hci_send_cmd(conn->hdev, HCI_OP_AUTH_REQUESTED,
                             sizeof(cp), &cp);
 
-               /* If we're already encrypted set the REAUTH_PEND flag,
-                * otherwise set the ENCRYPT_PEND.
+               /* Set the ENCRYPT_PEND to trigger encryption after
+                * authentication.
                 */
-               if (test_bit(HCI_CONN_ENCRYPT, &conn->flags))
-                       set_bit(HCI_CONN_REAUTH_PEND, &conn->flags);
-               else
+               if (!test_bit(HCI_CONN_ENCRYPT, &conn->flags))
                        set_bit(HCI_CONN_ENCRYPT_PEND, &conn->flags);
        }
 
 
 
        if (!ev->status) {
                clear_bit(HCI_CONN_AUTH_FAILURE, &conn->flags);
-
-               if (!hci_conn_ssp_enabled(conn) &&
-                   test_bit(HCI_CONN_REAUTH_PEND, &conn->flags)) {
-                       bt_dev_info(hdev, "re-auth of legacy device is not possible.");
-               } else {
-                       set_bit(HCI_CONN_AUTH, &conn->flags);
-                       conn->sec_level = conn->pending_sec_level;
-               }
+               set_bit(HCI_CONN_AUTH, &conn->flags);
+               conn->sec_level = conn->pending_sec_level;
        } else {
                if (ev->status == HCI_ERROR_PIN_OR_KEY_MISSING)
                        set_bit(HCI_CONN_AUTH_FAILURE, &conn->flags);
        }
 
        clear_bit(HCI_CONN_AUTH_PEND, &conn->flags);
-       clear_bit(HCI_CONN_REAUTH_PEND, &conn->flags);
 
        if (conn->state == BT_CONFIG) {
                if (!ev->status && hci_conn_ssp_enabled(conn)) {