Fast Transition FT(RRB): Failed to decrypt

Two Xiaomi access points, firmware 23.05.3
packages have been changed in the stock firmware
wpad-basic-mbedtls - removed
wpad-mesh-openssl - added
mesh11sd - installed for experiments, now disabled (service)

I configured fast roaming, but there is an error in the logs on both points:

Wed May 29 21:58:57 2024 daemon.err hostapd: FT(RRB): Failed to decrypt

Below are the settings at both points, the difference between them is only in two parameters:

option nasid
option r1_key_holder
Access Point 1
config wifi-iface 'default_radio1'
        option device 'radio1'
        option network 'lan'
        option mode 'ap'
        option ssid 'OpenWRT'
        option encryption 'psk2'
        option key '1234pass'
        option ieee80211r '1'
        option nasid '28D127BDBEF4'
        option mobility_domain '1981'
        option ft_over_ds '1'
        option ft_psk_generate_local '0'
        option r1_key_holder '28D127BDBEF4'
        option pmk_r1_push '1'
        list r0kh '28:D1:27:BD:BE:F4,28D127BDBEF4,b6702eb078ee3d6ee8684e4aee96ffff'
        list r0kh '44:DF:65:9E:1E:E9,44DF659E1EE9,b6702eb078ee3d6ee8684e4aee96ffff'
        list r1kh '28:D1:27:BD:BE:F4,28:D1:27:BD:BE:F4,b6702eb078ee3d6ee8684e4aee96ffff'
        list r1kh '44:DF:65:9E:1E:E9,44:DF:65:9E:1E:E9,b6702eb078ee3d6ee8684e4aee96ffff'
Access Point 2
config wifi-iface 'default_radio1'
        option device 'radio1'
        option network 'lan'
        option mode 'ap'
        option ssid 'OpenWRT'
        option encryption 'psk2'
        option key '1234pass'
        option ieee80211r '1'
        option nasid '44DF659E1EE9'
        option mobility_domain '1981'
        option ft_over_ds '1'
        option ft_psk_generate_local '0'
        option r1_key_holder '44DF659E1EE9'
        option pmk_r1_push '1'
        list r0kh '28:D1:27:BD:BE:F4,28D127BDBEF4,b6702eb078ee3d6ee8684e4aee96ffff'
        list r0kh '44:DF:65:9E:1E:E9,44DF659E1EE9,b6702eb078ee3d6ee8684e4aee96ffff'
        list r1kh '28:D1:27:BD:BE:F4,28:D1:27:BD:BE:F4,b6702eb078ee3d6ee8684e4aee96ffff'
        list r1kh '44:DF:65:9E:1E:E9,44:DF:65:9E:1E:E9,b6702eb078ee3d6ee8684e4aee96ffff'

Tried hostapd-full, or whatever it's called?

Enabled the option
ft_psk_generate_local = 1
I walked with my phone between these access points and another error appeared
Wed May 29 23:25:11 2024 daemon.err hostapd: nl80211: kernel reports: key addition failed

There is no requirement in the descriptions to install the full hostapd package (full), now installed:

root@OpenWrt:~# opkg list_installed |grep hostap
hostapd-common - 2023-09-08-e5ccbfc6-6

I know, but I wasn't sure of the name of the one between default (mini?) and full ,)

Just disable FT?

A unique offer, I just need to set this up, but do you suggest turning it off?

Uniquely disable it, and change one option a day to add it back. You need 11R checkbox, config ota, and same mobility domain and whole crypto-quackery just works.