cp.handle = cpu_to_le16(conn->handle);
                hci_send_cmd(conn->hdev, HCI_OP_AUTH_REQUESTED,
                                                        sizeof(cp), &cp);
+               if (conn->key_type != 0xff)
+                       set_bit(HCI_CONN_REAUTH_PEND, &conn->pend);
        }
 
        return 0;
 
        conn = hci_conn_hash_lookup_handle(hdev, __le16_to_cpu(ev->handle));
        if (conn) {
                if (!ev->status) {
-                       conn->link_mode |= HCI_LM_AUTH;
-                       conn->sec_level = conn->pending_sec_level;
+                       if (!(conn->ssp_mode > 0 && hdev->ssp_mode > 0) &&
+                                               test_bit(HCI_CONN_REAUTH_PEND,
+                                               &conn->pend)) {
+                               BT_INFO("re-auth of legacy device is not"
+                                                               "possible.");
+                       } else {
+                               conn->link_mode |= HCI_LM_AUTH;
+                               conn->sec_level = conn->pending_sec_level;
+                       }
                } else {
                        mgmt_auth_failed(hdev->id, &conn->dst, ev->status);
                }
 
                clear_bit(HCI_CONN_AUTH_PEND, &conn->pend);
+               clear_bit(HCI_CONN_REAUTH_PEND, &conn->pend);
 
                if (conn->state == BT_CONFIG) {
                        if (!ev->status && hdev->ssp_mode > 0 &&