I was reading through the answers of the question "How can I ensure that I connect to the right wireless Access Point?" and was wondering how it is possible for an access point to imitate another wifi network assuming I use WPA2.
I read the wikipedia article and it looks like that the PMK (Pairwise Master Key) is never actually send over the network. Also, the client station sends a Nonce to the access point, which the access point concatenates with the PMK and hashes to produce an authentication. How could an impostor produce a valid authentication without knowing the PMK?
What am I missing?
EDIT: I read a little further through the comments and it seems like I can only fake a wireless access point, if I actually have the PMK. Can somebody confirm, that I have the right idea?