................................. 56
7.3 Public key certificate types .......................................................................................................................... 56
7.3.1 Certificate Authority trust root certificates ...................................................................................... 56
7.3.2 OSU server certificate .................................................................................................................... 57
7.3.3 AAA server certificate..................................................................................................................... 58
7.3.4 AAA server certificate used with WFA Anonymous EAP-TLS ....................................................... 59
7.3.5 Subscription remediation server certificate .................................................................................... 60
7.3.6 Policy server certificate .................................................................................................................. 61
7.4 Message overview for online sign up .......................................................................................................... 61
7.5 OSU operational requirements ................................................................................................................... 63
7.6 Certificate enrollment and provisioning ....................................................................................................... 64
7.6.1 Simple PKI enrollment using EST .................................................................................................. 64
7.6.2 Restricted use of Passpoint client certificate ................................................................................. 65
7.6.3 Processing of mobile device credentials ........................................................................................ 65
7.6.4 Certificate enrollment message flow .............................................................................................. 65
7.7 Anonymous EAP-TLS ................................................................................................................................. 67
8 SUBSCRIPTION PROVISIONING ............................................................................................................................. 68
8.1 Overview ..................................................................................................................................................... 68
8.1.1 Subscription access restrictions ..................................................................................................... 69
8.1.2 Subscription credential provisioning options .................................................................................. 69
8.1.3 Subscription remediation ............................................................................................................... 70
8.1.4 Subscription management web content ......................................................................................... 71
8.1.5 Policy provisioning and update ...................................................................................................... 71
8.2 Mobile device management tree ................................................................................................................. 72
8.3 Provisioning using OMA DM ....................................................................................................................... 74
8.3.1 Overview ........................................................................................................................................ 74
8.3.2 Subscription provisioning ............................................................................................................... 74
8.3.3 Subscription management ............................................................................................................. 80
8.3.4 Policy provisioning ......................................................................................................................... 87
8.4 Provisioning using SOAP XML ................................................................................................................... 90
8.4.1 Overview ........................................................................................................................................ 90
8.4.2 Subscription provisioning ............................................................................................................... 92
8.4.3 Subscription management ............................................................................................................. 99
8.4.4 Policy provisioning ....................................................................................................................... 109
8.5 Provisioning of a mobile device that has a SIM card ................................................................................ 112
8.5.1 Initial subscription metadata and policy provisioning using OMA DM ......................................... 112
8.5.2 Initial subscription metadata and policy provisioning using SOAP XML ...................................... 114