Symptoms & scope
- A visible SSID repeatedly asks for a password or disconnects during authentication.
- The supplicant reports a four-way handshake or EAP failure before DHCP begins.
Relevant environment
NetworkManager Wi-Fi profiles using wpa_supplicant; iwd backends report different events, and enterprise settings depend on the network administrator.
Recognizable messages (synthetic examples)
wpa_supplicant[810]: wlan0: WPA: 4-Way Handshake failed - pre-shared key may be incorrectVerify the profile and credential, but also inspect preceding key-installation or radio failures before concluding that the password is wrong.
wpa_supplicant[810]: wlan0: CTRL-EVENT-EAP-FAILURE EAP authentication failedRead the preceding method and certificate events; this signal does not distinguish an account denial from a TLS validation problem.
Possible causes
These are possible explanations, not a confirmed diagnosis. Several independent faults can coexist.
- A personal-network handshake can fail with mismatched credentials, incompatible security mode or lower-level key installation/radio trouble; the password hint is not conclusive.
- An EAP failure can involve identity, method, account policy, certificate validation or the authentication server; earlier EAP/TLS details are needed.
Diagnose safely
Run one command at a time in the relevant session. Read the explanation first. Uppercase placeholders need your own values; tools and privileges vary by distribution. These commands are displayed here and never executed by the website.
Check 1
Read current-boot authentication events; journal access may require privileges. Retain preceding TLS, key-installation and association events and redact SSIDs or identities before sharing.
journalctl -b -u NetworkManager -u wpa_supplicant --no-pager -n 250Interpret the result: EAP failure belongs to enterprise authentication. A four-way handshake password hint also follows some driver failures; ip-config errors after completed authentication belong to address acquisition.
Check 2
Replace PROFILE with the exact saved connection name. Inspect SSID and security methods without --show-secrets; this does not expose the stored password.
nmcli -f 802-11-wireless.ssid,802-11-wireless-security.key-mgmt,802-11-wireless-security.pmf,802-1x.eap connection show "PROFILE"Interpret the result: Compare the profile with the actual AP policy: WPA-PSK, SAE and WPA-EAP are different methods. A missing 802-1x method is expected for a personal network.
Evidence-guided next steps
Correct the personal-network profile
If a personal network’s verified credentials or security mode differ from the saved profile, edit that specific profile in the desktop connection editor and re-enter the credential through its secure prompt. Compare one connection attempt while keeping driver errors in view.
Precautions: Keep the previous profile settings and use a local console when editing the only link. Do not place a password in command history or weaken the AP to open/WEP to suppress the symptom.
Recovery / rollback: Restore the saved SSID and security mode if the edit targets the wrong network; recover through Ethernet or the prior working profile.
Did this solution help you?
Repair the documented EAP configuration
If EAP or TLS details identify the enterprise path, compare method, inner authentication, CA certificate and server-name constraint with the administrator’s current profile. Correct an expired client certificate or incorrect system time only when those checks support it.
Precautions: Keep server certificate validation enabled and obtain credentials/certificates through the approved channel. Repeated blind retries can trigger account lockout.
Recovery / rollback: Restore the saved enterprise profile and certificate references if the new configuration fails; use a known working access path to contact the network administrator.
Did this solution help you?
References & review
This guide was prepared from primary project or distribution sources and reviewed on the date shown. This is an editorial source check, not evidence that a fix was reproduced on your hardware. Diagnostic log examples are synthetic fixtures. Version-dependent details must be checked against your installed release.
- NetworkManager: Wi-Fi authentication properties (project or distribution documentation)
- NetworkManager: nmcli queries, profiles and checkpoints (project or distribution documentation)
- wpa_supplicant: documented control-interface events (project or distribution documentation)
- Android source: wpa_supplicant handshake failure handling (upstream implementation; behavior can vary by version)